Tax disclaimer
Earnist is an expense-tracking and education tool, not a CPA, tax preparer, or registered tax advisor. Deduction estimates, IRS Schedule C mappings, and any quarterly figures displayed in the app are illustrative and may not apply to your specific situation. Always consult a qualified tax professional before filing.
This Privacy Policy explains how Earnist LLC ("Earnist," "we," "us," or "our") collects, uses, discloses, and protects your information when you use the Earnist web and mobile applications (the "Service"). By using the Service you agree to this Policy. If you don't agree, please don't use the Service.
1. Information we collect
We collect the following categories of information:
- Account info — name, email address, password (stored as a salted bcrypt hash), athlete type, primary sport, LLC status.
- Expense data — vendor, amount, date, category, business purpose, notes, and receipt images you upload, forward via email, or text via SMS.
- Contact identifiers (optional) — your unique Earnist email-forwarding address and, if you opt in, a phone number you link for SMS receipt capture.
- Payment metadata — when you subscribe to Earnist Pro we receive a Stripe customer ID and subscription status. We do not store your full card number; Stripe handles that.
- Referral / ambassador data — your referral code, who referred you, and aggregate counts of users you've referred.
- Usage and device data — log timestamps, IP address, and basic browser/device fingerprint for security and abuse prevention.
2. How we use your information
We use your information only to operate, secure, and improve the Service. Specifically:
- Run your account, sync your data across devices, and generate dashboards, reports, and CSV exports.
- Extract structured expense data from receipt images via our AI vendor (Anthropic Claude). Receipt images are sent over an encrypted connection, processed for OCR, and not used to train any third-party model.
- Bank connections (Plaid): if you choose to link a bank or card account, we use Plaid to fetch transactions in read-only mode. You enter your bank credentials inside Plaid's window — Earnist never sees, stores, or transmits them. We store only the Plaid access token needed to fetch transactions and a list of transactions themselves (date, amount, merchant, category). Earnist can never move money, initiate transfers, or change your bank settings. You can disconnect any linked bank at any time from Settings → Bank connections; future syncs stop immediately.
- Process Pro subscription payments via Stripe.
- Send transactional and account-related notifications. Marketing email is opt-out at any time in Settings.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Comply with applicable legal obligations.
3. Who we share information with
We do not sell your personal information. We share limited data with a small set of subprocessors that help us run the Service:
- Anthropic — receives receipt images and SMS text for OCR.
- Plaid — powers read-only bank/card account linking and transaction sync. Only used if you explicitly connect an account.
- Stripe — payment processing, subscription billing, and tax invoices.
- Twilio — inbound SMS/MMS parsing if you opt in.
- Resend — outbound transactional email (password resets, receipts, tax reminders).
- Cloud hosting — encrypted-at-rest database and application servers.
- CPA Connect share links — when you generate a read-only share link, anyone with the link can view your expense data until you revoke it.
We may also disclose information in response to lawful legal process, to protect the rights and safety of users and the public, or in connection with a merger, acquisition, or sale of assets (in which case continued use of the Service after notice of such transfer constitutes consent).
4. Your rights and choices
You can at any time:
- Export — download a full JSON copy of your account data from Settings.
- Edit / update — change your athlete type, sport, LLC status, and notification preferences.
- Revoke shares — revoke any active CPA Connect share link.
- Delete — permanently delete your account and all associated data from Settings. Deletion is immediate and irreversible.
- Unlink — unlink your phone number or stop forwarding receipts at any time.
If you are a California resident, you have additional rights under the CCPA / CPRA including the right to know, the right to delete, and the right to limit the use of sensitive personal information. To exercise these rights email legal@earnist.app.
5. Security
We use industry-standard safeguards: TLS 1.2+ enforced for all external traffic, bcrypt password hashing (per-password salt), JWT-bearer authentication with 30-day rotation, signed webhook verification (Stripe and Plaid), and Fernet (AES-128 CBC + HMAC-SHA256) encryption for stored Plaid access tokens. Application-level per-user access controls enforce that no user can read another user's records. Our hosting provider (Emergent) manages disk-level encryption on the underlying storage. We do not currently offer application-level multi-factor authentication; this is on our roadmap. No system is perfectly secure, but we work hard to keep yours safe. Report security concerns to security@earnist.app.
6. Data retention
We keep your data only as long as we need to provide the Service and meet legal / tax-recordkeeping obligations:
- Active accounts: personal data (expense records, income records, mileage, categories) is retained for as long as your account is active. This is the whole point of a tax-tracking product — the IRS requires taxpayers to retain records for at least 3 years and up to 7 years for underreported income.
- Deleted accounts: when you delete your account from Settings, all personal identifiers and financial records are removed from active systems within 24 hours. A minimal deletion-audit record (hashed email, timestamp, IP) is retained for up to 7 years for compliance evidence.
- Bank connections: when you disconnect a bank in Settings, or delete your account, the linked Plaid Item is revoked via Plaid's item/remove endpoint and the access token is deleted from our systems. Already-imported transactions that you confirmed as business expenses remain in your account (audit trail); unconfirmed pending transactions from that bank are purged.
- Support tickets: retained for 2 years for quality and audit purposes, then automatically purged.
- Payment records: Stripe retains billing history under its own retention policy (see Stripe's Privacy Policy). We store only a Stripe customer ID and subscription status locally.
- Backups: encrypted database backups roll off within 30 days.
You can at any time request a full export of your data (Settings → Data → Download all my data) or request deletion (Settings → Data → Delete account). Deletion is immediate and irreversible from your perspective; residual copies in encrypted backups are purged as backups age out (max 30 days).
7. Children
Earnist is not directed to children under 13. If a parent or guardian wishes to track expenses related to a junior athlete, the account must be created and managed by the adult. We do not knowingly collect personal information from children under 13.
8. International transfers
Earnist is operated from the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S.
9. Changes to this Policy
If we make material changes we'll notify you by email and post a new "Last updated" date. Continued use of the Service after notice constitutes acceptance.
10. Contact
Earnist LLC, California, USA. Email: legal@earnist.app.
Earnist provides expense tracking and educational content. Earnist is not a CPA, tax preparer, or registered tax advisor. Nothing in the Service is tax, legal, or financial advice. Always consult a qualified professional.