Privacy policy

Effective date: February 20, 2026

Last updated: August 9, 2026

This Privacy Policy explains how ArthaPilot collects, uses, shares, and protects personal information when you use our website, applications, APIs, and related services (collectively, the "Service").

1. Information we collect

We may collect the following categories of information:

  • Account and identity data, such as email address, authentication identifiers, and login provider details.
  • Profile and planning data you submit, such as filing status, state, income inputs, ticker lists, allocations, and strategy parameters.
  • Service usage and device data, such as IP address, browser type, pages/tools accessed, timestamps, and error logs.
  • Transaction and billing metadata if paid plans are offered (payment card data is handled by payment processors, not stored in full by us).
  • Communications data when you contact support or submit feedback.

2. Sources of information

We collect information:

  • Directly from you.
  • Automatically through your use of the Service and security logging.
  • From identity and infrastructure providers used to operate the Service.

3. How we use information

We use personal information to:

  • Operate, maintain, and secure the Service.
  • Authenticate users and manage accounts.
  • Process and return your requested analytics and model outputs.
  • Provide customer support and service communications.
  • Detect abuse, enforce Terms, and prevent fraud or security incidents.
  • Comply with legal obligations and resolve disputes.

4. Legal bases (EEA/UK users)

Where required, we process personal data under one or more of these legal bases: performance of a contract, legitimate interests (such as security and product improvement), legal obligations, and consent where applicable.

5. How we share information

We may share information with:

  • Service providers that host or support the Service, such as authentication, cloud infrastructure, database, and operational tooling providers.
  • Data and integration providers needed to fulfill requested analytics and market data operations.
  • Professional advisers, auditors, insurers, and legal authorities where necessary.
  • A successor entity in connection with a merger, acquisition, financing, or asset sale.

We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising.

6. ChatGPT and connected apps

If you use ArthaPilot through ChatGPT or another connected app, that provider sends us the structured inputs needed to complete the tool request. If you link your ArthaPilot account, requests also include an access token identifying the account and permissions you approved. We return requested results to the connected app, where they may become part of a conversation or other provider-managed content.

For security and reliability, ArthaPilot records bounded operational metadata for connected-app calls, including the tool name, status, latency, warning count, and error class. These logs do not record raw prompts, ticker lists, allocations, or analysis payloads. We may keep short-lived result, confirmation, and idempotency records needed to safely complete a save or other confirmed account change.

For anonymous connected-app calls, we may derive separate pseudonymous actor and session hashes for abuse prevention, short-lived result-handle binding, and operational correlation. These hashes do not identify an ArthaPilot account or authorize access. We do not log the raw connected-app subject or session values. Confirmed change replay records expire logically after 24 hours and are removed through bounded scheduled cleanup.

The connected-app provider controls its own conversation storage, retention, and data settings. Disconnecting ArthaPilot stops future linked-account access but does not delete results already included in a provider-managed conversation. Review and delete that content using the provider's controls.

7. Cookies, local storage, and similar technologies

We use cookies and browser storage (including localStorage) for session management, authentication, security, and user experience. Third-party providers may also use cookies or similar technologies according to their own policies.

8. Data retention

We retain personal information only for as long as needed for the purposes described in this Policy, including account operation, security, legal compliance, and dispute resolution.

Retention periods vary by data type, account status, and legal requirements. We may retain de-identified or aggregated information for analytics and product improvement.

9. Data security

We implement administrative, technical, and organizational safeguards designed to protect personal information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

10. International data transfers

Your information may be processed in countries other than your own. Where required, we use appropriate safeguards for cross-border transfers.

11. Your privacy rights

Depending on your jurisdiction, you may have rights to:

  • Access, correct, or delete personal information.
  • Request portability of personal information.
  • Object to or restrict certain processing.
  • Withdraw consent where processing relies on consent.
  • Appeal a denial of a rights request, where such rights are provided by law.

To exercise rights, contact . We may need to verify your identity before processing certain requests.

12. Children's privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

13. Changes to this policy

We may update this Privacy Policy from time to time. Updates are effective when posted. Continued use of the Service after updates means you accept the revised Policy.

14. Contact

Privacy questions or rights requests can be sent to .