Live discovery feed Demo workspace

Legal

Privacy policy

DealOS is a personal deal operating system in early beta. This policy explains what we collect, what we never collect, and how you stay in control.

Last updated: September 25, 2026

The short version

  • DealOS is read-only beta software. Real bank connections are disabled: we never ask for your bank login, and we never store bank logins or account numbers.
  • Anything you contribute (comments, direct-deposit reports, deal submissions, feedback) is tied to a local placeholder profile on your device, not a real identity account. Bank connections are the exception: they require a signed-in account, and their tokens are tied to that account, never to the local profile.
  • Bank access tokens never live in your browser. When real bank connections are enabled, they are stored encrypted on our servers, scoped to your signed-in account. The demo connector keeps no tokens anywhere.
  • Analytics are anonymous page-view counts with a random session id. We do not sell your data and we do not use it for advertising.

What DealOS collects

DealOS collects different things depending on what you do:

  • Your profile. DealOS uses a local placeholder identity on your device. We do not require your real name, and there is no password account to sign up for in this beta.
  • Community contributions. Comments, direct-deposit journey reports, deal submissions, and votes you submit are stored so they can be moderated and shown to other beta users. Each datapoint carries a provenance label showing where it came from.
  • Beta feedback. When you use the feedback button, we store the category, your message, the page you were on, an optional email if you provide one, and any context you attach (like an offer or deposit target). Feedback reports go to a private triage queue and are never published.
  • Anonymous analytics. We count which pages are opened, tagged only with a random session id that cannot identify you.
  • Your own data. Offers you track, checklists, reminders, and planner entries you create are kept on your own device where the feature says so, or in your synced store if you enabled syncing.

Bank connections: what Plaid does and does not do

DealOS uses Plaid to read transaction history when you connect a bank, purely to verify whether direct deposits arrived. Live, real-bank Plaid connections are disabled in this beta: the only connector available is the clearly-labeled demo connector, which uses sample payroll-style transactions generated in your browser. It keeps no tokens anywhere: there is nothing for anyone to steal and nothing to delete.

What is true when real bank connections are enabled:

  • Tokens are encrypted on our servers, never in your browser. Access tokens are stored server-side, encrypted at rest, and your browser only keeps connection metadata (the bank name and a connection id). The token is never returned to the browser, never written to localStorage, and never logged.
  • Connections require a signed-in account and stay scoped to it. One account cannot see or use another account's connections. Demo mode keeps working without sign-in and still keeps no tokens.
  • Transaction access is read-only and narrow. DealOS requests transactions only. Full account and routing numbers are not available through the integration, and Plaid itself never needs or receives your DealOS data.

Bank event updates arrive as Plaid webhooks, and we verify every one with Plaid's signed-key verification scheme before acting on it. Update notices only flag that a connection needs attention (for example, the bank asks you to log in again); transaction syncing stays pull-based, at your request.

How your data is processed

  • Transaction processing. Transaction data fetched for direct-deposit verification is matched on your device against the deposit patterns you care about. It is used only for your own verification: never sold, never shared with advertisers, never used for advertising.
  • Direct-deposit evidence. Published direct-deposit observations are community and reader sourced. They are reported observations, not proof that a method works, and they are labeled with their provenance (for example, community comment or official documentation).
  • Retention. Data on your device lives there until you clear it. Server-side data (feedback, contributions) is kept only as long as it is needed to run the beta and operate the service.

How to delete or disconnect

  • Disconnect a bank. Disconnect from the planner screen. For a real connection this revokes the token on Plaid's side first, then deletes our stored encrypted copy. The demo connector has nothing to delete: it keeps no tokens.
  • Clear device data. Clearing site data for this origin in your browser removes locally stored DealOS data: tracked offers, local settings, and bank connection metadata. It does not touch server-side data: encrypted bank tokens are removed only by disconnecting the bank or by asking us to delete them.
  • Remove server-side data. To ask us to delete your feedback, community contributions, or stored bank connections, contact the DealOS team through the feedback button (bottom-left of every page) and we will remove what we can, minus anything already quoted in published aggregates.

Security

We take reasonable steps to protect the data we hold: encrypted connections in transit, bank access tokens encrypted at rest and scoped to the signed-in account that created them, limited access to the backend, and no secret or sensitive financial data ever sent to your browser. This is still an early beta, and we are honest about its limits: keep your device and your sign-in secure, because your device is the key to your account.

Third parties

  • Plaid. Only involved if you connect a bank; currently the demo connector only. When live, Plaid's own privacy policy governs what Plaid does with the credentials you enter on their screens.
  • Hosting and database. DealOS is hosted on Vercel and stores server-side data with Supabase. They process data only to run the service.
  • Offer sources. DealOS imports offer data from third-party publishers such as Doctor of Credit and Frequent Miler. Visiting their sites is governed by their policies.

Changes to this policy

As the beta grows (real accounts, real bank connections, new features), this policy will grow with it. When it changes materially, we will update this page and the date at the top. Continuing to use DealOS after a change means you accept the updated policy.

Contact

Questions about this policy or about your data go to the DealOS team through the feedback button in the bottom-left corner of every page. You can reach us without giving any contact info.

Back to DealOS