RichFish
Privacy Policy
Effective: June 5, 2026
RichFish ("RichFish," "we," "us") is a personal financial dashboard operated by Nate Richards & Amy Fisher. This policy explains what information the application collects, how we use it, and the choices available to you.
Information we collect
- Identity & account information — when you sign in with Google, we receive your name and email address to create and secure your account.
- Financial information via Plaid — with your authorization, we use Plaid to connect to your financial institutions and retrieve account balances, transactions, investment holdings, and liabilities (such as credit-card due dates and statement balances).
- Information you provide — gross income figures you enter, and content you create such as goals, notes, transaction tags, and weekly check-in records.
How we use your information
We use it solely to operate the dashboard for you: displaying balances and net worth, categorizing and reviewing transactions, tracking investments and contributions, calculating shared-expense splits, surfacing upcoming payments, tracking goals, and answering questions you ask about your own data.
Plaid
We use Plaid Inc. to connect to your financial accounts. By using RichFish you also agree to Plaid's End User Privacy Policy (available at plaid.com/legal). Plaid's handling of your data is governed by that policy.
The "Ask" feature
When you ask a question in natural language, relevant financial context from your account is sent to a third-party AI provider to generate an answer. We send only what is needed to answer your question and do not use it for advertising.
How we share information
We do not sell your personal information, and we do not share it for advertising. We share data only with the service providers that make the app work, acting on our behalf: Plaid (account connectivity), Supabase (database and authentication hosting), Vercel (application hosting), Google (sign-in), and a third-party AI provider (the "Ask" feature). We may disclose information if required by law.
How we protect it
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access is restricted to authenticated household members through database-level controls, financial-institution access tokens are additionally encrypted and kept server-side, and administrative access is protected with multi-factor authentication. See our Data Retention & Deletion Policy for how long we keep data.
Your choices and rights
You can disconnect any financial institution at any time, which revokes our access to it. You may request access to, correction of, or deletion of your personal information by contacting privacy@richfishhome.com; see the Data Retention & Deletion Policy for timeframes.
Children
RichFish is not directed to anyone under 18 and we do not knowingly collect data from children.
Changes
We may update this policy; we will revise the effective date above and, for material changes, notify you within the app.
Contact
privacy@richfishhome.com. Governing law: State of Washington, USA.