Privacy Policy

Last updated: September 2026

Douse Technologies LLC ("Douse," "we," "us," or "our") operates the Douse web application, iOS app, and Android app. This Privacy Policy explains what data we collect, how we use it, and who we share it with.

1. What we collect

Bank transactions. When you connect a bank account via Plaid, Douse receives read-only access to your transaction history. We store transaction amounts, merchant names, dates, merchant category codes (MCC), and spending categories. For each linked account we also store its name, type, balance, and the last few digits of the account number, so we can tell your accounts apart. We do not store full account numbers, routing numbers, or bank login credentials, and we can never move money.

Account information. Your email address, display name, phone number (if provided for SMS alerts), timezone, the comfort zone amount you set, and your alert preferences.

Third-party sign-in. If you choose "Continue with Google" or "Continue with Apple" instead of a password, that provider tells us your email address and, where you allow it, your name. That is all we ask for and all we receive — we get no access to your contacts, calendar, files, or anything else in that account, and we never receive your password. Apple lets you hide your real address; if you do, we only ever see the private relay address Apple gives us, and we use it exactly as we would any other email address. Signing in this way also lists Douse among the connected apps in your Google or Apple account, where anyone with access to that account can see it. If you would rather Douse not appear there, sign up with an email address and password instead — every feature works the same either way.

Support person information. When you add a support person, we store their name, phone number, email (optional), and relationship label. This information is provided by you, not collected from the support person directly. A support person who accepts signs in with their own email address; we use it only to reach them if a text can't get through, and it is never shown to you.

Spending patterns. Derived data including weekly spending totals, streak counts, zone status (comfort / caution / warning / danger), and weekly insight reports (Pro tier). This is computed from your transactions and stored to power your dashboard.

Device information. Push notification tokens and platform type (iOS or Android) so we can deliver alerts to your device. We do not collect advertising identifiers or device fingerprints.

Panic button data. If you use the panic button, we store the timestamp, session duration, and the action you took. If you grant location permission, we may store your approximate GPS coordinates at the time of use. Location sharing is always optional and can be denied without affecting the feature.

Subscription data. If you subscribe to Douse Pro, we store your subscription status, platform (iOS, Android, or web), product identifier, and expiration date. Payment details (credit card numbers, billing addresses) are handled entirely by Apple, Google, or our payment processor and are never stored by Douse.

2. How we use it

  • Detecting spending activity and triggering alerts
  • Calculating your streak and current spending zone
  • Generating weekly insights (Pro tier)
  • Delivering push notifications and SMS alerts
  • Showing your dashboard and transaction history
  • Improving app stability and fixing errors
  • Understanding aggregate usage patterns (page views, not individual behavior)

We do not use your data for advertising, sell it to third parties, or use it to train machine learning models.

3. Who we share it with

Support persons. You choose what your support person sees. At the "light touch" level, they receive only a notification that spending activity was detected. At "moderate," they also see the amount. At "full transparency," they see the amount and merchant name. They cannot see anything by default — you control the permission level at any time from Settings, and you can remove a support person at any time.

Plaid Inc. We use Plaid to connect to your bank. Plaid's privacy policy applies to data collected through their service: plaid.com/legal. Your Plaid access token is stored on our server only — it never reaches your device or browser.

Twilio. We use Twilio to send SMS alerts to you and your support persons. Twilio receives the recipient phone number and message text. See Twilio's privacy policy. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, except with providers of the text messaging service that make delivery possible.

Resend. We use Resend to send sign-in and account emails, and to email a support person when a text to them can't get through (never after they have replied STOP). Resend receives the recipient email address and message text. See Resend's privacy policy.

Expo. We use Expo's push notification service to deliver alerts to your mobile device. Expo receives your push token and the notification content (title and body text). See Expo's privacy policy.

RevenueCat. We use RevenueCat to manage subscriptions across platforms. RevenueCat receives your anonymous user ID and subscription events (purchases, renewals, cancellations). RevenueCat does not receive your bank data, transaction data, or alert history. See RevenueCat's privacy policy.

Supabase. Our database and authentication provider. Data is stored in Supabase's infrastructure with row-level security enforced — no one can read your data except you and the people you've granted access to. See Supabase's privacy policy.

