Privacy Policy
Last updated: August 6, 2026 · Policy version 2026-08-06
Introduction
At Corra, we’re building a platform that helps you take back control of your finances. Corra relies on your financial data to do that work, and we are committed to protecting the security and privacy of that data. This policy sets out what personal information we collect, how we use it, who we share it with, and the rights and controls you have.
Your personal data will not be sold, distributed, or leased to any third party, and we will not transfer it for any monetization-related purpose; we share personal data only where necessary to provide our services (Section 4). Bank connections are handled by our third-party provider Plaid — Corra receives read-only financial data and at no point receives your bank login credentials (Section 2). Data processed by our AI provider is redacted before transmission and is not used to train AI models (Section 5).
Corra Finance Inc. (“Corra,” “we,” “us”) is federally incorporated in Canada and serves users in the United States. This policy covers the Corra iOS app, our website meetcorra.com, and our communications with you. It should be read alongside the Corra Terms of Service.
1. Accountability
We are responsible for the personal information in our possession, including information transferred to service providers processing it on our behalf. We have appointed a Privacy Officer to oversee privacy matters — reach them at privacy@meetcorra.com.
2. The data we collect
In the course of using Corra, you provide us with or we collect:
- Contact and profile details — your name, email address, phone number, the state you live in, and your time zone.
- Financial data from your connected accounts, provided through our third-party provider Plaid — account names and types, masked account numbers, balances, transaction history (dates, amounts, merchants, categories), liability details for credit cards, lines of credit, loans, and mortgages (balances, interest rates, minimum payments, due dates), and investment account balances. Your bank sign-in happens with Plaid or your bank directly — Corra never receives or stores your bank username or password.
- Financial details you enter yourself — debts you add yourself and details you provide about detected ones (such as interest rates and minimum payments), manually tracked assets, income confirmations, savings goals, upcoming expenses, and your payoff-plan choices.
- Your conversations with the Corra Assistant — the messages you send in chat, and the durable context Corra learns from them (Section 5).
- Technical data — device push-notification token (if you enable notifications), app version, and service and security logs (which include IP addresses) used to keep the service running and your account safe.
We do not collect your Social Security Number, government ID, or credit score, and we never receive your full card number (subscriptions are billed by Apple through the App Store). We do not collect information regarding your race, ethnicity, religious or political beliefs, sexual orientation, genetic or biometric data, or health — and if you mention something sensitive in chat, Section 5 explains how it is protected.
3. How and why we use data
We use the data above to provide the contracted service to you and to operate our business:
- Sync and display your accounts; categorize transactions; detect income and recurring payments; track debts and build your payoff plan; calculate disposable income, savings progress, net worth, and your emergency fund; and surface insights and alerts about your finances.
- Verify your identity, authenticate you (including two-step verification codes), and prevent fraud and abuse.
- Respond to your support requests and send you service messages about your account.
- Understand how features are used, fix problems, and improve Corra.
- Send marketing messages — only with your consent, always with a working unsubscribe. We do not send marketing SMS.
- Comply with law and enforce our terms.
We do not use your data for third-party advertising, and we do not make automated decisions about you that produce legal or similarly significant effects, such as approving or denying credit or insurance.
4. Who we share data with
We only share your personal data where it is necessary to provide our services. Below are the providers we share with, the role each plays, and what they process. We require each provider to respect the privacy and security of your personal data, and our written contracts with them restrict its use to providing their service to us.
- Plaid provides bank connectivity, processing your bank-connection and financial account data. Plaid’s own privacy policy applies to its handling of your data: https://plaid.com/legal/#end-user-privacy-policy. You can also manage and delete the data Plaid holds via Plaid Portal (https://my.plaid.com).
- Amazon Web Services provides our cloud infrastructure and data storage, hosting all application data in encrypted form.
- Stytch provides sign-in and account security services, processing your email, phone number, name, and authentication factors.
- OpenAI provides the AI functionality behind Corra’s features, processing redacted content only — see Section 5.
- Cloudflare provides network security, processing request metadata and IP addresses in transit.
- Resend provides email delivery, processing your email address and message content.
- Vercel hosts meetcorra.com.
- Apple bills your subscription through the App Store and delivers push notifications.
