Privacy Policy

Last updated: July 15, 2026

Effective date: July 15, 2026

Contents

1. Introduction2. Information We Collect3. How We Use Your Information4. Third-Party Services5. AI Coach & Insights — Data Access6. AI-Powered Budgeting7. Data Storage & Security8. Cookies & Local Storage9. Data Retention10. Your Rights11. California Privacy Rights12. Children's Privacy13. Changes to Policy14. Contact

1. Introduction

WealthWeave (“we,” “our,” or “us”) is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use and protect it, who we share it with, and the rights you have regarding your data. By using the Service, you agree to the practices described in this policy.

2. Information We Collect

We collect the following categories of information:

  • Account data: Your email address and encrypted password, managed by Supabase Auth. We do not store plaintext passwords. We also store your first and last name (optional, used to personalize emails) and account creation timestamp.
  • Financial data: Bank account names, balances, and transaction history retrieved from your linked financial institutions via Plaid, Inc. This includes transaction amounts, dates, merchant names, and spending categories. The last 90 days of transactions are synced to and stored in our database; holdings are stored separately. We also store a permanent Plaid access token per linked institution, which grants us ongoing read-only access to that institution on your behalf. We do not store or transmit your bank login credentials.
  • Financial goals: Goal titles, target amounts, current progress, target dates, and associated emojis that you create within the Service.
  • Subscription data: Your billing tier (Free, Trial, Pro, or Platinum), trial expiry date, Stripe customer ID, and subscription status. Full payment card details are handled exclusively by Stripe and are never stored by WealthWeave.
  • Investment holdings data: Brokerage and retirement account holdings retrieved via Plaid Investments, including security names, ticker symbols, quantities, and current market values. This data is stored in our database and displayed in the Investments section of the Service.
  • Preference data: Your AI Coach tone preference (direct, empathetic, or coaching), weekly digest notification opt-in, and spending alert opt-in. Stored in your account profile.
  • AI conversation data:Messages you send to the AI Coach and the AI’s responses, which may include a snapshot of your financial data at the time of the conversation. Conversation history is not retained server-side; your full message history is sent from your browser to our server on each request and is not stored in our database.
  • Bot-verification data: When you create an account or request a password reset, Cloudflare Turnstile verifies that the action is performed by a human. A verification token is generated client-side and validated server-side. We do not store this token after verification.
  • Trial suppression data: When an account is deleted, a one-way SHA-256 hash of the associated email address (lowercased and trimmed) is permanently stored in our database to prevent the same email from claiming a second free trial upon re-registration. No plaintext email address is retained for this purpose; the hash cannot be reversed.
  • Waitlist data: If you submitted your email address during our pre-launch waitlist period, that email is stored in our database. It is not linked to your account and is not used for advertising. Contact us at support@wealthweave.co to request removal.
  • Error and diagnostic data: When application errors occur in production, Sentry (our error monitoring service) may capture metadata including your user ID, the feature in use, and the error details. Session recording is disabled — no screen content or keystrokes are ever captured by Sentry.
  • Usage data: Pages visited, features used, session timestamps, and browser/device type, collected for product improvement and debugging.

3. How We Use Your Information

  • To provide, personalize, and improve the Service
  • To power the AI Coach with your real financial data so responses are accurate and relevant to your situation
  • To detect recurring subscriptions in your transaction history (Platinum tier) and display them in the Subscription Manager
  • To generate credit score simulations and credit-building insights (Platinum tier)
  • To categorize transactions for tax analysis features (Platinum tier)
  • To send weekly financial digest emails to Platinum subscribers who have opted into them
  • To process payments and manage your subscription through Stripe
  • To send transactional emails: account confirmations, security alerts, and billing receipts via Resend
  • To enforce rate limits on API usage using Upstash Redis, protecting platform availability for all users
  • To enforce our Terms and Conditions and prevent fraudulent or automated abuse
  • To improve platform performance and diagnose technical issues

We do not sell your personal information to third parties. We do not use your data for targeted advertising.

