HRC Ledger

Privacy Policy

Version 1.0Society Venture Investments, LLC

Who we are, and what this covers

HRC Ledger is an advisory financial planning service for self-employed people and their households. It is operated by Society Venture Investments, LLC, a Virginia limited liability company, at 1100 15th St NW, Washington, DC 20005 ("we," "us," or the "Company").

This notice explains what information the Service collects, why, who else touches it, how long we keep it, and how to get it out or get it deleted. It is part of our Terms of Service.

The Service is offered only to residents of the United States, for use in the United States.

Questions, or any request under this notice: contact@societyvc.com.

The short version

A summary for orientation. The sections below are the actual commitments — read those.

  • We do not sell or rent your information. We never have, and we do not operate an advertising or lead-generation business.
  • We run no analytics or tracking software. There is no advertising SDK, no product-analytics SDK, no session recording, and no cross-site tracking in the app — not configured off, not present.
  • We use no cookies or web beacons to track you, because the Service is a native iOS app rather than a browser product.
  • We do not know your location. We ask your device for its time zone so the Service can tell what "Sunday" means for you. We do not derive location from your IP address.
  • We never hold your banking password, and we hold no payment card details.
  • We never move your money. That is a term of the Terms of Service, not just a practice.

What we collect

Everything here is either something you typed, something a bank connection returned, or something the Service needed in order to reach you.

Account and identity. Your email address, your authentication identity at our identity provider, your role in the household, and a profile image if you set one. We never create, see, or store your password — authentication happens at our identity provider.

Household members. The Service models a household, so it stores, for each person in it: a display name, a role and relationship label you write yourself, whether they are a primary earner, whether they are included in the spend plan, an optional profile image, and an optional date of birth. Date of birth is never required and is never defaulted. Age is derived when needed and is not stored as a field.

Contact details and consent. A phone number or push token for each channel a person has enabled, together with the consent state for that channel and when it was set. No channel is enabled by default.

Messages. The full text of messages exchanged with the assistant — both what you send and what it replies — is stored so that you and your household have a transcript. Outbound messages routinely contain financial figures about your household.

Financial data from connected accounts. For each connection: the institution's name, an identifier for the connection, and an encrypted access token. For each transaction: date, amount, description, merchant name, an account reference, and a category the Service inferred.

Financial data you enter or the Service learns. Accounts and balances; debts with their interest rate, statement balance, minimum payment and due dates; income sources, which may include the name of an employer or client; goals, anticipated events, and reserves you describe; and records of arrangements between household members, such as an allowance or an informal family loan, including free-text notes you write on them.

Business information. If you tell the Service about a business you own: its name and the kind of entity, and the attribution of accounts and transactions to the business or personal book.

Tax settings. The rates and assumptions used to estimate a reserve. We do not collect or store tax returns, filings, or any tax identification number.

Subscription status. Which product a household is subscribed to, whether it is active, and until when.

Time zone. Reported by the device of the operator who created the household, so scheduled guidance arrives at a sensible local hour. You can correct it in settings.

What we deliberately do not collect

Verified against the database schema: there is no column anywhere for a Social Security number, a tax identification number, an EIN, a full bank account number, a routing number, a card number, or a card's last four digits. The Service does not request the bank-data product that would return account and routing numbers, because it has no use for them and no ability to move money.

Information about people who are not users

This is the part of this notice most worth reading, because it is unusual.

The Service models a household, and most people in a household never create an account. A spouse, a partner, a child, or a relative in your care can be modelled as a member — a person the Service holds information about — without ever signing in, seeing the app, or agreeing to anything.

Information about those people is entered by an operator of the household, not by them. It can include their name, their relationship to the household, an optional date of birth, a photograph, a phone number, income attributed to them, and — because transactions attribute to the scopes a member belongs to — their spending.

If you are an operator, the Terms of Service require you to have the authority and permission of every person whose information you enter, and to be the parent or guardian of any minor you model.

If you are a member of a household and not an operator, you still have privacy rights, and we honor them directly. You do not need an account, and you do not need an operator's permission, to exercise them. Write to contact@societyvc.com. See Your choices and rights below.

