shellwise/privacy-policy
Shellwise

Privacy Policy

Last Updated: May 5, 2026

This Privacy Policy describes how Shellwise (“Shellwise,” “we,” “us,” or “our”) collects, uses, discloses, stores, and otherwise processes information about individuals who use Shellwise, including our command-line interface application, hosted services, website, account-linking flows, communications, and any related products or services that link to this Privacy Policy.

Shellwise is a bring-your-own-agent financial data platform. Shellwise helps users connect financial accounts, structure and store financial information, and make that information available to user-authorized agents, tools, and interfaces so those agents can provide budgeting, analysis, monitoring, planning, and other financial-management assistance.

By accessing or using Shellwise, you acknowledge that you have read and understood this Privacy Policy.

Important: Shellwise is not a bank, broker-dealer, investment adviser, tax adviser, credit counselor, or legal adviser. Shellwise provides software and data tools. Any financial insights, summaries, categorization, projections, or agent-generated outputs should be reviewed carefully and are not a substitute for professional advice.


1. Scope

This Privacy Policy applies to information collected or processed when you:

  • visit or interact with shellwise.ai or related websites;
  • create or manage a Shellwise account;
  • install, authenticate with, or use the Shellwise CLI application;
  • connect financial accounts through Plaid or another account-linking provider;
  • authorize Shellwise to retrieve, store, structure, analyze, or expose your financial information;
  • authorize an agent, model, application, integration, or third-party tool to access your Shellwise data;
  • subscribe to or pay for Shellwise services;
  • join a waitlist or request product updates;
  • contact us, request support, provide feedback, or otherwise communicate with us.

This Privacy Policy does not apply to third-party websites, products, services, financial institutions, agents, AI tools, model providers, or integrations that are not controlled by Shellwise, even if they are linked to, integrated with, or accessible through Shellwise. Those third parties process information according to their own terms and privacy policies.


2. Information We Collect

We collect information directly from you, automatically when you use Shellwise, from Plaid and other service providers, from financial institutions when authorized by you, and from integrations that you choose to connect.

A. Information You Provide to Us

We may collect information you voluntarily provide, including when you:

  • create or manage an account;
  • join a waitlist;
  • authenticate into the CLI or web application;
  • configure your profile, preferences, connected accounts, agents, or integrations;
  • contact us for support;
  • provide feedback, survey responses, or product requests;
  • communicate with us by email, chat, form, or other means.

This information may include:

  • name;
  • email address;
  • username or account identifier;
  • company name or role, if provided;
  • billing and subscription information;
  • support messages, feedback, and communications;
  • product preferences, settings, and configuration choices;
  • any other information you choose to provide.

B. Account, Authentication, and CLI Information

When you use the Shellwise CLI application or related services, we may collect and process information related to account access and authentication, including:

  • account identifiers;
  • session identifiers;
  • API keys, access tokens, refresh tokens, or similar authentication credentials;
  • CLI device or environment metadata;
  • authentication timestamps;
  • login, logout, token refresh, and authorization events;
  • permissions, scopes, or access grants you configure;
  • command metadata, such as command name, status, timing, and error information.

Where possible, Shellwise seeks to limit collection of unnecessary command contents. However, depending on the feature, commands, parameters, prompts, filters, account names, notes, tags, or other user-provided inputs may be processed to provide the requested service.

You are responsible for securing the devices, terminals, shells, environment variables, local files, and configuration stores where you use Shellwise. If you store Shellwise credentials locally, anyone with access to that device or environment may be able to access your Shellwise account or data.

C. Financial Account Information Collected Through Plaid or Similar Providers

When you choose to connect a financial account, Shellwise may use Plaid or another account-linking provider to help you authenticate with your financial institution and authorize access to financial data.

