Privacy Policy
Last updated September 10, 2026
The product needs your financial data to be useful. It does not need an ad-targeting layer. This page is the long version of that distinction.
The short version
Bord collects what it needs to provide financial answers: your financial data through Plaid, your account info, and your subscription state. It collects nothing for ad targeting. We don't sell your data, we don't broker it, and we don't feed it to the AI models as training. You can delete all of it from Settings, or by emailing the address at the bottom.
Everything below is that paragraph, spelled out in full.
The data controller is Bord LLC, a North Carolina limited liability company, which operates the bordmoney.com and bord.money domains and publishes the Bord iOS application. “Bord”, “we”, “us”, and “our” below mean Bord LLC.
What we collect
Identity. Clerk handles sign-in. When you sign up, it stores your email, your name if you give one, and any social logins you connect. We get your Clerk user ID and a few basic profile fields and attach them to your Bord account.
Financial data, through Plaid. If you link a bank or brokerage, Plaid hands us a per-account access token and the data that account exposes: transactions, balances, holdings, and account metadata, for the accounts you authorize and no others. We encrypt the access token at rest with AES-256-GCM. The financial data itself lives in our database, scoped to your account ID and protected by row-level security.
Receipts in your email, through Composio, only if you connect Gmail. The connection runs through Composio, a provider that holds the Google login on Bord's behalf, so Google's consent screen names Composio, not Bord. The permission Google grants Composio's app is its full Gmail permission, the one Google describes as the ability to read, compose, send, and permanently delete mail, because that is the only permission Google allows that app to request. On its own, Bord only reads, and it never receives the Google token. Bord searches your recent mail for receipts, renewal notices, and refunds, and keeps only a pointer to each such message (its Gmail message id), the sender's domain, the merchant, the kind of message, the amount and date on it, and the charge it explains. It does not keep the subject, the body, or attachments; a message is read in memory and dropped. We also keep the email address of the connected inbox, shown to you shortened.
Mail Bord sends or tidies for you, only when you ask. By text or on the Connections page you can ask Bord to send an email, reply to one in your inbox, or archive, trash, or label mail from a sender. Bord shows you the exact mail (to, subject, and body) or the exact count first, and does nothing until you say yes; a reaction or a vague word does not count. We keep the mails Bord sent for you (to, subject, body, and Gmail's id for the sent message) as your own outbound record, and the ids of mail it archived, trashed, or labeled. A reply is drafted from the mail it answers, which is read in memory and not kept. Nothing is sent, moved, or deleted without your yes.
Subscription and payment. Stripe processes payments. Your card number never touches Bord; Stripe holds it. We keep your Stripe customer ID, your subscription details (plan, status, renewal date), and your invoice history.
Application activity. We log what the service needs to run: which feed events fired, which posts were generated, which posts you replied to, and what each model call cost. We keep enough of it to catch abuse, debug problems, and make the product better.
Product analytics. We use PostHog to count things, like how many people finish onboarding, or which feature gets tapped. It records product events only. It is not an ad pixel, and none of it goes to an ad network.
Error tracing. We use Sentry to catch errors, both on our servers and in your browser. A Sentry event may carry the address of the page or request that failed, with the query string removed, and your Clerk ID. Before anything is sent we strip request bodies, cookies, and authorization headers, and we redact dollar figures and long digit runs from error text. We do not send console logs, the labels on buttons you tap, or any recording of your screen or session.
What we don't collect
No ad-tracking pixels, anywhere on this site. No Facebook Pixel, no Google Ads tag, no TikTok Pixel, no programmatic-advertising cookie.
No data bought about you. Outside the Plaid link you start yourself, we don't ask third parties for extra information, and we don't buy demographic, behavioral, or marketing data from brokers.
No mining your messages or composer posts to target ads, sell, broker, or train advertising models. We read them to run the service, and for nothing else.
