Privacy Policy

Last updated June 9, 2026

Personnel Finance AI ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By creating an account or using the Service, you agree to the practices described here. If you do not agree, please discontinue use of the Service.

1. Information We Collect

We collect the following categories of information:

  • Personally Identifiable Information (PII) — name, email address, business name, mailing address, phone number, and billing details provided during registration or account management.
  • Financial Data — bank account numbers, routing numbers, account balances, and transaction history retrieved through Plaid; brokerage account holdings, trade history, positions, and portfolio data retrieved through Alpaca and TastyTrade; invoices, expense records, and financial reports you create or import.
  • Credential Data — brokerage API keys and access tokens for Alpaca and TastyTrade, stored encrypted and used solely to execute trading actions you authorize.
  • AI Interaction Data — messages and financial context you submit to the AI chat feature, which are transmitted to the Claude API (Anthropic) for processing.
  • Usage and Behavioral Data — pages visited, features used, actions taken within the app, session duration, and interaction patterns.
  • Device and Technical Data — IP address, browser type, operating system, referring URLs, and authentication event logs.

2. Data Classification Table

The table below summarizes how we classify, retain, control access to, and the GDPR lawful basis for each category of data we process.

ClassificationExamplesRetention PeriodWho Can AccessGDPR Lawful Basis
PIIName, email, business name, billing address, phoneDuration of account; 30-day grace period after a verified self-service deletion request, then permanent erasure (financial identifiers retained/anonymized per Financial row below)User, Personnel Finance AI staff (need-to-know), Auth0, StripeContract performance (Art. 6(1)(b))
FinancialBank balances, transactions, trade history, portfolio holdings, invoices7 years post account closure (IRS requirement)User, Personnel Finance AI staff (need-to-know), Plaid (retrieval), Alpaca/TastyTrade (brokerage data), Finnhub (ticker symbols only, for news headlines)Contract performance (Art. 6(1)(b)); Legal obligation — IRS (Art. 6(1)(c))
CredentialBrokerage API keys (Alpaca, TastyTrade), OAuth tokensDeleted immediately upon disconnection or account closureUser, Personnel Finance AI application layer only (AES-256-GCM encrypted; no staff access to plaintext)Contract performance (Art. 6(1)(b))
AI InteractionAI chat messages, financial context submitted to Claude API12 months (user may delete earlier via settings)User, Personnel Finance AI staff (need-to-know), Anthropic Claude API (processing only; not used for training)Contract performance (Art. 6(1)(b))
Behavioral / UsageFeature clicks, session duration, pages visited, in-app actionsIdentifiable: 12 months; aggregated/anonymized: 24 monthsPersonnel Finance AI staff (analytics); not shared with third partiesLegitimate interests — service improvement (Art. 6(1)(f))
Device / TechnicalIP address, browser type, OS, authentication event logs12 months (security logs); session cookies expire on logoutPersonnel Finance AI staff (security); Auth0 (authentication events)Legitimate interests — security (Art. 6(1)(f))
MarketingEmail opt-in, campaign click-throughUntil consent withdrawnPersonnel Finance AI marketing staff onlyConsent (Art. 6(1)(a))

3. How We Use Your Information

  • To provide, operate, maintain, and improve the Service
  • To process subscription billing via Stripe
  • To connect to your brokerage account (Alpaca, TastyTrade) so you can place your own trades, and to generate trade tickets and alerts for you to review and submit — the platform does not place or execute trades on your behalf
  • To retrieve and aggregate financial data from your linked bank accounts through Plaid
  • To generate AI-powered financial insights, summaries, and reports via the Claude API (Anthropic)
  • To authenticate your identity and manage access via Auth0
  • To send transactional communications (billing receipts, account alerts, security notifications)
  • To send product updates and promotional content where you have opted in
  • To detect fraud, abuse, and ensure platform security
  • To comply with legal obligations, including financial recordkeeping requirements

4. Third-Party Data Sharing

We do not sell your personal information. We share data only with the following categories of third parties, and only to the extent necessary to provide the Service:

