Privacy policy
Effective September 24, 2026
Who we are
LOAF is bookkeeping software operated by Future History Labs (“we”). It helps a business see where its money goes by importing transactions from the business's own bank and card accounts. This policy explains what LOAF collects, how it's used, and the choices you have.
What we collect
- Account information: your name and email address, and the business you set up in LOAF.
- Financial data you connect: when you connect a bank or card through Plaid, LOAF receives account names, the last digits of account numbers, balances, and transaction details (date, amount, description, merchant). LOAF never receives or stores your bank username or password.
- Your decisions in LOAF: categories, rules, notes, and a record of changes you make.
- Basic technical data: sign-in events and server logs needed to run and secure the service.
How we use it
- To import and categorize your business's transactions and show balances, cash flow and reports.
- To suggest categories and detect recurring charges, which you can review and change.
- To produce exports you request, such as a profit-and-loss statement for your accountant.
- To secure your account, prevent misuse, and meet legal and tax record-keeping obligations.
We do not sell your data, share it for advertising, or use it for anything other than providing LOAF to you.
Service providers
LOAF relies on these providers, each of which processes data only to provide its service to us:
- Plaid, to connect your financial accounts. Plaid's handling of your data is described in the Plaid End User Privacy Policy.
- Supabase, which hosts LOAF's database and sign-in (United States).
- Vercel, which hosts the LOAF application (United States).
- Anthropic, whose Claude models suggest transaction categories. Only transaction descriptions, merchant names, amounts, dates and account types are sent; no names, account numbers, balances or credentials.
- Resend, which delivers LOAF's account emails (sign-in, password reset, security notices).
How we protect it
Data is encrypted in transit and at rest. Bank access tokens are additionally encrypted by LOAF and never sent to your browser. Every sign-in requires two-factor authentication. Each business's data is kept separate from every other's, access is limited by role, and changes are recorded in an audit log.
How long we keep it
- Disconnecting a bank revokes LOAF's access at Plaid immediately and deletes the stored access token. Transactions already imported are kept as the business's financial records.
- Financial records (transactions, categories, reports) are kept for as long as the business uses LOAF and then up to seven years, the period generally recommended for tax records, unless you ask us to delete them sooner where the law allows.
- Backups are kept for a limited period and are deleted on a rolling basis.
Your choices and requests
You can disconnect accounts at any time in LOAF under Settings → Connections. To access, correct, export or delete your data, or to close your account, email integrations@futurehistorylabs.com. We respond within 30 days.
Changes
If we change this policy, we'll update the date above, and for significant changes we'll tell you in LOAF or by email before they take effect.
Contact
Future History Labs · integrations@futurehistorylabs.com