Legal and privacy
Privacy Policy
Stratos is a private household financial-planning workspace operated by Kapex Labs. This policy explains what information Stratos handles, why it is used, when it may be shared, and the choices available to you.
- Effective
- July 13, 2026
- Last updated
- July 13, 2026
On this page
Privacy at a glance
- Stratos uses information provided by authorized household members to organize a plan and calculate planning summaries.
- Household information is available to authenticated members of that household according to their role.
- Connecting a financial institution through Plaid is optional.
- Stratos does not currently import Plaid transaction history.
- Kapex Labs does not sell personal information or use household financial information for targeted advertising.
- Stratos is intended for adults and is not directed to children under 18.
This summary does not replace the complete policy below.
1. Scope
This Privacy Policy applies to the Stratos website, authenticated workspace, support communications, access requests, and related services operated by Kapex Labs.
It does not replace the privacy terms of third-party services you choose to use with Stratos. For example, Plaid separately explains how it processes information when you use Plaid to connect a financial institution.
2. Information Stratos handles
Account and identity information
Stratos may use information such as your name, email address, account identifier, authentication status, password-recovery state, invitation information, and household membership. Authentication credentials are handled through the authentication service; do not send passwords or authentication links to Kapex Labs by email.
Household access information
Stratos stores household membership, role, invitation, and access-related information so the service can open the correct household and enforce owner, editor, and viewer permissions.
Household financial-planning information
Stratos stores information that authorized household members enter or create, including:
- Expected and received income.
- Income classifications, planned extra income, and reimbursement links.
- Budget categories, pay periods, monthly plans, and allocations.
- Spending records, dates, categories, notes, and account references.
- Accounts, balances, credit limits, display modes, and account status.
- Bills, subscriptions, recurring obligations, due dates, payment status, and Auto Pay preferences.
- Debt accounts, balance segments, promotional terms, minimums, and debt-payment records.
- Desired cash buffer and other household planning preferences.
Because Stratos is a shared household workspace, information entered by one authorized member may be visible to other authorized members of the same household according to their role.
Optional linked-account information
If a household chooses to connect a financial institution through Plaid, Plaid may provide Stratos with information such as:
- Institution name.
- Account name, type, and subtype.
- A masked account number.
- Current or available balance.
- Currency.
- Connection and refresh status.
- Identifiers needed to maintain the connection and account mapping.
Financial-institution sign-in occurs in Plaid’s connection flow, not in a Stratos form. Stratos stores an encrypted connection token so an authorized owner or editor can request future balance refreshes.
The current Stratos integration does not import Plaid transaction history and does not initiate financial transactions.
Technical and operational information
When you use Stratos, Kapex Labs and its service providers may automatically receive limited technical information needed to deliver, secure, and troubleshoot the service. Depending on the request and provider, this may include IP address, browser or device information, timestamps, requested pages, authentication events, error information, security logs, and essential cookies or similar session technology.
The audited Stratos application currently uses essential technology for authentication, security, linked-account setup, and core service operation. It does not include advertising cookies, analytics scripts, session replay, or advertising pixels.
Communications
Kapex Labs receives the information you choose to include in support messages, access requests, privacy requests, security reports, and other direct communications.
Derived planning information
Stratos calculates summaries, warnings, and planning figures from household records. These may include Safe-to-Spend, budget status, bill and debt signals, period variance, and setup progress. These are planning outputs, not verified bank balances or professional financial advice.
3. How information is collected
Information may come from:
- You.
- Other authorized members of your household.
- Plaid and the financial institution you choose to connect.
- Authentication, hosting, security, and infrastructure providers as the service operates.
- Communications you send directly to Kapex Labs.
4. How information is used
Kapex Labs uses information to:
- Create and authenticate accounts.
- Route members to the correct household.
- Enforce household roles and permissions.
- Provide budgeting, income, spending, bill, account, debt, and Safe-to-Spend features.
- Maintain optional Plaid connections and retrieve requested balance updates.
- Respond to support, access, privacy, and security requests.
- Detect, investigate, prevent, and address misuse, fraud, technical problems, and security incidents.
- Maintain, debug, test, and improve service reliability and usability.
- Comply with applicable law and enforce the Terms of Use.
5. Household visibility and control
Stratos is designed for household collaboration, not individual secrecy within a shared household.
- Owners manage invitations, roles, and household access.
- Editors can update household financial records.
- Viewers can read the household plan without changing it.
Members should enter information only when they are authorized to make it available to the household. Removing a member stops future household access but does not remove records the person previously entered into the shared household workspace.
6. Service providers and disclosure
Service providers
Service providers process information for Kapex Labs to operate Stratos. Current providers and functions include:
- Supabase: authentication, database, and application-data infrastructure.
- Vercel: website hosting, deployment, delivery, and related operational infrastructure.
- Plaid: optional financial-institution connection and account-balance data.
