Privacy Policy

Last updated: July 22, 2026

1. Introduction

Cadus Labs LLC ("we," "our," or "us") operates the Cadus mobile application (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

We are committed to protecting your privacy and ensuring you have a positive experience using our expense tracking application.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Email address, name, and password when you create an account
  • Business Information: Business name, address, and tax identification for invoicing and tax reporting
  • Financial Data: Expense records, income records, receipt images, and transaction details you manually enter

2.2 Information Collected Automatically

  • Device Information: Device type, operating system, unique device identifiers
  • Diagnostic Data: App version information, crash reports, and diagnostic logs
  • Product Analytics: Pseudonymous account ID and coarse feature events such as onboarding completion, receipt saves, connection success, shares, paywall views, and subscriptions. We exclude exact financial amounts, email/vendor/bank names, document identifiers, and private URLs from analytics event parameters.
  • Notification Data: Push notification tokens and notification preferences when you enable notifications

2.3 Information from Third-Party Services

  • Bank Account Data (via Plaid): When you connect bank accounts, we receive transaction data including merchant names, amounts, dates, and categories. We do not store your bank login credentials.
  • Subscription Data (via RevenueCat): When you purchase or restore a subscription, we receive product identifiers, subscription status, renewal state, and expiration details.

3. Plaid Data Handling (Bank Connections)

We use Plaid Inc. to connect your bank accounts securely. When you connect an account:

  • Authentication: Your bank credentials are entered directly into Plaid's secure interface. We never see, receive, or store your bank username or password.
  • Data received: We receive transaction data (merchant name, amount, date, category), account balances, and account metadata.
  • Data storage: Transaction data is stored encrypted at rest using AES-256 encryption in our Supabase database.
  • Data in transit: All data transfers use TLS 1.3 encryption.
  • Access tokens: Plaid access tokens are stored securely and are revoked immediately when you disconnect an account.
  • Data deletion: When you disconnect a bank account, we revoke the connection. When you delete your Cadus account, we revoke every linked bank connection and delete associated active-system data unless a narrowly defined legal obligation requires retention.
  • No data selling: We never sell, rent, or share your financial data with third parties for marketing purposes.

Your use of Plaid is also subject to the Plaid End User Privacy Policy.

4. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our expense tracking services
  • Process and categorize your expenses automatically
  • Generate tax reports and financial summaries
  • Scan receipts and extract transaction data using AI/OCR technology
  • Create and send invoices on your behalf
  • Send you service updates and important notifications
  • Respond to your support requests
  • Measure privacy-safe product funnels and feature reliability
  • Detect and prevent fraud or abuse

5. Data Sharing and Disclosure

We do not sell your personal information. We may share your information with:

  • Service Providers: Third-party companies that help us provide user-facing services, including cloud hosting, payment processing, infrastructure monitoring, and email delivery.
  • Plaid: For bank account connections (governed by Plaid's privacy policy)
  • Firebase: For product analytics, crash reporting, and push notifications. Analytics receives a pseudonymous account ID, device/app information, and coarse feature events—not exact financial amounts or document, vendor, bank, or email identifiers.
  • RevenueCat: For subscription status, purchase validation, and entitlement management
  • Anthropic and OpenAI: When AI extraction is needed, receipt images may be processed solely to return bookkeeping data to the requesting user. Cadus does not use or permit this data for advertising or generalized AI-model training.
  • Legal Requirements: When required by law, court order, or government request
  • Business Transfers: In connection with a merger, acquisition, or sale of assets where legally permitted.

6. Data Security

We implement industry-standard security measures including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Secure authentication with encrypted password storage
  • Regular security audits and monitoring
  • Limited employee access to personal data
  • Row-level security ensuring users can only access their own data

7. Data Retention and Disposal

Cadus follows deletion by default and retention by exception. We keep personal data only while it is needed to provide the Service or for a documented legal, security, fraud-prevention, or dispute-resolution purpose.

Account deletion

  • Active account data: Authentication records, profile and business information, imported bank data, user-created financial records, receipts and other uploads are deleted through the verified account-deletion workflow.
  • Connections and processors: We revoke linked bank and sign-in access and request deletion of associated data from applicable service providers. If a provider is still processing or temporarily unavailable, we report deletion as processing—not completed—and continue the same request.
  • Device data: The app clears the deleted account's session, notification token, preferences, offline caches, and locally controllable provider state from the device used to delete the account. If a provider SDK cannot safely erase its local identifier without creating or reassigning an account, Cadus blocks further SDK use for that identifier instead.
  • Completion: We begin immediately and ordinarily complete active-system deletion while the request is processed. Ordinary provider cleanup is targeted within 30 days. If funds, payouts, chargebacks, or another financial settlement are still active, normal app access is locked and the deletion remains pending until those records can be reconciled safely; the same request then resumes automatically. Unresolved cleanup is escalated for review after 30 days. A settlement, legal hold, or provider's processing or legally required retention period may take longer, and we report the request as processing until final deletion is complete.

Limited retention exceptions

We do not use retained exception data to operate a deleted account, personalize the Service, or market to you. It is access-restricted, minimized where possible, and deleted when its retention period ends.

  • Deletion and security records: A minimal, pseudonymous record needed to prove completion, prevent restoration, investigate abuse, or protect the Service may be retained for up to 2 years.
  • Email safety records: A minimal suppression record may remain to honor an unsubscribe, spam complaint, or hard bounce and prevent unwanted or unsafe delivery. It is not used as an active profile or to resume marketing.
  • Infrastructure logs: Short-lived, access-restricted operational and security logs may remain until normal log rotation or a documented incident hold ends. They are not used to restore or operate a deleted account.
  • Disputes, fraud, and legal holds: Relevant records may be retained only for the life of the matter and any legally required limitation period, then deleted.
  • Payment or tax records: Cadus retains only the fields needed to complete an open transaction, meet a named statutory recordkeeping duty, or resolve an active dispute or legal hold. Each retained category has a documented start event and deletion criterion; we do not apply a blanket retention period to all user financial data.
  • Shared and counterparty records: A record another user must retain, such as a finalized payment or shared project fact, may remain for that user. We detach the deleted account and remove or anonymize its profile and contact details.
  • Service-provider records: Payment processors and financial institutions may independently retain regulated transaction records under their legal obligations. Those records are not available as an active Cadus account.

Backups

Deleted data may remain temporarily in encrypted, access-restricted disaster-recovery backups that are not used for ordinary business operations. Each copy is deleted or overwritten when its backup generation ages out of the configured disaster-recovery rotation. If a backup is restored, deletion records are reapplied before the restored system returns to service so a deleted account is not resurrected.

8. Your Rights

Depending on your location, you may have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your data
  • Export your data in a portable format
  • Opt out of certain data processing
  • Withdraw consent for optional features, including disabling product analytics in the mobile app under Settings → Privacy

To exercise these rights, use our account deletion page or contact us at support@cadus.app.

9. Children's Privacy

Our Service is not intended for users under 18 years of age. We do not knowingly collect personal information from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy, please contact us:

  • Email: support@cadus.app
  • Mailing Address: Cadus Labs LLC, 8 The Green, Suite A, Dover, DE 19901