You should also know two things about how households work:

  • Every operator of a household can see all of that household's financial information — including information about every member. Marking finances "separate" changes how figures are grouped and totalled; it does not hide them from an operator.
  • If a member has no contact channel of their own, notices about them are delivered to the household's heads of household instead.

How we use information

We use what we collect to:

  • build the financial model the Service reasons over, and produce plans, forecasts, shortfall warnings, tax reserve estimates and answers to questions you ask;
  • deliver those to you on the channels you have enabled;
  • learn recurring facts — a bill's cadence, a due date, a category — from transaction history, so you are not asked to type them in;
  • authenticate you, keep your household's data separate from every other household's, and investigate abuse or fraud;
  • provide support when you contact us;
  • fix and improve the Service; and
  • comply with law.

We do not use your financial information to build advertising profiles, to score you, or to make any automated decision that has a legal or similarly significant effect on you. We make no eligibility determination about you, and we provide none to anyone else.

What we do not do

Stated as commitments, not as description, so that changing them requires changing this notice.

  • We do not sell or rent your personal or financial information, and we have never done so. We do not "share" it for cross-context behavioral advertising as California defines that term.
  • We do not disclose it to affiliates for their own marketing.
  • We do not build or commercialize aggregated or de-identified datasets from your financial data.
  • We do not permit any model provider to train on your data, and we do not opt in to any training or data-sharing programme a provider offers.
  • We display no advertising, and we currently receive no referral, affiliate, or lead-generation compensation. If that changes, we will disclose it clearly where it appears, and update this notice.

Who else handles your information

A short list, because the Service uses few vendors and no advertising or analytics vendors at all.

WhoWhat they doWhat reaches them
ClerkAuthentication and identityYour email, authentication identity, profile image, and household membership
PlaidRead-only bank dataYour banking credentials go to Plaid and your institution, never to us; they return transactions and balances
TwilioText messagesThe recipient's phone number and the message body, which may contain financial figures
ResendAccount and legal emailYour account email address and the notice itself — a change to the terms, a response to a privacy request, a warning before a household is deleted
Expo (and Apple's push service)Push notificationsA device push token and a notification title. Push titles are deliberately free of figures
RevenueCatSubscription statusAn identifier for your household and your subscription state. Never payment details
NeonDatabase hostingEverything the Service stores
RenderApplication hostingEverything the Service processes
A language model providerPhrasing answersSee Automated systems and AI below
BraintrustDiagnostics for model outputModel input and output, only where this is enabled. See below

Apple is the merchant of record for any purchase and handles billing under its own terms; we never receive your card details.

We may also disclose information where the law requires it, to enforce our agreements, to prevent fraud or harm, or in connection with a merger or sale of the business — in which case, as the Terms of Service commit, any successor is bound by the promises in this notice for information collected before the transfer unless you agree otherwise.

Connected financial accounts

Connections are read-only. We request only transaction and liability data. We do not request, and cannot use, any product that would let us move money, initiate a payment, or obtain account and routing numbers for payment.

The access token that lets us read your data is encrypted at rest by us using AES-256-GCM, with the key held in the hosting platform's secret store and never in our source code.

When you disconnect an account in the app, we delete the transactions we ingested through it and destroy the access token. Two things that does not do:

  • Figures already derived from that data — plans, forecasts, learned billing patterns — are retained in archived form so your history stays explainable. Ask us and we will delete those too.
  • It does not revoke the authorization you granted at your bank or at Plaid. To end that, revoke access directly with your institution and with Plaid as well.

Automated systems and AI

The Service uses a language model to phrase answers. The figures themselves are computed by deterministic software, not by the model — the architecture separates the two so the model cannot reach the calculation engine.

What is sent to a model:

  • Where the model runs outside our own infrastructure, we send the minimum context needed, with member names and direct identifiers removed. That context does include financial figures — amounts, balances, dates.
  • Text you write is sent as you wrote it. If you type a name or an account number into a question, it goes as typed. Avoid putting either in a message if you would rather it not leave our systems.
  • Where the model runs on our own infrastructure, it may receive fuller context including member names, because no third party is involved.

