Bord

Privacy Policy

Last updated July 8, 2026

The product needs your financial data to be useful. It does not need an ad-targeting layer. This page is the long version of that distinction.

The short version

Bord collects what it needs to make the voices useful: your financial data through Plaid, your account info, and your subscription state. It collects nothing for ad targeting. We don't sell your data, we don't broker it, and we don't feed it to the voice models as training. You can delete all of it from Settings, or by emailing the address at the bottom.

Everything below is that paragraph, spelled out in full.

What we collect

Identity. Clerk handles sign-in. When you sign up, it stores your email, your name if you give one, and any social logins you connect. We get your Clerk user ID and a few basic profile fields and attach them to your Bord account.

Financial data, through Plaid. If you link a bank or brokerage, Plaid hands us a per-account access token and the data that account exposes: transactions, balances, holdings, and account metadata, for the accounts you authorize and no others. We encrypt the access token at rest with AES-256-GCM. The financial data itself lives in our database, scoped to your account ID and protected by row-level security.

Subscription and payment. Stripe processes payments. Your card number never touches Bord; Stripe holds it. We keep your Stripe customer ID, your subscription details (plan, status, renewal date), and your invoice history.

Application activity. We log what the service needs to run: which feed events fired, which voice posts were generated, which posts you liked or replied to, and what each voice call cost. We keep enough of it to catch abuse, debug problems, and make the product better.

Product analytics. We use PostHog to count things, like how many people finish onboarding, or which feature gets tapped. It records product events only. It is not an ad pixel, and none of it goes to an ad network.

Error tracing. We use Sentry to catch server errors. A Sentry event may carry the URL and Clerk ID of the request that failed. It does not carry the request body, or the personal data that request was moving.

What we don't collect

No ad-tracking pixels, anywhere on this site. No Facebook Pixel, no Google Ads tag, no TikTok Pixel, no programmatic-advertising cookie.

No data bought about you. Outside the Plaid link you start yourself, we don't ask third parties for extra information, and we don't buy demographic, behavioral, or marketing data from brokers.

No mining your messages or composer posts to target ads, sell, broker, or train advertising models. We read them to run the service, and for nothing else.

How we use what we collect

To run the product. The voices need your financial data to have anything to say about it. Your subscription sets your tier.

To keep it working. Logs and analytics tell us when something breaks, why, how fast the service is running, and what to build next.

To hold up the rules. Rate-limit counters, webhook dedup state, and security events (failed logins, replay attempts) exist to enforce our Terms of Service.

To reach you. Trial-ending reminders, failed-payment notices, the occasional product note. You can opt out of the non-essential email. Billing and security email you can't, for obvious reasons.

AI / voice model providers

The voices run on large language models from outside providers: OpenAI, Anthropic, Google, xAI, and Groq. Which one answers depends on which voice is talking, and the roster changes over time. When a voice replies, we send its provider a structured prompt built from de-identified facts about your money, like “savings rate is 18% over the trailing 30 days” or “largest holding is 18% of the portfolio.” We do not send your name, your account numbers, raw transaction descriptions, or anything that identifies another person.

Where a provider offers a train-on-this setting, we keep it off. Our agreements limit them to answering the one request we sent, and nothing beyond it.

If you'd rather none of your data reach a model provider, disconnect Plaid. With no data, the voices have nothing to react to. You can also delete your account outright; see “Your rights” below.

Who we share data with

We share data with the providers that run parts of Bord: Clerk (sign-in), Plaid (account linking), Stripe (payments), Supabase (our database), Vercel (hosting), the model providers (OpenAI, Anthropic, Google, xAI, Groq), PostHog (product analytics), and Sentry (error tracing). Each one sees only what its job requires. None may use your data for their own marketing, ad targeting, or resale.

We do not share data with advertisers, ad networks, or data brokers. At all.

We will hand over data when the law makes us (a subpoena, court order, or lawful regulatory request), as part of a merger or sale of the business (and we'll tell you if that happens), or to protect the rights, property, or safety of Bord, our users, or the public.

Cookies and similar technologies

We set a small number of strictly-necessary cookies, mostly for sign-in (session cookies from Clerk) and CSRF protection, plus PostHog cookies for product analytics. We set no third-party advertising cookies.

We honor your browser's “Do Not Track.” When it's on, PostHog treats you as opted out, captures no product analytics, and writes no analytics state to your browser's local storage. The strictly-necessary sign-in cookies still load, or you can't log in.

Retention

Account data (your profile, subscription state, and linked-account references) is kept while your account exists.

Feed events, the structured records that drive the voices, are kept for 90 days, then a scheduled job prunes them. If you want a longer window for your own reasons, email us.

Voice posts and what you did with them (likes, replies) are kept while your account exists. Recap content is kept for the window the product shows it, plus a short buffer.

Payment records (invoices, charge history) are kept for at least seven years, because U.S. tax rules require it.

Logs and analytics rollups are kept for 12 months. Once the operational reason for holding them passes, the personal parts are removed or anonymized.

Your rights

Access. Your subscription, your linked accounts, and your profile are visible inside the app. For a full export of your account data, email the address at the bottom.

Correction. Most fields are editable in Settings. For anything you can't change yourself, email us.

Deletion. Delete your account from Settings → Account → Delete. That clears your profile, your Plaid connection (which fires a Plaid itemRemove on their end), your subscription, your feed events, your voice posts, and your interactions. A few records (billing history, and security logs tied to abuse or fraud) survive for the legal-retention windows above, with personal data stripped to the minimum.

Disconnect Plaid only. To keep your Bord account but stop sending us any further financial data, disconnect Plaid from Settings without deleting the account. We delete the access token and the financial history we had collected.

State privacy rights (California, Virginia, Colorado, and others). If you live in a U.S. state with a consumer-privacy law, your rights may include knowing what we've collected, asking us to delete it, correcting what's wrong, and opting out of certain processing. Email the address at the bottom, and we'll respond inside the window your state's law requires.

EU / UK GDPR. In the EEA or UK, you have rights of access, rectification, erasure, restriction, portability, and objection. We process your data on three lawful bases: contract (to provide the service), consent (where it applies), and legitimate interests (security, abuse prevention, product improvement). You can withdraw consent at any time by emailing the address at the bottom.

Security

We build on defensive defaults: webhook signatures verified on raw bytes, atomic database writes on sensitive paths, row-level security, Plaid access tokens encrypted at rest with AES-256-GCM, CSRF origin checks on anything that changes state, rate limits around authentication, and a content-security policy. No system is bulletproof. If you find a security hole, email the address at the bottom. We read those reports, and we act on them.

Children

Bord is not for anyone under 18. We do not knowingly collect data from minors, and if we learn that we have, we delete it. If you believe a minor has signed up, email the address at the bottom.

International transfers

Bord is operated from the United States. If you use it from outside the U.S., your data is transferred to and processed in the U.S. Our providers may process data in other jurisdictions; where that happens, we rely on standard contractual clauses and the providers' own legal frameworks.

Changes to this policy

We update this policy when things change. When we do, the new version goes up at /privacy and the “Last updated” date below moves. For a material change, like a new category of data or a new sharing relationship, we'll tell you in-app or by email. Keep using Bord after the effective date and you're accepting the update.

Contact

Privacy questions, data-rights requests, and security reports go to justineyoo2005@gmail.com. A person reads these. An auto-reply doesn't.