Skip to content
Forktail
Privacy Terms Help
Join the waitlist

Last updated July 13, 2026

Privacy, in plain language.

Forktail works with sensitive financial information, so this policy is intentionally specific. It explains what the current Forktail app and website collect, where information is processed, how it is used, and what you can control.

On this page

Scope What we collect How we use it Where it goes Retention Your choices Security Contact

1. Scope

This Privacy Policy applies to the Forktail iOS app, Forktail’s cloud services, the Forktail website, the early-access waitlist, and support communications. “Forktail,” “we,” “us,” and “our” refer to the operator of the Forktail service.

Two important promises: Forktail does not sell personal information, and Forktail does not use financial information for third-party advertising or cross-context behavioral advertising.

2. Information we collect and store

The exact information depends on the features you choose to use. Forktail does not require a connected financial account to visit the website or read these policies.

Category Examples When collected
Account and contact Email address, optional display name, Firebase user ID, authentication provider, email-verification status When you create or use a Forktail account
Connected financial data Institution and account names, account type, masked account number, balances, limits, transactions, merchant and category details, recurring-payment indicators, investment holdings, and transaction location when a provider supplies it When you authorize an account connection
Connection records Connection status, provider and institution identifiers, account identifiers, sync cursors, and encrypted provider access or refresh tokens While a financial connection remains active
Plans and preferences Responsibilities, goals, expected income, flexible-spending amounts, due dates, protection mode, category corrections, review decisions, alert rules, and notification preferences When you create, approve, or change a plan or setting
Advisor and insight data Questions, responses, generated insights, structured financial summaries, advisor profile and memory records, feedback on insights, and response-continuity identifiers When you use Forktail Advisor or insight features
Voice data An audio recording you intentionally send and the resulting transcript Only when you use the microphone button
Device and notifications Push-notification token, time zone, notification settings, app version, build number, device model, and iOS version When you enable notifications, sign in, or send feedback
Optional feedback Your message, optional screen capture, optional diagnostic logs, function names, call timing and status, sanitized error text, and chat-performance counts When you review and submit the in-app feedback form
Website waitlist Email address, selected product interests, source, and created/updated timestamps When you join or update your waitlist preferences

Your bank credentials

Forktail does not receive or store your bank username or password. Financial-account authentication happens through Plaid, Akoya, or the participating financial institution. Those providers may collect credentials or other information under their own terms. Forktail receives the financial data and connection tokens you authorize them to provide.

Information kept on your device

Forktail stores cached accounts and transactions, balance history, conversation history, interface preferences, category icons, and similar product state on your device using iOS storage such as Core Data and UserDefaults. Forktail stores your Forktail user ID and email in the iOS Keychain for session continuity. On-device information may also be included in an iCloud or device backup depending on your Apple settings.

Website data

The Forktail marketing site does not use advertising cookies or analytics trackers. Like most internet services, hosting and infrastructure providers may automatically process request information such as IP address, browser type, requested page, and time for delivery, security, and operational logging. Forktail’s waitlist record itself does not store your IP address or browser fingerprint.

3. How we use information

  • Authenticate you, maintain your account, and keep your data associated with the correct user.
  • Connect and refresh financial accounts, import transactions, and show current balances.
  • Calculate Safe to Spend, cash forecasts, money plans, spending summaries, subscriptions, and other requested features.
  • Generate personalized Advisor responses and verified insights from the financial context you ask Forktail to use.
  • Deliver alerts, weekly recaps, connection-status messages, and other notifications you enable.
  • Remember your preferences, corrections, approvals, and prior context so Forktail becomes more useful over time.
  • Respond to feedback, troubleshoot failures, protect the service, prevent abuse, and meet legal obligations.
  • Send launch and product emails to waitlist members who asked to receive them.

