Capitowl uses the companies below to run the App. This page lists each one, what it does for us, what information it receives, and whether deleting your Capitowl account removes your information from it. We update this page when a provider changes; the Privacy Policy explains the categories and your rights.
How to read “Deletion”: Yes means that when you delete your account, Capitowl removes or revokes your information at that provider. Not applicable means the provider never receives anything that identifies you. Not yet means the provider holds information linked to you and we have not yet built the deletion step; we say so rather than leave it implicit, and we are working on each one.
Account aggregation and exchanges
| Provider | What it does for us | What it receives | Deletion |
|---|
| Plaid | Connects bank, card, and brokerage accounts | Your institution login, entered in Plaid’s own screen and never stored by Capitowl; account and transaction data | Yes. The connection is removed at Plaid when you delete your account. Account and transaction data already delivered to Capitowl is covered by the Privacy Policy’s retention section. |
| Akoya | Connects accounts at institutions that use Akoya | Same as Plaid | Yes. Same mechanism. |
| Coinbase | Connects your Coinbase account, if you choose to | Authorization to read your Coinbase balances, transactions, payment methods, and profile | Yes. The authorization is revoked at Coinbase when you delete your account. |
| Alchemy | Reads balances for Ethereum wallets you add by address | The wallet address | Not applicable. A wallet address is not linked to your Capitowl account at the provider. |
| mempool.space | Reads balances for Bitcoin wallets you add by address | The wallet address or extended public key | Not applicable. Same as above. An extended public key reveals all addresses of that wallet; add one only if you are comfortable with that. |
Sign-in, notifications, and device integrity
| Provider | What it does for us | What it receives | Deletion |
|---|
| Google Firebase Authentication | Sign-in and account security | Email address and sign-in identifiers; for Google or Apple sign-in, the name that provider supplies. Capitowl does not write your name to it. | Yes. The sign-in account is deleted when the grace period ends. |
| Google Firebase Cloud Messaging | Push notifications | A device push token | Yes. Stored push tokens are deleted when the grace period ends. |
| Google Firebase App Check and Apple App Attest | Confirm requests come from a genuine copy of the App | Device attestation only | Not applicable. |
| Apple Push Notification service | Delivers push notifications on iOS | A device push token | Not applicable. Governed by Apple; no account identifier. |
Payments and subscriptions
| Provider | What it does for us | What it receives | Deletion |
|---|
| Apple App Store / Google Play | Process purchases | Your store account and payment method, held by the store; Capitowl sees only purchase status | Not applicable. Governed by the store. |
| RevenueCat | Tracks subscription status across platforms | Your Capitowl account identifier, email address, name, and purchase history | Not yet. Your customer record is not removed at deletion. We are adding that. |
Analytics and stability
| Provider | What it does for us | What it receives | Deletion |
|---|
| Google Firebase Analytics | Measures how the App is used | Usage events, your account identifier, and five coarse account attributes (subscription state, connected-institution bucket, setup stage, notification permission, platform). No amounts or account details. | Not yet. The deletion request is recorded when you delete your account; sending it to Google is not yet switched on. We are completing that now. |
| Google BigQuery | Stores an export of the analytics above for our own analysis | Same as Firebase Analytics | Not yet. Same as above. |
| Google Firebase Crashlytics | Crash and error reports | Crash details keyed to a device installation identifier; no account, name, or email | Not applicable. Nothing is linked to you. |
| Google Firebase Performance Monitoring | Measures app performance: startup time, screen-rendering speed, and network-request timing | App-start, screen-rendering, and network-request timing data, keyed to a device installation identifier; no account, name, or email | Not applicable. Nothing is tied to your account; the data is keyed only to a device installation identifier. |
Support
| Provider | What it does for us | What it receives | Deletion |
|---|
| Intercom | In-app support chat and help centre | Your Capitowl account identifier, email address, your device’s push token, and your messages to support | Not yet. Your contact and conversation history are not removed at deletion. We are adding that. |
Mailboxes you connect
| Provider | What it does for us | What it receives | Deletion |
|---|
| Google (Gmail) | Reads financial emails you authorize, to find receipts, statements, and subscriptions | The mailbox access you grant; matching messages and attachments | Yes. Access is revoked and the stored messages and attachments are deleted when the grace period ends. |
| Microsoft (Outlook) | Same, for Outlook mailboxes | Same | Partly. Stored messages are deleted when the grace period ends. Microsoft provides no way for us to revoke the mailbox permission on your behalf; revoke it yourself at account.live.com. |
Assistant
| Provider | What it does for us | What it receives | Deletion |
|---|
| OpenAI, Anthropic | Power the in-app assistant | The messages you send in the assistant and a snapshot of your accounts (names, last four digits, balances, budgets, recurring payments). When the assistant looks up your profile, your name, phone number, date of birth, and account identifiers are included. | Not yet. These providers offer no per-user deletion for API traffic. We are reducing what the assistant sends and confirming the providers’ retention terms. |
Hosting and processing
| Provider | What it does for us | What it receives | Deletion |
|---|
| Google Cloud (Cloud Run, Cloud SQL, Cloud Storage, Pub/Sub, Document AI) | Runs the App’s servers and databases; extracts text from receipts you upload or that arrive in a connected mailbox | All information the App stores | These are Capitowl’s own systems. What deletion removes from them is described in the Privacy Policy. |
| Provider | What it does for us | What it receives | Deletion |
|---|
| Polygon, CoinGecko, OpenFIGI | Security and crypto prices and identifiers | Ticker symbols and identifiers only | Not applicable. |
| RentCast | Estimates home values | The property address or coordinates and the property details you enter (bedrooms, bathrooms, square footage). No account identifier. | Not applicable. Whether the provider retains the address is governed by its own terms. |
| Google Maps | Address lookup, directions, and maps | Address text, coordinates, and place lookups sent through Capitowl’s servers; map tiles are fetched by your device directly | Not applicable. |
Not in use
Resend is configured for sending transactional email but is not in use; verification and password-reset emails are sent by Google Firebase Authentication.