4. Third-Party Services and Data Sharing

We share data with the following trusted third-party service providers only as necessary to operate the Service:

  • Plaid, Inc.: Bank account and transaction data aggregation. Your use of Plaid is also governed by Plaid’s End User Privacy Policy. WealthWeave never receives or stores your bank credentials.
  • Stripe, Inc.: Payment processing and subscription management. WealthWeave transmits only the minimum required billing data to Stripe and never stores full card numbers. Stripe is PCI-DSS Level 1 compliant.
  • Supabase: Secure cloud database hosting and user authentication. Data is stored in encrypted databases with row-level security enforced per user account. Supabase runs on AWS infrastructure.
  • Google (Gemini API): AI coaching responses and AI-powered budget recommendations. When you use the AI Coach, a snapshot of your financial profile (accounts, balances, recent transactions, goals, net worth) may be transmitted to Google’s Gemini API to generate your response; when you use our budgeting features, your transaction history is sent to generate budget suggestions. This data is subject to Google’s Privacy Policy.
  • Cloudflare (Turnstile): Bot-detection and human verification for account registration. Cloudflare Turnstile processes browser-level signals to distinguish human users from automated bots. No advertising or tracking cookies are set. Governed by Cloudflare’s Privacy Policy.
  • Upstash (Redis): Rate-limiting infrastructure and short-term caching. Rate-limit identifiers expire within 1 hour. Generated AI insight results (text summaries derived from your financial data) are cached for up to 24 hours, with a fallback copy retained up to 7 days, after which they expire automatically. Bank credentials and raw account numbers are never stored in Redis.
  • Finnhub.io:Equity market price data for the Live Markets feature. Your queries (ticker symbols) are sent to Finnhub’s API. No personal account data is transmitted to Finnhub.
  • Kraken (WebSocket API): Real-time cryptocurrency price data. Ticker subscriptions are established via WebSocket. No personal account data is transmitted to Kraken.
  • Yahoo Finance (public API): Historical OHLCV candlestick price data for market charts. Requests are proxied server-side using only ticker symbols. No personal account data is transmitted.
  • Resend: Transactional and digest email delivery. Only your email address and the content of the email (financial summary data for digest emails) are shared. Resend does not use your data for advertising.
  • Sentry: Application error monitoring. When an error occurs in production, Sentry may capture your user ID, the feature being used, and error context (stack trace, request metadata). Session replay is fully disabled — no screen content, keystrokes, or financial data are captured by Sentry.
  • Vercel: Application hosting and edge delivery. Vercel may log request metadata (IP address, user agent) for security and performance monitoring. Governed by Vercel’s Privacy Policy.

We may also disclose information if required by law, court order, or to protect the rights, property, or safety of WealthWeave, our users, or the public.

5. AI Coach and AI Insights — Financial Data Access

WealthWeave’s AI features — the AI Coach, AI Insights, and AI Budgeting (see Section 6) — send some of your financial data to Google Gemini, a third-party AI service, to generate responses. This section explains what is sent, what is never sent, how the data is handled, and how to control it.

Your consent is required first

Before any of your financial data is sent to Google Gemini for the first time, we ask for your explicit, in-app consent and show you exactly what will be shared. No financial data is transmitted to Gemini until you accept. If you decline, the AI features remain unavailable until you choose to enable them.

What is sent

  • Account balances, limits, and utilization — labeled only by generic type (e.g. “Checking 1”, “Credit Card”), never by your bank or account name
  • Recent transactions, including merchant names, dates, and amounts
  • Spending totals by category
  • The titles and amounts of goals you have created
  • The messages you type to the AI Coach

AI Insights sends a narrower subset — an aggregated spending summary and your net worth only, not individual transactions or goal titles.

What is never sent

Your name, email address, account numbers, and bank login credentials are never transmitted to Google Gemini.

Not used to train AI models

WealthWeave uses a paid Google Gemini API tier. Under Google’s Cloud Data Processing Addendum, which governs paid API usage, your prompts and financial data are not used to train Google’s AI models. Google retains this data only for a limited period for security, abuse detection, and legal compliance. WealthWeave does not use your financial data to train any AI models.

AI Coach (Chat)

  • Each conversation assembles a fresh snapshot of the data listed above and transmits it to the Google Gemini API as part of the conversation context
  • WealthWeave does not retain AI conversation history server-side; your message history exists only in your browser and is sent to our server on each request, then discarded
  • Rate limits are enforced (15 conversations per hour) to protect service availability and prevent abuse

AI Insights (Platinum)

  • Generates 4 personalized financial insight cards by sending an aggregated spending summary and your net worth to the Google Gemini API
  • Only triggered when you click Generate or Refresh — the page never auto-loads insights on visit
  • Results are cached in your browser’s sessionStorage for up to 55 minutes to avoid redundant API calls
  • Generated insights are also cached server-side (Upstash Redis) for up to 24 hours — with a fallback copy for up to 7 days — so repeat visits do not re-transmit your data to Google. Cached insights expire automatically.
  • Rate limited to 5 AI insight refreshes per hour per user (cache hits do not count toward this limit)

Turning AI off

You can turn AI features off at any time from Settings → AI Preferences. When AI is off, no data is sent to Google Gemini and the AI Coach, Insights, and Budgeting features are disabled — but your bank accounts stay linked and everything else in WealthWeave keeps working. You can also stop all data sharing entirely by unlinking your bank accounts from the Accounts page.

