Poppy

Privacy policy

Effective October 5, 2026

Poppy helps a household see where its money goes. This page says what we collect, why, who else is involved, and how to get your data deleted. Questions go to danbruder@hey.com.

What we collect

  • Your account: your email address and a one-way hash of your password (we never store the password itself). If you turn on two-factor sign-in, an encrypted authenticator secret and hashed recovery codes.
  • Your household: its name, who belongs to it and their roles, and invitations sent.
  • Bank data, when an owner connects a bank through Plaid: the institution's name, account names, types and last four digits, balances, and transactions (date, amount, description, merchant). We never see or store your bank username or password; you give those to Plaid.
  • A security log: sign-ins and failed sign-in attempts, two-factor and password changes, banks connected and removed, and membership changes, each with the time and the IP address it came from.
  • What you add: categories, budgets, goals, trips, notes, CSV statements and order histories you upload.

How we use it

Only to run Poppy for your household: importing and categorizing transactions, showing spending, trends and plans, and sending account emails (confirmations, invitations, password resets). We don't sell your data, show ads, or use it to build profiles, and we have no analytics or tracking.

Who else is involved

  • Plaid connects your bank. Plaid's handling of your data is covered by the Plaid End User Privacy Policy. Disconnecting a bank in Poppy tells Plaid to stop sharing data with us.
  • Resend delivers our emails, so it sees your email address and the message.
  • Our hosting provider runs the servers where your data is stored.
  • Pages load fonts from Google Fonts, card and merchant icons from Google's icon service, a chart library from jsDelivr, and Plaid's Link script from Plaid. Like any web request, these see your IP address and browser, not your financial data.

Cookies

We use only the cookies needed to keep you signed in: an encrypted session cookie, and a "keep me logged in" cookie if you ask for one.

How we protect it

Everything travels over HTTPS. Each household's data is kept in its own database, and only its members can see it. Bank access tokens and authenticator secrets are encrypted, passwords are hashed, and you can turn on two-factor sign-in in your account settings.

How long we keep it, and deleting it

  • We keep your data while your account and household exist.
  • A household owner can delete the household in Settings → Household. That disconnects its banks at Plaid and deletes all of its data.
  • You can delete your account in your account settings. Households where you are the only member are deleted with it.
  • Disconnecting a bank stops new data from it; transactions already imported stay until you delete them or the household.
  • Deleted data may remain in server backups for a while after it is deleted from Poppy.
  • You can also ask us to export or delete your data by emailing danbruder@hey.com.

Changes

If we change how we handle your data, we'll update this page and its date, and email you about significant changes.