This policy explains what Northstar collects, why, who it is shared with, how it is protected, and the choices you have. It covers the web application and the iOS and Android apps. Northstar is a private, invite-only service: there is no public signup, and accounts are created only from an invitation.
Account and identity: email address, display name, and the credentials used to sign in (passwords are stored only as a salted hash, never in readable form), plus two-factor and passkey enrolment data.
Financial data you connect or import: account names and numbers in masked form, balances, transactions, holdings, investment activity, loan and card terms, and the contents of statements, pay stubs, and policy documents you choose to upload.
Household roster: the people you add for spending attribution or shared access, and their role in your household.
Operational records: sign-in and activity logs, IP address, request and error logs, and records of changes you make — retained to operate the service, show you your own account activity, and investigate abuse.
To provide the service: aggregate your accounts, price your holdings, and produce the net-worth, spending, income, investment, tax, and planning views you asked for.
To secure your account: authenticate you, enforce two-factor and step-up checks, detect and investigate suspicious access, and keep an audit trail you can review.
To support and improve the service: diagnose errors, monitor data-feed health, and fix defects. We do NOT use your financial data to build advertising profiles, and we do not sell or rent it.
Northstar requests read-only access from data providers. It cannot execute trades, move funds, or initiate payments, and it does not request the permissions that would allow it to.
Isolation: every household’s data is separated at the database level by row-level security, which fails closed — a request without a valid household context returns nothing rather than everything. One household cannot read another’s data.
Encryption: provider access tokens, two-factor secrets, and uploaded documents are encrypted at rest with per-field encryption; all traffic is served over TLS; the database is encrypted with customer-managed keys.
Access control: sign-in requires a password plus a mandatory second factor, or a passkey. Sensitive actions (linking an institution, managing security settings, deleting data) require a fresh re-authentication, not merely a recent login.
Account aggregation: we use financial-data providers, currently Plaid and SnapTrade, to connect to your institutions. You authenticate directly with your institution through the provider; we never see or store your banking username or password. We share with a provider only what is needed to retrieve your data, under their terms and privacy policies.
Market data: prices, fundamentals, and company news come from market-data providers using only a security symbol — no personal information is sent.
Infrastructure: the service runs on cloud infrastructure that stores data on our behalf under contractual confidentiality and security obligations.
Some features use AI models to read documents you upload (statements, pay stubs, insurance policies) and to answer questions in the in-app chat. Document contents are processed in memory and are not written to disk in readable form; for insurance policies only a distilled extract is stored, with identifiers such as government ID, card, and account numbers removed before storage.
Chat memory stores only facts you ask it to remember, with secrets and card numbers redacted before saving. You can view, edit, and delete these at any time, or turn the feature off.
AI providers process this content to return a result and act as processors on our behalf. We record only usage metadata (model, token counts, cost) for cost control.
We use a single essential session cookie to keep you signed in, plus a preference cookie for your chosen theme. There are no advertising cookies.
We do not use Google Analytics or any third-party analytics, tag manager, session recorder, or advertising pixel. The application enforces a strict content-security policy that blocks external scripts outright, and all scripts, styles, and fonts are served from our own domain.
If you arrive from a campaign link we record the campaign parameters from the URL (such as source and medium) so we can count how many signups a channel produced. This is aggregate and first-party; it is not linked to your financial data and is never shared with an advertising network.
We do not sell your personal or financial data, and we do not share it for cross-context behavioural advertising.
We disclose data only: to the providers and infrastructure described above, to carry out your instructions; to other members of your own household, according to the access level you grant them (a view-only member cannot change anything); and where required by law, legal process, or to protect the rights and safety of users.
We keep your data while your account is active. You can delete your household from within the app: this permanently removes accounts, transactions, holdings, uploaded documents, sessions, and security credentials, and revokes the connections to your financial institutions. The deletion is verified by a census confirming no records remain, and we retain only a minimal, non-identifying record that a deletion occurred, plus anything we must keep for legal or tax reasons.
Operational logs are retained on a rolling basis and then pruned automatically.
You can view all of your data in the app, disconnect any linked institution at any time, correct or re-categorise records, export transaction and tax data, and delete your household outright.
Depending on where you live you may have additional rights — including access, correction, deletion, portability, and the right not to be discriminated against for exercising them. Because we do not sell or share personal information for advertising, there is nothing to opt out of in that respect. To exercise any right, use the in-app controls or the operator contact provided in-app; we will not charge you for it.
The service is not directed to children under 13 (or under 16 where a higher age applies), and we do not knowingly collect their personal information. A child may appear in your household roster as a name for attribution, or as the beneficiary of an education savings account, without holding an account of their own.
Data is processed and stored in the United States. If you access the service from outside the United States, you understand that your information will be processed there, where privacy laws may differ from those in your country.
If we change this policy materially we will publish the updated version, change its version identifier, and ask you to review and accept it before you continue using the service. The version in force is shown at the top of this page.
[PLACEHOLDER pending launch] Privacy questions and rights requests can be sent to the operator contact provided in-app; the responsible legal entity, its postal address, and the governing law will be named here before the service is offered publicly.