Depending on the accounts you connect, the permissions you grant, the products we use, and the information made available by your financial institution, Shellwise may collect and store financial information such as:

  • financial institution name;
  • account names, official names, nicknames, masks, and account identifiers;
  • account type and subtype, such as checking, savings, credit card, loan, mortgage, investment, or brokerage;
  • account balances;
  • available balances and current balances;
  • transaction history;
  • pending and posted transactions;
  • transaction dates, amounts, descriptions, merchant names, categories, locations, payment channels, and related metadata;
  • recurring transactions and income-related signals;
  • account and routing information where authorized and available;
  • liability information, such as credit card, student loan, auto loan, mortgage, or other debt information;
  • investment account holdings, securities, balances, transactions, cost basis, quantities, prices, and related metadata;
  • identity information made available by the provider or institution, such as account owner names, addresses, phone numbers, or email addresses;
  • account status, error codes, connection health, institution availability, and synchronization metadata;
  • any other financial account data you authorize us to access.

Shellwise does not receive or store your financial institution login credentials when you authenticate through Plaid. Your interactions with Plaid and your financial institution are also subject to Plaid’s privacy policy and the privacy policies and terms of your financial institutions.

D. Information Generated by Shellwise

Shellwise may generate, derive, or infer additional information from the data we process, including:

  • normalized account and transaction records;
  • categorization, tagging, enrichment, and merchant cleanup;
  • spending summaries and trends;
  • budget views and cash-flow projections;
  • net-worth snapshots;
  • account-linking and sync status;
  • risk, anomaly, alert, or monitoring signals;
  • scenario-planning outputs;
  • agent-readable context summaries;
  • embeddings, indexes, metadata, or other structured representations used to retrieve, summarize, or expose your information to authorized tools or agents;
  • audit logs showing access, authorization, syncing, export, or deletion activity.

E. Information from Agents, Models, and Integrations You Authorize

Shellwise is designed to support user-authorized agents and integrations. If you connect or authorize an agent, AI model, application, MCP server, CLI tool, API client, or other integration, we may collect and process information related to that integration, including:

  • the identity of the integration or agent;
  • the permissions, scopes, and data access you grant;
  • requests made by the integration;
  • responses returned by Shellwise;
  • access logs and usage events;
  • prompts, instructions, summaries, tool calls, or output metadata, depending on the integration and feature;
  • revocation, expiration, or permission-change events.

You should authorize access only for agents, models, tools, or providers you trust. Once information is shared with a third party at your direction, that third party’s handling of the information is governed by its own terms and privacy practices.

F. Payment and Subscription Information

If you purchase a subscription or paid service, we may collect and process billing-related information. Payments may be processed by third-party payment processors such as Stripe. Depending on the payment flow, we may receive limited payment-related information, such as:

  • billing name;
  • billing email;
  • billing address;
  • subscription plan;
  • payment status;
  • invoice history;
  • partial payment-card details, such as card brand and last four digits;
  • tax, receipt, refund, or charge-related records.

We do not intend to store full payment-card numbers unless explicitly stated in a separate payment flow. Payment processors process payment information according to their own privacy policies and terms.

G. Information Collected Automatically

When you access or use Shellwise, we and our service providers may automatically collect information about your device, browser, network, application, and interactions, including:

  • IP address;
  • browser type and version;
  • device type;
  • operating system;
  • CLI version;
  • package or installation metadata;
  • language settings;
  • referring URLs;
  • pages viewed;
  • links clicked;
  • time spent on pages;
  • feature usage;
  • API requests and response metadata;
  • timestamps and usage logs;
  • crash reports, diagnostics, and performance logs;
  • approximate geolocation inferred from IP address;
  • cookie identifiers, local storage identifiers, and similar online identifiers.

H. Cookies and Similar Technologies

We may use cookies, pixels, local storage, analytics tags, session technologies, and similar tools to operate Shellwise, remember preferences, authenticate users, secure sessions, understand usage, improve product performance, and evaluate marketing or outreach.


