Privacy Policy
Effective date: August 14, 2026
Vigilant Works, LLC (doing business as Thermal / Thermal Finance, "we," "us," or "our") operates the Thermal Finance application. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
Information We Collect
We collect the following categories of information:
- Account information: name, email address, and authentication credentials when you create an account.
- Financial data: bank account balances, transactions, and investment holdings synced through Plaid and SnapTrade, plus market data associated with securities you hold, such as prices, dividends, and security metadata. We never store your bank or brokerage login credentials.
- Receipts you upload: if you use receipt scanning, we store the image you upload and the line items read from it. Receipt images are sent to our AI provider for reading, which is described under Third-Party Services below. A receipt photo can contain your name, a store address, and the last four digits of a card, so treat it the same way you would treat the paper receipt.
- Property information: if you add a property to track its value, we store the address you enter and send it to our valuation provider to retrieve an estimate.
- Billing information: payment details are processed and stored by Stripe, or by Apple or Google for subscriptions purchased in the mobile app. We do not store full credit card numbers.
- Usage analytics: pages visited, features used, and general interaction patterns to improve the service.
- Device & browser information: browser type, operating system, and screen size for compatibility and troubleshooting.
How We Use Your Information
- Provide, operate, and maintain the Thermal service.
- Sync and display your financial accounts, transactions, and balances.
- Generate budgets, projections, retirement simulations, and AI insights based on your data.
- Process payments and manage your subscription.
- Send transactional emails (trial reminders, receipts, security alerts).
- Improve, personalize, and expand our service.
- Detect and prevent fraud or abuse.
Third-Party Services
We share data with the following third-party providers only as necessary to operate the service:
- Plaid: securely connect your bank accounts and retrieve financial data. By connecting an account through Plaid, you authorize Thermal to access, retrieve, store, and use the associated financial data on your behalf, solely to provide the service. You can disconnect any connection at any time from Settings → Accounts, which stops future data retrieval via Plaid. Subject to Plaid's Privacy Policy.
- SnapTrade: securely connect your brokerage and retirement accounts and retrieve holdings, balances, and investment activity. As with Plaid, you authorize Thermal to access and store that data solely to provide the service, and you can disconnect a brokerage at any time from Settings → Accounts. Subject to SnapTrade's Privacy Policy.
- Stripe: payment processing. Subject to Stripe's Privacy Policy.
- RevenueCat: subscription management for purchases made in the mobile app through the App Store or Google Play. RevenueCat receives an app-specific user identifier, your purchase receipts, and your subscription state so your subscription stays active across your devices. It never receives your financial data, name, email address, or payment card details. Subject to RevenueCat's Privacy Policy.
- MarketStack: market data provider used to retrieve delayed or historical security prices, dividends, and related security metadata for investment features. We send ticker symbols and market-data request details to MarketStack; we do not send your account credentials or full account holdings to MarketStack.
- OpenRouter: the AI gateway behind our AI features, and nothing else. Your data reaches it only through those features: receipt scanning, transaction categorization, and insights. Ordinary syncing, budgeting, net worth, and retirement planning never send anything to it. Depending on the feature, we send it the receipt images you upload and transaction details such as merchant names, amounts, and dates. OpenRouter routes each request to the underlying model provider that serves it, currently Google, OpenAI, or Alibaba depending on the feature. The specific models we use may change over time, but we are committed to routing through zero data retention endpoints only: the providers that serve our requests are not permitted to store your data or use it for training. These requests do not include your name, email address, account numbers, or login credentials, though an image you upload will contain whatever is printed on the receipt itself. Thermal does not use your data to train AI models either. Subject to OpenRouter's Privacy Policy.
- RentCast: property valuation estimates. When you track a property, we send its address to RentCast to retrieve an estimated value. We do not send your name or any account information with it.
- Convex: cloud database and backend infrastructure where your data is stored.
- Vercel: application hosting and delivery.
- Resend: transactional email delivery.
- Grafana Faro: frontend observability (performance metrics, error traces, and anonymized usage events) to help us detect and fix issues.
- Sentry: crash and error reporting for the web and mobile apps, so we learn that something broke and can fix it. Reports carry the error itself plus device and app version details. We disable Sentry's personal-data collection, session replay, and screenshots, and we scrub report contents before they are sent.
We do not sell your personal information to third parties.
Browser Extension
Thermal offers an optional Chrome extension, Thermal Finance - Order Sync, that imports your online purchase history so your budget can show line-item detail your bank feed does not. It is a companion to your Thermal account and is entirely optional.
- What it reads: on the retailers you explicitly enable (Amazon, including Whole Foods and Amazon Fresh, Target, Costco, and Walmart), the extension reads your own order-history and order-detail pages to extract line items, quantities, subtotals, tax, and tips. It reads only your order pages, and only on the retailers you turn on.
- Where it goes: the order data is sent to your own Thermal account, where it is matched to your existing transactions. It is not sold, shared with third parties, or used for advertising.
- What it never handles: the extension does not ask for, store, or transmit your retailer or bank passwords. You sign in to each retailer on the retailer's own site; the extension reads pages you are already logged in to. It signs in to Thermal with a scoped session token, never a password, and it does not handle Plaid or bank connections.
- Local storage: the extension stores only your sync preferences (which retailers are enabled, last-sync times) and a short-lived session token in your browser. Imported purchase data is not retained in the extension after it reaches your Thermal account.
You can remove the extension at any time from your browser; doing so stops all order syncing. Removing it does not delete orders already imported into your Thermal account, which you can manage from the Receipts page.
Data Security
We implement industry-standard security measures to protect your data. All data is encrypted in transit (TLS) and at rest. Bank credentials are never stored on our servers. Plaid handles authentication directly. Access to production systems is restricted and audited. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
Data Retention & Deletion
We retain your data for as long as your account is active or as needed to provide the service. When you delete your account, we delete your financial data, account information, and associated records within 30 days. Some data may be retained longer where required by law (e.g., billing records for tax purposes).
Your Rights
You have the right to:
- Access: request a copy of the personal data we hold about you.
- Export: download your financial data in a portable format.
- Delete: request deletion of your account and associated data.
- Correct: request correction of inaccurate personal data.
- Opt out: manage email preferences and opt out of non-essential communications.
To exercise any of these rights, contact us at privacy@thermalfinance.com.
Cookies
We use essential cookies to maintain your authentication session and preferences. We do not use third-party advertising or tracking cookies. Analytics cookies, if used, are anonymized and can be disabled in your browser settings.
Children's Privacy
Thermal is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA). You may request disclosure of the categories and specific pieces of personal information we have collected, request deletion, and opt out of the sale of personal information. We do not sell personal information. To submit a request, email privacy@thermalfinance.com with the subject line "CCPA Request."
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice within the app. Your continued use of Thermal after changes take effect constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy, contact us at:
Vigilant Works, LLC
Email: privacy@thermalfinance.com