How we use what we collect
To run the product. Bord uses your financial data to answer questions about it. Your subscription sets your tier.
To keep it working. Logs and analytics tell us when something breaks, why, how fast the service is running, and what to build next.
To hold up the rules. Rate-limit counters, webhook dedup state, and security events (failed logins, replay attempts) exist to enforce our Terms of Service.
To reach you. Trial-ending reminders, failed-payment notices, the occasional product note. You can opt out of the non-essential email. Billing and security email you can't, for obvious reasons.
AI model providers
Bord runs on large language models from outside providers: OpenAI, Anthropic, Google, xAI, and Groq. The model used to answer can change over time. When Bord replies, we send its provider a structured prompt built from de-identified facts about your money, like “savings rate is 18% over the trailing 30 days” or “largest holding is 18% of the portfolio.” Apart from the one case in the next paragraph, we do not send your name, your account numbers, raw transaction descriptions, or anything that identifies another person.
The exception is a photo you choose to send. If you text Bord a picture of a receipt, bill or invoice, that image is sent to a model provider to be read, and an image can carry things a structured prompt never would, including your name as it is printed on the receipt and the last four digits of a card. We do not keep the image or its link. We do keep what was read from it, the amounts and the line-item names, alongside that conversation, so a follow-up question can refer back to it. Code, not the model, checks the arithmetic. If you would rather this never happen, do not send photos: nothing else in Bord sends an image to a provider.
A voice note works the same way and carries the same trade. If you send Bord a recording, the audio is sent to a model provider to be transcribed, and a recording carries your voice, which identifies you in a way a structured prompt never does. We do not keep the audio. We do keep the transcript alongside that conversation, so a follow-up question can refer back to it. If you would rather this never happen, do not send voice notes.
Where a provider offers a train-on-this setting, we keep it off. Our agreements limit them to answering the one request we sent, and nothing beyond it.
If you'd rather none of your data reach a model provider, disconnect Plaid. Bord will no longer receive new financial data from that connection. You can also delete your account outright; see “Your rights” below.
Text messages
When you text Bord, we store the phone number or messaging identifier you texted from, the messages exchanged, and whether you have asked us to stop. We keep the record of a STOP so that we can honour it.
Delivery runs through an outside messaging provider, which necessarily handles the contents of those messages on the way. Messages can include figures drawn from the accounts you have connected, so treat the thread the way you would any other place your balances appear, and remember that anyone who can read your phone can read it.
If you tell Bord someone's Venmo handle or Cash App cashtag so it can make you a payment link, we store that handle with the name you gave it, and a record of each link we composed (who, how much, when). We never receive or store your own Venmo or Cash App login, and we learn nothing about whether a payment was made. Text "forget <name>" to delete a saved handle.
If you enable bank transfers, Natural collects and verifies your identity and bank details directly; Bord never receives, stores or transmits them. Bord stores that you connected, the limit you set, the phone or email you gave for each person you pay, and a record of each transfer you asked for and its status. Text "disconnect natural" to end the connection; Natural keeps its own records under its policy.
Reply STOP at any time to stop receiving messages, or HELP for help.
Who we share data with
We share data with the providers that run parts of Bord: Clerk (sign-in), Plaid (account linking), Composio (the Gmail connection, if you make one), Stripe (payments), Supabase (our database), Vercel (hosting), the model providers (OpenAI, Anthropic, Google, xAI, Groq), PostHog (product analytics), and Sentry (error tracing). Each one sees only what its job requires. None may use your data for their own marketing, ad targeting, or resale.
Composio is different from the others in one way worth stating plainly: it holds your Google grant, and the grant is Google's full Gmail permission. Bord reads through it on its own and writes through it only on your yes, as described above. Composio's own privacy policy governs how it holds that grant. Removing Gmail in Bord deletes the connection at Composio and everything Bord kept from your mail; you can also revoke Composio's access at any time from your Google Account's third-party connections page.