4. Service providers and where information goes

Forktail shares information only as needed to provide the service, when you direct us, to protect rights and security, or when law requires it. Current service providers and data paths include:

  • Google Firebase and Google Cloud for authentication, databases, file storage, cloud functions, and push-notification infrastructure. See Firebase Privacy and Security.
  • Plaid for permissioned financial-account connections and financial data. See Plaid’s End User Privacy Policy.
  • Akoya for supported direct institution connections. See Akoya’s Privacy Policy.
  • OpenAI for Advisor responses, generated insights, and voice transcription. Prompts may include the question you ask, recent conversation context, and relevant financial summaries, accounts, or transactions. Advisor requests normally route through Forktail’s cloud service; some early-access builds may send the request from the device to OpenAI’s API. OpenAI states that API data is not used to train its models by default unless the customer opts in. See OpenAI API data controls.
  • Apple for iOS distribution, device services, and Apple Push Notification service.
  • Resend or SendGrid when configured to deliver an optional feedback report to Forktail support.
  • Vercel to host and deliver the public website and account-connection return pages.

Forktail may disclose information to comply with a valid legal process; investigate fraud, abuse, or security incidents; protect users or the public; or as part of a merger, financing, acquisition, reorganization, or sale of assets. If ownership changes, this policy continues to apply to the transferred information unless users are notified of a change.

5. Retention and deletion

We retain information for as long as reasonably needed to provide the feature, maintain security and records, resolve disputes, and meet legal obligations. In practice:

  • Account, financial, plan, and insight data generally remains while your Forktail account or related feature is active.
  • Disconnecting a financial institution stops future access and removes its active connection token and connection-specific transaction records from Forktail’s primary system. Derived summaries, operational records, and backups may take additional time to expire or be deleted.
  • Conversation history stored by the app remains on your device until you delete it, clear the app’s data, or uninstall the app. Relevant Advisor context or generated insights stored in the cloud follow the account-retention period.
  • Voice audio is forwarded for transcription and is not intentionally saved to Forktail’s database. The transcript may become part of your conversation. OpenAI may retain API data temporarily under its published API data controls.
  • Feedback reports, including any screenshot or logs you choose to include, are kept as needed to investigate and resolve the report and maintain security records.
  • Waitlist information remains until you unsubscribe, ask us to remove it, or the waitlist is no longer needed.
  • Backups and security logs may persist for a limited period after primary records are deleted.

To request deletion of your Forktail account or personal information, email maazali40@gmail.com from the address associated with your account. We may need to verify your identity before completing the request.

6. Your choices and controls

  • Financial connections: disconnect an institution from Forktail’s Settings or revoke access through Plaid, Akoya, or your financial institution where supported.
  • Notifications: adjust Forktail notification settings in the app and iOS Settings.
  • Voice: do not use the microphone feature, or revoke microphone permission in iOS Settings.
  • Feedback: turn off the optional screenshot or logs before sending a feedback report.
  • Conversations: delete individual Forktail Advisor messages or conversations in the app where available.
  • Waitlist email: use the unsubscribe link in a message or email support to be removed.
  • Access, correction, or deletion: contact us using the address below. Depending on where you live, you may have additional privacy rights and the right to appeal a denied request.

Forktail does not discriminate against people for exercising applicable privacy rights.

7. Security

Forktail uses safeguards designed for the sensitivity of financial information, including TLS-encrypted network transport, Firebase authentication and user-scoped access controls, restricted backend access to feedback records, and device-level protections provided by iOS. Plaid and Akoya connection tokens stored by Forktail are encrypted using AES-256-GCM.

No system is perfectly secure. Keep your device and Forktail password protected, use a unique password, and contact us if you believe your account or information has been compromised.

8. Children

Forktail is intended for adults age 18 and older. We do not knowingly collect personal information from children. If you believe a child has provided personal information to Forktail, contact us so we can investigate and delete it.

9. Processing in the United States

Forktail and its service providers may process information in the United States and other locations where they operate. Data-protection laws in those locations may differ from the laws where you live.

10. Changes to this policy

We may update this policy as Forktail changes. We will post the revised policy here and update the date at the top. If a change materially affects how we use information already collected, we will provide additional notice when appropriate.

11. Contact

For privacy questions, access requests, corrections, deletion requests, or appeals, email maazali40@gmail.com. Please do not include bank credentials, full account numbers, or other unnecessary sensitive information in email.

© 2026 Forktail. All rights reserved.

Terms · Help · Home