1. Overview & Scope
This Privacy Policy covers the Net Worth Nexus marketing website (networth.nexus), the web application (app.networth.nexus), the iOS application, and the backend services behind them (together, the “Service”). It describes what we collect, why, who processes it, how long we keep it, and the choices you have. It is incorporated into our Terms of Service.
Net Worth Nexus is subscription-funded. You are the customer — your data is not the product. That is a business-model fact, not a slogan: we have no advertising revenue and no data-licensing revenue, so there is no commercial pressure behind any of the collection described below.
What this policy does not cover: our community Discord server (hosted and governed by Discord), the connection portals operated by SnapTrade and Quiltt where you authenticate with your bank or broker, and the checkout screens operated by Stripe and Apple. Those are their systems and their privacy policies.
2. Notice at Collection — the whole picture on one screen
Everything we collect, why, where it comes from, who else sees it, and how long it lasts. Detail follows in Sections 3 through 10.
| Category | Examples | Why we collect it | Who else receives it | How long we keep it |
|---|---|---|---|---|
| Identifiers | Email, username, full name, account ID | Create and secure your account; contact you | Resend (email delivery); Stripe (if you subscribe) | Life of the account |
| Authentication data | Hashed password, session tokens, revocation timestamps | Sign you in; end sessions when you ask | Nobody | Sessions expire per your setting; hash lives with the account |
| Demographics (optional) | Birth year, gender, U.S. state | Age eligibility; the optional benchmark lens | Nobody | Life of the account; clearable in Settings |
| Financial account data | Balances, holdings, options, transactions, institution names | Compute your net worth, history, and analytics | SnapTrade / Quiltt (source); Google Gemini (numeric subset, only if you turn on the Daily Briefing, Section 6) | Life of the account |
| Content you write | Manual assets, wagers, watchlist theses, nicknames, notes | Show you what you entered | Nobody (a numeric subset reaches Gemini if you turn on the Daily Briefing) | Until you delete it |
| Derived records | Daily snapshots, computed analytics, AI briefings | Your history and insights | Nobody | Snapshots: life of account. Briefings: rolling window |
| Billing metadata | Subscription status, customer and transaction IDs | Grant and sync your entitlement | Stripe (web) or Apple (iOS) | Life of account; billing records per law (typically 7 years) |
| Support & communications | Tickets, emails, assistant messages, mailing-list signup | Answer you and fix problems | Google Gemini (assistant messages); Resend (email) | Tickets: while open, then as the record. Assistant threads: not stored server-side |
| Page-view analytics | Page path (never its query string), referring site, browser, operating system, device type, country, load timings | See which pages are used and how fast they load | Cloudflare (Web Analytics) | Kept by Cloudflare: every record for 7 days, then a sample of about 10%, viewable for 6 months |
| Operational & security data | IP-derived rate-limit counters, request metadata, error diagnostics, push tokens | Keep the Service up and abuse out | Cloudflare, Railway (infrastructure); Apple (push delivery) | Webhook bodies 7–60 days; event metadata 90–365 days; error diagnostics until resolved |
We do not sell personal information, share it for cross-context behavioral advertising, or use it for profiling that produces legal or similarly significant effects. We collect no precise geolocation, no contacts, no photos or files, no biometric templates, no browsing history off our own site, and no advertising identifiers.
3. Information We Collect
3.1 Account & identity
- Email address, username, full name, and a hashed password (we never store or can recover the plain text).
- Consent records: which Terms and Privacy versions you accepted and when.
- Role and entitlement flags (plan tier, admin status) and account timestamps, including last login and a coarse last-active marker used to pause history for dormant accounts.
3.2 Profile & preferences (some optional)
- Birth year (required — age eligibility), and optionally gender and U.S. state if you enable the demographic benchmark lens.
- Settings: theme, navigation order, session-timeout length, notification and product-update opt-ins.
3.3 Financial data you add or connect
- Manual entries: accounts, balances, tracked tickers, option contracts, and sportsbook wagers you type in yourself.
- Connected brokerage data (Pro, via SnapTrade): read-only account, balance, holding, option, and transaction records.
- Connected banking data (Nexus, via Quiltt with Finicity connectivity and FinGoal enrichment): read-only account, balance, and transaction records with merchant metadata.
