Softkeep privacy
For people who use Softkeep · Updated Sep 23, 2026 · Softkeep is the app; Penny is the quiet voice inside it
Why we need any of this
Softkeep is a household money app. It needs enough of your money picture to keep one leftover number honest — what’s left after bills, what’s due, what you told it about your situation. Without that, it would be guessing. Penny is the quiet voice inside Softkeep you can talk to; she uses the same books.
What we access
If you connect a bank (optional)
- You sign in on your bank’s own screen through Plaid. Softkeep never sees your bank password.
- We request Plaid’s Transactions product only. That syncs transactions and also lets us read balances (accounts/balance, including a live-balance path).
- We do not use Plaid Transfer — Softkeep cannot move money through Plaid.
- We do not use Plaid Auth today — we do not pull account/routing numbers that way.
When you chat (with Penny)
- What you type goes to Anthropic’s API so Softkeep can understand it.
- For money questions Softkeep also sends the labels and numbers needed to answer (bill names, debt names, pay you track, a short stretch of recent chat) — not a dump of your whole life.
Voice (where it exists)
- On the native / phone API path, spoken replies can go through ElevenLabs (text-to-speech). That is not on the hosted Dad/tester box today (no /speak on host).
- The short in-app privacy note emphasizes Anthropic + Plaid; this page names ElevenLabs so nothing is hidden.
What we do not access
- Your bank password
- Ability to send money from your bank via Plaid
- Contacts, photos, or unrelated phone data
What we store
Your household books, which may include:
- Bills and debts you added
- Transactions and balances (if a bank is linked)
- Pay / household labels and situation notes
- Chat history
- A Plaid access token when linked (refreshes bank data — not your password)
- Derived money state Softkeep computes from the above (including Living / Foundation / emergency cushion tags)
Service secrets (Anthropic, Plaid client keys, AWS/KMS, alert email) live in protected config — not in your books. Native phone builds may also hold ElevenLabs config; the hosted box does not run that voice path today.
How it is stored
- Hosted (Dad / testers): household books on the Softkeep host disk as AWS KMS envelopes, served over HTTPS. Households isolated; wrong household → 403.
- Nightly backups: ciphertext to Amazon S3. Everyday backup credentials are write-oriented (put new backups; not meant to wipe the trail). Roll off on a ~30-day cycle.
- Greg desktop / native: local books with encryption on where that path is used; offsite desktop backup scripts strip the Plaid token so that copy isn’t a live bank key.
Why each piece is kept
| Data | Why |
|---|---|
| Bills, debts, income, notes | So leftover and “what’s due” are about your household |
| Balances / transactions | So the picture stays fresh without typing every number |
| Plaid token | Refresh bank data without logging in every time |
| Chat history | Remember the thread you’re in |
| Encrypted backups | A dead disk shouldn’t erase the books |
Who else can see something
| Who | What | Why |
|---|---|---|
| Plaid | Bank link; transactions + balances you approve | Bank connection |
| Anthropic | Chat + money labels / recent messages needed to answer | Understanding & replies |
| Amazon Web Services | KMS key use, encrypted books, S3 backups | Host, storage, encryption |
| ElevenLabs | Text sent for spoken voice (native/API path only today) | Text-to-speech |
| Us (operators) | We don’t read balances/debts as a habit. Fixing a wrong number may mean looking at that number — and we say when we do. | Support only |
We do not sell your data.
Consent — you choose
We only keep your data with your consent. You should be able to say yes (or no) in plain language before Softkeep holds household books or connects a bank.
- Before a bank link: Softkeep shows a short privacy note, then you choose to continue on Plaid’s screen (or cancel). Connecting is optional.
- Using the app: Creating / using a household means you agree we may store the books described above (bills, debts, chat, and bank data if you link) so Softkeep can do its job — under the commitments on this page.
- You can withdraw: ask us to delete your data (live app within 7 days; backups age out in roughly 30 days). Stop using Softkeep anytime; bank link can be removed without wiping everything if you only want to disconnect the bank.
- Kids / someone else’s money: only connect accounts and enter books you have the right to manage.
If consent is missing, unclear, or can’t be recorded for a new user path, that path should not collect data until consent is fixed — that is a product rule, not fine print.
Your choices (hosted commitments — live in app)
- Bank link is optional.
- Ask anytime: “what happens to my data” (source of truth in the app).
- Delete: ask us — gone from the live app within 7 days; backups age out in roughly 30 days.
- If you go quiet: we currently keep books about 12 months; email ~30 days before delete.
- Breach: we tell you within 72 hours of confirming it.
What this is not
- Not “bank certified” or third-party audited.
- Not a full GDPR/CCPA pack for strangers worldwide yet (lawyer before opening beyond people we know).
- Not a claim that every product money-gate is finished shipping.
- Not financial advice — Softkeep prepares numbers; you decide. Softkeep is not a licensed advisor.
Questions: tell Greg, or penny-crew@agentmail.to
Softkeep · privacy statement · updated Sep 23, 2026
In-app source of truth: ask “what happens to my data.”