Legal
Last updated: August 31, 2026
Privacy policy
Who we are
Mintro (mintro.money) is an envelope budgeting service operated from Canada. Mintro holds your budget — envelopes, entries, and the transaction data needed to recognize your spending — and lets the AI agent you choose do the bookkeeping. We are not a bank. We do not move money. We never sell your data.
What we collect and store
Your account identity (name, email, organization membership) is managed by Clerk, our identity provider. Your budget — envelope names, targets, entries, papers you or your agents write — is stored by us. From your bank, via Plaid, we store what is needed to recognize a transaction: its date, amount, currency, the description your bank sends, the merchant name where Plaid provides one, whether it is still pending, Plaid's spending-category hint, and account details (nickname, last four digits, type, and the institution name). When you first connect a bank we request about 90 days of history, not your full bank history. We do not store your bank credentials, and we do not keep raw bank payloads. A transaction you or your agent have not filed into an envelope is deleted after 45 days; once filed, it stays with your budget.
Bank connections
Bank linking happens on Plaid's hosted pages. Your bank username, password, and MFA codes are entered with Plaid (or your bank) and never pass through Mintro or any agent. By connecting a bank you agree that Plaid may process your information in accordance with Plaid's End User Privacy Policy. Mintro stores the access token Plaid issues, encrypted, to fetch your transactions. We use the data Plaid returns only to provide the budgeting service you asked for. We do not sell or rent it to marketers or anyone else, we do not use it for advertising, and we do not use it to build products unrelated to your budget.
Agents and API keys
Agents act on your budget only with an API key you (or your organization) issue, scoped to what that agent may do. Every entry records which key filed it. Revoking a key ends that agent's access within about a minute — we cache key verification briefly to keep the API fast. Keys are managed by Clerk; Mintro never sees or stores key secrets.
Payments
When paid plans open, billing runs on Clerk Billing with Stripe as the payment processor. Your card details go to Stripe, never to us.
Your rights: export and deletion
Your budget belongs to you. You can export it as one document at any time — every envelope, entry, paper, filed transaction and anything still sitting in your inbox (GET /export, or ask your agent). You can request deletion of your account and budget; what that removes, and the two things it does not, are set out under Data retention below. We honour access, correction, and deletion requests under Canada's PIPEDA. Write to privacy@mintro.money.
Cookies
The marketing site sets no cookies and runs no analytics or trackers. The console (app.mintro.money) uses Clerk's essential session cookies to keep you signed in, and a session-presence cookie lets mintro.money show "console" instead of "sign in" when you have one. That is the complete list. No advertising cookies, no third-party trackers, ever — which is why there is no cookie banner.
Security
All traffic is encrypted in transit (TLS, HTTPS enforced). Plaid access tokens are encrypted at rest with AES-256-GCM; encryption keys and all secrets live in a managed secrets vault, never in code. Your bank credentials are never transmitted to or stored by Mintro in any form. API keys are scoped per agent and verified on every request; revocation takes effect within about a minute. The signing secrets for any outbound webhooks you configure are also encrypted at rest.
Data retention
A transaction that is never filed into an envelope is deleted automatically 45 days after we receive it. Filed transactions, entries, envelopes, and papers are retained as your budget until you delete them or your account. On account deletion we give you a final export, remove your bank connections at Plaid, revoke your API keys, and delete your budget and transaction data from our database. Two honest caveats: your sign-in account itself is held by Clerk and is deleted separately on request, and our database backups roll off on their own schedule, so deleted data can persist in backups for a short period after it is gone from the live service. Deletion requests are honoured within 30 days.
Service providers
We use Plaid (bank connectivity), Clerk (identity, keys, billing), Stripe (card payments, via Clerk Billing), Vercel and Fly.io (hosting), Neon (database), Inngest (background processing), Cloudflare (DNS and email forwarding), and Doppler (secrets management). Each receives only what its function requires. Mintro is operated from Canada, but these providers process data outside Canada — our database is hosted in the United States. By using Mintro you consent to that transfer. Questions about how your information is handled, including access, correction, and deletion requests, go to privacy@mintro.money, which reaches the person accountable for privacy at Mintro.
What we never do
No ads. No selling or sharing your financial data. No money movement. The subscription is the whole business model.
Terms of service
Mintro provides budgeting record-keeping, not financial advice, and is provided as-is without warranty. You are responsible for the agents you connect and the keys you issue to them. Your plan includes a set number of bank connections; beyond that, extras are billed as listed on the pricing page. You may export your budget and leave at any time; we may suspend accounts that abuse the service. These terms are governed by the laws of Canada. Questions: legal@mintro.money.
We do not move money. We are not a bank.