- Derived records: daily net-worth snapshots and computed analytics that power your history and insights.
- Connection secrets issued by the providers (not your credentials) — stored encrypted at rest so we can refresh your data.
3.4 Billing metadata
- Subscription status and identifiers from Stripe (web) or Apple (iOS), plus an opaque token we generate to bind an App Store purchase to your account. Card numbers are handled entirely by Stripe and Apple and never touch our servers.
3.5 Support & communications
- Support tickets you submit (email address, category, platform, the page you were on, and your description), emails you send to support, and mailing-list signups.
- Messages you type into the support assistant, on the website or in the app’s Help & Support. The conversation thread stays on your device (on the website, in your browser’s session storage), not on our servers; the message text is sent to Google’s Gemini API to compose an answer (Section 6), and is attached to a support ticket only if you choose to escalate.
3.6 Operational & diagnostic data
- Request metadata and session records used for security and reliability.
- Rate-limit counters keyed to a coarsened form of your IP address. We do not build a browsing profile from it; it exists to stop credential-stuffing and abuse.
- Error diagnostics. When something breaks, we record the error type, the code location, a redacted excerpt of the message, and the account IDs affected, so we can find and fix it. The excerpt passes through a secret-redaction filter before it is stored. We do not deliberately collect financial values in error reports and remove them when we find them.
- Device push tokens, if you opt into notifications.
- Page-view analytics on this website and the web app, through Cloudflare Web Analytics: the path of each page you open (never its query string, so a password-reset or verification link is not recorded), the referring site, your browser, operating system and device type, your country, and how quickly the page loaded. It sets no cookie, stores nothing in your browser, and does not fingerprint you by IP address, browser details, or anything else. It runs only on web pages, including any the iOS app opens in Safari; the app’s own screens do not use it.
4. What We Never Collect
- Your institution credentials. Bank and brokerage logins are entered in SnapTrade’s or Quiltt’s own secure flows — they never pass through or rest in our systems.
- Card numbers, CVVs, or bank routing details. Payment details live with Stripe and Apple.
- Social Security numbers or government identifiers. The Service never asks for one, and no field accepts one.
- Files of any kind. There is no upload control anywhere in the Service and no endpoint that accepts a file — no documents, statements, images, or attachments. Nothing of yours is stored in any object store or public bucket, because none exists.
- Advertising identifiers or ad-network SDKs. There are none in the app, in the iOS binary, or on this website. The one analytics tool is the cookieless page-view count in Section 3.6.
- Precise geolocation. We use a coarse, country-level network signal at signup to enforce U.S.-only availability, and nothing finer.
- Biometric data. Face ID and Touch ID run entirely on your device; we receive only the yes/no unlock result and never a biometric template.
- Your contacts, calendar, photos, microphone, or camera. The apps request none of these permissions.
5. How We Use Information
- To run the product: aggregate your accounts, compute net worth, history, analytics, and simulations (heavy math runs once, server-side, so web and iOS agree).
- To personalize: apply your theme, navigation, onboarding answers, and the opt-in demographic benchmark.
- To generate your Daily Briefing and answer support questions (Section 6).
- To operate billing through Stripe and Apple and keep entitlements in sync.
- To secure the Service: session management, rate limiting, abuse and fraud prevention, and diagnosing errors.
- To communicate: transactional and legally required messages (verification, password resets, security alerts, subscription confirmations, renewal and price-change notices), support replies, the optional daily notification, and product updates if you opted in.
- To improve the Service using aggregated and de-identified figures — counts, error rates, feature usage in the aggregate. We do not read individual users’ financial data to develop features.
- To comply with law and enforce our Terms.
We do not use your personal data for third-party advertising, we do not sell it, and we do not use your financial data to train any machine-learning model of ours.
6. AI Processing — exactly what leaves, and what happens to it
Two features send data to Google’s Gemini API. Nothing else in the Service uses AI, and no other AI provider receives anything.
6.1 The Daily Briefing (Pro and Nexus)
Once a day we send Google a JSON snapshot of your portfolio and it returns one short written observation. The payload contains:
- net worth, equity, and cash totals and their percentages;
- daily, weekly, and monthly changes, and a windowed net-worth history;
- your largest holdings by symbol and market value, and your manual tickers;
- a count of connected accounts and a breakdown of manual accounts by type (bank, brokerage, crypto and so on), never the institution’s name;
- pre-computed patterns and the titles of your recent briefings, so it does not repeat itself.
