Pyrse

Privacy Policy

Last updated August 2026

What this policy covers

This explains what Pyrse collects, how it's used, and what we never do with it. We wrote this in plain language because your privacy isn't something to bury in jargon.

What we collect

When you create an account, we store your email address and a password hash (never the password itself).

When you set up your business, you give us a business name and time zone so Pyrse knows what "this week" means for you.

When you connect a bank account, you authorize Pyrse to read your balances and transaction history through Plaid. Pyrse stores encrypted bank access tokens so it can keep your numbers up to date.

When you connect your register (Square), you authorize Pyrse to read your menu and catalog items — names and prices — so your dashboard reflects what you actually sell.

When you ask Bursar a question, the question is sent alongside a snapshot of your own numbers to the AI provider that powers the answer. The snapshot contains the same figures already visible on your dashboard.

How we use your information

Your data is used solely to power your dashboard: computing the numbers you see, spotting bills coming up, and making your weekly outlook.

We use basic, anonymized logs (how many pages loaded, which features people use) to fix bugs and make the product better. We never log bank amounts, transaction details, merchant names, or balances in our analytics.

What we never do

We will never sell your data — not your email, not your bank information, not anything.

We will never show your business's numbers to another user.

We will never move your money. Pyrse is strictly read-only. It cannot initiate transfers, payments, or withdrawals — for banks or your register.

We will never share your bank or register credentials. Access tokens are encrypted with AES-256-GCM and never leave our servers.

How we protect your data

All data is encrypted in transit (HTTPS) and at rest. Bank access tokens — the keys that let Pyrse read your accounts — are encrypted with AES-256-GCM and never exposed to your browser.

Our database is protected at the row level: no matter what happens, a query from one business can never read another business's rows. This is enforced at the database layer, not just in application code.

Only the minimum number of people running the service ever have access to the systems holding your data, and only for the purpose of keeping the service working.

Third parties that touch your data

We use a small number of external services, each only to the extent needed to provide the service:

  • Plaid — handles the secure connection between Pyrse and your bank. Plaid's own privacy terms apply when you connect an account: plaid.com/legal
  • Square — handles the connection to your register and catalog. Square's own terms apply when you connect: squareup.com/legal
  • AI provider — powers Bursar's plain-language answers. Receives the question and a snapshot of your dashboard numbers, which we instruct it to use only to answer the question.
  • Supabase — hosts our database, with built-in encryption and row-level security.
  • Vercel — hosts the website and application.
  • Email provider — sends account confirmation and password-reset emails.

How long we keep your data

Your data is kept as long as your account is active. You can disconnect a bank account in Settings to remove that bank's numbers from your dashboard, and disconnect your register to stop menu updates — the last-synced items stay. You can email us to delete your account entirely — we'll remove your personal and financial data within 30 days.

Your rights and choices

You can edit your business name and time zone in Settings at any time.

You can disconnect a bank account or your register at any time.

You can request a copy of the data Pyrse holds about you, or ask us to delete it, by emailing vaughn@mypyrse.com.

We will never use your data for targeted advertising or share it with anyone for marketing purposes.

Cookies

Pyrse uses a single session cookie to keep you signed in. It expires automatically and is never used for tracking or advertising.

Children

Pyrse is not directed at children under 13, and we do not knowingly collect data from them.

Changes to this policy

We may update this policy occasionally. If we make a meaningful change, we'll update the date here and may notify you through the app or by email.

Questions

Anything unclear in this policy, or want to exercise a right listed above? Reach us at vaughn@mypyrse.com — we respond to every message.