Privacy Policy
xquid — operated by Helios Portal, LLC (xquid.tech)
| Version | 1.0 |
|---|---|
| Effective date | To be set at publication |
| Privacy contact | privacy@xquid.tech |
| Security contact | security@xquid.tech |
The short version
xquid is a tool for planning your financial future — it takes the recurring pieces of your money life and plays them forward so you can see where you're headed. To do that, it holds the planning data you enter. It is built on a deliberate principle: we collect as little about you as the product can possibly work with.
In particular, when you connect a bank, we never see your bank login and never receive your full account or routing numbers — so they cannot be exposed through us, even in the worst case. We don't sell your information, and we don't build advertising profiles out of it. You can delete everything at any time.
The rest of this page is the detail.
1. Who we are
xquid is a personal financial-planning web application operated by Helios Portal, LLC ("we," "us," "the Company"), a single-member company. When this policy says "you," it means a person using xquid.
2. What we collect
Planning data you author. The substance of xquid is the plan you build: your category and account structure, budgets, projection scenarios, account balances, and the forward-looking projections the app produces from them. You create this data; it is yours.
Account and sign-in data. You sign in through Google Sign-In (using Firebase Authentication). We receive the basic identifiers that sign-in provides. We never receive or store your Google password.
Bank-connection data (only if you choose to connect a bank). If you link a financial institution through Plaid, we store only the minimum needed to keep your balances current: the last four digits of an account (a "mask"), the institution's name, the account's name, its type and subtype, and dated balance amounts. See Section 5 for exactly what we deliberately do not receive.
Technical and diagnostic data. Like any web application, we process basic technical information needed to operate and secure the service — sign-in identifiers and diagnostic error context when something goes wrong. This is governed by a hard privacy rule described in Section 7.
3. What we deliberately do not collect
The following are never collected, stored, or processed by us:
- Your bank login. When you connect a bank, you enter your credentials inside Plaid's own secure screen, which runs in Plaid's context — not ours. Your bank username and password never pass through, and are never seen by, our systems.
- Full account numbers or routing numbers. We do not enable Plaid's account-verification ("Auth") or identity products, so those numbers are never sent to us. This is a fixed rule built into how the app is configured, not an incidental setting.
- Payment card details. When subscription billing is introduced, card entry will happen inside the payment provider's own hosted checkout; card data will not touch our systems.
- Government identifiers such as Social Security or tax ID numbers.
4. How we use your information
We use the data above to:
- Provide the service — store your plan, run your projections, and show you the results.
- Keep your balances current — if you've connected a bank, retrieve up-to-date balances when you ask us to, so a projection starts from where you actually stand.
- Operate the optional AI assistant — only if you choose to use it. When you do, the specific planning details you bring into that conversation are sent to our AI provider (Anthropic) to generate a response. Your bank login and account numbers are never part of this, because we never hold them. We do not build or train AI models on your data.
- Keep the service secure and working — diagnose errors and detect abuse.
We do not sell your personal information, and we do not use your financial data to target advertising.
5. Bank connections through Plaid — the detail
Connecting a bank is entirely optional; xquid works fully without it.
When you connect an institution, Plaid handles the login and returns to us only the limited fields in Section 2. Behind the scenes, connecting a bank produces an access token that lets us fetch your balances. That token is held server-side only, in a store that no user — not even you, and not a compromised copy of the app — can read. It exists only for our backend to use on your behalf.
You are in control of the connection:
- You confirm each discovered account before it is linked to your plan; nothing is merged silently.
- You can disconnect a linked institution at any time from within the app. Disconnecting
immediately severs our access at Plaid (via Plaid's
/item/remove), after which we can retrieve nothing further from that institution.
6. Who we share data with
We use a small set of established service providers, each only for its specific function and each given only the data that function requires. We do not sell your data to anyone.
| Provider | Why | What they receive |
|---|---|---|
| Google Cloud / Firebase | Hosting, sign-in, database, backend functions | Your application data, encrypted in transit and at rest |
| Plaid | Bank connectivity (balances) | Only what's needed to establish and maintain a connection you initiate; your credentials never pass through us |
| Anthropic | The optional AI assistant | Only the planning details you choose to discuss — no credentials, no account numbers |
| (Payment provider — planned) | Subscription billing | Card data handled entirely in the provider's hosted checkout; none retained by us |
We may also disclose information if required by law, or to protect the rights, safety, or security of our users or the service.
7. How we protect your information
- Encryption everywhere. Traffic is encrypted in transit with TLS (1.2 or better); stored data is encrypted at rest (AES-256) by our cloud provider.
- Server-enforced access. Who can read or change a given plan is decided by the database itself, on every request — not by the app on your screen. A modified or hostile copy of the app cannot get around it.
- Secrets stay on the server. Bank access tokens and application keys are never sent to your browser and are never readable by any client.
- A hard privacy floor on logs and analytics. No financial values, no account or entity names, and no personally identifying information ever appear in our logs, error reports, or product analytics. Those records carry identifiers and error context only — never the contents of your plan.
Full detail lives in our Information Security Policy, available on request.
8. How long we keep your data, and deleting it
We keep your data only while you keep your account. Your financial plan has no value to us once you leave, so we have no reason to hold onto it — and we don't.
You can delete everything at any time. Contact us at privacy@xquid.tech to request deletion. When you do, we will:
- Sever any connected bank link (via Plaid's
/item/remove), ending our ability to fetch any further data; - Delete your account sets and all associated financial data;
- Delete your sign-in record; and
- Complete this within 30 days and confirm to you when it's done.
You can also disconnect a bank on its own — from within the app, at any time — without deleting the rest of your account. Accounts left inactive for an extended period may be reviewed and deleted after notice to you.
9. Your choices
You may ask us to access, correct, or delete the personal data we hold about you, and you may disconnect a linked bank at any time. To exercise any of these, contact privacy@xquid.tech. Depending on where you live, additional privacy rights may apply; we will honor those that the law provides.
10. Children
xquid is not directed to children under 13, and we do not knowingly collect personal information from them. During the current pre-release phase, access is limited to an explicit list of invited testers. If you believe a child under 13 has provided us information, contact privacy@xquid.tech and we will delete it.
11. Changes to this policy
We may update this policy as xquid evolves. When we make a material change, we will revise the version and effective date above and, where appropriate, notify you. Continued use after an update means you accept the revised policy.
12. Contact us
Questions about this policy or your data: privacy@xquid.tech
Security concerns: security@xquid.tech
Helios Portal, LLC — operator of xquid (xquid.tech)