3. How We Use Information

We may use the information we collect for the following purposes:

  • to provide, operate, maintain, and improve Shellwise;
  • to create and manage user accounts;
  • to authenticate users and secure sessions;
  • to connect financial accounts at your direction;
  • to retrieve, sync, normalize, enrich, categorize, and store financial account data;
  • to make your financial data available to agents, tools, and integrations that you authorize;
  • to provide account summaries, transaction views, budgeting tools, cash-flow analysis, alerts, projections, and related functionality;
  • to support CLI commands, API requests, exports, and integrations;
  • to process subscriptions, payments, invoices, and related billing records;
  • to provide customer support and respond to inquiries;
  • to send service-related notices, security alerts, account messages, and product updates;
  • to send marketing or promotional communications where permitted;
  • to understand product usage, user interest, and feature performance;
  • to debug, troubleshoot, and maintain reliability;
  • to detect, prevent, investigate, or respond to fraud, abuse, security incidents, policy violations, or unlawful activity;
  • to protect the rights, property, and safety of Shellwise, users, financial institutions, service providers, and others;
  • to comply with legal obligations, resolve disputes, and enforce agreements;
  • for any other purpose described at the time of collection or with your consent.

We do not use your consumer financial data for unrelated advertising. We do not sell your consumer financial data.


4. Plaid and Financial Account Linking

Shellwise uses Plaid or similar account-linking providers to help you connect financial accounts securely. When you connect an account, you may be asked to authenticate directly with your financial institution through Plaid’s interface and authorize specific types of data access.

By connecting an account, you authorize Shellwise and our account-linking provider to access, retrieve, and process the financial account information made available through that connection for the purposes described in this Privacy Policy and any applicable user agreements.

You may be able to disconnect accounts through Shellwise, Plaid, your financial institution, or other available controls. Disconnecting an account may stop future data syncing, but it may not automatically delete information already stored by Shellwise unless you request deletion or use available deletion controls.

Plaid and your financial institutions are independent third parties. Their collection, use, storage, and disclosure of information are governed by their own privacy policies, terms, and authorization flows.


5. Agent Access and User-Directed Sharing

Shellwise is designed to let you make your financial context available to agents and tools that you choose. This may include agents running locally on your device, hosted agents, AI model providers, MCP clients or servers, automation tools, scripts, or other applications.

When you authorize an agent or integration, Shellwise may disclose information to that agent or integration according to the permissions, scopes, and configuration you select. Depending on your choices, this may include highly sensitive financial information, such as transaction history, account balances, investment holdings, liabilities, identity information, or financial summaries.

You are responsible for deciding which agents and integrations to authorize. Before granting access, you should review the provider’s privacy policy, security practices, data retention practices, and terms. Shellwise is not responsible for how third-party agents or integrations use, store, disclose, or secure information after you direct Shellwise to share it with them.

Where supported, Shellwise may provide controls to:

  • limit the categories of data available to an agent;
  • restrict access to specific accounts or time periods;
  • issue and revoke API keys or tokens;
  • view connected integrations;
  • review access logs;
  • disconnect or revoke access.

6. How We Disclose Information

We may disclose information in the following circumstances.

A. Service Providers and Contractors

We may disclose information to service providers, contractors, and vendors that perform services on our behalf, such as providers of:

  • cloud hosting and infrastructure;
  • databases and storage;
  • account-linking and financial data aggregation;
  • analytics and performance monitoring;
  • authentication and identity management;
  • email delivery and customer communications;
  • billing and payment processing;
  • security, logging, auditing, and fraud prevention;
  • customer support and productivity tools.

These parties are authorized to access and process information only as reasonably necessary to perform services for us or as otherwise permitted by law and contract.

B. Plaid, Financial Institutions, and Account-Linking Providers

We may disclose information to Plaid, financial institutions, and related providers as necessary to establish, maintain, troubleshoot, refresh, or terminate account connections; comply with provider requirements; prevent fraud or abuse; and provide the services you request.

C. Agents, Tools, and Integrations You Authorize

We may disclose your information to agents, AI tools, applications, APIs, MCP clients or servers, scripts, or integrations when you direct us to do so or configure Shellwise to make information available to them.

D. Payment Processors

If you purchase a paid service, we may disclose billing and subscription information to payment processors and related providers to process payments, manage subscriptions, issue invoices, prevent fraud, and handle refunds or disputes.

