Privacy Policy
Platru ("we", "us") helps you understand your personal finances by organizing transactions, statements, and related documents. The controller of your data is Platru Inc., 1990 Brickell Ave, Apt C, Miami, FL 33129, United States.
Platru is offered to users in Costa Rica and elsewhere in the Americas. We do not direct our services to, or market them in, the European Economic Area or the United Kingdom, and this policy is not an offer of services to individuals located there. The policy is written to a GDPR-level standard as a baseline of care, and adds region-specific rights below. Where your local law gives you stronger rights, those apply.
Data we collect
| Category | Examples | Source |
|---|---|---|
| Account & identity | name, email, password (hashed), Cognito user id | you / Google sign-in / Sign in with Apple |
| Waitlist | email address, IP address and browser user-agent, if you join the waitlist on our homepage | you |
| Google / Gmail data | your email address and profile, and — with your consent — the contents of bank-alert, statement, invoice and receipt emails and attachments, plus the subject lines and sender addresses of the other emails in each scanned window (used only for automated relevance classification — see below) | Google, via OAuth |
| Financial data | transactions, balances, accounts, statements, invoices, receipts you import or we extract | your documents / your inbox |
| Uploaded & imported files | statement PDFs/CSVs/XLSX and email attachments you import | you / your inbox |
| Technical | IP address, approximate country, device/browser, log data | automatically |
| Usage | features used, import history | automatically |
How we use it & legal bases
We use your data only to provide and improve the features visible to you in the app — never to sell, never for advertising.
- Authenticate you (including "Sign in with Google").
- Find and extract financial activity from your inbox, with your consent, to show it back to you for review and import.
- Scanning is continuous while your Gmail is connected, and automatic import is on by default. After you connect, Platru checks your mailbox in the background (about every few minutes) for new bank-alert emails, and charges that pass our safety checks are added to your ledger without a manual step — you are notified of each one. You can turn automatic import off (keeping manual review only) or disconnect Gmail entirely, both in the app's Gmail settings.
- Detect your country/bank (from your IP and from the bank emails in your own inbox) to improve accuracy and currency/locale defaults — you can correct this anytime.
- Store your imported originals for re-view, re-parse, and audit trail.
- Operate, secure, and debug the service.
Legal bases (GDPR Art. 6 / equivalent): your consent (Gmail access and AI processing of email content), performance of our contract with you (core features), and legitimate interests (security, abuse prevention) where permitted. You can withdraw consent at any time.
What we do in your mailbox
Gmail is optional to Platru, though not to signing in with Google:
Google presents your identity and the single Gmail permission as one
authorization, so continuing with Google grants us gmail.readonly. To use
Platru without connecting a mailbox, create an account with email and
password on the web and import statements and receipts as files. You can
connect Gmail later, and disconnect it at any time from settings.
We request read-only access (gmail.readonly) — the narrowest Gmail
permission that lets us read the messages and attachments described above.
We cannot write to your mailbox at all: not delete, not archive, not
label, not send, not change whether a message is read. Keeping the same
charge from importing twice is handled entirely in our own records, never by
marking your mail.
(Earlier versions of the app applied a "Finance MVP/Imported" label to imported messages, which required a broader permission. We removed that — along with the label itself from connected mailboxes — so the app is read-only by construction.)
AI processing of your email content
To recognize financial activity in emails whose format we don't already know, we send the relevant content to our AI provider, OpenAI, acting strictly as our data processor:
- OpenAI processes content only to return a result to us, and does not use it to train or improve any AI model.
- Retention at OpenAI: we send content with storage disabled, so it is not kept in our OpenAI account. OpenAI itself may retain API content for a limited period (up to 30 days) solely to detect and investigate abuse of its own service, after which it is deleted. Access during that window is restricted to authorized OpenAI personnel and happens only where a request is flagged for security review — it is a security control on OpenAI's systems, not a review of your mail on our behalf.
- We never use your email content to train any AI/ML model, and never build cross-user databases from it. Any bank-format knowledge reused across users is de-identified structural metadata only (how a bank formats its emails) and contains none of your personal or financial data.
- This happens only with your consent, to power features you see.
- This is automated extraction for your review — we do not use it for legal or credit decisions about you.
Finding financial emails (subject-line classification) — OFF unless you turn it on. Some financial email has a subject our keyword filters don't match (an Uber receipt, an Amazon order). To find those, this optional feature sends the subject lines and sender addresses — never the bodies — of the other emails in a scanned window to the same AI processor, to classify which look like a record of a financial event.
That includes the subjects and senders of your non-financial mail, which is why it is off by default and you must turn it on yourself — in the app's Gmail import settings. We don't enable it for you. The same guarantees apply while it is on: no training, automated-only, and only while your Gmail connection and consent are active. For emails classified as not financial we keep only a yes/no marker against the message id — no subject, sender, or content — so the same message is never sent for classification twice; the markers are deleted when you disconnect Gmail. Those emails are never fetched or processed further. Turn the feature off at any time in the same place, or by disconnecting Gmail.
