1. Who we are
Guaca is a personal finance application available at useguaca.com and as apps for iPhone, iPad, and Mac. This policy describes what data we collect, how we use it, and the rights you have over it. It applies to the web app and to the native Guaca apps.
2. Data we collect
Account data. Your name, email address, and — if you sign in with Google — the profile picture associated with your Google account. If you sign in with Apple, we receive only the name and email address Apple shares with us (which may be a private relay address if you choose to hide your email).
Financial data you enter. Accounts, assets, debts, transactions, budgets, income, and your retirement plan settings. You enter this data yourself and it is visible only to you.
Data from integrations you connect. We process only the data needed to provide each integration. For MCP connections to AI assistants, Guaca issues revocable OAuth grants and returns only the financial fields needed by the tool you or the assistant invokes.
Technical and connector data. Session cookies and OAuth grant records keep you signed in and connected. Security logs may include your internal user identifier, connected client identifier, tool name, response status, and timing. MCP tool arguments and results are not written to application logs.
Usage analytics. When usage analytics is enabled, Guaca records your last activity and distinct days used while the app is in the foreground and connected. Signed-in activity is linked to your Guaca account. The native apps use Google Analytics for Firebase for usage and onboarding events, with a random account identifier to link future events across signed-in devices. We do not send your name, email address, financial data, or transaction details to Google Analytics. You can disable usage reporting in Settings > Privacy in the native apps, or on the Account page on the web; the choice applies to that device or browser. Account activity records are retained while your account exists and deleted with it. Analytics is not used for advertising.
3. Sign in with Google or Apple
If you choose to sign in with Google, we request only your basic profile information: name, email address, and profile picture. We do not access your email messages, contacts, files, or any other data in your Google account. If you sign in with Apple, we receive only your name and email address — never any other data from your Apple account.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. How we use your data
- Provide the service: display your net worth, budgets, expenses, and projections.
- Sync your information across your devices (web, iPhone, iPad, and Mac).
- Run calculations such as valuations, currency conversion, and retirement planning.
- Answer questions through Guaca's built-in AI chat or an external AI assistant you connect through MCP. Only the messages, tool inputs, and financial context needed for the requested response are processed; the external assistant handles data it receives under its own terms and privacy policy.
- Manage your subscription, if you have one.
We do not sell your data or use it for advertising.
5. Who we share data with
We share data only with the infrastructure providers required to operate Guaca, which process it on our behalf:
- Application hosting, networking, and execution (Oracle Cloud Infrastructure and Cloudflare).
- Database (Supabase).
- Cross-device sync (PowerSync).
- Google authentication (Google LLC).
- Apple authentication (Apple Inc.).
- Subscription management (RevenueCat and the app stores).
- AI providers and assistant platforms, only when you use Guaca's financial chat or explicitly connect and invoke Guaca through MCP.
We may also disclose information when required by law or a competent authority.
6. Retention and deletion
We keep your financial data and active connector grants while your account exists. Disconnecting an MCP client revokes its access; account deletion removes your account data within 30 days at most. Limited security logs are retained only as long as reasonably needed to prevent abuse, diagnose incidents, and meet legal obligations, then deleted or de-identified. See Delete your account for the full steps.
7. Security
All communication with Guaca is encrypted in transit using TLS. Database access is restricted, and your financial data is only reachable from your own account. Still, no system is infallible: we recommend using a unique password, Sign in with Google, or Sign in with Apple.
8. Your rights
Under Colombia's personal data protection regime (Law 1581 of 2012) and equivalent regulations, you have the right to access, update, rectify, and delete your personal data, and to revoke your consent to its processing. You can exercise these rights from within the app or by writing to our contact email.
9. Children
Guaca is not directed at people under 18, and we do not knowingly collect data from minors. If you believe a minor has provided us with data, contact us so we can delete it.
10. Changes to this policy
We may update this policy from time to time. The current version will always be published on this page with its update date, and if a change is significant we will notify you in the app.
11. Contact
For any privacy questions or to exercise your rights, write to [email protected].