E. Legal, Compliance, and Safety Purposes

We may disclose information if we believe disclosure is reasonably necessary to:

  • comply with applicable law, regulation, subpoena, court order, legal process, or governmental request;
  • enforce our terms, agreements, or policies;
  • detect, investigate, or prevent fraud, abuse, security issues, or illegal activity;
  • protect the rights, property, or safety of Shellwise, users, service providers, financial institutions, or others;
  • respond to claims that content, data, or activity violates the rights of others.

F. Corporate Transactions

We may disclose information in connection with an actual or proposed merger, acquisition, financing, investment, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider.

G. With Your Direction or Consent

We may disclose information when you direct us to do so, configure the service to do so, or otherwise consent.

H. Aggregated or De-Identified Information

We may use and disclose aggregated, anonymized, or de-identified information for lawful business purposes, including analytics, research, product development, benchmarking, and market understanding. We will not attempt to re-identify information that we maintain as de-identified except as permitted by law, such as to test our de-identification processes.


7. Data Storage and Retention

Shellwise may store consumer financial data so that your authorized agents and tools can access useful historical context over time. This may include account records, transaction history, balances, investment data, liability data, categorization data, derived summaries, indexes, and logs.

We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to:

  • provide and maintain Shellwise;
  • maintain connected-account history and agent-readable context;
  • support account recovery, troubleshooting, and customer support;
  • comply with legal, tax, accounting, contractual, and security obligations;
  • resolve disputes and enforce agreements;
  • maintain operational, audit, and compliance records.

Retention periods may vary based on the nature and sensitivity of the information, the feature used, legal requirements, user settings, account status, and our operational needs.

If you disconnect a financial account, Shellwise may stop future syncing but may retain previously collected data unless you request deletion or use available deletion controls. If you delete your Shellwise account or request deletion of your data, we will take reasonable steps to delete or de-identify personal information associated with your account, subject to legal, security, backup, fraud-prevention, dispute-resolution, and compliance retention requirements.

Residual copies may remain in backups or logs for a limited period before being overwritten or deleted according to our data lifecycle practices.


8. Security

We use reasonable administrative, technical, and organizational measures designed to protect personal information, including consumer financial data, against unauthorized access, disclosure, alteration, and destruction.

These safeguards may include, as appropriate:

  • encryption in transit using TLS 1.2 or better;
  • encryption at rest where supported by our infrastructure and storage providers;
  • access controls and least-privilege permissions;
  • authentication requirements;
  • multi-factor authentication for critical internal systems where available;
  • credential and secret management practices;
  • logging, monitoring, and audit controls;
  • vendor security review and contractual controls;
  • vulnerability management and security updates;
  • incident detection and response procedures.

However, no website, application, CLI, API, system, or method of electronic transmission or storage is completely secure. We cannot guarantee absolute security.

You are responsible for maintaining the security of your own devices, terminals, shells, local configuration files, environment variables, SSH keys, API keys, access tokens, passwords, and any agents or integrations you authorize.

If you believe your Shellwise account, credentials, API keys, device, or connected agent has been compromised, contact us promptly at the address listed below.


9. Local CLI Storage and User Device Security

The Shellwise CLI may store or access local configuration, authentication state, cached metadata, logs, or other files on your device depending on how you install and configure it.

Local files may include sensitive information such as access tokens, account identifiers, command history, logs, configuration values, or references to connected financial accounts. You should protect your device with appropriate security controls, such as full-disk encryption, operating-system account passwords, secure keychains or secret stores, and limited shell history for sensitive commands.

Shellwise is not responsible for unauthorized access caused by compromised devices, insecure terminals, exposed environment variables, leaked API keys, shared shell history, malicious local software, or unauthorized agents running in your environment.


10. Email Communications

If you provide your email address, we may send you communications such as:

  • account and authentication notices;
  • security alerts;
  • connected-account or sync notifications;
  • billing and subscription notices;
  • product and launch updates;
  • service-related announcements;
  • requests for feedback;
  • customer support messages;
  • marketing communications where permitted.

You may opt out of promotional or marketing emails at any time by using the unsubscribe link included in the email or by contacting us. Even if you opt out of marketing messages, we may still send you non-promotional messages, such as security, account, billing, legal, or transactional notices.


