Privacy policy
Checkpoint helps you plan your income, track spending and savings, manage medical bills and HSA reimbursements, and prepare for retirement. To do that we handle sensitive financial and health information, so here is exactly what we collect, why, who we share it with, how long we keep it, and how you stay in control. In short: we use your data only to provide Checkpoint to you, we never sell it, and you can download or delete it at any time.
Checkpoint is operated by Luke Salomone ("Checkpoint", "we", "us"). Questions: hello@checkpointfinance.app.
Information we collect
- Account information: your email address, name, password (stored only as a one-way hash), and settings.
- Household and planning details you enter: such as birth year, filing status, state, income, goals and assumptions.
- Financial information you add: paychecks, account balances, holdings, contributions, budgets, transactions, medical claims and plan items — typed in, imported from files, or synced from linked accounts.
- Documents you upload: such as paystubs, explanations of benefits, receipts and account exports.
- Health and insurance information you add: medical claims, bills, explanations of benefits, payments, procedure (CPT) and diagnosis codes, health plans and the family members on them.
- Information from connected health insurers: if you choose to connect a health insurer (for example Aetna, Anthem or BlueCross BlueShield of Tennessee), we receive, through the insurer's official Patient Access API, your claims and explanations of benefits, coverage details, and related records such as providers and visit dates. You sign in on your insurer's own website; we never see or store your insurer password. We collect this information only after you connect, and only until you disconnect.
- Information from linked financial accounts: if you choose to connect an account through Plaid, we receive account names, the last four digits of account numbers, balances, investment holdings and transactions. We do not receive your bank login credentials.
- Security and technical information: sign-in events (including failed attempts), IP address, and basic request logs used to keep the service secure and working.
We use only the cookies needed to keep you signed in and protect against forged requests. We do not use advertising or third-party tracking cookies.
How we use it
- To provide Checkpoint to you: your budget, income plan, tax estimate, contribution tracking, projections and recommendations.
- To keep your account secure, prevent abuse, and troubleshoot problems.
- To contact you about your account, such as password resets or important changes to the service.
We do not sell your personal information, rent it, share it for advertising, or use it to train AI models. We will never use your information to market third-party products to you, or share it to help others market to you, unless you give separate, specific consent first.
We do not create de-identified or aggregated data sets from your information for sale or for others' use. If we ever use de-identified information internally (for example, to count how many people use a feature), we will not attempt to re-identify it, and we will not allow anyone else to.
How we share it
- Plaid, only when you choose to link an account. Plaid connects to your financial institution and returns data to Checkpoint. Plaid's handling of your data is described in the Plaid End User Privacy Policy. You can disconnect an account in Checkpoint at any time, which also revokes Checkpoint's access through Plaid.
- Service providers that host and operate Checkpoint (cloud hosting, database and email delivery), under contracts that limit their use of your data to running the service.
- Your health insurer, only when you choose to connect it. The insurer verifies your identity and asks for your permission, then sends your records to Checkpoint. Its practices are described in its own privacy notice.
- Google (Gemini API), only if you turn on AI features. AI features are off by default. If you turn them on, we send a summary of your totals (never your name, employers, account numbers or documents) to write a review, or a specific document or screenshot you ask us to read. You can preview exactly what is sent and turn AI off at any time. Records we receive from a connected health insurer are never sent to AI services.
- Legal reasons, if required by law, legal process, or to protect the rights, safety and security of our users or Checkpoint.
- Business transfers, if Checkpoint is involved in a merger, acquisition or sale of assets. We will email you at least 30 days before your information is transferred, the new owner must honor this policy, and you can export and delete your data before the transfer.
Other than these, we disclose your information to a third party only with your specific, explicit consent.
Substance use disorder records. Records from a connected insurer may include information protected by federal confidentiality rules (42 CFR Part 2). Federal law prohibits us from making any further disclosure of that information unless expressly permitted by your written consent or by those rules; we treat all insurer records this way and do not disclose them to anyone.
How long we keep it
| Information | Kept |
|---|---|
| Your account, financial records and documents | While your account is open, or until you delete them |
| Bank connections (Plaid access) | Until you disconnect the account or delete your Checkpoint account |
| Health insurer connections (access tokens) | Deleted immediately when you disconnect, or when the insurer's permission expires |
| Records received from a health insurer | While connected; deleted within 30 days after you disconnect, unless you choose to keep claims already in your records |
| Security logs | 12 months |
| Backups | Up to 35 days, then permanently overwritten |
| Inactive accounts | Deleted after 24 months without a sign-in, with 30 days' notice by email |
Your choices and rights
- Access and download: export all of your data and documents any time from Settings → Your data.
- Correct: edit or delete any record inside the app.
- Disconnect: remove a linked financial account or health insurer at any time. When you disconnect an insurer we stop collecting immediately, delete its access tokens, and delete the records we received from it within 30 days — or, if you choose, keep the claims you've already added to your records. Some insurers also require you to renew your permission periodically (for example every 90 days); if you don't, we simply stop receiving new data.
- Consent: each connection is your choice and covers only that insurer or account. You can review and change your connections in Settings at any time.
- Delete: delete your account from Settings → Your data. This immediately deletes your records and documents and revokes bank connections; remaining backup copies expire within 35 days. You can also email us and we'll complete verified requests within 30 days.
- AI features: turn them on or off in Settings → Privacy.
Depending on where you live (for example California), you may have additional rights to know, access, correct or delete your information and to not be discriminated against for using them. Email us to make a request; we will verify it with your account before acting.
Security
We protect your information with encryption in transit (HTTPS) and at rest, additional encryption for uploaded documents and for bank and insurer connection tokens, strong password hashing, rate-limited sign-ins, audit logs, and access restricted to the people who operate Checkpoint. No system is perfectly secure. If a breach affects your information, we will notify you without unreasonable delay and no later than 60 days after we discover it, and notify regulators where required — including under the FTC Health Breach Notification Rule. More detail is in our security overview.
Our commitments for health data
For health information, including data from connected insurers, we follow the CARIN Alliance Code of Conduct for consumer health apps: we're transparent about what we collect and why, collect and use it only with your consent, never sell it, let you access, export and delete it, keep it secure, and follow applicable federal and state law.
Children
Checkpoint is for adults. We do not knowingly collect information from anyone under 18.
Where we operate
Checkpoint is offered in the United States. Your information is stored and processed only in the United States.
If Checkpoint shuts down
If we ever decide to discontinue Checkpoint, we will email you at least 30 days in advance so you can export your data, then permanently delete all user information, including records received from insurers, after that period.
Changes to this policy
If we make material changes, we'll update the date above and tell you in the app or by email before the changes take effect. If a change affects how we use or share health information from a connected insurer, we will ask you to agree again; until you do, we stop collecting new data from that insurer, and you can disconnect and have that data deleted instead.
Contact
Email hello@checkpointfinance.app with any question or request about your privacy.