Privacy Policy
FinanceCompass (“we,” “us,” or “our”) operates financecompass.io. This Privacy Policy explains what personal information we collect, why we collect it, how it is used and stored, and what choices you have. We have written it in plain English and organized it by data flow so you can quickly find what matters to you.
By using FinanceCompass you agree to the practices described below. If you disagree, please do not use the service.
1. Information we collect and why
We collect the minimum information needed to operate the service. Here is every category, where it goes, and what it is used for.
1a. Account and authentication data
What: Email address, password (hashed, never stored in plaintext), session tokens, and login timestamps.
Where it goes: Stored in Supabase, a PostgreSQL-based backend-as-a-service. Supabase handles authentication including OAuth flows, token refresh, and session management. Your password is hashed using bcrypt before it ever reaches our servers. We never have access to your raw password.
Why: To identify your account, maintain your session, and gate access to paid features.
1b. Tool usage data
What: A count of how many times you have run each tool in a given calendar month. This is stored in a tool_usage table in our database as an integer — not the specific inputs you entered.
Where it goes: Supabase, associated with your user ID.
Why: To enforce the monthly usage limit for free-tier accounts (3 analyses per tool per month) and to display your usage counter in the dashboard.
1c. Tool input parameters
What:The ticker symbols, dates, and other parameters you type into tools (for example, “VTI” and “VXUS” in the ETF Overlap Analyzer).
Where it goes: These are sent to our server for processing and passed to third-party data providers and the Anthropic Claude API (see 1d below) to generate your result. They are not permanently stored in our database unless you explicitly save an analysis to your history (a Pro feature).
Why: To run the analysis you requested.
1d. AI narrative generation — Anthropic Claude
What: Tool results and contextual parameters (e.g., overlap percentage, holding counts) are sent to the Anthropic Claude API to generate a plain-English narrative explaining the result.
Where it goes: Anthropic’s API servers. This data is governed by Anthropic’s Privacy Policy. Anthropic states that API inputs and outputs are not used to train their models for customers on API plans.
Why: To provide the AI-generated explanation that accompanies each analysis result.
1e. Subscription and billing data
What: Your subscription tier (free, Pro, or Unlimited), subscription status, billing period dates, and Stripe customer/subscription IDs.
Where it goes: Stored in our Supabase database (subscription metadata) and on Stripe’s servers (all payment processing). We never see, receive, or store your card number, CVV, or bank account details. All payment data is handled entirely by Stripe under their Privacy Policy.
Why: To determine which features you have access to and to process subscription payments.
1f. Transactional email
What: Your email address is used to send account confirmation, welcome, and (for Unlimited plan) alert notification emails.
Where it goes: Email is delivered via Resend, a transactional email API. Resend logs delivery events (sent, delivered, bounced, opened) associated with your email address. See Resend’s Privacy Policy.
Why: To confirm your account, send password resets, and deliver time-sensitive alerts you have subscribed to.
1g. Contact form submissions
What: If you submit the contact form, we collect your name (optional), email address, topic selection, and the message text you provide. A Cloudflare Turnstile challenge token is also generated and verified to prevent automated submissions.
Where it goes: Your message is emailed directly to our support inbox via Resend. We do not store contact form submissions in a database.
Why: To respond to your inquiry.
1h. Cookies and local storage
We set one first-party cookie: fc_theme, which stores your selected color theme (e.g., “lp” for Light Purple). It contains no personal information, does not track you across sites, and persists for one year. Supabase also sets authentication cookies required for session management.
We do not use advertising cookies, cross-site tracking pixels, Google Analytics, Facebook Pixel, or any third-party analytics that monitor your behavior across the web.
1i. Infrastructure and server logs
Our application is hosted on Vercel. Vercel automatically logs HTTP request metadata (IP address, user agent, request path, timestamps) for security and performance purposes. Cloudflare may also process IP addresses and request metadata as part of DDoS protection and content delivery. These logs are retained according to Vercel’s and Cloudflare’s respective data retention policies.
2. Third-party data processors — summary
The table below lists every third party that may receive your personal data, the category of data, and the legal basis.
3. How long we retain your data
Account and usage data is retained for as long as your account is active. If you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law (e.g., financial transaction records). Stripe retains billing records per their own legal obligations.
4. Your rights
Depending on your jurisdiction you may have the right to access, correct, export, or delete your personal data; to restrict or object to processing; and to withdraw consent. To exercise any of these rights, contact us at [email protected] or use the contact form. We will respond within 30 days.
5. Children
FinanceCompass is not directed at children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe we have inadvertently collected information from a child, contact us immediately and we will delete it.
6. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced by updating the “Last updated” date at the top of this page and, where appropriate, by email notification. Continued use of the service after a change constitutes acceptance.
7. Contact
Questions about this Privacy Policy? Email [email protected] or use our contact form.