- We may also use Sentry (crash diagnostics, with personal information scrubbed and no financial data), Mixpanel (product usage analytics, never your financial data), and RevenueCat (subscription status).
Beyond these providers, we disclose personal information only: if required by law or valid legal process (where the law allows, we will tell you first); to protect your safety, our rights, or to prevent fraud; or as part of a merger, financing, or sale of the business — in which case this policy continues to apply and you will be notified. We may use aggregated, de-identified data that cannot be linked to you to analyze and improve the product; we do not attempt to re-identify it and we do not sell it.
5. AI at Corra
Corra’s AI features are powered by OpenAI. Before anything is sent to OpenAI, we strip the identifying details we can recognize: email addresses, phone numbers, street addresses, postal and ZIP codes, account and routing numbers, and government or tax identification numbers are removed before any data leaves Corra’s systems. Transaction data is reduced further — only a cleaned merchant description, an amount, and a date are sent. Redaction works by recognizing the shape of these details, so a personal name typed into a conversation is not detected and may be transmitted. Under our API terms, OpenAI does not use your data to train its models. Your conversations and everything Corra learns are stored in Corra’s own infrastructure, not OpenAI’s.
Two kinds of AI processing run at Corra:
- Transaction categorization is part of how the product fundamentally works — your plan, spending views, and income detection are built on it — so it runs for every account, on redacted transaction data.
- The Corra Assistant (chat, and what Corra learns and remembers from your conversations) is on by default and you can turn it off any time in Settings → Privacy → Corra Assistant. Turning it off stops all assistant processing and learning; it does not affect categorization or your plan.
Corra’s memory of you is under your control. In Settings → Privacy → Corra Assistant → Corra Memory you can see everything Corra has learned, in plain language, and delete any of it — or delete all AI data (everything learned plus your conversation history) in one clearly separate action, distinct from deleting your account. Clearing a chat thread removes the visible conversation but not what Corra has learned. Balances and running totals are never stored as memories — those figures always come from your live data. The one exception is a number you attach to a plan yourself (“I’ve set aside $3,000 for taxes”): Corra keeps that as something you said on a given date, so it can pick the thread back up later, and it never overrides what your accounts actually show. Highly sensitive disclosures — a health event, a bereavement — are never attached to unrelated conversations. These controls work even when the assistant is off.
6. Where your data is stored
Your personal information is stored and processed in the United States — Corra’s infrastructure and service providers are located there. Corra is a Canadian company, so our team also accesses that information from Canada in the course of running the service. Your information may therefore be subject to the laws of, and be accessible to the courts, law enforcement, and national-security authorities of, both countries. We remain accountable for it wherever it is, and we protect it with the same contractual and technical safeguards throughout. Contact our Privacy Officer for more information about our cross-border practices.
7. How long we keep data
Your data is retained while your account is active, because the service’s analysis — trends, payoff progress, income history — depends on it. When you delete your account, your data is deleted from our live systems immediately, deletion is propagated to the providers that hold your data (your bank connections are revoked at Plaid, your identity record is deleted at Stytch), and encrypted backups expire automatically within 30 days. You can also delete at a finer grain — a single linked account, a whole bank connection, or all AI data — at any time, with deletion handled the same way and on the same schedule.
If you never finish setting up your account — you sign in but never tell us where you live — we delete it after 12 months, since there is nothing we can do with it and no reason to keep it.
A small set of records is kept longer where the law requires it: security audit logs (up to two years) and legally mandated deletion and incident records (at least 24 months). Those records are stripped down rather than erased: the link to your account is removed and the details are cleared, but a one-way scrambled form of your email address remains, so that we can show the deletion took place and so the deleted account cannot be silently recreated. It cannot be converted back into your address. The deletion policies of Plaid (https://plaid.com/legal/) and OpenAI (https://openai.com/policies/) apply to data they process and form part of the basis of our contracts with them.
