← Residual ForgePublic planning beta · sign in for saved plans and banksSign in with ChatGPT
Residual Payoff

Privacy notice

Effective September 12, 2026. Residual Payoff is operated by Residual Forge. Contact Srikant Voruganti at srikantvoruganti@gmail.com about your information or this notice.

Information used to provide the app

Planning inputs include debts, income, expenses, assets, cash-flow dates, scenarios and transaction categories. Unsaved inputs are held in the browser session. Cloud saving sends the plan to the service, associated with your hosting-provided sign-in identifier. The app does not maintain a separate password database.

When you authorize Plaid, the service receives connection tokens and the accounts and financial data supported by your chosen connection. This can include account names, masked account identifiers, balances, transactions, mortgage, credit-card and student-loan details. Access tokens stay on the server. The app does not ask you for a bank password. Plaid and your bank process authentication according to their own notices.

Optional budget and balance automation uses selected cached accounts to update your saved plan. You can turn it off and save the changed settings. Calculations do not move money, apply for credit or submit payment instructions.

Providers and storage

OpenAI Sites supplies hosting and sign-in; Cloudflare Workers and D1 run the service and database; Plaid supplies authorized bank data. When billing is enabled, Stripe processes checkout and recurring billing. The app keeps subscription status and provider identifiers, and does not receive full payment-card details. Billing is currently disabled.

Saved plans, bank access tokens, cached accounts, loan details and transactions use application encryption with account-specific authenticated data. Provider infrastructure also has its own controls. Authorized service operation still requires access to encryption keys; no service can promise absolute security. Hosting and other providers may process request metadata and operational logs under their own policies. This app does not add advertising trackers or sell bank data.

Retention and your controls

Private optimization runs in the browser. Saving a plan also saves your optimization preferences. Coaching is optional: creating an invitation stores an encrypted snapshot containing the account names, balances, rates, payment terms and budget totals you preview, plus your alias and question. It excludes bank tokens and transaction history. A claimant’s sign-in name and email are shown to you for approval; no financial snapshot or question is revealed to them before approval.

Coaching invitations expire after seven days. Approved access lasts 90 days. Expiry stops coach access but does not automatically delete the record: the customer can export or delete it. Shared snapshots and written messages/actions remain until either participant deletes the workspace or the customer deletes their cloud plan. Account export includes your available coaching workspaces. Revocation cannot recall copies already viewed or downloaded. A coach’s credentials and independent retention practices are not verified by the app. No email notifications are sent.

Manual cloud saves retain up to five previous encrypted plan versions. Deleting the cloud plan also deletes these versions. Background bank updates do not create a new version on every sync.

If you enroll a passkey, the service stores its public key, identifier, device label, signature counter and registration date. It also stores hashed recovery codes and temporary verification challenges. Your device’s biometric or PIN information is not shared with the app. These security records remain to protect your account after financial-plan deletion.

Saved plans and cached bank information remain until you delete the plan or disconnect the relevant bank. There is currently no automatic inactive-account expiry. Disconnecting revokes that Plaid connection and removes its app cache. Copies previously imported into your plan are removed separately. Account & data provides export and combined removal controls.

Deletion controls remove active application records; they do not promise immediate removal from provider backups or operational logs. Those records follow provider retention settings and obligations. Downloaded files remain on your devices. The password-protected plan backup option encrypts its file in your browser; ordinary JSON and CSV exports are unencrypted. The service never receives your backup password. You can contact the operator to request help with access, correction or deletion. The app’s controls do not delete your OpenAI sign-in account or records held independently by your bank or Plaid.

Scope and updates

This U.S. household planning beta is intended for adults. Do not enter another person’s information without permission. Public pages may be viewed without saving financial data. Material changes to this notice will appear here with an updated effective date. Review provider notices as well: Plaid, Stripe and OpenAI.