6. AI-Powered Budgeting

When you use our budgeting features, WealthWeave sends your spending totals by category (derived from your transaction history) and an estimated monthly income figure to Google’s Gemini API to automatically generate budget suggestions. This is subject to the same consent requirement, data-handling terms, and Settings opt-out described in Section 5: no data is sent to Gemini until you have consented; your data is not used to train Google’s AI models (paid Gemini tier under Google’s Cloud Data Processing Addendum); and Google retains it only briefly for security, abuse detection, and legal compliance.

7. Data Storage and Security

We implement industry-standard security measures to protect your data:

  • TLS 1.2+ encryption for all data transmitted between your browser and our servers
  • Row-level security (RLS) in our Supabase database — each user can only access their own data
  • Bank login credentials are never stored — all credential handling is performed by Plaid. WealthWeave does store Plaid access tokens (permanent per-institution tokens that grant read-only access to your account data on your behalf). These tokens are stored in our encrypted database and are revoked immediately when you disconnect an institution or delete your account.
  • Payment card data is handled exclusively by Stripe’s PCI-DSS compliant infrastructure
  • API endpoints are protected by CSRF origin validation and per-user rate limiting via Upstash Redis
  • Optional multi-factor authentication (TOTP via authenticator app) is available on your WealthWeave account and can be enabled in Settings
  • Admin access to the production database is restricted to authorized personnel only and requires authentication
  • Content Security Policy (CSP) headers prevent unauthorized scripts from executing in your browser

Despite these measures, no system is completely secure. You use the Service at your own risk. We recommend using a strong, unique password and enabling multi-factor authentication on your WealthWeave account.

8. Cookies and Local Storage

WealthWeave uses the following client-side storage mechanisms:

  • Session cookies (httpOnly): Required for authentication, managed by Supabase Auth. These cookies are not accessible to JavaScript and are required for the Service to function.
  • Preference cookies: Optional cookies used for UI state, such as admin tier preview mode. These do not contain financial data.
  • Local storage: Used to persist user interface preferences including which widgets are visible on your dashboard, widget display order, and watchlist state in the Markets feature. This data stays on your device and is never transmitted to our servers.
  • Session storage: Used to cache AI-generated financial insights within your browser tab session (up to 55 minutes) to avoid unnecessary API calls when you revisit the Insights page. This cache is cleared when the browser tab is closed. A server-side copy of generated insights is cached separately as described in Section 5.
  • Cloudflare Turnstile: Sets a temporary browser-side token during registration verification. This token is single-use and expires after the registration flow is complete.

We do not use advertising cookies, third-party tracking pixels, or analytics services that identify you across sites.

9. Data Retention

We retain your account data for as long as your account remains active or until you request deletion. Transaction data (last 90 days) and investment holdings are stored in our database and refreshed via Plaid webhooks. Account balances are fetched live from Plaid on demand and not independently stored. Generated AI insights are cached for up to 7 days server-side. Rate-limiting data in Upstash Redis expires automatically within 1 hour. If you delete your account, your personal data, financial records, goals, and linked institution access are removed from our systems immediately upon deletion. Stripe billing records may be retained as required by applicable law and financial regulations for up to 7 years. The trial-suppression record (a one-way hash of your email) is retained permanently after account deletion to prevent re-registration abuse, but contains no personally identifiable information.

10. Your Rights and Choices

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Delete your account and associated data directly from Account Settings, or by contacting us
  • Portability: Request your data in a structured, machine-readable format
  • Objection: Object to certain types of processing
  • Withdraw consent: Revoke bank account access at any time from the Accounts page; opt out of digest emails from Settings

To exercise any of these rights, email us at support@wealthweave.co. We will respond within 30 days.

11. California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know what personal information we collect and how it is used, the right to delete your personal information, the right to correct inaccurate personal information, and the right to opt out of the “sale” or “sharing” of your personal information. WealthWeave does not sell or share personal information for cross-context behavioral advertising. To exercise your California privacy rights, contact us at support@wealthweave.co.

12. Children’s Privacy

WealthWeave is not directed at children under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has created an account or provided us with personal data, contact us at support@wealthweave.co and we will delete the information promptly.

13. Changes to This Policy

We may update this Privacy Policy periodically. We will post the revised policy with a new “Last updated” date. For material changes, we will provide advance notice via email or in-app notification at least 30 days before the change takes effect. Continued use of the Service after updates take effect constitutes your acceptance of the revised policy.

14. Contact

For privacy-related questions, data requests, or to report a concern, contact us at support@wealthweave.co. We will respond within 30 days.