Privacy Policy

Last updated: March 18, 2026

1. Who We Are

DealAgent ("we," "us," "our") operates the web application at dealagent.app. We provide automated bill tracking, savings analysis, expense categorization, and tax estimation tools for individuals and small businesses.

2. Information We Collect

Account Information

When you create an account, we collect your name, email address, and (if applicable) a hashed version of your password. If you sign up via Google or Microsoft OAuth, we receive your name and email from the provider. We never receive or store your Google or Microsoft passwords.

Bank & Financial Data (via Plaid)

If you connect a bank account, we use Plaid Inc. to securely access your transaction data. We never receive, see, or store your bank login credentials — Plaid handles all authentication directly. We receive and store: transaction amounts, merchant names, dates, and categories. This data is used to categorize expenses, detect recurring bills, estimate tax deductions, and identify savings opportunities. You can disconnect your bank account at any time, which deletes all associated transaction data from our system.

By connecting your bank, you also agree to Plaid's End User Privacy Policy.

Payment Information

If you subscribe to DealAgent Pro, payments are processed entirely by Stripe Inc. We never receive, process, or store your credit card number, bank account number, or other payment credentials. We only receive confirmation of payment status from Stripe.

Usage Data

We collect basic usage analytics such as pages visited, features used, and general interaction patterns to improve the product. We do not use third-party tracking pixels or sell usage data to advertisers.

3. How We Use Your Data

  • Automatically detect and categorize your bills and recurring expenses
  • Generate savings analysis reports with market comparisons
  • Estimate quarterly taxes and map expenses to IRS Schedule C categories (business accounts)
  • Send price alerts when we detect changes in your bills
  • Provide AI-powered chat assistance for expense questions
  • Process subscription payments
  • Send important account notifications (trial expiration, tax deadlines)

We never sell, rent, license, or trade your personal or financial data to any third party for any purpose.

4. Data Security

We take the security of your data seriously:

  • All OAuth tokens (email access, bank access) are encrypted at rest using AES-256-GCM encryption
  • All data transmitted between your browser and our servers is encrypted with TLS/HTTPS
  • Passwords are hashed with bcrypt (we never store plaintext passwords)
  • Bank credentials are never transmitted to or stored by DealAgent — Plaid handles all bank authentication
  • Payment processing is handled entirely by Stripe (PCI DSS Level 1 compliant)
  • Our database is hosted on encrypted infrastructure with restricted access

5. Third-Party Services

We use the following third-party services, each governed by their own privacy policies:

  • Plaid Inc. — Bank account connections and transaction data (Privacy Policy)
  • Stripe Inc. — Payment processing (Privacy Policy)
  • Google OAuth — Account authentication and sign-in (Privacy Policy)
  • Anthropic (Claude AI) — AI-powered expense analysis and chat (Privacy Policy)
  • Vercel — Application hosting
  • Neon — Database hosting

6. Your Rights

You have the following rights regarding your data:

  • Access: You can view all data we hold about you from your Settings and Dashboard pages
  • Disconnect: You can disconnect bank accounts at any time, which revokes our access and deletes associated data
  • Deletion: You can request complete deletion of your account and all associated data from your Settings page or by contacting us
  • Portability: You can request an export of your data by contacting us
  • Opt-out: You can unsubscribe from non-essential emails at any time

California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA). You have the right to know what personal information we collect, to request deletion of your personal information, and to opt-out of the sale of your personal information. We do not sell your personal information. To exercise your rights, use the "Delete Account" option in Settings or contact us at privacy@dealagent.app.

European Users (GDPR)

If you are in the European Economic Area, you have rights under the General Data Protection Regulation including the right to access, rectification, erasure, data portability, and the right to object to processing. Our legal basis for processing your data is your consent (which you provide when connecting accounts) and legitimate interest (providing the service you signed up for). Contact us at privacy@dealagent.app to exercise these rights.

7. Data Retention

We retain your account data and transaction history for as long as your account is active. When you delete your account, we permanently delete all associated data within 30 days, including transaction records, bill data, connected account tokens, and AI chat history. Anonymized, aggregated analytics data (not tied to your identity) may be retained for product improvement.

8. Data Breach Notification

In the unlikely event of a data breach that affects your personal or financial information, we will notify you via email within 72 hours of discovering the breach. We will also notify relevant regulatory authorities as required by applicable law.

9. Children's Privacy

DealAgent is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from minors. If we learn that we have collected data from a user under 18, we will delete that account and data promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on the app. Your continued use of DealAgent after changes take effect constitutes acceptance of the updated policy.

11. Contact Us

For questions, concerns, or requests related to your privacy, contact us at:

privacy@dealagent.app