- Google/Gmail: messages you choose to send to the public Kapex Labs contact destination shown for the relevant purpose.
Each provider processes information under its own terms and privacy documentation. Plaid’s End User Privacy Policy applies when you use Plaid’s connection flow.
Household members
Information is disclosed to authenticated members of the same household according to their role.
Legal, safety, and security reasons
Kapex Labs may preserve or disclose information when reasonably necessary to comply with law, legal process, or lawful government requests; protect the rights, safety, and security of users, Kapex Labs, or others; investigate fraud or misuse; or enforce agreements.
Business changes
If Stratos or Kapex Labs is involved in a merger, financing, acquisition, reorganization, sale of assets, or similar transaction, information may be reviewed or transferred as part of that process, subject to appropriate confidentiality and notice where required.
At your direction
Information may be disclosed when you request or authorize the disclosure.
7. Sale and targeted advertising
Kapex Labs does not sell personal information. Stratos does not use household financial information for cross-context behavioral advertising or targeted advertising.
If the product later introduces advertising, marketing pixels, data brokerage, or a materially different sharing practice, this policy will be updated and any required consent or opt-out controls will be implemented before that practice begins.
8. Retention
Kapex Labs retains information for as long as reasonably necessary to provide Stratos, maintain household records, protect the service, comply with legal obligations, resolve disputes, and enforce agreements.
- Active account and household information is retained while the account or household remains active.
- Shared household records may remain after an individual member is removed.
- Deleted spending records may remain as soft-deleted database records.
- Disconnected Plaid records, including an encrypted connection token, may be retained for security, reconciliation, audit, or legal purposes, but the connection is no longer used for future refreshes.
- Verified deletion requests are applied to active systems subject to shared-household authority, legal obligations, security needs, dispute preservation, and technical backup cycles.
- Residual copies may remain temporarily in backups and logs until they expire or are overwritten through ordinary system processes.
- Support and legal-request communications may be retained as needed to document and resolve the request.
9. Your choices and requests
Depending on your relationship to the household and applicable law, you may request to:
- Learn whether Kapex Labs holds information associated with your account.
- Access or receive a copy of certain information.
- Correct inaccurate account information.
- Delete your individual account information.
- Request deletion of a household if you are authorized to control it.
- Object to or restrict certain processing where applicable.
Kapex Labs may need to verify your identity and authority before completing a request. An individual member may not have authority to delete records owned collectively by a household, and deleting an entire household may require verification from a household owner.
Email from the address associated with Stratos and use the subject “Stratos privacy request.” Do not include passwords, bank credentials, authentication links, or full account numbers. Kapex Labs will respond as required by applicable law. Some information may be retained when permitted or required for security, fraud prevention, legal compliance, dispute resolution, or the rights of other household members.
Privacy contact: kapexlabs@gmail.com
The address stays visible if no email app is configured.
10. Security
Kapex Labs uses administrative, technical, and organizational safeguards intended to protect Stratos information. The audited application uses authenticated access, household role controls, database access policies, server-only handling for service credentials, and application-level encryption of Plaid connection tokens.
No online service can guarantee absolute security. You are responsible for protecting your email account, password, devices, and invitation or recovery links. Contact Kapex Labs promptly if you believe your Stratos account or household access has been compromised.
If Kapex Labs identifies a security incident involving personal information, it will investigate, take appropriate remediation steps, and provide notices when required by applicable law. Visit the security support path to report a concern.
11. Children’s privacy
Stratos is intended for adults and is not directed to children under 18. Do not create an account for or invite a person under 18. Kapex Labs does not knowingly collect personal information from children through Stratos. If you believe a child has provided personal information, contact Kapex Labs so the situation can be reviewed.
12. Processing location
Kapex Labs and its service providers may process information in the United States and other locations where they operate. Data-protection laws in those locations may differ from the laws where you live.
13. Third-party services
Stratos may link to or integrate with services operated by others. Kapex Labs does not control the independent privacy practices of those services. Review their terms and privacy notices before using them.
For Plaid-connected accounts, review the Plaid End User Privacy Policy (opens Plaid’s site in a new tab).
14. Changes to this policy
Kapex Labs may update this Privacy Policy as Stratos changes. This page will show the effective and last-updated dates. If a change materially affects how existing personal information is used, Kapex Labs will provide additional notice through Stratos, email, or another appropriate channel before or when the change takes effect, as required.
Material policy changes receive a new policy version. Typographical or non-material clarifications may retain the current version.
15. Contact
Questions, requests, or concerns about this policy may be sent to Kapex Labs at kapexlabs@gmail.com. Use the suggested subject “Stratos privacy request.” Do not send passwords, bank credentials, authentication links, or full account numbers.
Privacy contact: kapexlabs@gmail.com
The address stays visible if no email app is configured.
Policy version: privacy-2026-07-13-v1
URL: https://stratos.kapexlabs.app/privacy