Privacy Policy

Effective 2026-08-24 · Operator: Wealth Navigator · Contact: privacy@wealth-nav.com

The short version

Wealth Navigator is built so that we cannot read your financial data. Your accounts, transactions, plans, and tax data live in an encrypted file that only your devices can decrypt. Our server stores that file as an opaque blob for cross-device sync; it never holds the keys. We do not sell data, we do not run advertising, and we do not use third-party analytics in the app.

What we collect, and why

1. Account data (needed to operate your account — lawful basis: contract). Your username, a salted password hash (Argon2id — we never store the password), hashed recovery codes, and opaque household/device identifiers used to route your encrypted data between your devices. We do not ask for your email or phone number.

2. Encrypted sync data (contract). The application encrypts your financial data on your device before upload. We store the resulting sealed container and a version counter. We cannot decrypt it, and we do not hold or escrow keys.

3. Bank-connection data via Plaid (consent — you approve each connection explicitly in the app). If you choose to link a bank or card account, the transaction feed is fetched through Plaid, Inc. acting as our sub-processor. The feed passes through our relay server to your device and is encrypted there; our relay does not store, parse, or log its content — this is enforced in the relay's code, not just promised. The credential that authorizes the connection is held on your device, not our server. Investment holdings, cost basis, and tax documents are never collected through Plaid.

4. Operational metadata (legitimate interest — security, reliability, and understanding aggregate site usage). Standard access logs (timestamp, request path, status code — never request or response bodies or query strings) and aggregate service counters. For the public marketing and documentation pages only, we also keep a first-party, cookie-free page-view log: the page path and status, a coarse browser and operating-system family (such as “Chrome on Windows” — never the full browser signature), the referring site's hostname when you arrive via a link (never the full address), the country the connecting network is registered to, and a pseudonymous daily visitor number computed with a secret key that exists only in server memory and is replaced every day — so visits cannot be linked across days or traced to a person. Your IP address is never written to any log — with one narrow exception: requests probing for vulnerabilities (URLs that have never existed on this site) are logged with their IP address for security monitoring and deleted after 30 days. Browsing the site or using the application can never trigger that log: it records only requests for pages that never existed, which no link, page, or app ever points to. Application and API traffic gets no per-request record of any kind — only per-service totals. No per-user behavioral analytics are collected from the application.

5. Billing and entitlement data (contract — only if you use a paid plan or trial). Your household's plan identifier, paid-until date, opaque customer and subscription identifiers issued by our payment provider, and a count of linked bank connections (a number only — never their contents). Payment itself is handled by the payment provider as merchant of record: your card number, billing name, and billing address are collected on their checkout pages and never reach us. Prepaid codes are stored only as one-way hashes; a code's purchase record holds no account and its redemption record holds no purchase, so we cannot link a code purchase to an account.

6. Market quotes (legitimate interest — valuing your portfolio at current prices; only while the app is connected to our server). To show live values, the app asks our server for the current price of the securities you hold, by ticker symbol; our server fetches the public price from a market-data provider and passes it back. The server therefore sees which symbols were requested — never how many you hold, what you paid, or which account holds them. Requested symbols are not stored on disk, not logged, not linked to your account, and not analysed; a public price is kept in server memory for at most 24 hours after it was last requested, purely to avoid re-fetching it. Without a server connection the app values holdings from prices you enter or that your imports contain.

What we do not do

No sale or sharing of personal data for advertising. No cross-site tracking. No third-party analytics or advertising SDKs. No collection of your financial content in readable form, ever. There are now no exceptions to this: no page on this site loads code from another company.

Site search. Searching the site sends your words to us and to nobody else. The search runs against an index built into our own server, so the terms you type never leave it. We do not record what you search for: the request is logged as the path /search with no query string, and results are served with Cache-Control: no-store so they are not retained by intermediaries.

Until recently this page used Google Programmable Search, which received your search terms, your IP address, and set its own cookies, and which loaded Google's advertising script. That has been removed entirely and replaced with the first-party index described above. The hostname search.wealth-nav.com now only redirects to the search page on this site.

Sub-processors and payment provider

ProviderPurposeData exposed
Amazon Web Servicesserver hostingencrypted blobs and the account data above
Plaid, Inc.bank/card transaction aggregation (opt-in)your bank login happens on Plaid's or your bank's own pages; see Plaid's privacy policy
Stripe, Inc. (Stripe Managed Payments)subscription and prepaid-code purchases (opt-in)acts as merchant of record (an independent seller, not our sub-processor): payment details are collected on Stripe's checkout pages and stay with them; see Stripe's privacy policy

We sign data-processing agreements with sub-processors and will update this list before adding any.

Your rights and controls

Retention

Summarized in the Data Retention Policy: account data and the entitlement record for the life of the account; a bounded number of encrypted blob versions (dormant device holds expire after 90 days); logs 30 days; backups 35 days; requested quote symbols in server memory only, at most 24 hours after the last request. Deleting your account also erases the entitlement record and cancels any live subscription at the payment provider.

Security

TLS 1.3 in transit; client-side authenticated encryption (with post-quantum hybrid key exchange) for your content; Argon2id password hashing; least-privilege, key-only production access; sandboxed services; automatic security patching. Server code never logs message bodies.

Children

The service is not directed at children under 16 and we do not knowingly collect their data. Household features are managed by adult account holders.

International users

Accounts are hosted in the region where you sign up; encrypted content is not moved across regions.

Changes

We will post changes here with a new effective date, and notify account holders in-app for material changes.