Privacy policy
Last updated: July 17, 2026
Privacy at a glance
- We never receive or store your bank password.
- Secure bank connections are powered by Plaid.
- PeakWorth cannot move your money.
- We don't sell your personal financial information.
- Your financial data is never used for advertising.
- You can disconnect accounts at any time.
- You can permanently delete your account and data.
- Optional two-factor authentication helps protect your account.
- Questions? Email us anytime at support@peakworth.com.
Read the full Privacy Policy below for complete legal details.
A note from the founder
I built PeakWorth after years of relying on detailed financial models to make major decisions for my own family—from career moves to home purchases to retirement planning. Professionally, I've spent my career helping technology companies make complex financial decisions as a CFO, and I previously practiced as a licensed CPA. Those experiences shaped how I think about balancing today's choices against long-term financial outcomes.
Over time, I realized households deserved the same kind of decision engine that businesses rely on. That's why I built PeakWorth—to help people make better financial decisions with greater confidence and a clearer understanding of the long-term tradeoffs.
If you trust us with your financial information, I believe we owe you complete transparency about how we protect it. PeakWorth exists to help people make better financial decisions—not to monetize their financial data or push financial products.
1. Introduction
2. Information We Collect
Account Information
Financial Profile Data
Linked Account Data (Plaid)
- Account information: account name, type (checking, savings, credit, loan, investment), masked account and routing numbers, and account ownership details where available.
- Balances: current and available balances, credit limits, and last-updated timestamps.
- Transactions: historical and ongoing transaction data including amount, date, merchant or counterparty, category, and pending status.
- Investment holdings: for connected brokerage accounts, security identifiers, quantities, cost basis where provided, and current values.
- Liabilities: for connected loan and credit accounts, balances, interest rates, minimum payments, and due dates.
- Institution and item metadata: the institution name, connection status, and the Plaid item identifier needed to maintain the connection.
We use this data only to populate your financial profile, generate projections, and surface insights inside your account. We do not resell linked-account data, do not use it for advertising, and do not share it with other PeakWorth users. Plaid's own handling of your data is governed by the Plaid End User Privacy Policy, which we encourage you to review.
Usage Data
Payment Information (Stripe)
3. How We Use Your Information
- Provide, maintain, and improve the Service
- Generate personalized financial projections and AI-powered insights
- Process transactions and manage your subscription
- Send account-related communications (e.g., password resets, plan changes)
- Detect and prevent fraud or unauthorized access
- Comply with legal obligations
4. Data Sharing
- Service Providers: We use Stripe (payments), Plaid (account linking), and Anthropic (AI insights) to deliver the Service. These providers only receive the minimum data necessary. Before sending financial context to our AI provider, PeakWorth removes direct identifiers such as your name, email address and account numbers; the provider receives only the financial context needed to generate the response, along with the message you submit. We use contractual and technical safeguards designed to limit service providers to processing personal information only as necessary to provide their services to PeakWorth.
- Legal Requirements: We may disclose information if required by law, regulation, or legal process.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. Any successor must handle your personal information consistently with this policy unless you are notified of a material change and given any rights required by applicable law.
Each provider's own practices are described in its privacy policy: Stripe, Plaid, and Anthropic.
4a. AI Data Handling
AI features (the AI Advisor, AI Insights, and AI-assisted imports) are optional — you can use PeakWorth without them. When you do use them, here is exactly what happens with your data:
- What is sent: Before sending financial context to our AI provider (Anthropic), PeakWorth removes direct identifiers such as your name, email address and account numbers. The provider receives only the financial context needed to generate the response, along with the message you submit. Messages are transmitted as entered, so do not include full account numbers, government identifiers or passwords.
- No training on your data: Our requests are processed under Anthropic's commercial API terms and are not used to train general-purpose models.
- Provider retention: Anthropic may retain API inputs and outputs for a limited period, and authorized personnel may review them, for security, abuse-prevention, and reliability purposes, per its commercial terms.
- Your chat history: PeakWorth stores your AI conversation history in your account so you can revisit it. You can delete any conversation at any time from the AI Advisor; deleting a conversation removes it and its messages from our production database. Deleting your account deletes your chat history on the timelines described in Section 6.
5. Data Security
For a plain-English overview of how we protect your data — encryption, hashed passwords, session revocation, subprocessors, and our incident-response commitment — see our Security overview.
