Privacy Policy
Last updated: draft — not yet effective. This policy is a placeholder aligned with our technical security posture and must be reviewed by privacy counsel before onboarding real users.
What we collect
- Account information (email and sign-in credentials, managed by our authentication provider, Clerk — we do not store your password).
- Financial profile data, conversation transcripts, and plan outputs you provide or generate through the service.
- Technical logs with PII redaction (no profile contents in logs).
How we use it
- To authenticate you and run the planning pipeline on your inputs.
- To store and deliver your intakes, runs, and artifacts.
- To operate, secure, and improve the service.
How we protect it
- Sensitive fields are encrypted at the application layer before database storage.
- Authentication is handled by Clerk; session tokens are verified server-side on every request. Legacy accounts' passwords are bcrypt-hashed — never stored in plaintext.
- Per-user server-side authorization on every data access.
- TLS required in production.
Retention & deletion
You may delete individual intakes or runs, or delete your entire account and all associated data from the dashboard. Runs and artifacts may be purged after a configurable retention period. Intake data persists until you delete it or your account.
Third parties & cross-border transfer
We use a small number of service providers to operate the service. Each processes only what its role requires:
- Clerk (authentication) — your email and sign-in credentials.
- Plaid (bank connections) — your banking credentials are entered with Plaid directly and never reach our servers; Plaid returns account and transaction data to us with your approval.
- Neon (database hosting) — stores your data; sensitive fields are encrypted by the application before storage.
- Vercel and Railway (application hosting) — serve the web interface and run the backend that processes your plan.
- Anthropic (AI intake) — conversation content is processed to extract and organise your profile information.
These providers store and process data on infrastructure located in the United States. While your information is outside Canada, it is subject to the laws of that jurisdiction, and may be accessible to its courts and authorities under lawful access regimes. We rely on contractual safeguards and the technical measures described above (including application-layer encryption of sensitive fields) to provide comparable protection, as PIPEDA requires. Draft — confirm subprocessor agreements, and assess Quebec Law 25 obligations (including a transfer privacy assessment) with counsel before launch. We do not sell personal information.
Your rights
Under PIPEDA and applicable provincial privacy law, you may have rights to access, correct, or delete personal information. Contact the operator to exercise these rights. Draft — add contact details and breach-notification procedures.
Analytics
We do not load third-party analytics scripts by default. If analytics are added in the future, they will use a privacy-respecting approach with no PII, and this policy will be updated accordingly.