Privacy
What this collects, and what it doesn’t.
Less is More reads a small amount of data from services you connect and stores only what the product needs to remember. This covers both the website and the iOS app. Last updated 5 September 2026.
What is collected
Connected-service data is collected only when you explicitly connect it. The website fetches this when you use it; if you add the iOS widget, iOS also refreshes its brief periodically in the background. The website and iOS app additionally collect anonymous, aggregate product analytics as described below.
- Brokerage positions, through Plaid: holdings, quantities, prices and account balances, read-only. For private retirement-plan funds, opening the growth view can also fetch up to 24 months of investment transaction dates, unit prices, quantities, transaction amounts and any tax lots the institution reports. Those fields support the chart and can fill cost basis only when the ledger reconciles to the current holding. No account or routing numbers, and no ability to move money.
- Calendar events, if you connect Google Calendar: event titles, times, locations and descriptions within the calendar window you open, plus names and time zones of calendars you choose. Calendar access begins read-only. If you separately enable editing, events you deliberately save are created or updated in your connected Google Calendar.
- News: articles from a public news API. If you connect a brokerage and agree to portfolio reporting, holding ticker symbols are used to request relevant coverage. Quantities, values, account details and your identity are not sent.
- Anonymous publisher opens: when you choose to open a news story, Less records only the publisher domain, whether the open came from Today, Reading, Saved or Money, and whether it came from the website or iOS app. It does not record the article URL, headline, topic, ticker, account, device identifier or a reading history. Custom-feed opens are excluded.
- Account information: the identity information needed to sign you in and keep connected providers private to your account.
How Less is More uses Google user data
If you choose to connect Google Calendar, Less is More accesses your Google account email address and events from your primary calendar or the calendars you select. Event data can include titles, descriptions, start and end times, locations, response status, attendee information used to show an attendee count, and links back to Google Calendar. Less is More uses your email address only to identify the connected Calendar account. It uses event data only to show your calendar in the website and iOS app, prepare the upcoming-events portion of your daily brief and widget, and open the selected event in Google Calendar.
Calendar access is read-only when you first connect it. If you separately choose to enable editing, Less is More requests additional permission to create events and update events that you own. The title, description, time and location you enter are then sent to Google Calendar solely to perform the save you requested. Less is More does not use Google user data for advertising, sell it, use it to determine creditworthiness, or use it to train AI or machine-learning models.
Less is More does not transfer or disclose Google user data to third parties except as necessary to provide these user-facing features: Vercel processes requests as the hosting provider, Clerk stores the encrypted Google authorization token for your account, and the current widget timeline is delivered to your own device. Google Calendar contents are not included in product analytics, publisher-open analytics, or server error logs.
How Google user data is protected
Google user data is protected in transit with HTTPS. Google access and refresh tokens are encrypted at rest with AES-256-GCM before they are stored with Clerk. The encryption key is held separately by Less is More, so Clerk cannot read those tokens. Stored credentials are bound to the authenticated account that connected them, and server-side access checks prevent one account from using another account's connection. The application requests only the Google permissions needed for the feature you choose, does not store Calendar event contents on its servers after responding to a request, and revokes the Google token when you disconnect Calendar or delete your account. Legacy browser-held credentials are encrypted and kept in HttpOnly, Secure cookies that expire after 90 days.
Where it is stored
Content preferences, routines, selected calendars, temperature units and deliberately saved weather locations are stored with your account. Automatically detected device coordinates are not saved to your account.
Brokerage positions and Calendar events are fetched when the dashboard or iOS widget loads. Calendar responses are discarded after the request. Brokerage responses can be reused for up to 20 seconds in server memory to avoid duplicate provider requests, then removed; they are not written to a database or disk. WidgetKit keeps the current widget timeline in the app’s protected on-device container so it can render while the app is closed. A widget snapshot may contain the portfolio total, daily change, three largest holdings, weather, quote, and next event title and time. Financial and event views are marked as privacy-sensitive for iOS lock-screen redaction. Private-fund transaction details, derived cost basis, account names, share quantities and provider identifiers are never included in the widget snapshot.
Access tokens are encrypted with AES-256-GCM, bound to your signed-in account, and stored against that account with Clerk. The encryption key is held by this application and never by Clerk, so the stored value is unreadable to anyone with access to Clerk alone. This is what lets a brokerage you link on one device show up on the others. Connections made before this changed are still read from an HttpOnly, Secure cookie in the browser that created them, and those expire after 90 days. Clerk also stores the account used to sign in. No provider tokens are stored on your phone.
Short-lived rate-limit counters are stored in Upstash Redis. They contain an opaque Clerk user identifier, route name, count and expiry only — never your email, topics, holdings, values, transaction prices or provider credentials — and expire within one day.
