Privacy Policy

Last updated 15 September 2026

nbdomains LLC, a Kentucky limited liability company ("we", "us"), is the parent company and operator of Fovar. This Privacy Policy explains what we collect when you use the Fovar mobile application and the fovar.app website (together, the "Service"), why, who we share it with, and what control you have.

This document is published at nbdomains.com/privacy by nbdomains LLC as the operating entity. It was previously published at fovar.app/privacy; the substance is unchanged by the move.

If you do not agree with this Policy, please do not use the Service.

  • Data controller: nbdomains LLC (parent company and operator of Fovar)
  • Contact: support@nbdomains.com
  • Telephone: 331-642-0883
  • Postal: 212 N. 2nd St. Ste 100, Richmond, KY 40475, Madison County, United States

1. The short version

Fovar is a shared treasury for a small group — a youth group, a ladies' circle, a few friends helping each other. Here is the whole of it in seven lines:

  • We never see your online banking login. You type it into Plaid's screen, not ours.
  • We do not keep the key to your bank. Plaid gives us a long-lived access token and we deliberately throw it away.
  • We store no Social Security Number, no date of birth, and no ID document. Not encrypted, not restricted — there is no column for them. Stripe handles identity verification and keeps that data.
  • We never see your full card number.
  • We do not track you. No advertising, no analytics profile, no location, no device fingerprint.
  • Your group's ledger cannot be deleted, including by you. It belongs to your group as much as to you. See §6.
  • We are a small company and we would rather tell you the awkward parts than bury them.

2. What we collect

2.1 What you give us

Email addressto sign you in and reach you
Passwordstored only as a hash — we never see it in readable form
Full nameshown to other members of your group
Phone numberoptional
City and statetyped by you. We never collect GPS or device location, and the app never asks for location permission
Profile pictureoptional

2.2 What your group activity creates

Your contributions and their amounts and dates; which group and which fund; withdrawal requests, who approved them, and where the money was sent.

Whether your name appears next to a contribution for other members to see is your group's setting. It is off by default, because making non-payment visible to everyone is a decision a group should make deliberately.

2.3 Subscription billing

If your Group is on a paid plan ($29 or $129 a month), Stripe collects and holds the payment card. We never see the card number — we store only a reference, the last four digits, and whether the subscription is active.

Groups on the Free plan give us no billing information at all, because there is nothing to bill.

2.4 What we collect automatically

Crash reports and performance diagnostics, so we can fix things that break. Two things about this:

  • We do not attach your IP address, and we do not automatically identify you in a crash report.
  • Every report is scrubbed before it leaves your phone. An automated pass strips email addresses and access tokens from error messages, so your data does not reach our monitoring tools even when a mistake in our code would have put it in an error string.

We also store a push notification token so we can send you notices.

2.5 What we do NOT collect

  • No location, ever. No GPS, no coarse location, no IP-based location.
  • No advertising or tracking identifiers. There is no ad SDK, no attribution SDK and no cross-app identifier in our app.
  • No contact list, no photo library, no microphone, no camera roll.

3. Your bank details — what Plaid holds and what we do not

When you link a bank account:

  1. You tap Link a bank in Fovar.
  2. Plaid's own screen opens, and you type your bank username and password into it. Our code never draws those fields and has no way to read them.
  3. Plaid confirms the account to us.

What we store, in full:

  • an opaque reference number from Plaid;
  • an opaque reference number from Stripe for the payment method;
  • your bank's name (e.g. "Chase");
  • the last four digits of the account number, and nothing more — our database physically rejects any other value in that field.

What we do not store:

  • your bank username or password, ever;
  • your full account number or routing number;
  • the Plaid access token. This one is worth explaining. When you link a bank, Plaid gives us a long-lived key to that connection. Nothing in Fovar needs to read your balance or your transactions once Stripe handles the debits — so we discard that key without ever writing it down.

What that means for you: if someone stole our entire database tomorrow, they could not read your bank account and could not move money out of it.


4. Identity verification — Stripe holds it, we do not

If you are the adult Account Holder for a group, you complete identity verification to receive money.

You do that on Stripe's own website. Your Social Security Number, date of birth and any photograph of an ID go to Stripe, under Stripe's agreement with you.

What Fovar receives back: an opaque account reference (like acct_1A2B…) and a few yes-or-no flags — verified or not, payouts enabled or not, and the dates.