Google API data — Limited Use
Platru's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
The use of raw or derived user data received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: we only use Gmail data to provide user-facing Platru features, do not transfer it except to provide those features (to the processors named below, with your consent) or as required by law/security, do not use it for advertising, and do not let humans read it except with your explicit consent, for security, to comply with law, or where the data has been aggregated and anonymized for internal operations.
"Do not let humans read it" covers Platru's own personnel and anyone we send it to for the purposes above. Our infrastructure and AI providers maintain security controls that may, in narrow and audited circumstances, let their own authorized staff review flagged content in order to detect abuse of their systems — that is the "for security" exception described above, and it is the same control every major cloud provider operates.
We do not retain Google user data to develop, improve, or train non-personalized AI or machine-learning models, and we do not store it in conjunction with any such model. The AI processing described above is inference only: content is sent to get a result back for you, and that result is shown only to you.
Who we share data with
| Recipient | Purpose | Safeguard |
|---|---|---|
| OpenAI | AI extraction of email/document content | Processor under their API terms; no training; storage disabled on our account; limited abuse-monitoring retention at OpenAI (see above) |
| Pinecone | Search index over your own transactions, so you can ask questions about your finances | Processor; stores numeric vectors together with the transaction's description, amount, currency, date, type, category and account name — and, where recorded, its location and country — so answers can be shown without a second lookup; isolated per user; deleted when you delete your data or delete your account (disconnecting Gmail keeps the transactions you reviewed, and their search index with them) |
| AWS (Cognito, S3, hosting) | Auth, storage, compute | Processor; encryption at rest/in transit; DPA |
| Expo (and Apple/Google push services) | Delivering push notifications you enable, which can name a merchant and an amount | Processor; only if you turn notifications on |
| Sign-in and Gmail access you authorize | Your OAuth grant | |
| Apple | Sign in with Apple (mobile app) | Your Apple ID authorization; we revoke it when you delete your account |
| Legal/authorities | When required by applicable law | Legal obligation |
We do not sell or "share" (as defined by US state laws) your data and we do not use it for advertising.
Storage, security & retention
- Gmail tokens and sensitive data are encrypted at rest (AES-256) and in transit (TLS); imported files are stored encrypted and isolated per user.
- We retain financial data while your account is active. Imported original files expire automatically about 30 days after upload.
- Original documents from your email. When we import an electronic invoice (a Costa Rican DTE), we keep the original XML document alongside the information we extract from it, so we can re-read it if a charge needs to be re-matched or corrected. We do not keep the original PDFs of bank statements, and we never keep the body of an alert email.
- Disconnecting Gmail erases what came from your mailbox. We revoke our access at Google and delete the records we derived directly from your mail — the parsed contents of statements, account and card identifiers read from them, sender addresses, and our record of which messages we looked at. The financial records you reviewed and kept — your transactions and invoices — remain, because those are your own records; deleting your account removes those too.
- Diagnostics. To keep automated importing honest we log why each charge was or wasn't imported. Those entries can include a card's last four digits, a merchant name and the amount — never your email's contents, attachments, or credentials — and they are deleted automatically on a short schedule (at most 30 days, and 7 days for routine entries).
Cookies
We use only the cookies needed to keep you signed in and to remember your settings. We run no advertising or analytics trackers, and no third-party cookies.
International transfers
Our systems run in the United States (AWS, us-east-1), so if you are
outside the United States your data is processed there — under Standard
Contractual Clauses and equivalent mechanisms where your law requires them,
plus our processors' data-protection terms.
Your rights
Wherever you are, you may access, correct, delete, export (portability), and object to or restrict processing of your data, and withdraw consent. Contact us at privacy@platru.com; we respond within the timeframe your law requires.
Region-specific rights
- United States: we may be a "financial institution" under the Gramm-Leach-Bliley Act. Where GLBA applies, we provide a GLBA privacy notice and an opt-out of sharing with non-affiliated third parties (sharing with our processors to deliver the service is not third-party sharing). Under California (CCPA/CPRA), Virginia, Colorado, Connecticut, Texas and other state laws you may know/access, delete, correct, and opt out of sale/sharing and targeted advertising. We do none of those things — we do not sell your data, do not share it for cross-context behavioral advertising, and serve no ads — so there is nothing to opt out of, and opt-out signals such as Global Privacy Control have no sale or sharing to stop.
- Other regions: residents of Brazil (LGPD), Canada (PIPEDA / Québec Law 25), Costa Rica (Ley 8968), and other jurisdictions have rights under their local laws; the baseline above meets or exceeds most of them. Contact us to exercise any local right.
Children
Platru is not directed to children under 18; we do not knowingly collect their data.
Changes & contact
We post changes here and update the "last updated" date shown with this policy. Your use of Platru is also governed by our Terms of Use. Questions or requests: privacy@platru.com — Platru Inc., 1990 Brickell Ave, Apt C, Miami, FL 33129, United States.
Last updated: September 3, 2026