Shillak Privacy Policy
Last Updated: April 20, 2026
In Brief: Shillak connects your bank accounts via Plaid to help you and your partner manage finances together. We do not sell your data. Your bank credentials are never stored on our servers — Plaid handles all bank authentication securely.
1. Information We Collect
1.1 Account Information
- Phone number (for authentication via Firebase)
- Display name (if provided)
1.2 Financial Data (via Plaid)
- Bank account names and types (checking, savings, credit)
- Account balances
- Institution names
Important: Your bank login credentials are handled entirely by Plaid. We never see, store, or have access to your bank username or password.
1.3 Household Data
- Household membership and invite codes
- Low balance alert thresholds
- Transfer request history
1.4 Device Information
- FCM push notification token
- Device type and OS version (via Firebase)
2. How We Use Your Information
| Purpose | Data Used |
| Display account balances | Bank account data via Plaid |
| Low balance alerts | Account balances, threshold settings |
| Transfer requests | Household membership, account info |
| Push notifications | FCM token, alert preferences |
| Authentication | Phone number via Firebase |
3. Data Sharing
3.1 We DO NOT Sell Your Data
Shillak does not sell, rent, or trade your personal or financial information.
3.2 Third-Party Services
- Plaid: Bank account linking and balance retrieval
- Firebase (Google): Authentication and push notifications
3.3 Household Sharing
When you join a household, your linked account balances are visible to all household members. Transfer requests are shared within the household.
4. Data Security
- Bank Credentials: Handled by Plaid — never touch our servers
- Encryption: All data encrypted in transit (HTTPS)
- Authentication: Firebase phone authentication with secure tokens
- Access Tokens: Plaid access tokens stored securely on our servers
5. Data Retention
- Account data retained while your account is active
- Transfer history retained for 1 year
- You can unlink bank accounts at any time
6. Your Rights
- Unlink Accounts: Remove any bank connection from Settings
- Delete Account: Contact us to delete all your data
- Revoke Plaid Access: You can revoke Shillak's access to your bank directly through your bank's settings
7. Children's Privacy
Shillak is not intended for children under 13.
8. Changes to This Policy
We may update this policy periodically. Continued use after changes constitutes acceptance.