Skip to main content
Granary
← Back to dashboard

Privacy Policy

Last updated: 2026-08-21

Granary is a personal-finance and retirement-planning tool. We take privacy seriously because the data you give us is sensitive — net worth, income, medical costs, family details. This document describes exactly what happens to that data.

This page is about your data. On what the app's numbers mean: everything Granary calculates — projections, tax figures, Social Security benefits, Medicare premiums, subsidies — is a modeled estimate based on what you enter, not a determination or a guarantee. See Terms of Service, section 1.1.

1. What we collect

2. What we don't collect

3. Where data lives

Local-only mode: if you turn on local-only storage in Settings → Data & Sync, your financial data stays on your device and is not synced to Firestore. Your email address is still used for sign-in and billing, and the app makes one cloud read — your subscription status — when it loads. Cloud copies that existed before you switched are kept until you delete them from the same Settings card. Daily backup emails are always opt-in; if you opt in, each backup sends your data through our email service. AI features are also opt-in per run — local-only mode controls where your data is stored, and running an AI analysis is a separate, explicit choice that sends a snapshot off your device (see "AI features" below).

4. Encryption

5. AI features

What's sent: when you run an AI feature (AI Insights, What-If advice, AI CSV mapping, or AI categorization), Granary sends the relevant financial snapshot — the same numbers you see in the app, without your name or email — to an AI model provider via our server and the Vercel AI Gateway. The primary model is Anthropic's Claude; if it is unavailable, the request falls back to Google (Gemini) or OpenAI models. When: only when you explicitly run an AI feature; nothing is sent in the background, and the first run on each device asks you to confirm. Retention: Granary doesn't store the snapshot and doesn't retain AI request history; we also strip email and IP from error reports before they reach Sentry. Once the snapshot reaches the model provider, processing is subject to that provider's API terms — we can't independently verify how providers handle data on the API tiers we use, so if that tradeoff isn't acceptable to you, simply don't run the AI features; the rest of the app works without them. Accuracy: AI-generated insights and suggestions are estimates and commentary, not advice, and language models can be confidently wrong. Treat them as a starting point to verify, never as a figure to act on directly.

6. Sharing

We do not sell, rent, or share your personal data. Specific exceptions:

7. Your rights

8. Cookies

Granary uses no advertising cookies. We use a small number of strictly necessary cookies / localStorage entries to keep you signed in and remember your preferences (theme, dashboard layout). Our page analytics (Vercel Web Analytics) are cookie-free.

9. Contact

Privacy questions: Everyoneneedsasamwise@gmail.com. We respond within 5 business days.

This is a good-faith summary, not legal advice. The latest revision applies to all use of the service from the date noted above.