It does not contain your name, email, username, account numbers, institution credentials, or any identifier that points back to you at Google. The data is financial and specific, though, and holding symbols plus dollar amounts are sensitive even without a name attached — so this is worth an informed choice.
The Daily Briefing is off until you turn it on. The first time it would appear, the Dashboard says what is sent and to whom, and asks. Nothing is sent to Google unless you choose Turn on. You can turn it off at any time in Settings (Profile, Preferences, AI Daily Briefing). When you do, we stop sending and delete the briefings already written for you.
6.2 The support assistant
The free-text questions you type into the support assistant, in the app’s Help & Support or the widget on networth.nexus, are sent to Gemini with our public product documentation so it can compose an answer. Before your first question we say so and ask you to confirm. Whatever you type goes, which is why we ask you not to include passwords, full account numbers, or other sensitive details in chat. It has no access to your account and cannot look anything up about you. The website’s quick-topic answers are written in advance and never reach Gemini.
6.3 Training, human review, and retention at the provider
We use the Gemini API on a paid service tier, under terms in which Google does not use our prompts or the model’s outputs to train or improve its general models, and does not route them to human reviewers for that purpose. Google retains data briefly for abuse monitoring and service operation under its own API terms. If that arrangement ever changes, or if we change AI providers, we will update this section and give notice before the change takes effect.
6.4 Limits you should know about
- AI output is informational only, can be wrong, and is never financial advice. Human support is always available at support@networth.nexus.
- No automated decision with legal or similarly significant effects is made about you. Entitlement, billing, refunds, and account standing are decided by rules and people, never by a model.
- The assistant is not a crisis service and cannot help in an emergency — see Section 14 of the Terms.
7. Every Third Party That Receives Data
This is the complete list. Each one is a service provider acting on our instructions under a contract limiting it to that role — none of them is permitted to use your information for its own purposes or to sell it.
| Provider | Role | What it receives |
|---|---|---|
| SnapTrade | Brokerage aggregation (Pro) | An opaque user ID we generate, and the read-only account, balance, holding, option and transaction data it returns to us. You authenticate with your broker inside SnapTrade’s own flow. |
| Quiltt, with Finicity connectivity and FinGoal enrichment | Bank and credit aggregation (Nexus) | An opaque profile identifier we generate, and the read-only account, balance and transaction data plus merchant metadata it returns. You authenticate with your bank inside Quiltt’s own flow. |
| Stripe | Web payments | Your email address, a customer and subscription ID, and payment details you enter directly into Stripe’s checkout. Stripe is the card processor; we never see the card. |
| Apple | iOS purchases, receipt verification, push delivery | Transaction identifiers and an opaque account token for purchase verification; device push tokens and notification content for delivery. Apple also independently holds your Apple ID relationship, which we cannot see. |
| Google (Gemini API) | AI generation | The payloads described in Section 6, and nothing else. No name, email, or account identifier. |
| Railway | Application hosting, Postgres database, Redis cache | Everything the Service stores, at rest on its infrastructure. Railway does not access it in the ordinary course. |
| Cloudflare | DNS, CDN, edge security, uptime monitoring, page-view analytics, encrypted backup storage (R2) | Connection metadata for requests to our sites: IP address, approximate country, user agent, and request headers. On this website and the web app, the page-view analytics described in Section 3.6 (Cloudflare Web Analytics). It also stores our nightly, weekly and monthly database backups — which is every piece of data the Service holds — but only as ciphertext it cannot read: each backup is encrypted before it is uploaded, to a public key whose private half is never held by Cloudflare, never present in our build system, and kept only in a password manager. |
| GitHub | Source control and the automated backup pipeline | Our code, plus a transient copy of the full database during the nightly backup job: the export runs on a GitHub-hosted machine and is encrypted there before being uploaded, so an unencrypted copy exists on GitHub’s infrastructure for the seconds between those two steps and is destroyed with the machine when the job ends. Listed because that is processing, however brief. |
| Resend | Transactional email delivery | Your email address and the full contents of the messages we send you. |
| Discord | Optional community server | Only what you choose to post there, under Discord’s own terms. Entirely separate from your Net Worth Nexus account — we cannot link the two unless you tell us. |
Public data shown in Markets (FRED, SEC EDGAR, press feeds) flows to you — no personal data is sent to those sources, and they do not know you exist.
