Privacy Policy
Template awaiting owner review — last updated August 2026.
1. What we collect
- Account data — email, name, phone (if provided), and authenticator enrollment status.
- Workspace content — the records and documents you and your workspace members add (which may include financial, insurance, and household information you choose to store).
- Security logs — sign-in attempts, audit trails of workspace actions, and security events, kept to protect accounts.
2. How your data is protected
- Every workspace is isolated with database row-level security — members of one workspace cannot read another's data.
- Uploaded documents live in private storage; they are only ever served through short-lived signed links to authorized members.
- Connected-service credentials (e.g. bank or Google tokens) are encrypted at rest with a dedicated key.
- Two-factor authentication is required on every account.
3. AI features
Document extraction and the assistant send relevant content to our AI providers (Anthropic and/or OpenAI) to produce results. Extracted data is never saved to your records without your explicit approval. We do not train models on your data. [OWNER REVIEW: confirm provider data-retention settings match this claim.]
4. Processors
We rely on: Supabase (database, auth, storage), Vercel (hosting), Resend (transactional email), Anthropic and OpenAI (AI features), and — only when you connect them — Google (Calendar/Drive) and Plaid (bank connections).
5. Retention and deletion
Workspace content stays until you delete it or your workspace is removed. You may request account erasure: personal data (name, phone, email, avatar) is scrubbed and access is permanently revoked, while minimal audit records are retained for accountability. [OWNER REVIEW: retention windows for logs and backups.]
6. What we don't do
- No selling of personal data.
- No advertising trackers in the product.
- No storage of full identity-document numbers or card numbers by design.
7. Contact
For privacy questions or erasure requests: [OWNER REVIEW: contact address — see the support-channel backlog card (E10-T4).]