Sentry. We use Sentry for error tracking to identify and fix bugs. If an error occurs, Sentry may receive the error message, stack trace, request URL, and basic device or browser information. Sentry does not receive your transaction data, bank data, or alert content. We sample 10% of interactions for performance monitoring and do not record session replays. See Sentry's privacy policy.

Plausible Analytics. We use Plausible for privacy-first web analytics. Plausible does not use cookies, does not collect IP addresses, and does not track individual users across sessions. It records only aggregate page views, traffic sources, and country-level location. See Plausible's data policy.

Apple App Store and Google Play. If you purchase a subscription through the App Store or Google Play, Apple or Google processes the payment. We receive only the subscription status and product identifier — never your payment method or billing details.

Sign in with Google and Sign in with Apple. Only if you choose one of them to sign in. They confirm to us that the account is yours and pass along your email address and, where you allow it, your name. We send them nothing about your spending, your alerts, or your support people. You can disconnect Douse at any time from your Google account or your Apple account settings; doing so does not delete your Douse account, so set a password first if that is your only way in. See Google's privacy policy and Apple's privacy policy.

4. Data security

All data is encrypted in transit using TLS and encrypted at rest in our database. Your Plaid access token — the credential that connects to your bank — is stored server-side only and never transmitted to your device, browser, or any third party other than Plaid.

Our database enforces row-level security (RLS), which means every query is scoped to your user account. Even in the event of an application-level bug, the database will not return another user's data.

We follow the principle of least privilege: our client applications only have access to anonymous-level database keys. Administrative operations use separate server-side credentials that are never exposed to client code.

5. Cookies and tracking

Douse does not use cookies for analytics or advertising. We do not engage in cross-site tracking or behavioral advertising. Our analytics provider (Plausible) is cookieless by design. Authentication state is stored in your browser's local storage, not in cookies.

6. Data retention and deletion

Your data is retained for as long as your account is active. You can delete your account and all associated data at any time from the Settings page. Deletion is immediate and permanent — bank connections are revoked via Plaid, and all records (transactions, alerts, streaks, bank connections, support person relationships) are removed from our database.

You may also request deletion by emailing privacy@douse.app. We will process the request within 30 days.

7. Your rights

You have the right to access, correct, or delete your personal data at any time. You may also request a copy of your data in a portable format, or object to certain processing. To exercise any of these rights, contact us using the information in Section 13.

California residents (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) gives you additional rights:

  • Right to know. You can request a copy of the personal information we hold about you.
  • Right to delete. You can request deletion of your account and all associated data at any time from the Settings page, or by emailing privacy@douse.app.
  • Right to opt out of sale. Douse does not sell your personal information to third parties.
  • Right to non-discrimination. We will not discriminate against you for exercising any of these rights.

Douse does not sell or share your personal data for cross-context behavioral advertising. The only sharing that occurs is described in Section 3.

8. International users

Douse is operated from the United States. If you are located outside the United States, your data will be transferred to and processed in the United States. By using Douse, you consent to this transfer. We process your data on the legal basis of your consent (when you connect your bank account) and our legitimate interest in providing the service (for account management and error tracking).

If you are in the European Economic Area (EEA) or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR), including the right to lodge a complaint with your local data protection authority. For data protection inquiries, contact privacy@douse.app.

9. Do Not Track

Douse honors Do Not Track (DNT) browser signals. Our analytics provider, Plausible, respects DNT by default. We do not engage in cross-site tracking regardless of DNT settings.

10. Law enforcement requests

We will disclose your data to law enforcement only in response to a valid legal process (such as a subpoena, court order, or warrant). Where permitted by law, we will notify you before disclosing your data so you have the opportunity to object.

11. Children

Douse is not intended for users under 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, contact privacy@douse.app and we will delete the account promptly.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email and display a banner in the app. The "Last updated" date at the top of this page reflects the most recent revision. Your continued use of Douse after the updated policy takes effect constitutes your acceptance of the changes.

13. Contact

For privacy questions, data requests, or to close your account, email privacy@douse.app.

Douse Technologies LLC