Privacy Policy
Effective 2026-07-19 · Operator: Wealth Navigator · Contact: privacy@wealth-nav.com
The short version
Wealth Navigator is built so that we cannot read your financial data. Your accounts, transactions, plans, and tax data live in an encrypted file that only your devices can decrypt. Our server stores that file as an opaque blob for cross-device sync; it never holds the keys. We do not sell data, we do not run advertising, and we do not use third-party analytics in the app.
What we collect, and why
1. Account data (needed to operate your account — lawful basis: contract). Your username, a salted password hash (Argon2id — we never store the password), hashed recovery codes, and opaque household/device identifiers used to route your encrypted data between your devices. We do not ask for your email or phone number.
2. Encrypted sync data (contract). The application encrypts your financial data on your device before upload. We store the resulting sealed container and a version counter. We cannot decrypt it, and we do not hold or escrow keys.
3. Bank-connection data via Plaid (consent — you approve each connection explicitly in the app). If you choose to link a bank or card account, the transaction feed is fetched through Plaid, Inc. acting as our sub-processor. The feed passes through our relay server to your device and is encrypted there; our relay does not store, parse, or log its content — this is enforced in the relay's code, not just promised. The credential that authorizes the connection is held on your device, not our server. Investment holdings, cost basis, and tax documents are never collected through Plaid.
4. Operational metadata (legitimate interest — security and reliability). Standard access logs (timestamp, request path, status code — never request or response bodies) and aggregate service counters. No per-user behavioral analytics are collected from the application.
5. Billing and entitlement data (contract — only if you use a paid plan or trial). Your household's plan identifier, paid-until date, opaque customer and subscription identifiers issued by our payment provider, and a count of linked bank connections (a number only — never their contents). Payment itself is handled by the payment provider as merchant of record: your card number, billing name, and billing address are collected on their checkout pages and never reach us. Prepaid codes are stored only as one-way hashes; a code's purchase record holds no account and its redemption record holds no purchase, so we cannot link a code purchase to an account.
What we do not do
No sale or sharing of personal data for advertising. No cross-site tracking. No third-party analytics or advertising SDKs. No collection of your financial content in readable form, ever.
Sub-processors and payment provider
| Provider | Purpose | Data exposed |
|---|---|---|
| Amazon Web Services | server hosting | encrypted blobs and the account data above |
| Plaid, Inc. | bank/card transaction aggregation (opt-in) | your bank login happens on Plaid's or your bank's own pages; see Plaid's privacy policy |
| Lemon Squeezy, LLC | subscription and prepaid-code purchases (opt-in) | acts as merchant of record (an independent seller, not our sub-processor): payment details are collected on their checkout pages and stay with them; see Lemon Squeezy's privacy policy |
We sign data-processing agreements with sub-processors and will update this list before adding any.
Your rights and controls
- Access & portability: your data is on your device; the app exports it in documented, open formats at any time.
- Deletion: delete your account in-app (or by written request). Deletion removes your account record, all stored blob versions, and device registrations immediately, and revokes outstanding sessions; residual copies in encrypted backups expire per our Data Retention Policy (outer bound: 35 days). Linked bank connections are unlinked at deletion.
- Correction / objection / restriction: contact us; note that we cannot read or edit your encrypted content — corrections happen in your app.
- EU/UK (GDPR), California (CCPA/CPRA), and other regimes' rights apply per your residency. You may lodge a complaint with your supervisory authority.
Retention
Summarized in the Data Retention Policy: account data and the entitlement record for the life of the account; a bounded number of encrypted blob versions (dormant device holds expire after 90 days); logs 30 days; backups 35 days. Deleting your account also erases the entitlement record and cancels any live subscription at the payment provider.
Security
TLS 1.3 in transit; client-side authenticated encryption (with post-quantum hybrid key exchange) for your content; Argon2id password hashing; least-privilege, key-only production access; sandboxed services; automatic security patching. Server code never logs message bodies.
Children
The service is not directed at children under 16 and we do not knowingly collect their data. Household features are managed by adult account holders.
International users
Accounts are hosted in the region where you sign up; encrypted content is not moved across regions.
Changes
We will post changes here with a new effective date, and notify account holders in-app for material changes.