Copper

Information Security Policy

Effective September 28, 2026 · Next review September 2027

This policy describes how SUPERNIGHT, LLC ("we", "us") protects the systems behind the Copper app and the consumer financial data they process, including data received from Plaid. It applies to everyone with access to Copper's production systems, including employees, contractors, and the company's owner.

1. Ownership and responsibility

Dakota Perry, owner of SUPERNIGHT, LLC, is responsible for information security. That covers keeping this policy current, approving access to production systems, running the reviews below, and leading incident response. Security questions can be sent to the contact address in our Privacy Policy.

2. Data we protect

3. Access control

4. Consumer authentication

5. Encryption

6. Secure development

7. Vulnerability and patch management

8. Logging and monitoring

Authentication, database and server function logs are kept by our providers and reviewed when something looks wrong. Bank-connection errors reported by Plaid are recorded and shown to the affected user so the connection can be repaired.

9. Vendors

We only use vendors that protect data at a level comparable to this policy. Their security reports (for example SOC 2) are reviewed when we start using them and again once a year. Current vendors that handle consumer data are Plaid (bank connections), Supabase (database, authentication and server functions), Railway (hosting), Apple and Google (sign-in and app distribution), RevenueCat (subscription status) and Expo (app builds and push notifications).

10. Incident response

  1. Detect and triage: confirm what happened and which data and systems are affected.
  2. Contain: revoke the affected sessions and credentials, rotate keys, and disconnect affected bank connections if needed.
  3. Recover: fix the cause and restore service.
  4. Notify: tell affected users, Plaid and any other affected partners without undue delay, and as the law and our contracts require.
  5. Review: write down the cause and fix, and update this policy if needed.

11. Data retention and deletion

We keep consumer data only while the account is open. People can delete their account in the app at any time. Doing so removes every linked bank at Plaid and permanently deletes their budgets, transactions, images and profile. Removing a single bank disconnects it at Plaid and stops syncing. Backups roll off after a limited period. The full details are in our Privacy Policy. We review our retention practices at least once a year to make sure they still meet applicable privacy laws.

12. Policy review

We review and update this policy at least once a year, and whenever our systems or legal requirements change significantly.