There is no field anywhere in our database for a Social Security Number, a date of birth, a passport, a driver's licence, an ID photograph or a tax identifier. We checked the entire schema and every change ever made to it. This is not a promise about our procedures; it is the shape of the system.


5. Who we share information with

We do not sell your data. We have never sold it and the business does not depend on it.

We share what is necessary with the companies that make the Service work:

WhoWhat they getWhy
SupabaseYour account and group dataOur database, sign-in and file storage (United States)
StripePayment details, and your identity data directly from youMoving money, payouts, identity verification
PlaidYour bank credentials directly from you, and account detailsConnecting your bank
Google (Firebase)Push token, crash diagnosticsNotifications and crash reporting
SentryScrubbed error reportsFinding bugs
ResendYour email address and message contentSending you email and running support
VercelOrdinary web request dataHosting fovar.app

Stripe and Plaid are independent companies that decide for themselves how to handle the data you give them directly. Their own privacy policies apply.

We will also share information when the law requires it — a valid subpoena, court order or lawful request from a regulator — and where we need to in order to investigate fraud or protect someone from harm.


6. Deleting your account, and the one thing that stays

You can delete your account from inside the app. We will remove your profile, your contact details and your login.

Your entries in a group's ledger do not go away, and we want to be straight with you about why.

A group's ledger is not only your record — it is simultaneously every other member's record of what the group collected and what it holds. It is append-only by design: nobody can edit or delete an entry, including us, and a correction is a new entry rather than a change to an old one.

If one member's departure could erase their contributions, then:

  • the group's balance would no longer add up;
  • every other member's record of what they are owed would silently change;
  • the trust that makes a shared treasury work would be gone.

So contribution and withdrawal entries remain, as part of the group's financial record. Where we can, we disconnect them from your personal profile.

We keep this information because we have a legitimate interest in the integrity of other members' financial records, and because a group may need those records for its own accounting.

If you believe this affects you unfairly, write to us at support@nbdomains.com and we will look at your situation individually.


7. How long we keep things

  • Account and profile data — until you delete your account.
  • Ledger entries — indefinitely, as §6 explains.
  • Support email — up to 3 years, so we can see the history of a problem.
  • Crash reports — up to 90 days.
  • Bank link records — for as long as the link is active, and afterwards as part of the record of payments made through it.

8. Remote settings — one thing people ask about

Fovar can turn a feature off, or put one screen into maintenance, without releasing an app update. We use it when something is broken.

This works by your phone asking our server what the product is currently doing. It is a one-way read.

Your phone sends its sign-in token, and nothing else — no device identifier, no advertising ID, no fingerprint of your handset, no record of what you were looking at. We are not collecting anything to make that decision, and what you see is not personalised based on you.


9. Children

You must be 13 or older to have a Fovar account, and 18 or older to be the Account Holder for a group, connect a payment account, or move a group's money.

If you are between 13 and 17, you need a parent or guardian's permission, and they are responsible for your use of the Service.

We do not knowingly collect information from anyone under 13. If you believe a child under 13 has an account, email support@nbdomains.com and we will delete it.


10. Security

  • Passwords are stored as hashes. Nobody at Fovar can read your password.
  • Your sign-in session is kept in your phone's secure hardware storage — the iOS Keychain or the Android Keystore — not in ordinary app storage.
  • All traffic is encrypted in transit. The app refuses unencrypted connections.
  • Access to your group's data is enforced by the database itself, not only by the app, so a bug in one screen cannot expose another group's records.
  • Error reports are scrubbed before they leave your phone (§2.4).

No system is perfectly secure, and we will not pretend otherwise. If we discover a breach affecting your personal information, we will tell you and the relevant authorities as the law requires.


11. Your rights

Depending on where you live, you may have the right to:

  • see what personal information we hold about you;
  • correct it if it is wrong;
  • delete it, subject to §6;
  • export it in a portable form — you can export your group's ledger from the app at any time;
  • object to a particular use.

We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing for you to opt out of on that front.

To exercise any of these, email support@nbdomains.com. We will verify who you are before acting, and respond within the time the law allows.


12. Where your data is

Fovar operates in the United States and our providers store data there. If you use the Service from elsewhere, your information will be transferred to and processed in the United States.


13. Changes

We may update this Policy. If a change materially affects you, we will tell you in the app or by email before it takes effect. The date at the top always shows the current version.


14. Contact

  • Entity: nbdomains LLC
  • Postal: 212 N. 2nd St. Ste 100, Richmond, KY 40475, Madison County, United States
  • Email: support@nbdomains.com