11. Cookies, Analytics, and Similar Tools

Most web browsers allow you to manage cookie preferences through browser settings. You may be able to delete or block cookies and similar technologies, though doing so may affect some functionality.

We may use analytics and performance-monitoring tools to understand how users interact with Shellwise, diagnose issues, measure product performance, and improve user experience. These tools may collect information about interactions with our website, hosted application, APIs, or CLI-related services over time.

We do not use consumer financial data for cross-context behavioral advertising. If our practices change, we will update this Privacy Policy and provide any required notices or choices.


12. Third-Party Services

Shellwise may integrate with or rely on third-party services, including Plaid, financial institutions, payment processors, cloud infrastructure providers, authentication providers, analytics tools, customer support tools, AI model providers, agents, and other integrations.

Third-party services are governed by their own privacy policies, security practices, and terms. We encourage you to review those policies before connecting accounts, authorizing agents, or using integrations.

Shellwise is not responsible for the privacy or security practices of third parties that are not controlled by Shellwise.


13. International Data Transfers

Shellwise and its service providers may process and store information in the United States and other jurisdictions where we or our providers operate. These jurisdictions may have data protection laws that differ from those in your place of residence.

Where required by applicable law, we will take steps intended to provide appropriate safeguards for cross-border transfers of personal information.


14. Children’s Privacy

Shellwise is not intended for children under the age of 13, and we do not knowingly collect personal information from children under 13. Shellwise is intended for individuals who are legally able to manage financial accounts and authorize financial data access.

If you believe a child has provided us with personal information, please contact us so that we may take appropriate steps.

If applicable law in your jurisdiction provides a different age threshold for children’s privacy rights, we will apply that standard as required.


15. Your Rights and Choices

Depending on where you live, you may have rights regarding your personal information, subject to applicable law and exceptions. These rights may include the right to:

  • know whether we process your personal information;
  • request access to personal information we hold about you;
  • request correction of inaccurate personal information;
  • request deletion of personal information;
  • request portability of certain information;
  • opt out of certain processing activities where applicable;
  • withdraw consent where processing is based on consent;
  • appeal a denied privacy request, where applicable.

You may also have product-level choices, depending on available features, such as the ability to:

  • disconnect a financial account;
  • revoke an agent or integration;
  • delete an API key or token;
  • export certain data;
  • delete certain stored records;
  • close your Shellwise account.

To exercise available rights, contact us using the contact details below. We may need to verify your identity before fulfilling a request, and we may limit or deny requests where permitted by law.


16. U.S. State Privacy Disclosures

Residents of certain U.S. states may have additional rights under applicable privacy laws. If such laws apply to Shellwise and your data, you may have rights related to access, deletion, correction, portability, appeal, and certain opt-outs.

Shellwise does not knowingly sell personal information or consumer financial data. Shellwise does not knowingly share consumer financial data for cross-context behavioral advertising as defined by certain state privacy laws.

If our practices change, we will update this Privacy Policy and provide any required notices or choices.


17. Gramm-Leach-Bliley Act and Financial Privacy

Because Shellwise may collect, receive, or store consumer financial information, some data we process may be subject to financial privacy laws, including the Gramm-Leach-Bliley Act and related rules, depending on Shellwise’s final product design, regulatory status, partnerships, and applicable law.

Where financial privacy laws apply, we will use and disclose covered financial information in accordance with applicable requirements, user authorizations, provider obligations, and this Privacy Policy.


18. Changes to This Privacy Policy

We may revise this Privacy Policy from time to time. When we do, we will update the “Last Updated” date above and, where required by law, provide additional notice.

Your continued use of Shellwise after an updated Privacy Policy becomes effective means that you acknowledge the revised policy. If we make material changes to how we collect, use, disclose, or store consumer financial data, we will provide notice as required by applicable law.


19. Contact Us

If you have questions or requests regarding this Privacy Policy or our privacy practices, please contact us at:

Email: [email protected] Website: shellwise.ai

← Back to home