Legal
Privacy Policy
Last updated
You get in either with an email address and a password or with Google, and the account that either one creates holds your email, your name, a profile image if Google gave us one, an unreadable digest of your password if you set one, the persona you chose, and your watchlist with any notes on it. A firm domain is derived from your email address unless it is a free-mail provider. We count page views on this domain, without cookies and without joining them to your account. There is no advertising, no tracking across other sites, and nothing here is sold. Email us and it is deleted.
Template, pending counsel reviewThis document is a working template drafted in-house and published so the terms are visible before anyone signs up. It has not been reviewed by outside counsel. Where it is silent or ambiguous, ask rather than assume.
Who we are
Fin360AI is operated by Infinidatum LLC, a Connecticut limited liability company, which is the controller of the personal information described here. Reach us at admin@infinidatum.net.
What we store, exactly
7 things. Not 7 categories — 7 fields, one row each, listed individually so this page can be checked against the product rather than taken on trust. The count is computed from the same list the table renders, because a policy that miscounts its own table is not checkable.
| Field | Where it comes from | Why it exists |
|---|---|---|
| Email address | Typed by you at sign-up, or returned by your Google account at sign-in | It identifies the account, and it is how we reach you about access. It is also what the firm domain is derived from. |
| Name and profile image | Typed by you at sign-up, or returned by your Google account at sign-in. The name is optional and there is no profile image on a password account. | Shown to you in the product so you can see which account you are signed in as. Neither is displayed to anybody else. |
| A digest of your password | Derived at sign-up from the password you chose, if you chose one | It is what a later sign-in is checked against. It is a scrypt digest, not the password: the password itself is never written down here, is not recoverable from what is stored, and an account created through Google has nothing in this field at all. |
| Persona | Chosen by you, changeable at any time | It decides which ranked list leads and how a row is described. Without it the product has to guess which of four readers you are. |
| Firm domain | Derived from your email address | It lets colleagues from the same firm share a scope, and it tells us which kinds of firms are actually using this. Free-mail domains are discarded rather than stored, because they say nothing about a firm. |
| Watchlist items | Saved by you, in the product | The plans you asked to keep track of. Stored against your account because that is the entire feature. |
| Notes you write on a plan | Typed by you, against a watchlist entry | Free text, stored verbatim against your account and shown only to you. The field asks for call notes, so it can hold the names and words of people at a plan sponsor who never came here themselves. It is never read to build a profile, never used to train anything and never shown to another user — but it is the one field here whose contents we do not choose, so it has a clause of its own below. |
Alongside these, ordinary server and security logs are generated when you use the site — request paths, timestamps, IP address, user agent — as they are for any web service. They are used to keep the service running and to investigate abuse, and they are not joined to your account to build a profile of you.
Notes you write about other people
The note field on a watchlist entry is free text and it asks you for call notes, so in ordinary use it will contain information about people at a plan sponsor — a name, what they said, when to call back. Those people are not our users. They did not come here, and they cannot see what is written about them because nobody can except you.
What we do with it: nothing. Notes are stored so the feature works and are returned to you. They are not read to build a profile, not mined to improve rankings, not used as training data for any model, not shared with another user, and not sold or disclosed to anyone — the same commitments that apply to every other field on this page. Deleting a watchlist entry deletes its note; closing your account deletes all of them, because the records are tied to your account and go when it does.
What is yours to get right. You decide what goes in the box, so you are the one who controls whether it holds anything sensitive. Two practical asks, and they are asks rather than conditions of using the product: keep notes to what you need for the business reason you wrote them, and do not put anything in there you would not be willing to show the person it is about. A note is a business record. If your firm has a records policy or a supervisory obligation that governs call notes, this field sits inside it, not outside it.
If you believe a note held here contains information about you and you are not the account holder, write to admin@infinidatum.net. We can see that notes exist and can delete them, and we will act on a well-founded request — but the account holder, not Fin360AI, decided what to record, and we will usually need to involve them to resolve it properly.
What we do not collect
- No retirement plan participant data. The product is built on plan-level and sponsor-level filings. There are no individual participant records in the source and none in the product. Nothing here is a consumer report and nothing here is subject to the Fair Credit Reporting Act.
- No readable passwords. If you set a password, what is stored is a scrypt digest of it — a one-way function with a per-account salt and a deliberate memory cost. It cannot be turned back into your password by us or by anyone who takes a copy of the table, so there is no password here to hand over, to leak, or to read back to you. We never see the password after the form that set it, and an account created through Google has no password at all.
