Privacy Policy
Last updated: October 8, 2026
Introduction
Churn ("we," "our," or "us") helps you pick the right credit card for each purchase and keep track of fees, bonuses and benefits. Churn is available at getchurn.app, as an iPhone and Android app, and as a Chrome extension. This policy explains what we collect in each of them, why, who we share it with, how long we keep it, and how to delete it. Questions go to privacy@getchurn.app.
Information We Collect
Account
Your email address and password (stored hashed by Supabase Auth), or, if you sign in with Google, the name, email address and profile picture Google provides. Your account works on the web and in the mobile app.
Your wallet and settings
The cards you add and what you record about them: opened and annual-fee dates, welcome-bonus targets and progress, notes, benefit usage and status. Also your monthly spending estimates, country, card-type preference, the credit score range you choose (self-reported, never a credit check), goals, recurring charges you track, achievements and notification state. If you use Churn without an account, this stays on your device. On the web, the annual income you enter stays in your browser.
Bank and card data (optional, through Plaid)
If you link a bank or card account, Plaid sends us: the accounts' names, types and last four digits; your transactions (date, amount, merchant name and category, which account); for credit cards, liabilities such as APR, statement balance, minimum payment, due dates and credit limit; and recurring payments Plaid detects. We use it to track welcome-bonus spending and benefits, show which card would have earned more, and power the paid analysis pages. We store Plaid's access token encrypted. We never receive your bank username or password.
Virtual card (mobile, beta)
If you create a Churn virtual card, Lithic issues it and tells us about the transactions made with it (merchant, category, amount) so we can recommend the right card. We don't store the card number.
Household
If you create or join a household, we store its members and the email addresses invited. Members can see each other's cards and spending; nobody outside the household can.
Payments and subscriptions
For Churn Pro bought on getchurn.app, Stripe handles your payment details; we keep your Stripe customer id, plan, status and renewal date. For purchases in the mobile app, Apple or Google handle payment and RevenueCat tells us your subscription status.
AI chat (Churn Pro)
Questions you ask the AI assistant are sent, with a summary of your wallet, to Anthropic to generate the answer (see below). The mobile app asks for your permission before your first chat message and sends nothing until you allow it; you can withdraw it in Settings. We don't keep chat transcripts on our servers; we record when a message is sent to enforce the daily limit.
The one exception is an answer you report. In the mobile app you can report an AI answer or call script that is offensive, harmful or wrong. We then keep that answer, with the reason and note you add, linked to your account, so we can review it. Nothing else from the conversation is sent.
Location
If you allow it, the web app (browser geolocation) and the mobile app (location services, including in the background if you choose "Always") use your location to suggest the spending category of the place you're at. Coordinates are sent to OpenStreetMap's Nominatim service to look up the place; we don't store your location history.
Device
If you turn on notifications in the mobile app, we store your device's push token (and Live Activity token on iPhone). If you add a card to Apple Wallet, we store the pass's serial number.
Chrome extension
The extension looks at the address of the site you're on to suggest a card, without sending it to us. If you sign in and use Amex offer sync on americanexpress.com, the offers listed in your Amex account (merchant, card, expiry) are saved to your Churn account.
Emails, forms and referrals
Your email preferences; messages you send through the contact form; your email address if you join the newsletter or an app waitlist; and, for the referral program, your referral code and who signed up with it.
Usage, diagnostics and feedback
Product analytics (PostHog) and page-view and speed measurements (Vercel), error reports (Sentry), which card links you click (with your account id if you're signed in), and card-data corrections you report.
What We Don't Collect
- The numbers, CVVs or PINs of your own credit cards
- Your bank username or password (you enter them with Plaid, not with us)
- Credit reports or credit scores from a bureau (only the range you choose yourself)
- Social Security, Social Insurance or other government ID numbers
We don't sell your personal information, and we don't share it for cross-context behavioral advertising.