Providers process data under their own security and privacy obligations. Certifications such as SOC 2 belong to those providers; Net Worth Nexus does not hold its own SOC 2 certification and does not claim one. Before engaging a new provider that would receive personal information, we assess it and add it to this table; a material addition is a change to this policy and gets notice under Section 18.
9. We Do Not Sell Your Data or Advertise To You
- We have never sold or shared personal information as those terms are defined under California, Colorado, Connecticut, Texas, Utah, Virginia, Nevada, or any other state privacy law, and we do not sell the personal information of minors.
- We do not share personal information for cross-context behavioral advertising or targeted advertising, and we run no advertising on the Service.
- We do not engage in profiling in furtherance of decisions producing legal or similarly significant effects.
- Because there is nothing to opt out of, there is no “Do Not Sell or Share My Personal Information” link. If you send a Global Privacy Control signal, it is honored automatically and changes nothing, because we already do not sell or share.
- If this ever changes we will update this policy, give advance notice, and build a working opt-out before the first such disclosure occurs — not after.
10. Data Retention & Deletion
| What | How long |
|---|---|
| Sessions | Expire per your configured timeout (15 minutes to 24 hours; default 1 hour), and immediately on password change or sign-out everywhere |
| Financial records, snapshots, transactions, manual entries, settings | While your account exists — they are your history |
| AI daily briefings | A short rolling window — currently 3 days — then purged automatically |
| Connection webhook records | Raw bodies pruned after about 60 days (brokerage) or 7 days (banking); event metadata about 365 days (brokerage) or 90 days (banking), for diagnostics |
| Error diagnostics | Kept while the underlying defect is live, and cleared when it is resolved. They hold a redacted excerpt and the numeric account IDs affected — nothing else about you, and those numbers stop resolving to anyone once the account is deleted |
| Support tickets | Kept while the issue is open and afterward as the record of what we did. Deleted with your account, and on request at any time |
| Closed-account email fingerprint | Only when we close an account for a breach of the Terms, and only for a verified address: a one-way, keyed fingerprint of the address (never the address itself), so it cannot open a new account. Kept until we agree to lift it; signing up with the address sends it a link to ask. Deleting your own account never creates one |
| Support-assistant conversations | Not stored on our servers. The thread lives in your browser session and is gone when you close the tab, unless you escalate it into a ticket |
| Mailing-list address | Until you ask us to remove it, or your account is deleted |
| Billing and tax records | As long as law requires, typically 7 years, in minimized form (amounts, dates, identifiers) |
| Encrypted backups | Rotated on a fixed schedule; deleted data ages out of backups as they rotate, and is never restored into production |
10.1 Deleting your account
Settings → Danger Zone → Delete Account, confirmed by typing DELETE.It is never blocked by a subscription — you do not have to cancel first, and a paid account always keeps a delete path. You can also request deletion by writing to support@networth.nexus from your account address.
Deleting your account does not cancel an App Store subscription. If you subscribed on iOS, Apple controls that billing and it keeps renewing after your account is gone — cancel it in iPhone Settings → your name → Subscriptions (Terms Section 10). A web subscription is cancelled for you as part of the deletion.
Deletion purges, from production systems:
- your profile, credentials, preferences, and consent records;
- every connected authorization, and the provider-side registration where the provider supports deletion;
- all snapshots, transactions, holdings, manual entries, watchlist items, wagers, and AI briefings;
- your support tickets and any push tokens.
What survives, and why: billing records required by tax and accounting law; if we closed the account for a breach of the Terms, the email fingerprint described above; records we are legally obliged to preserve, such as those under an active legal hold; aggregated or de-identified figures that can no longer be linked to you; and residual copies inside encrypted backups until those backups rotate out. Deletion is permanent and irreversible — we cannot restore a deleted account, so export your data first if you want a copy.
