Privacy Policy
The short version. Branch reads your accounts so it can show you one honest picture of what you own. Connections are read-only — Branch cannot move your money. We do not sell or rent your data, and we do not use your financial information for advertising. You can export everything or delete it permanently from inside the app.
Branch is a product of Runloop d.o.o., a limited liability company registered in Croatia. This policy explains what Branch ("Branch", "we", "us") collects when you use the Branch iPhone app and this website, why we collect it, who we share it with, and what rights you have over it.
1. Who is responsible for your data
Runloop d.o.o., trading as Branch, is the data controller for the information described here.
- Registered office: Šibička ulica 15, 10290 Zaprešić, Croatia
- Company identification number (OIB): 71093241471
- Court register number (MBS): 081609698
If you have questions about this policy or want to exercise any of the rights in section 9, contact us at privacy@branchfinance.app.
2. Information we collect
Information you give us
- Account identity. When you sign in with Apple or Google we receive a unique identifier, and your name and email address where you choose to share them. If you use Apple's Hide My Email, we only ever see the relay address.
- Manually entered financial data. Accounts and balances you add by hand, transactions you log, and assets you track — including each purchase lot's quantity, price paid, purchase date and any notes you write.
- Goals. Savings, investment, payoff and budget goals, their targets and dates, and which accounts or assets fund them.
- Onboarding answers. Age range, income range, primary financial goal, time horizon, and how you currently track your money. These personalise your plan and projections. They are ranges and categories, never exact figures.
- Assistant conversations. Messages you send to the in-app assistant, and the financial context needed to answer them.
Information from your connected institutions
When you link a bank or brokerage, our provider Plaid returns data which we store to build your picture:
- Account names, types, currencies and the last digits of account numbers
- Balances, including available and limit amounts where the institution provides them
- Transactions — amount, date, description, merchant and category
- Investment holdings and positions, where applicable
- The name and logo of the institution
We never receive your online banking username or password. Those are entered inside Plaid's own secure flow and are never visible to Branch. If you connect Trading 212, the API key you generate is stored encrypted in your device's Keychain.
What Plaid itself collects when you make that connection, and how they use it, is governed by their own Plaid End User Privacy Policy.
If you join the waitlist
Joining the waitlist does not create an account. We store your email address, which platform you asked about, where the signup came from, the country the request came from, and the time you consented — nothing else. We do not store your IP address. Every email carries a one-click unsubscribe link, and unsubscribing stops all further mail.
Information collected automatically
- Product analytics. Which screens you open and which features you use, so we can see where the app is confusing. These events deliberately exclude amounts, account names and transaction details. We measure this website the same way — which pages are viewed, and whether a visit ends in a waitlist signup. The website analytics set no cookies and store nothing on your device, so no consent banner is needed; the trade-off is that we cannot recognise a returning visitor.
- Crash and diagnostic data. Stack traces, device model and OS version when something fails, so we can fix it.
- Subscription status. Whether you have an active trial or subscription, handled through Apple and RevenueCat. We never see your card details.
3. What we do not collect
- Your banking credentials.
- Your payment card or bank card numbers.
- Government identity documents. Branch does not perform identity verification, because it never holds or moves your money.
- Your device's contacts, photos, precise location or advertising identifier.
4. How we use your information
- To show your accounts, assets, net worth, activity and goals.
- To calculate projections and keep prices current.
- To sync your data between your devices and, if you use family sharing, with the people you have explicitly invited.
- To answer your questions through the in-app assistant.
- To operate subscriptions, provide support, and detect abuse or fraud.
- To improve the app through aggregate, non-financial usage analysis.
We do not use your financial data to build advertising profiles, and we do not make automated decisions that produce legal effects for you.
5. Legal bases (UK and EU users)
- Contract — to provide the service you signed up for, including syncing and linking accounts.
- Consent — to link a specific financial institution, to join the launch waitlist, and for optional marketing email. You can withdraw either at any time.
- Legitimate interests — to keep the service secure, prevent abuse, and understand aggregate product usage.
- Legal obligation — where we must retain records or respond to lawful requests.
6. Who we share data with
We share only what each provider needs to do its job. We do not sell or rent personal information, and we have never done so.
| Provider | Purpose | What they receive |
|---|---|---|
| Plaid | Connecting banks and brokerages | Your institution credentials (entered directly with them, never seen by us) and the resulting account and transaction data |
| Cloudflare | Hosting our API and database | All account data described above, stored encrypted at rest |
| Google (Firebase) | Sign-in, crash reporting and app integrity | Account identifier, crash diagnostics, device and OS details |
| Google (Gemini) | Powering the in-app assistant | Your question and the financial context needed to answer it. Not used to train Google's general models. |
| PostHog | Product and website analytics | Pseudonymous usage events, excluding financial values |
| Resend | Sending waitlist and announcement email | Your email address and the contents of the message |
| RevenueCat | Subscription management | Account identifier and subscription status |
| Apple | Sign-in and payments | Handled entirely by Apple; we receive only an identifier and subscription state |
| CoinGecko, metals price providers | Live asset prices | Only asset symbols. No personal or account data is sent. |
We may also disclose information where legally required, or as part of a merger or acquisition — in which case you will be told before your data becomes subject to a different policy.
7. International transfers
Branch operates in the United States and the United Kingdom, and some providers process data in the United States. Where data leaves the UK or EEA, transfers rely on Standard Contractual Clauses or an adequacy decision.
8. How long we keep it
We keep your data for as long as your account exists. When you delete your account, we permanently delete your profile, accounts, assets, transactions and goals from our systems, and we revoke every institution connection you created. Deletion is immediate and cannot be undone. Limited records may persist briefly in encrypted backups and in logs kept for security purposes.
If you joined the waitlist without creating an account, we keep that entry until you unsubscribe. After that we retain only what is needed to honour the unsubscribe and not mail you again. You can ask us to erase it entirely at privacy@branchfinance.app.
9. Your rights
You can, at any time:
- Access and export your data in a portable format.
- Correct anything inaccurate, directly in the app.
- Delete your account and all associated data, from Profile → My Account → Delete Account.
- Disconnect any linked institution without deleting your account.
- Withdraw consent for marketing email or a specific connection.
- Object or restrict certain processing, and lodge a complaint with your data protection authority — in the UK, the Information Commissioner's Office.
California residents have the right to know what is collected, to delete it, and not to be discriminated against for exercising those rights. Branch does not sell personal information as defined by the CCPA.
10. Security
- All traffic is encrypted in transit with TLS.
- Data on your device is protected by iOS Data Protection and can be locked behind Face ID.
- Access tokens are stored in the iOS Keychain, never in plain files.
- Institution access tokens are encrypted at rest on our servers.
- App content is hidden in the iOS app switcher.
No system is perfectly secure, but Branch is designed so that the worst case is exposure of a read-only picture — never the ability to move your money.
11. Children
Branch is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal information, contact us and we will delete it.
12. Changes to this policy
If we change this policy materially, we will update the date above and notify you in the app before the change takes effect.
13. Contact
Privacy questions:
privacy@branchfinance.app
Everything else:
support@branchfinance.app