8. Security
We encrypt your data in transit (TLS 1.2+) — between your device and Corra, and between Corra and every provider it talks to — and at rest. Bank-connection tokens carry an additional layer of application-level encryption, with keys held in a separate secrets vault and never shared with any third party. Our databases run in private network segments with no internet exposure; administrative access requires multi-factor authentication and is logged and audited. Our critical providers hold recognized security certifications (SOC 2 Type II at minimum), verified at selection and reviewed regularly. Signing in always requires two-step verification, and you can add a passcode and Face ID lock on your device for another layer.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach ever affects your information in a way that creates a real risk of harm, we will notify you and the appropriate regulators as required by law. We will never ask you for your password or bank credentials in any unsolicited communication — if someone claiming to be Corra does, contact us.
9. Consent
By creating an account, you review and accept this policy, and that acceptance is the basis on which Corra processes your data for the purposes above. Connecting a bank is a further action you take knowingly through Plaid; the Corra Assistant has its own off-switch (Section 5).
You can withdraw consent at any time: turn off the assistant, unsubscribe from marketing, disconnect a bank, or delete your account entirely. Because Corra cannot function without processing your financial data, withdrawing consent for the core service means deleting your account. Withdrawal is never penalized and does not affect the lawfulness of processing that happened before it.
10. Your rights
Wherever you live, you have the right to:
- Access and export your personal information — request a complete, machine-readable copy (JSON) of your data.
- Correct it — edit your profile, recategorize transactions, adjust income and debt details directly in the app; for a wrong AI memory, delete it and state the correct fact in chat.
- Delete it — a single account, a whole bank, all AI data, or your entire account, all self-serve in the app (Section 7).
- Port it — the JSON export is a structured, commonly used, machine-readable format.
- Withdraw consent (Section 9) and opt out of marketing at any time.
- Not be discriminated against for exercising any of these rights — we never degrade service, charge more, or penalize you for a privacy choice.
Most of the above actions are self-serve and immediate in the app. You can also make any request at privacy@meetcorra.com; we respond within 30 days and never charge a fee for it. For requests made outside the app we may need to verify your identity first (typically by confirming control of your account email — never your bank credentials). An authorized agent may act for you with your signed written permission. If we decline a request, we will tell you why and how to challenge the decision.
11. United States: state privacy rights
Residents of a growing set of states — including California, Colorado, Connecticut, Montana, Oregon, Texas, Utah, and Virginia — have statutory rights to access, correct, delete, and obtain a copy of their personal information, and to opt out of its sale, its sharing for targeted advertising, and certain profiling. Corra extends the access, correction, deletion, and portability rights to all US users regardless of state, through Section 10.
On the opt-outs: we do not sell your personal information and do not share it for targeted advertising — there is nothing to opt out of and no “Do Not Sell or Share” link is needed — and we do not profile you in furtherance of decisions with legal or similarly significant effects. Your financial data is sensitive personal information; we use it only to provide the service you asked for, which is the limited use state law contemplates. Because we sell and share nothing, browser opt-out signals such as Global Privacy Control are honored by default, for everyone.
If we decline a request and you disagree, you may appeal by emailing privacy@meetcorra.com with “Appeal” in the subject line; if we deny the appeal, you may contact your state Attorney General.
12. Corra is a Canadian company
Because Corra Finance Inc. is Canadian, Canada’s federal privacy law — PIPEDA — governs how we handle your personal information alongside the US laws above, and our Privacy Officer is accountable for meeting it. That accountability follows your data: it applies equally to the information our service providers process for us, wherever they are.
For you this is an additional route rather than a different standard. If you are not satisfied with how we have handled a privacy concern, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) as well as to the authorities described in Section 11.
13. Cookies
meetcorra.com uses only strictly necessary cookies — the minimum required for the site to function. We do not use advertising, targeting, or retargeting cookies, or third-party advertising trackers, on the website or in the app. If that changes, we will update this policy before doing so.
14. Children
Corra is for adults — you must be 18 or older to create an account, and you confirm that when you set your account up. We do not knowingly collect personal information from anyone under 18; if you believe a minor has provided us personal information, contact privacy@meetcorra.com and we will delete it.
15. Changes to this policy
When we change this policy we update the date and version at the top. For material changes we will notify you actively — by email or in the app — before they take effect, and where a change involves a new use of your data, we will ask for your consent.
16. Contact us
Privacy Officer, Corra Finance Inc.
privacy@meetcorra.com
General support: support@meetcorra.com
If you have a disability and need this policy in an accessible format, contact us and we will provide it.