Diagnostics. We can enable a third-party service (Braintrust) that records the input and output of model calls so we can check answer quality and safety. When it is enabled, those records include the financial figures in an answer, and on some configurations household member names. It is off unless a key is configured, and it is used for nothing else — not advertising, not analytics about you.

How long we keep information

We keep your information for as long as your household has an account with us, because the Service's value is in the history it reasons over — a forecast is built from a year of transactions.

Two specifics worth stating plainly:

  • Archiving is not deletion. When you remove a member, a scope, or a financial resource, the Service marks the record archived and keeps it, so past figures remain explainable and auditable. Removing something in the app does not erase it.
  • Message transcripts are currently kept for the life of the account. They are not automatically pruned.

Our internal event queue is purged on a 30-day cycle. Backups are retained on their normal rotation and deletions propagate as those age out. Where we must keep something to comply with law, resolve a dispute, prevent fraud, or enforce our agreements, we keep the minimum necessary, restrict access to it, and delete it when the reason lapses.

Your choices and rights

Anyone whose information the Service holds may exercise these rights — including household members who have no account. We do not discriminate against anyone for exercising them.

You may ask us to:

  • tell you what we hold about you, where it came from, why we have it, and who we have disclosed it to;
  • give you a copy of it;
  • correct anything inaccurate;
  • delete it; or
  • stop contacting you on any or all channels.

How to ask. Write to contact@societyvc.com. You can also reply STOP to any text message to stop texts immediately, turn off notification permissions for the app in your device settings, or change channel settings in the app.

How we handle it. We will acknowledge your request within 10 days and complete it within 30 days, or tell you why we need longer. We have to verify your identity first — using information already associated with the account, or a code sent to a contact detail we hold — because this is financial information and the alternative is handing it to whoever asks. An authorized agent may act for you; we may still verify you directly.

If we deny a request, we will tell you why, and how to appeal.

Two honest notes about deletion:

  1. Erasure is a manual operation we perform on request. It is not yet a button in the app. It is deliberate, logged, and we will tell you what was deleted and what was retained.
  2. Because household records are archived rather than destroyed in ordinary use, "delete my account" and "remove this member" are different requests. Ask for erasure explicitly and you will get erasure.

State privacy rights. If you live in California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, the rights above are the ones those laws give you, and we extend them to everyone regardless of where they live. Because we do not sell or share personal information, there is nothing to opt out of — but you may still tell us not to, and we will record it.

Financial privacy. As a provider of financial advisory services we are treated as a financial institution under the federal Gramm-Leach-Bliley Act. We do not disclose nonpublic personal information about you to anyone except as described in this notice.

Children

The Service is not offered to anyone under 18, and a person under 18 cannot hold an account or operate a household.

A minor may be modelled as a household member — that is the point of a household product — in which case an adult operator has entered their information and, under the Terms of Service, has represented that they are that child's parent or guardian. Operators may not enrol a phone number belonging to anyone under 18 to receive messages from the Service.

If you believe a child's information is in the Service without a parent or guardian's authority, write to contact@societyvc.com and we will delete it.

Security

What is actually true, rather than what is reassuring.

  • Financial data and personal identifiers are kept out of our application logs by a redaction layer, and an automated test suite runs on every change and fails the build if a sensitive value reaches a log.
  • Bank and accounting access tokens are encrypted by us with AES-256-GCM before they are stored.
  • Data is encrypted in transit, and the database and its backups are encrypted at rest by our hosting provider.
  • Every request is authenticated and scoped to the requesting household, and access to production systems is limited to authorized personnel.
  • Message transcripts are stored in ordinary database columns. They are protected by the provider's at-rest encryption, but unlike access tokens they are not separately encrypted by us — so do not treat a message to the assistant as a vault.
  • Text messages are not an encrypted channel and may be visible on a lock screen.

No method of transmitting or storing information is completely secure, and we cannot guarantee the security of information you provide. If a breach affects your information, we will notify you as the law requires.

Changes to this notice

We will update this notice as the Service changes. The date at the top always reflects the current version. If we make a material change — particularly one that widens how your information is used — we will tell you in the Service and by email before it takes effect, and where the law requires your consent, we will ask for it rather than assume it.

Contact

Society Venture Investments, LLC 1100 15th St NW, Washington, DC 20005 contact@societyvc.com