Privacy notice
This notice explains what personal information Tovi collects when you connect a financial account, what we do with it, who we share it with, how long we keep it, and what you can require us to do about it. Tovi's whole purpose is to read payments you have already made, so this page is specific about them.
1. Who is responsible for your information
Tovi is operated by GenesisX Group LLC, a limited liability company registered in Delaware, United States, with registered address at 10001 Lewes Road, Wilmington, DE 19709, United States. This notice covers tovifinance.com and the Tovi application.
Privacy questions, access requests and deletion requests go to max@genesisglobal.group or +1 412 313 1314. A real person answers, and the same address is the one that can delete your data.
2. What we collect
From the account you connect
Tovi uses Plaid Inc. to connect the bank account you already pay bills from. Depending on your institution and the permissions you give, we receive:
- Account information — the institution name, the account name and type, the last four digits of the account number, and the available or current balance.
- Transaction history — up to 24 months of transactions, each with its date, amount, description or merchant name, and the category the provider assigns it.
Tovi does not receive or store your online banking username or password. Access is read-only: Tovi cannot move money out of a connected account.
What Tovi works out from it
- Recurring obligations — the category (rent, utilities, insurance, phone, internet, childcare, tuition, mortgage), the payee as your bank writes it, the typical monthly amount, the number of months observed, the total paid, and a confidence figure.
- Your decisions — which obligations you have approved for reporting, which you have withdrawn, and which you have dismissed, with the time of each decision.
- Tovi Reliability — a 0–100 score, the five factors behind it, and the sentences shown under “working for you” and “needs attention”. A snapshot is kept each time it is calculated so that changes over time can be shown to you.
Technical information
- A session — connecting an account creates a session for your browser. Only a one-way hash of the session token is stored, so a copy of our database does not let anyone sign in as you.
- Your browser's user-agent string, shortened, recorded once when the profile is created.
- A one-way hash of your IP address, used only to limit how many connection attempts can come from one network in an hour. The address itself is not stored.
What we do not collect
Tovi performs no credit check, hard or soft, and does not pull your credit report. Tovi does not ask for a Social Security number to use the product as described here. Tovi runs no advertising pixel and no analytics tracker, and sets no advertising cookies.
What we will never ask for
Nobody from Tovi will ever ask you for your online banking password, your card PIN, a one-time passcode, or an account-recovery code. Bank authentication happens inside Plaid or at your bank, never through us. Please do not email or message financial documents to us.
3. Why we collect it
- To find the recurring payments in your transaction history — the service you came for.
- To judge how much confidence to place in each one, and to show you which are eligible for credit reporting and which are not.
- To calculate and explain your Tovi Reliability score.
- To show what is coming up in the next 30 days and whether the connected account covers it.
- To furnish approved positive payment history to a consumer reporting agency, where you have approved that specific obligation. See section 6.
- To detect fraud and protect the service from automated abuse.
- To answer you when you contact support.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not use your information for automated decision-making that produces legal effects about you without human involvement — the Tovi Reliability score is shown to you and is not sold or given to lenders.
4. Your choices
Connecting an account is voluntary, and you authorise it inside Plaid's own flow before anything is read. You can disconnect at any time from the You screen in the app: Tovi stops reading new transactions, the connection is revoked at Plaid, and the stored credential is deleted.
Approving an obligation for reporting is a separate, per-obligation decision, and every one starts unapproved. Nothing is reported because Tovi detected it.
5. Who we share it with
Plaid
Plaid Inc. provides the bank connection. When you connect, information necessary to establish and maintain that connection passes between you, Plaid, your financial institution and Tovi. Plaid processes information under its own privacy policy and the terms shown to you during its flow. Tovi receives only what the products we use and your permissions make available.
Service providers
- Supabase Inc. — the database and the server code that processes it, hosted in the United States.
- Cloudflare, Inc. — serving tovifinance.com, and the human-verification check that protects the connection endpoint from automated abuse.
Both act as our processors, under contract, and only as necessary to provide their services.
Consumer reporting agencies
Where a category is supported and you have approved that specific obligation, Tovi may furnish the positive payment history for it — the category, the payee, the amounts and the dates paid — to a consumer reporting agency. Nothing else about your account is sent, and nothing at all is sent for an obligation you have not approved.