  • Plaid (Financial Data Aggregation)— We use Plaid to connect to your bank accounts. When you link a bank account, you interact directly with Plaid's interface and Plaid retrieves account data on our behalf. Plaid's use of your data is governed by the Plaid Privacy Policy.
  • Alpaca Markets (Automated Trading)— We transmit trade orders and retrieve portfolio data via your Alpaca brokerage account using API credentials you provide. Your use of Alpaca is governed by Alpaca's terms and privacy policy.
  • TastyTrade (Automated Trading)— We transmit trade orders and retrieve portfolio and options data via your TastyTrade account using API credentials you provide. Your use of TastyTrade is governed by TastyTrade's terms and privacy policy.
  • Auth0 (Authentication)— We use Auth0 to manage user authentication, session management, and multi-factor authentication. Auth0 processes your email address and authentication metadata. Auth0's privacy practices are described in the Auth0 Privacy Policy.
  • Amazon Web Services (Cloud Hosting) — The Service runs on AWS infrastructure. Your data is stored on AWS servers located in the United States. AWS processes data as a sub-processor under our instructions. AWS infrastructure complies with SOC 2, ISO 27001, and other industry certifications.
  • Anthropic / Claude API (AI Processing) — When you use the AI chat feature, messages and any financial context you include are transmitted to the Claude API operated by Anthropic, PBC for processing. Anthropic does not use data submitted through the API to train its models, consistent with Anthropic's API Data Usage Policy. We encourage you to avoid submitting sensitive credentials or unredacted account numbers in chat messages.
  • Stripe (Billing)— We use Stripe to process subscription payments. Stripe receives your payment card information directly; we do not store full card numbers. Stripe's privacy practices are described in the Stripe Privacy Policy.
  • Finnhub (Portfolio News)— market news for your holdings (ticker symbols sent to retrieve headlines). Headlines, publisher/source names, and links are displayed as provided by Finnhub and its third-party publishers for information only; clicking a headline opens the original article on the publisher's site.
  • Legal Authorities — We may disclose information when required by law, court order, subpoena, or government request, or to protect the rights, property, or safety of Personnel Finance AI, our users, or the public.

5. Data Security

We implement multiple layers of security controls to protect your data:

  • Encryption at rest: All financial data and PII stored in our PostgreSQL database on AWS is encrypted using AES-256-GCM. Broker API credentials (Alpaca, TastyTrade) are additionally encrypted at the application layer with AES-256-GCM using a server-held key before being written to the database.
  • Encryption in transit: All API traffic between your browser or client and our servers is transmitted over HTTPS using TLS 1.3. Internal service-to-service communication occurs within an AWS Virtual Private Cloud (VPC) and is not exposed to the public internet.
  • Row-Level Security (RLS):We enforce database-layer row-level security policies so that queries executed by one customer context cannot access another customer's rows. Each authenticated session is scoped to the correct tenant at the database level, preventing cross-customer data leakage even in the event of application-layer misconfiguration.
  • Multi-Factor Authentication (MFA): MFA is available and encouraged for all accounts, enforced through Auth0.
  • Access controls: Personnel Finance AI employees access production data only on a need-to-know basis and are subject to background checks and security training. Administrative access requires MFA.

No method of electronic transmission or storage is 100% secure. While we apply industry-leading controls, we cannot guarantee absolute security.

6. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. Specific retention periods by category:

  • Financial records (transactions, trade history, balances, reports): retained for 7 years following account closure, in accordance with IRS recordkeeping guidance under IRC § 6001 and related regulations.
  • PII and account data:retained for the duration of your active account. You may request deletion at any time from the Data & Privacy section of account settings, confirmed by typing your account email. A verified request starts a 30-day grace period, during which you may cancel the request from the same settings page. If the grace period elapses without cancellation, an automated daily process permanently erases your personal data, revokes access to any linked bank (Plaid) and brokerage accounts, cancels your subscription, deletes stored files, and deletes your login identity (Auth0) — subject to the 7-year financial records requirement above, which is anonymized and retained rather than deleted.
  • Broker and Plaid credentials: access tokens are revoked immediately upon disconnection of the relevant account, or automatically as part of account deletion.
  • Usage and behavioral data: aggregated and anonymized after 24 months; identifiable logs retained for up to 12 months for security purposes.
  • AI chat history: retained for 12 months for continuity of context and audit purposes; you may delete your chat history at any time through account settings.