11. Security & Breach Notification
- Passwords hashed with PBKDF2-HMAC-SHA256 at a high iteration count with per-user random salts, transparently upgraded as the work factor rises.
- Connection secrets encrypted at rest with authenticated symmetric encryption under a server-managed key.
- HTTP-only, SameSite session cookies; login rate limiting and account lockout; configurable session expiry; server-side session revocation on password change.
- Optional two-factor authentication (TOTP) on web and iOS, with single-use recovery codes and a revocable, per-device option to skip the second step for 30 days. Enrolling, disabling, or regenerating recovery codes each require your password again, and a password reset ends every session and forgets every remembered device.
- Transport encryption (TLS) everywhere, with HSTS, a Content-Security-Policy, frame denial, content-type protection, and restrictive referrer and permissions policies enforced on every response.
- Every inbound webhook — Stripe, Apple, SnapTrade, and Quiltt — is cryptographically verified before it is processed: signature checked against the provider’s secret or signing certificate, and replays rejected by deduplication. An unsigned or mis-signed webhook cannot change your subscription, your entitlement, or your data.
- Secrets are redacted from logs and error reports before storage.
- Read-only data model: no institution credentials to steal, and no money-movement capability to abuse.
- On iOS, biometric-login credentials are stored only in the device Keychain, accessible only when the device is unlocked.
- Encrypted, offsite backups on a fixed rotation, restorable and periodically verified.
We maintain a written information security program with administrative, technical, and physical safeguards appropriate to our size and to the sensitivity of financial data, reviewed as the Service changes.
No system is perfectly secure. If we learn of a breach of the security, confidentiality, or integrity of your private information, we will notify you and the appropriate authorities as required by law — including New York’s breach notification statute (GBL § 899-aa) and the SHIELD Act — in the most expedient time possible and without unreasonable delay. Report suspected vulnerabilities to support@networth.nexus; good-faith security research is welcome and we will not pursue researchers who follow the boundaries in Terms Section 16.
12. Your Rights & Choices
These are available to every user, in every state, regardless of whether a statute requires it:
- Access & correction: view and edit your profile, preferences, and manual data in Settings, or edit and remove manual assets directly on the Assets page.
- Export (portability): Settings → Your Data & Legal → Download My Data returns everything we hold about your account as a single JSON file — profile, snapshots, account history, manual entries, watchlist, and transactions. It contains no credentials. Data still held by SnapTrade, Quiltt, Stripe, or Apple must be requested from them.
- Deletion: self-service in Settings, as described in Section 10.1.
- Disconnecting accounts: remove any brokerage or banking connection in Settings → Connections at any time. Removing it stops future syncing immediately; use deletion to remove the history it produced.
- AI is opt-in: the Daily Briefing is off until you turn it on, and the AI Daily Briefing switch in Settings turns it off again. Off means nothing is sent to Google.
- Opt-outs: product-update emails, the daily push notification, and the demographic benchmark are all off by default or toggleable in Settings. We do not currently send any marketing email; when we begin, every message will carry a working one-click unsubscribe and our postal address, and unsubscribing will never affect the transactional messages you need.
- Mailing list: if you gave us your address on the marketing site without creating an account, write to support@networth.nexus and we will remove it.
- Withdrawing consent: you may withdraw consent to any optional processing at any time; it does not affect processing already carried out.
- Appeal: if we decline a request, we will tell you why and how to appeal. Write to support@networth.nexus with “Appeal” in the subject and a different reviewer will look at it and respond within 45 days.
How to make a request: use Settings where a control exists, or write to support@networth.nexus or to the postal address in Section 19. We verify requests against the email on the account — for sensitive requests we may ask you to confirm from that address or to re-authenticate. An authorized agent may act for you with written permission we can verify. We respond within 45 days, extendable once by another 45 with notice. There is no charge, and we will never discriminate against you for exercising a privacy right — no price change, no service degradation, no denial.
13. U.S. State Privacy Rights
Depending on your state — including California, Colorado, Connecticut, Delaware, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Utah, and Virginia — you may have statutory rights to know and access, correct, delete, and port personal information, and to opt out of sale, of sharing for targeted advertising, and of certain profiling. Section 12 gives every user all of these regardless.
- We do not sell personal information and do not share it for cross-context behavioral advertising or targeted advertising, so those opt-outs have nothing to act on (Section 9).
