Privacy Policy
Effective 16 September 2026
Simpl Finance MCP is operated by Simpl Finances LLC ("we", "us"). This policy explains what we collect, why, and what we do not do. It applies to simplfinancemcp.com and the Simpl Finance MCP connector.
The short version
- We never receive or store your bank username or password.
- We do not store your transactions. They are fetched from your bank when your AI asks, and passed straight back.
- Access is read-only. Nothing we operate can move money.
- We do not sell your data, and we do not use it for advertising.
- You can disconnect a bank or delete your account at any time.
What we collect
Account information
Your email address, and either a hashed password or a Google account identifier if you sign in with Google. Passwords are hashed with bcrypt and cannot be reversed.
Bank connection information
When you connect a bank through Plaid, we receive and store an access token, encrypted at rest. We also store the institution's name, the last four digits of the account, and the connection's status and timestamps — enough to show you what is connected and whether it is working.
We do not store your transactions, balances, or account numbers. When your AI assistant asks a question, we request that data from Plaid, return it to your assistant, and keep no copy.
Usage records
We log every request your AI assistant makes: which tool it called, when, whether it succeeded, and how long it took. This is what lets you see what your assistant has been asking for, and it is how we detect abuse and faults. You can view this in your dashboard.
Billing information
Payments are handled by Stripe. We store your Stripe customer identifier and subscription status. We never see or store your card details.
How your bank connection works
We use Plaid to connect to financial institutions. When you link an account, you enter your credentials directly with Plaid — they never pass through our servers and we never see them.
By connecting an account you also agree to Plaid's End User Privacy Policy, which governs how Plaid handles the data it collects on your behalf.
We request read-only access to transactions and account information. We do not request, and could not use, permission to initiate payments or transfers.
What your AI assistant can see
When you connect Simpl Finance MCP to an AI assistant, that assistant can request your transactions, balances, account list, and spending by category. It receives that data directly in your conversation.
The assistant's provider — Anthropic, OpenAI, or whoever operates it — will handle that data under their own privacy policy, not ours. We have no control over what they retain. Review their terms before connecting, and disconnect if you are not comfortable with them.
Your assistant never receives your bank credentials or the access token that reads your account. It receives only the answer to what it asked.
Who we share data with
We share data only with the services required to operate the product:
- Plaid — bank connections and financial data retrieval
- Stripe — payment processing and subscription management
- Google Cloud and Supabase — hosting and database infrastructure
- Google — only if you choose to sign in with Google
We do not sell your personal information. We do not share it with advertisers or data brokers. We may disclose information if required by law, and we will tell you unless legally prevented.
Security
- Bank access tokens are encrypted at rest.
- Your connector token is stored only as a cryptographic hash and shown to you once.
- All traffic is encrypted in transit over HTTPS.
- Each account's data is accessible only to that account.
- Requests are rate limited, and every request is logged.
No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, please write to us before disclosing it publicly.
How long we keep things
Account information, bank connection records and usage logs are kept while your account is open. When you delete your account, all of it is deleted — including your usage history — and we revoke your bank connections with Plaid and cancel your subscription. Stripe retains payment records independently, as required for financial recordkeeping.
Your choices
- See what is connected — your dashboard lists every linked account.
- See what was asked — your dashboard shows your assistant's request history.
- Disconnect a bank — at any time, from the app. We revoke the token with Plaid.
- Revoke an assistant's access — regenerate your connector token, which invalidates the old one immediately.
- Delete your account — from Settings. This is immediate and cannot be undone.
- Request a copy of your data — write to us and we will provide it.
Depending on where you live you may have additional rights under laws such as the CCPA or GDPR. Contact us and we will honour them.
Children
Simpl Finance MCP is not intended for anyone under 18, and we do not knowingly collect information from children.
Changes
If we change this policy materially we will email you before the change takes effect. The effective date above always reflects the current version.
Contact
Simpl Finances LLC — support@simplfinancemcp.com