7. Your Rights (GDPR / CCPA)

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Correction — request correction of inaccurate or incomplete data.
  • Deletion— request deletion of your personal data. Deletion is self-service: submit the request from the Data & Privacy section of account settings and confirm by typing your account email. This starts a 30-day grace period during which you may cancel the request; if not canceled, your personal data is automatically and permanently erased at the end of that period, subject to the retention requirements described above.
  • Portability — export your financial data in a machine-readable format (CSV/JSON) through the data export feature in account settings.
  • Restriction / Objection — object to or request restriction of certain processing activities (e.g., marketing communications).
  • Opt-out of sale (CCPA) — we do not sell personal information. If our practices change, we will update this policy and provide an opt-out mechanism.
  • Withdraw consent — withdraw consent for marketing communications at any time via unsubscribe links or account settings.

To exercise the rights above — other than self-service deletion, which is handled directly in Data & Privacy settings as described — contact our Data Privacy Officer at privacy@personnelfinanceai.com. We will acknowledge and respond to such requests within 30 days (or within the timeframe required by applicable law). This acknowledgement window is separate from the 30-day grace period that follows a self-service deletion request: the grace period governs when erasure is executed, not when we respond to other rights requests. We may need to verify your identity before processing certain requests.

8. Cookies and Tracking Technologies

We use cookies and similar technologies for session management, authentication (via Auth0), and personalization. Cookies we use include: (a) strictly necessary cookies for authentication and security (Auth0 session tokens — cannot be disabled without losing login); and (b) functional cookies to remember your preferences (theme, language, consent choice). We do not currently use third-party advertising or cross-site tracking cookies. You can manage cookie preferences using the banner shown on first visit or by . Disabling strictly necessary cookies will prevent you from logging in. We do not respond to "Do Not Track" browser signals.

13. California Privacy Rights (CCPA / CPRA)

This section applies to California residents and supplements the rights described in Section 7. Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), California residents have the following rights:

CCPA CategoryExamplesCollected?SourceBusiness PurposeShared With
IdentifiersName, email address, IP address, Auth0 user IDYesDirectly from you; automaticallyAccount creation, authentication, securityAuth0, AWS
Commercial informationSubscription plan, billing history, payment method typeYesDirectly from youBilling and subscription managementStripe
Financial information (Sensitive PI)Bank account details, balances, transactions, brokerage holdings, trade historyYesVia Plaid (bank), Alpaca/TastyTrade (brokerage)Core service — financial aggregation, reporting, AI insightsPlaid, Alpaca, TastyTrade (your accounts only)
Internet / network activityPages visited, features used, session duration, browser typeYesAutomaticallySecurity, service improvementAWS (infrastructure)
Professional / employmentBusiness name, entity type, job titleYesDirectly from youTax reporting, AI categorization contextNone
InferencesAI-generated transaction categories, financial summariesYesDerived from your financial dataAI-powered reporting and chatAnthropic Claude API (processing only)

Do Not Sell or Share. We do not sell or share your personal information as defined under CCPA. No opt-out action is required. For more details, see our Do Not Sell or Share My Personal Information page.

Sensitive Personal Information. Your financial data (bank account details, transactions, brokerage holdings) constitutes sensitive personal information under CPRA §1798.121. We use it solely to provide the Service and do not use it to infer characteristics for advertising purposes.

To exercise your California rights, email privacy@personnelfinanceai.com or use the Data & Privacy section of your account settings. For requests submitted by email, we respond within 45 days (extendable by 45 days with notice). The right to delete can also be exercised directly and immediately in Data & Privacy settings: self-service deletion requests there are confirmed by typing your account email and trigger a 30-day grace period before your personal data is automatically and permanently erased (see Sections 6 and 7 above). Sensitive financial records are retained in anonymized form for 7 years as required by law rather than deleted.

9. Children's Privacy

The Service is intended exclusively for business users who are at least 18 years of age. We do not knowingly collect personal information from individuals under 18. If you believe a minor has provided us with personal information, please contact us immediately at privacy@personnelfinanceai.com and we will promptly delete it.

10. International Data Transfers

The Service is hosted on AWS infrastructure in the United States. If you access the Service from outside the United States, your data will be transferred to and processed in the U.S. For users in the European Economic Area (EEA), United Kingdom, or Switzerland, such transfers are made pursuant to Standard Contractual Clauses (SCCs) or other appropriate safeguards under GDPR Chapter V.

11. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of significant changes via email or in-app notification at least 14 days before the changes take effect. The most current version will always be available at personnelfinanceai.com/privacy. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

12. Contact and Data Privacy Officer

For privacy-related questions, data subject requests, or concerns, please contact our Data Privacy Officer:

Do Not Sell or Share My Personal InformationTerms of ServiceCompliance