We implement industry-standard security measures to protect your data:
- All data is encrypted in transit using TLS/HTTPS
- Passwords are hashed using bcrypt with a cost factor of 12 — never stored in plain text
- Optional two-factor authentication (TOTP) using authenticator apps; TOTP secrets are stored encrypted at rest with AES-256-GCM, and one-time backup codes are bcrypt-hashed
- Sessions use HTTP-only, secure cookies stored server-side in a PostgreSQL-backed session store
- Security headers (HSTS, X-Content-Type-Options, X-Frame-Options) are enforced on every response
- Rate limiting protects login, registration, and two-factor verification endpoints against brute-force attacks
- Sensitive actions (linking new bank accounts, disabling two-factor) require a verified two-factor session for users who have enrolled
- Financial profile data is scoped to individual user accounts with server-side access controls
- Bank account linking is handled by Plaid — we never see or store your bank login credentials
- Before sending financial context to our AI provider (Anthropic), PeakWorth removes direct identifiers such as your name, email address and account numbers. The provider receives only the financial context needed to generate the response, along with the message you submit. Messages are transmitted as entered, so do not include full account numbers, government identifiers or passwords
5a. Two-Factor Authentication and Account Recovery
If you enable two-factor authentication (TOTP), we store the shared secret encrypted at rest with AES-256-GCM and bcrypt-hash any one-time backup codes you generate. We also retain a small audit trail of two-factor events (enable, disable, successful verification, failed verification, recovery requested, recovery completed) so you and our support team can investigate suspicious activity.
If you lose access to your authenticator and your backup codes, you may submit an account recovery request from the sign-in page. Recovery requests are intentionally manual: we verify your identity through email confirmation and a mandatory cool-down period before two-factor is reset. During recovery we may temporarily collect and review additional information (such as the email you signed up with, recent activity timestamps, and the IP/device used to submit the request) solely to confirm you are the legitimate account holder. Recovery records are retained for 24 months for fraud-prevention and compliance purposes, after which they are deleted or anonymized.
We will never ask for your password, your full TOTP secret, or your backup codes by email, chat, or phone.
6. Data Retention
Account & Profile Data
Linked Account (Plaid) Data
Email Logs
Backups
7. Your Rights
- Access: View your financial profile data at any time from the Account page
- Correction: Update or correct any information in your profile
- Deletion: Request deletion of your account and associated data by contacting support
- Opt-out: Unsubscribe from non-essential communications
To exercise any of these rights — whether for yourself or as an authorized agent acting on someone's behalf — you can submit a request on our Data rights requests page. We respond to verifiable CCPA requests within 45 days, and, where GDPR or similar laws apply to you, within the timelines those laws require. We may need to verify your identity before we act.
8a. Session Replay
With your explicit consent (collected via our cookie banner), we record session replays of how you interact with the PeakWorth web app using PostHog. Session replays help us understand why users get stuck — for example, why a signup, CSV upload, or upgrade flow drops off — so we can fix it.
Mobile app: session replay is not enabled in the PeakWorth iOS/Android app. The mobile app only emits anonymous, hashed event-level analytics (e.g. "screen viewed", "decision applied") and crash diagnostics — never screen recordings of your balances, transactions, or anything you type. You can disable mobile diagnostics entirely from Settings → Diagnostics.
Replay is consent-based and designed to mask sensitive content before it leaves your browser: financial figures and free-text inputs are replaced with grey boxes, form fields are masked at the source, network requests are not recorded, and payment and bank-linking screens (Stripe, Plaid) are excluded entirely. For the implementation-level detail of what is masked and how, see the Security overview.
You can withdraw consent at any time from the cookie banner or the Account page; doing so disables PostHog and stops all future replay capture. Existing replays are automatically deleted no later than 90 days after they are recorded.
8b. Optional Contribution of Import Samples
When you import data from another tool, we may ask — with an unchecked-by-default checkbox — whether you'd like to contribute a scrubbed copy of that import to help us test and improve our import tools. If you don't check the box, nothing is kept.
If you do opt in, we keep at most 10 examples per source. Before storage, an automated scrubber removes the personal details it can detect — email addresses, phone numbers, account and card numbers, government IDs, names, and links. Scrubbing is automated and may not catch everything, so the copy should be considered de-identified rather than perfectly anonymous. It is stored in restricted storage accessible only to PeakWorth engineering, used solely to improve our import tools, and never shared with third parties. You can review or delete your contributions, or opt out of future prompts, any time from Account → Migration fixtures; deleting removes both the record and the stored file.
8c. Ad Measurement (Server-Side Conversions)
Separately from the product analytics described in Section 8, if you signed up after seeing one of our ads we may report key conversion events (for example, completing signup, starting a trial or checkout, or a first successful payment) to the ad platform that showed you the ad — currently Meta (Facebook/Instagram ads) and Google Ads — so we can measure whether our advertising works. For matching purposes, these reports include your email address in a hashed form (a one-way SHA-256 fingerprint, per each platform's documented conversion API); we never send your plaintext email, and the report never includes any of your financial data — no balances, transactions, linked-account data, or financial profile details. It carries only the conversion event itself and, for a payment, the plan purchased and the amount paid.
These conversion reports are sent only when your analytics consent is set to granted: reports to Meta are gated on the consent choice stored with your account, and if you decline analytics (or have made no choice) they are not sent. You can change your consent choice at any time from the cookie banner or your Account page.
9. Children's Privacy
10. Changes to This Policy
11. Contact Us
If you have questions or concerns about this Privacy Policy, please contact PeakWorth.ai, LLC:
