Northstar
Privacy & Data Security Policy
Version 2026-08-06

Privacy & Data Security Policy

Scope

This policy explains what Northstar collects, why, who it is shared with, how it is protected, and the choices you have. It covers the web application and the iOS and Android apps. Northstar is a private, invite-only service: there is no public signup, and accounts are created only from an invitation.

Information we collect

Account and identity: email address, display name, and the credentials used to sign in (passwords are stored only as a salted hash, never in readable form), plus two-factor and passkey enrolment data.

Financial data you connect or import: account names and numbers in masked form, balances, transactions, holdings, investment activity, loan and card terms, and the contents of statements, pay stubs, and policy documents you choose to upload.

Household roster: the people you add for spending attribution or shared access, and their role in your household.

Operational records: sign-in and activity logs, IP address, request and error logs, and records of changes you make — retained to operate the service, show you your own account activity, and investigate abuse.

How we use your information

To provide the service: aggregate your accounts, price your holdings, and produce the net-worth, spending, income, investment, tax, and planning views you asked for.

To secure your account: authenticate you, enforce two-factor and step-up checks, detect and investigate suspicious access, and keep an audit trail you can review.

To support and improve the service: diagnose errors, monitor data-feed health, and fix defects. We do NOT use your financial data to build advertising profiles, and we do not sell or rent it.

Access to your money is read-only

Northstar requests read-only access from data providers. It cannot execute trades, move funds, or initiate payments, and it does not request the permissions that would allow it to.

How your data is protected

Isolation: every household’s data is separated at the database level by row-level security, which fails closed — a request without a valid household context returns nothing rather than everything. One household cannot read another’s data.

Encryption: provider access tokens, two-factor secrets, and uploaded documents are encrypted at rest with per-field encryption; all traffic is served over TLS; the database is encrypted with customer-managed keys.

Access control: sign-in requires a password plus a mandatory second factor, or a passkey. Sensitive actions (linking an institution, managing security settings, deleting data) require a fresh re-authentication, not merely a recent login.

Third-party providers

Account aggregation: we use financial-data providers, currently Plaid and SnapTrade, to connect to your institutions. You authenticate directly with your institution through the provider; we never see or store your banking username or password. We share with a provider only what is needed to retrieve your data, under their terms and privacy policies.

Market data: prices, fundamentals, and company news come from market-data providers using only a security symbol — no personal information is sent.

Infrastructure: the service runs on cloud infrastructure that stores data on our behalf under contractual confidentiality and security obligations.

Automated processing and AI features

Some features use AI models to read documents you upload (statements, pay stubs, insurance policies) and to answer questions in the in-app chat. Document contents are processed in memory and are not written to disk in readable form; for insurance policies only a distilled extract is stored, with identifiers such as government ID, card, and account numbers removed before storage.

Chat memory stores only facts you ask it to remember, with secrets and card numbers redacted before saving. You can view, edit, and delete these at any time, or turn the feature off.

AI providers process this content to return a result and act as processors on our behalf. We record only usage metadata (model, token counts, cost) for cost control.

Cookies, tracking, and analytics

We use a single essential session cookie to keep you signed in, plus a preference cookie for your chosen theme. There are no advertising cookies.

We do not use Google Analytics or any third-party analytics, tag manager, session recorder, or advertising pixel. The application enforces a strict content-security policy that blocks external scripts outright, and all scripts, styles, and fonts are served from our own domain.

If you arrive from a campaign link we record the campaign parameters from the URL (such as source and medium) so we can count how many signups a channel produced. This is aggregate and first-party; it is not linked to your financial data and is never shared with an advertising network.

When we disclose information

We do not sell your personal or financial data, and we do not share it for cross-context behavioural advertising.

We disclose data only: to the providers and infrastructure described above, to carry out your instructions; to other members of your own household, according to the access level you grant them (a view-only member cannot change anything); and where required by law, legal process, or to protect the rights and safety of users.

Retention and deletion

We keep your data while your account is active. You can delete your household from within the app: this permanently removes accounts, transactions, holdings, uploaded documents, sessions, and security credentials, and revokes the connections to your financial institutions. The deletion is verified by a census confirming no records remain, and we retain only a minimal, non-identifying record that a deletion occurred, plus anything we must keep for legal or tax reasons.

Operational logs are retained on a rolling basis and then pruned automatically.

Your rights and choices

You can view all of your data in the app, disconnect any linked institution at any time, correct or re-categorise records, export transaction and tax data, and delete your household outright.

Depending on where you live you may have additional rights — including access, correction, deletion, portability, and the right not to be discriminated against for exercising them. Because we do not sell or share personal information for advertising, there is nothing to opt out of in that respect. To exercise any right, use the in-app controls or the operator contact provided in-app; we will not charge you for it.

Children

The service is not directed to children under 13 (or under 16 where a higher age applies), and we do not knowingly collect their personal information. A child may appear in your household roster as a name for attribution, or as the beneficiary of an education savings account, without holding an account of their own.

Where your data is processed

Data is processed and stored in the United States. If you access the service from outside the United States, you understand that your information will be processed there, where privacy laws may differ from those in your country.

Changes to this policy

If we change this policy materially we will publish the updated version, change its version identifier, and ask you to review and accept it before you continue using the service. The version in force is shown at the top of this page.

Contact

[PLACEHOLDER pending launch] Privacy questions and rights requests can be sent to the operator contact provided in-app; the responsible legal entity, its postal address, and the governing law will be named here before the service is offered publicly.