We do not share data with advertisers, ad networks, or data brokers. At all.
We will hand over data when the law makes us (a subpoena, court order, or lawful regulatory request), as part of a merger or sale of the business (and we'll tell you if that happens), or to protect the rights, property, or safety of Bord, our users, or the public.
Cookies and similar technologies
We set a small number of strictly-necessary cookies, mostly for sign-in (session cookies from Clerk) and CSRF protection, plus PostHog cookies for product analytics. We set no third-party advertising cookies.
We honor your browser's “Do Not Track.” When it's on, PostHog treats you as opted out, captures no product analytics, and writes no analytics state to your browser's local storage. The strictly-necessary sign-in cookies still load, or you can't log in.
Retention
Account data (your profile, subscription state, and linked-account references) is kept while your account exists.
Feed events, the structured records that drive financial commentary, are kept for 90 days, then a scheduled job prunes them. If you want a longer window for your own reasons, email us.
Posts and your interactions with them (including historical likes and replies) are kept while your account exists. Recap content is kept for the window the product shows it, plus a short buffer.
Payment records (invoices, charge history) are kept for at least seven years, because U.S. tax rules require it.
Logs and analytics rollups are kept for 12 months. Once the operational reason for holding them passes, the personal parts are removed or anonymized.
Your rights
Access. Your subscription, your linked accounts, and your profile are visible inside the app. For a full export of your account data, email the address at the bottom.
Correction. Most fields are editable in Settings. For anything you can't change yourself, email us.
Deletion. Delete your account from Settings → Account → Delete. That clears your profile, your Plaid connection (which fires a Plaid itemRemove on their end), your subscription, your feed events, your posts, and your interactions. A few records (billing history, and security logs tied to abuse or fraud) survive for the legal-retention windows above, with personal data stripped to the minimum.
Disconnect Plaid only. To keep your Bord account but stop sending us any further financial data, disconnect Plaid from Settings without deleting the account. We delete the access token and the financial history we had collected.
Remove Gmail only. To keep your Bord account but end the email connection, remove Gmail from Connections. We delete the connection at Composio and every record we kept from your mail. Deleting your account does the same.
State privacy rights (California, Virginia, Colorado, and others). If you live in a U.S. state with a consumer-privacy law, your rights may include knowing what we've collected, asking us to delete it, correcting what's wrong, and opting out of certain processing. Email the address at the bottom, and we'll respond inside the window your state's law requires.
EU / UK GDPR. In the EEA or UK, you have rights of access, rectification, erasure, restriction, portability, and objection. We process your data on three lawful bases: contract (to provide the service), consent (where it applies), and legitimate interests (security, abuse prevention, product improvement). You can withdraw consent at any time by emailing the address at the bottom.
Security
We build on defensive defaults: webhook signatures verified on raw bytes, atomic database writes on sensitive paths, row-level security, Plaid access tokens encrypted at rest with AES-256-GCM, CSRF origin checks on anything that changes state, rate limits around authentication, and a content-security policy. No system is bulletproof. If you find a security hole, email the address at the bottom. We read those reports, and we act on them.
Children
Bord is not for anyone under 18. We do not knowingly collect data from minors, and if we learn that we have, we delete it. If you believe a minor has signed up, email the address at the bottom.
International transfers
Bord is operated from the United States. If you use it from outside the U.S., your data is transferred to and processed in the U.S. Our providers may process data in other jurisdictions; where that happens, we rely on standard contractual clauses and the providers' own legal frameworks.
Changes to this policy
We update this policy when things change. When we do, the new version goes up at /privacy and the “Last updated” date below moves. For a material change, like a new category of data or a new sharing relationship, we'll tell you in-app or by email. Keep using Bord after the effective date and you're accepting the update.
Contact
Privacy questions, data-rights requests, and security reports go to justineyoo2005@gmail.com. A person reads these. An auto-reply doesn't.