How We Use Your Information
- Rank your cards for each spending category and recommend new ones
- Calculate your Churn Score, missed rewards, annual-fee value and other analysis
- Track welcome-bonus deadlines, annual fees and benefits, and remind you about them
- Sync your data between the web, mobile app and extension when you're signed in
- Run Churn Pro: billing, the AI assistant, household and the other paid features
- Send the emails you've chosen to receive, and account and billing emails
- Answer your messages and handle privacy requests
- Find bugs, keep the service secure and see which features are used
Service Providers
We share personal information only with the services below, which process it for us to run Churn, and when the law requires it.
- Supabase — Sign-in, our database and server functions, for web and mobile. Your account, wallet, preferences and synced data are stored here (United States). Privacy policy.
- Vercel — Hosts getchurn.app. Vercel Web Analytics and Speed Insights record page views and page-speed measurements without cookies. Privacy policy.
- GitHub — Runs our nightly database backup (GitHub Actions). The backup copies the whole Churn database, including your account, wallet and bank data, and encrypts it on GitHub's servers; GitHub stores the encrypted backup files for 30 days, then deletes them. Privacy policy.
- Stripe — Processes Churn Pro payments made on getchurn.app. Stripe holds your card details; we only store your Stripe customer id, plan, status and renewal date. Privacy policy.
- Apple and Google — App Store and Google Play distribute the mobile app and process in-app purchases, and Apple and Google deliver its push notifications. Google also provides Sign in with Google (including One Tap on the web). On iPhone, Apple provides Sign in with Apple: we receive your name the first time you sign in and your email address, or a private relay address if you choose to hide yours. Privacy policy.
- RevenueCat — Manages App Store and Google Play subscriptions for the mobile app. It receives your Churn account id and your purchase history in the store. Privacy policy.
- Plaid — Connects your bank or card accounts when you choose to link them, and sends us the account and transaction data described above. You sign in to your bank through Plaid; we never see those credentials. Privacy policy.
- Lithic — Issues the optional Churn virtual card (mobile, beta) and reports the transactions made with it. Privacy policy.
- Anthropic — Generates AI chat answers (Churn Pro). Your messages and a summary of your wallet (cards, spending estimates, country, and on mobile your current location's merchant category if you've allowed location) are sent with each question. Anthropic's commercial terms don't allow it to train its models on this data. Privacy policy.
- PostHog — Product analytics: which pages and features are used. Before you sign in, analytics on the web is anonymous and sets no cookies; after you sign in, events are linked to your Churn account id (not your name or email). Privacy policy.
- Sentry — Error and crash reports from the web and mobile apps and our servers: what went wrong, browser or device details and, for some server errors, your Churn account id so we can trace the problem. Privacy policy.
- Resend — Delivers our emails (reminders, weekly summary, account email) and may hold the newsletter mailing list. Privacy policy.
- Expo — Delivers push notifications to the mobile app (using your device's push token) and ships app updates. Privacy policy.
- OpenStreetMap Nominatim — Turns your location into a nearby place name when you use location-based suggestions. Your coordinates are sent at that moment and are not stored by Churn. Privacy policy.
Card details such as fees and reward rates come from CardAPI, a card database we also run; no personal information is sent to it.
Google User Data
Churn's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data accessed
When you sign in with Google, Churn receives your basic profile (name, email address and profile picture). We don't request access to Gmail, Drive, Calendar, Contacts or any other Google service.
How we use it
Only to create and run your Churn account: your email is your account identifier and where account email goes, your name personalizes the app, and your picture is shown in the app. We don't use it for advertising or anything unrelated to Churn.
Sharing, storage and deletion
Google data is stored in Supabase with the rest of your account and is not shared with anyone else. Deleting your account (see below) deletes it. You can also revoke Churn's access in your Google Account permissions.
Affiliate Links
Some links to card issuers may be affiliate links, which can earn Churn a commission if you're approved, at no cost to you. Affiliate links are labelled where they appear. Affiliate relationships never affect how Churn ranks or recommends cards. See our advertiser disclosure.