- California residents (CCPA/CPRA): the categories of personal information collected, the sources, and the business purposes are in Sections 2, 3, and 5; the categories disclosed for a business purpose and the recipients are in Sections 7 and 8; retention is in Section 10. We disclosed no category for monetary or other valuable consideration in the preceding 12 months. You have the right to know, delete, correct, opt out, and limit the use of sensitive personal information — and we already limit sensitive personal information to what is necessary to provide the Service, and never use or disclose it for inferring characteristics. You may designate an authorized agent. Contact is in Section 19.
- Nevada residents may direct a covered operator not to sell certain covered information. We do not sell it; a request to support@networth.nexus is honored and recorded regardless.
- Texas, Colorado, and Connecticut residents: we recognize universal opt-out mechanisms including the Global Privacy Control (Section 9) and provide the appeal process in Section 12.
- Where a state law gives you a right this policy does not name, you have that right; write to us and we will honor it.
14. Financial Privacy (Gramm-Leach-Bliley)
Because we handle nonpublic personal financial information about consumers, we treat ourselves as subject to the federal financial privacy and safeguards standards, and this section serves as our financial privacy notice.
- What we collect: information you give us (identity, profile, manual account details); information from your transactions with us (subscription and payment history); and information from your financial institutions, obtained with your authorization through SnapTrade and Quiltt (balances, holdings, transactions).
- Whether we disclose it: we disclose nonpublic personal information only to the service providers named in Section 7, and only as necessary to perform services for us and to service your account — a permitted disclosure that requires no opt-out. We make no disclosures for marketing purposes, none to affiliates (we have none), and none to unaffiliated third parties for their own use.
- Your opt-out right: because we make no disclosures of the kind that trigger an opt-out, there is nothing for you to opt out of. If that ever changes, we will give you notice and a working opt-out before any such disclosure is made.
- If you close your account: we continue to treat your information under this policy for as long as we retain any of it.
- Safeguards: the security program described in Section 11 is designed to protect the security and confidentiality of this information and to protect against anticipated threats and unauthorized access.
Nothing in this section makes us a bank, broker, adviser, or lender, and nothing in the Service is a consumer report — see Terms Section 5.
15. Adults Only
The Service is for adults. It is not directed to children, and registration requires you to be at least 18 years old. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete the account and its data promptly. Parents or guardians who believe a minor has created an account can contact support@networth.nexus and we will act on it. We do not sell or share the personal information of minors under any circumstances.
16. United States Only
The Service is operated from the United States, processed and stored on U.S. infrastructure, and offered solely to residents of the United States. We do not offer, market, or make it available to people in the European Economic Area, the United Kingdom, Switzerland, or elsewhere outside the United States; the iOS application is distributed only on the United States App Store, prices are in U.S. dollars, and the Service is provided in English only. Account creation is declined when network-level signals place the request outside the United States, and agreeing to the Terms at registration confirms your U.S. residency.
Because we do not target or offer the Service outside the United States, we do not position ourselves as a controller under the EU or UK GDPR. If you reach the Service from outside the United States anyway, you do so on your own initiative and you understand your information is transferred to and processed in the United States, where privacy laws differ from your jurisdiction’s.
18. Changes to This Policy
We may update this policy at any time as the product and the law evolve. For material changes — a new category of data, a new purpose, a new recipient, or anything that reduces your protections — we will give reasonable advance notice by posting on this page with a new effective date and by in-app notice or email, and where the change is significant the app will ask you to accept it before you continue. Non-material changes (clarity, formatting, a corrected typo) take effect on posting. Changes are prospective. The version you consented to is recorded with your account, and previous versions are available on request from support@networth.nexus.
19. Contact
NexTech Innovations LLC — operator of Net Worth Nexus
3 E Evergreen Rd Ste 101 PMB 270
New City, NY 10956, United States
Privacy questions, rights requests, appeals, complaints, and general support all reach us at support@networth.nexus. Writing “Privacy request” in the subject line gets it to the right place fastest.
If you are not satisfied with our response, you may contact the New York State Attorney General’s Bureau of Internet and Technology, your own state attorney general, or the Federal Trade Commission at reportfraud.ftc.gov.