Aura List
Privacy Policy
Aura List is a public leaderboard of net worth. You connect a bank, we read the balances, and we publish one number beside your name. This page explains exactly what that means: what is public, what stays private, and how to remove all of it.
Effective 25 August 2026. Last updated 25 August 2026.
Who this covers
This policy applies to Aura List, the web application at aurali.st (also reachable at trustworth.vercel.app). It covers everyone who visits the board and everyone who connects a bank account to it. In this policy, "we" means the operators of Aura List and "you" means the person using it.
What we collect
Three categories, and the difference between them is the most important thing on this page.
Public Shown on the board to anyone
- The name you typed. You choose what to type.
- The handle you typed, and the link your row points to, if you set one.
- Your profile picture, if you upload one. It is stored at a public web address.
- Your total net worth, in dollars, and the previous total so the board can show which way it moved.
- How many banks and how many accounts stand behind that total, as counts only, and the time of the last refresh.
Private Held by us, shown only to you
- The name, type and last four digits of each account you shared, and the balance of each one.
- The name of each institution you connected.
- The access token Plaid gives us for each connection, which is what lets us re-read a balance. It is encrypted before it is stored.
- A one-way hash of your recovery key, so the key can be checked without us holding it.
This detail is served only to the browser holding your session cookie, from an endpoint that takes no account identifier, so there is nothing for anyone to enumerate. It is never included in the public board.
Never Things we do not collect at all
- Your bank username or password. Those are entered inside Plaid's own secure flow and never reach our servers or our code.
- Your transaction history. We do not request it from Plaid. We ask for balances, and nothing about where your money came from or went.
- Your email address, phone number, or a password. There is no sign-up.
- Analytics, advertising or tracking data. We run no trackers of any kind.
How the bank connection works
We use Plaid to connect accounts. When you click to connect, Plaid opens its own secure window, you log in to your bank there, and your bank tells Plaid which accounts you agreed to share. Plaid hands us a token for those accounts. Your credentials stay between you, Plaid and your bank.
Plaid processes your information under its own End User Privacy Policy. You can see and revoke every connection you have ever made through Plaid, to us or to anyone, at my.plaid.com.
Why we hold it
- To publish your total. That is the product, and it is the reason you connected an account.
- To refresh it. A net worth is only true as of a moment, so we re-read balances and store the new total against your row.
- To keep the board honest. We compare the masked account details of a new connection against existing ones so that the same bank cannot be counted twice, or claimed under two names.
- To let you back in. Your row lives behind a cookie and a recovery key, which is what stands in for an account.
We do not sell your data. We do not share it with advertisers, data brokers, or anyone building a marketing profile. We do not use it to train machine learning models.
Who else touches it
Only the companies we need to run the service:
- Plaid — connects your bank and returns balances.
- Vercel — hosts the application and stores profile pictures.
- Our database provider — stores the rows described above, encrypted at rest.
We may also disclose information if the law requires it, and we will say so publicly where we are permitted to.
How we protect it
- Every Plaid access token is individually encrypted with AES-256-GCM before it is written to the database. The key is held outside the database and is not in our source code.
- All traffic is served over TLS 1.2 or better, and connections to the database and to Plaid are encrypted in transit.
- The database and the picture storage are encrypted at rest.
- Your session cookie is signed, httpOnly and secure, so it cannot be read by scripts or forged to impersonate you.
- Your recovery key is stored only as a one-way hash.
- Access to production systems is limited to named accounts with multi-factor authentication.
How long we keep it
- While your row exists, we keep your public row, your private account breakdown, and your encrypted access tokens.
- Balances are overwritten, not accumulated. Each refresh replaces the last one. We do not build a history of your balances over time.
- If you hide your row, it leaves the public board and your data stays so you can come back.
- If you delete your row, everything goes, as described below.
- Dormant rows are deleted. If a row has not been refreshed for 12 months, we delete it and revoke its bank connections.
This policy, and the retention periods in it, are reviewed at least once a year.
Deleting everything
From your own row, Delete and forget me does all of this in one action:
- Revokes every bank connection at Plaid, so we can never read your accounts again.
- Deletes every stored access token.
- Deletes your account breakdown and balances.
- Deletes your row, your name, your handle and your total from the board.
- Deletes your profile picture from storage.
- Clears your session.
It is immediate and it is not recoverable. There is a separate, gentler option that only takes you off the public board and leaves your data with you.
You can also revoke our access directly at my.plaid.com at any time, with or without deleting your row.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal information, to withdraw consent, and to object to how we use it. Aura List is built so that you can exercise most of these yourself: your row shows you everything private we hold about you, and the delete button removes all of it without asking us.
For anything the app cannot do for you, email us and we will respond within 30 days. We will not charge you and we will not treat you differently for asking.
Consent
We collect your information because you asked us to publish a number, and you tell us so twice: once when you connect a bank through Plaid's consent screen, and once by choosing to appear on a board whose entire purpose is public. You can withdraw that consent at any time by hiding or deleting your row, or by revoking access at Plaid.
Cookies
We set exactly one cookie. It holds a signed identifier for your row so that the site knows which row is yours, and it lasts a year unless you delete it. It is strictly necessary for the service to work. We use no analytics, advertising or third-party tracking cookies.
Children
Aura List is not for anyone under 18, and we do not knowingly collect information from children. If you believe a child has connected an account, email us and we will delete it.
Changes to this policy
If we change how we handle your information, we will update this page and change the date at the top. If a change materially affects what is public about you, we will say so on the board itself before it takes effect.
Contact
Privacy questions, deletion requests, and anything else about this policy: privacy@aurali.st.
Security reports: security@aurali.st.