Otherwise
We may disclose information where required by law, by a court, or by a regulator, and to protect against fraud or a threat to someone's safety. If Tovi is ever sold or merged, information may pass to the acquirer under this notice until it is changed, and we will tell you if it is.
6. What gets reported, and what does not
This is the part of Tovi people worry about most, so it is set out plainly.
- Finding a payment and reporting a payment are separate. Detection alone never turns a transaction into reported credit information.
- Only obligations Tovi has marked verified, in a category a bureau currently accepts, can be approved at all. The app says which ones those are.
- Every approval is yours, made per obligation, and starts off.
- Withdraw an approval and Tovi stops including that obligation from that moment. Information already furnished cannot be unsent, but we will tell the receiving agency that you withdrew it.
- Tovi reports positive payment history. It is not a debt collector and does not report missed payments, defaults, or derogatory information.
- If you believe something Tovi furnished about you is wrong, write to max@genesisglobal.group. You also have the right to dispute the information directly with the consumer reporting agency that holds it, and we will investigate any dispute they pass to us.
As of the date above, no furnishing arrangement is live and no information has been sent to any consumer reporting agency. This section describes how it will work when one exists.
7. How long we keep it
Unless a longer period is required by law or necessary for an ongoing dispute:
| What | How long |
|---|---|
| Transaction lines read from your bank | 400 days from the date of the transaction, then deleted automatically |
| Discovered obligations, your decisions about them, and Tovi Reliability snapshots | For as long as you have a Tovi profile |
| The bank credential that reads your account | Deleted, and revoked at Plaid, as soon as you disconnect |
| Account display details (institution, name, mask, balance) | With the connection record; marked revoked when you disconnect |
| Session records | 180 days, then swept once expired |
| Abuse-prevention hashes | 2 days |
| Records of furnishing and of privacy requests | As long as required to demonstrate compliance |
Ask us to delete your profile and we will, subject to anything we are required to keep. Deleting from active systems does not instantly remove information from encrypted backups where individual records cannot be picked out; those copies stay protected, are not used for ordinary processing, and fall out with the normal backup lifecycle. Our data retention and disposal policy has the detail.
8. How we protect it
Information travels over an encrypted connection and is stored encrypted at rest.
The credential that can read your bank account is stored in a table of its own, separate from everything else, and is reachable by only the two pieces of server code that need it. Our database has row-level security enabled on every table with no access policies at all, which means the key present in your browser can read nothing whatsoever — every request goes through server code that checks your session first. Session tokens are stored only as hashes.
Our information security policy sets out the rest. No system is perfectly secure; if a breach occurs that puts you at real risk, we will notify you and the authorities required by applicable law.
9. Your rights
Wherever you live, you can ask us to:
- tell you what personal information we hold about you, and where it came from;
- give you a copy in a portable, machine-readable form;
- correct anything inaccurate — including an obligation Tovi has misread;
- delete your information;
- stop any reporting, and withdraw an approval you previously gave;
- disconnect your bank, which you can also do yourself, immediately, in the app.
Depending on your state you may have specific rights to know, delete, correct, and to opt out of sale, sharing or profiling, and a right not to be treated differently for exercising them. Tovi does not sell or share personal information for advertising, so there is nothing to opt out of there.
Email max@genesisglobal.group. We respond within 45 days and will tell you if we need longer. We may ask you to confirm who you are first, so that nobody else can obtain your financial records. If you are not satisfied, you may complain to your state attorney general or to the Consumer Financial Protection Bureau.
10. Cookies and local storage
Tovi sets no advertising or analytics cookies, and runs no tracking pixel.
Your browser holds three things for the site to work at all:
- your session token, so you return to your own history without a password;
- while a bank connection is in progress, the short-lived link token, so a bank that takes over the tab can hand you back to us. It expires after 30 minutes and is cleared as soon as the connection resolves either way;
- if you use the site with no backend configured, the state of the demonstration walkthrough.
Because the session lives on the device, use Tovi on a device that is yours, and press “sign out on this device” if you lend it to someone.
Plaid Link may use cookies or local storage of its own while a connection is being made, and the human-verification check sets a cookie that is necessary for it to function.
11. Children
Tovi is for adults. We do not knowingly collect information from anyone under 18. If you believe a minor has connected an account, contact us and we will delete it.
12. Changes to this notice
If we change how we handle your information we will update this page and its version number, and where the change is significant we will tell you directly.