Cookies and Local Storage
- Sign-in cookies (Supabase) — keep you signed in. Essential.
- Local storage — your wallet, settings and preferences on this device, so the app loads instantly.
- Analytics — none before you sign in. Once you're signed in, PostHog stores an identifier in a cookie and local storage; it's removed from the device when you sign out.
- Third-party widgets — Google's sign-in prompt, Plaid Link and Stripe Checkout set their own cookies when they're shown or used, under their own policies.
We don't use advertising cookies.
How Long We Keep It
- Your account and wallet data: until you delete your account.
- Bank data from Plaid: while the account stays linked. Disconnecting your last bank deletes the transactions; deleting your account deletes all of it.
- Contact messages: until your request is handled; deleted with your account or on request.
- AI answers you report, with your reason and note: until you delete your account, or sooner on request.
- Newsletter and waitlist signups: until you unsubscribe or ask us to remove them.
- Backups: deleted data can remain in encrypted database backups for up to 30 days before they expire.
- Stripe keeps payment records for as long as financial law requires; PostHog, Sentry and Resend keep event, error and email logs for a limited period under their own retention settings.
Deleting Your Data
Delete your account in Settings, on the web or in the mobile app. This immediately: cancels a Churn Pro subscription bought on getchurn.app and deletes your saved payment details at Stripe; disconnects linked banks at Plaid and closes a virtual card; and deletes your cards, settings, transactions, household membership (and any household you own), referrals, preferences, AI answers you reported, form submissions and newsletter signups made with your email, household invitations sent to it, and your sign-in. Copies in our encrypted database backups are deleted when those backups expire, within 30 days. Subscriptions bought through the App Store or Google Play are billed by Apple or Google and must be cancelled in your device's subscription settings.
You can also disconnect a bank in Settings at any time, turn off any email from its unsubscribe link or in Settings, or email privacy@getchurn.app to have us delete your account or specific data, including analytics tied to your account. We answer within 30 days.
Clear data on this device in Settings only removes the copy stored in that browser; it doesn't delete your account.
Data Security
Data is encrypted in transit (HTTPS/TLS). Our database enforces row-level security, so each account can read only its own data (and household members' shared data). Plaid access tokens are encrypted before they are stored. Passwords are handled by Supabase Auth and stored only as hashes. No system is perfectly secure; if we learn of a breach affecting your data, we'll tell you as the law requires.
Where Your Data Is Processed
Churn's database and servers are in the United States. If you use Churn from Canada or elsewhere, your information is transferred to and processed in the United States, where it may be accessible to authorities under U.S. law.
Your Rights
Canada (PIPEDA and provincial laws) — you can access and correct your information, withdraw consent for optional collection (location, notifications, bank linking) at any time, and have your account deleted.
California (CCPA/CPRA) — you have the right to know what personal information we collect and how we use and disclose it, to access, correct and delete it, to opt out of its sale or sharing (we do neither), to limit the use of sensitive information (we use financial data only to provide the service you asked for), and not to be discriminated against for exercising these rights.
Other U.S. states — residents of Virginia, Colorado, Connecticut, Texas, Oregon and other states with privacy laws have similar rights to access, correct, delete and port their data and to opt out of sale and targeted advertising (we don't do either).
To exercise any right, use the tools in Settings or email privacy@getchurn.app. We may need to confirm your identity, usually by replying from your account's email address.
Children's Privacy
Churn is not intended for anyone under 18, and we don't knowingly collect information from minors. If you believe a minor has given us personal information, email privacy@getchurn.app and we'll delete it.
Changes to This Policy
When we change this policy we update the date at the top. If a change materially affects how we use information we already have, we'll tell signed-in users by email or in the app before it applies.
Contact
Privacy questions and requests: privacy@getchurn.app. Everything else: support@getchurn.app or the contact form.