Ask Misto
Misto · privacy policy

Privacy policy.

The short version: we collect only what's needed to run the app, we never sell your financial information, and you can delete everything in a single tap. The full version follows — written in plain English so you actually read it.

01

Who we are

Mistos Technologies LLC (“Misto's,” “we,” “us”), doing business as Misto's Financial, is a personal-finance application registered in Oregon, United States. Our mailing address is 5411 S. Macadam Ave. #4644, Portland, OR 97239. You can reach our privacy team any time at privacy@mistosfinancial.com.

02

What we collect

  • Account info: your name, email, hashed password.
  • Financial data you add: accounts, transactions, budgets, goals, recurring bills, notes.
  • Bank-sync data (optional, Premium): when you utilize Misto Private Sync to import transactions via file upload, that data is processed and stored locally on your device. Hashed or encrypted backup payloads are securely synced to our cloud only if you choose to enable the optional cloud backup.
  • Payment data (Premium): Stripe handles every payment. We see the last 4 digits of the card and a transaction ID — never the full PAN or CVV.
  • Diagnostic logs: anonymous aggregate counts and error traces. No individual transaction rows are ever logged for diagnostics.
03

What we don't collect

  • We don't track you across other websites.
  • We don't run third-party advertising pixels.
  • We don't sell, rent, or “share” your data with marketing partners — not even anonymized segments.
  • We don't have transfer or payment permissions. Misto's is entirely read-only, and because bank data is ingested locally, there is no technical avenue to touch your funds.
04

How we use it

Strictly to run the app: showing you your dashboard, computing budgets and Misto's insights, sending reminders you opted into, and processing your Premium subscription. We use Anthropic / OpenAI / Google LLMs to generate Misto's narration — these calls send derived summaries (totals, deltas, top categories), never raw transaction rows.

05

Where it lives

Your account credentials and session tokens live in an isolated serverless Cloudflare D1 database. Your transaction histories, budgets, and other financial records are stored 100% locally on your own device inside your browser's IndexedDB. If you choose to enable the optional cloud sync, your backups are encrypted client-side using a key derived from your master password (via AES-GCM) and stored securely in Cloudflare R2 object storage. All bytes in transit are protected by TLS 1.3.

06

Your rights (GDPR + CCPA)

Wherever you live, you can ask us to:

  • See a copy of everything we hold about you.
  • Correct anything inaccurate.
  • Delete your account and data — completed within 24 hours, with encrypted backups expiring within 30 days.
  • Export your data in a portable JSON / CSV format.
  • Withdraw consent for anything you previously opted into (email summaries, bank sync, etc.).

California residents have the additional right under CCPA to opt out of “sale” of personal information — we don't sell anyway, but the right is yours. Email privacy@mistosfinancial.com for any of the above. We respond within 30 days; usually within 48 hours.

07

Cookies and storage

We use localStorage to keep you signed in and to remember your language and theme. We don't set any tracking cookies. The only third-party script that loads is Stripe Checkout (when you upgrade) — both are essential for the feature you're using.

08

When we update this policy

If we materially change how we handle your data, we'll email every member before the change takes effect — not a “we've updated our terms” footer link. The current version of this policy is always at /privacy.

09

Children

Misto's isn't designed for anyone under 16. If you believe a child has signed up, email us and we'll remove the account.

10

Questions

Write to privacy@mistosfinancial.com any time. A real person reads every message and replies within two business days.

Last updated July 17, 2026.

We'll email every member before any material change takes effect.