For private retirement-plan funds, dated unit prices observed during syncs are encrypted and saved in Upstash Redis for up to 400 days to calculate price changes and fill the growth chart. These records use hashed account and security identifiers; they contain no quantities, balances, account names or provider credentials. They are removed when you disconnect the brokerage or delete your account.
Your reading queue and saved artworks stay on the device that saved them — browser storage on the web, app storage on iOS — and are never sent to the server. They do not sync between devices. Saves are separated by account. Older saves without an account label are shown only after you explicitly import them as yours. Completed deletion clears this account’s saves on the device used; other devices retain isolated local copies until you clear their storage.
Aggregate page views and publisher-open counts are processed by Vercel Web Analytics. Its visitor hash rotates daily and is not connected to a Less account. Publisher-open events contain only the publisher domain, product surface and platform, and remain available in the analytics dashboard for the plan’s reporting window.
Membership and payment records
When you start a trial or purchase a membership, we keep account-linked trial dates, subscription status, provider customer identifiers, and verified offer redemptions in a dedicated billing database. RevenueCat verifies Apple and Stripe purchases so access follows your account across platforms. Apple and Stripe handle payment details; card numbers are not stored by Less is More. These services do not receive your holdings, calendar, or reading history from our billing integration.
Completed billing notification receipts are removed after 30 days. During account deletion, we remove the local subscription details and retain the opaque provider mapping and deletion record needed to prevent late notifications from restoring the account or restarting web billing. Unresolved encrypted revocation credentials remain only while cleanup is pending. Payment providers retain their own transaction records under their policies and applicable recordkeeping requirements. Trial access ends without an automatic payment.
To prevent repeated free trials, phone and email verification is required when claiming a trial. Clerk handles verification. We retain keyed hashes of verified email addresses and phone numbers in a separate trial-redemption record for 365 days after redemption, including after account deletion. This record contains no raw email, phone number, or account ID. The hashes are pseudonymous personal data, not anonymous data. Expired records are removed by scheduled maintenance. Short-lived trial-attempt counters are removed after one day. If a shared or reassigned number affects eligibility, contact support. You can still subscribe or restore an existing purchase without claiming another trial.
Who it is shared with
Data is not sold, not shared with advertisers, and not used by Less is More to train anything. The third parties involved are the providers needed to answer your request — Plaid, Google, Clerk, Apple and Stripe for payments, RevenueCat for subscription verification, a PostgreSQL hosting provider for billing records, Upstash for abuse-prevention counters, Vercel for hosting and anonymous aggregate analytics, the configured news and market-data APIs, a weather and geocoding provider, and the museum collections behind the culture feed. For portfolio reporting, the news and market-data APIs receive ticker symbols only. Coinbase supplies public 24-hour USD prices for supported cryptocurrencies and receives only the coin symbol, never balances or account details. The weather provider receives coordinates: precise ones only if you grant location permission or search for a place, and otherwise an approximate position derived from your connection. Each provider handles data under its own terms and privacy policy.
Removing it
Disconnect any source from the Connections screen. Brokerage disconnect revokes the Plaid Item; Calendar disconnect revokes the Google token. The stored encrypted session is cleared at the same time, on every device rather than just the one you used.
Signing out removes access to the current account on that device and leaves its saved reading and art isolated for a later sign-in. Your connections stay in place, so signing out on a laptop does not unlink the brokerage on your phone. Disconnect and Delete account revoke a provider; confirmed membership expiry also schedules brokerage revocation.
Use Delete account in Settings to revoke providers and remove the Clerk account. If a provider cannot be revoked, the account remains pending and encrypted credentials for only the unresolved connections are retained for retry. You can explicitly finish deletion and remove those permissions yourself at the named providers. Completed account deletion cannot be undone.
Retention
Connected-service contents are retained only for the request that displays them, except for the encrypted fund-unit price history and current iOS widget timeline described above. The widget remains on that device until iOS replaces it or the widget/app is removed. Access tokens are retained until you disconnect or delete your account; pre-existing copies held in a browser cookie expire after 90 days. The Clerk identity is retained until you delete the account. Saved items on a device remain until you clear them or remove the app. Server rate-limit counters expire within one day. Server logs record errors, not account contents, and follow the hosting platform’s retention window.
A waitlist address is kept only until the single launch notice promised on the public page has been sent, after which the whole list is deleted rather than kept as a marketing list. It is stored before any account exists, so it is not covered by deleting an account — write to the address below and it is removed on request.
Contact
Questions, or a request to remove data: support@lessismore.media. The terms of service cover the rest of the arrangement.