- No payment card details. There is no paid checkout on this site today. If and when there is, payment details will be handled by a payment processor and this policy will be updated before that goes live rather than after.
- No advertising or cross-site tracking. No advertising network, no data broker relationship, and no sale or sharing of personal information for cross-context behavioural advertising. We do count page views — see below — and that counter cannot follow you to another site, because it only exists on this one.
Google sign-in
Google is one of two ways in and is optional; the other is an email address and a password, which involves Google not at all. If you choose it, signing in sends you to Google, which authenticates you and returns your email, name and profile image to us. We request nothing beyond basic profile and email scope, and we do not receive access to your Gmail, Drive, Calendar or contacts. You can revoke Fin360AI’s access to your Google account at any time from your Google account’s security settings; doing so ends your ability to sign in but does not by itself delete the account record here, which you can ask us to remove.
Page-view counting
We count page views, using Vercel Analytics. It runs on this domain rather than from a third party’s servers: the script and the count it sends are both served from this site’s own address, so nothing about your visit is handed to an advertising network or an analytics company with a business of its own.
It records the page you reached, the referring page, and coarse details of your device and country. It sets no cookie, stores nothing on your device, and does not build a profile: repeat visits are not linked across days, and a visit is never joined to your account, your watchlist or anything else on this site. We use it to learn which screens people reach and where they stop, and for nothing else.
Who else processes it
We use a small number of infrastructure providers to run the service. They process data on our instructions and for no purpose of their own:
- Google — identity provider, for the accounts that choose to sign in with it. An account made with an email address and a password sends nothing to Google.
- Vercel — application hosting and delivery, and the page-view counting described above.
- Neon — managed PostgreSQL, where the account record and your watchlist are stored.
We do not sell personal information, and we do not share it with anyone else except where we are legally required to, or where it is necessary to protect the service or someone’s safety. If the business is ever sold or merged, account records may transfer as part of it; you would be told before that took effect.
How long it is kept
Account records and watchlists are kept for as long as your account exists, and deleted when you ask us to delete it. Server and security logs are kept for a short operational period and then discarded. We do not keep a shadow copy of a deleted account in order to reconstruct it later.
Your rights
Whatever jurisdiction you are in, the practical position here is the same: email admin@infinidatum.net and ask. You can ask for a copy of what is held about you, ask for it to be corrected, ask for it to be deleted, or ask for it in a portable form. There is nothing to opt out of in respect of sale or targeted advertising, because neither happens.
We aim to respond within thirty days. We will not charge you for a request, and we will not treat you differently for making one.
US state privacy rights, including California
Several US states — California, Colorado, Connecticut, Virginia and others — give residents specific rights over personal information. Fin360AI is a small business and on current volumes does not meet the revenue or headcount thresholds that make most of those statutes binding on it. We are setting the rights out anyway and honouring them for everyone, because working out whether you are entitled to ask should not be a precondition of asking.
The categories held, in the vocabulary those statutes use, are: identifiers (your email address, name and the firm domain derived from your email); internet or network activity (server and security logs, and the page-view counting described above); and the content you create in the product (watchlist entries and the notes on them). No other category is collected. Each is obtained either from the sign-up form, from your Google account at sign-in, or from your own use of the product, and each is used only for the purpose given in the table above. The password digest is a credential rather than an identifier: it describes nothing about you and exists only to check the next sign-in.
We do not sell personal information and we do not share it for cross-context behavioural advertising, under any definition those statutes use. There is no advertising on this site, no advertising network embedded in it and no data broker relationship. There is therefore nothing for a “do not sell or share” request to switch off, and a Global Privacy Control signal from your browser changes nothing here because the thing it disables never happens.
No sensitive personal information is collected — no government identifiers, precise geolocation, financial account numbers, health data, biometric data, or data about racial or ethnic origin, religion, sexual orientation or union membership. Nothing here is used for profiling that produces legal or similarly significant effects about you, and no automated decision is made about you: the models in this product score retirement plans, not people.
To exercise any right — to know, access, correct, delete, obtain a portable copy, or appeal a refusal — email admin@infinidatum.net. An authorised agent may act for you if you say so in writing. We verify a request against the email address on the account, which is the only identifier we hold, and we will not ask you for new information in order to verify one. We aim to respond within thirty days and will tell you if a request needs longer. Making a request costs nothing and changes nothing about the service you receive. If we refuse a request we will say why, and you can reply to that refusal and have it looked at again.
If something goes wrong
If personal information held here is exposed by a security incident, we will investigate it, take reasonable steps to contain it, and notify affected users by email without undue delay and within the period the applicable breach-notification law requires — along with any regulator that law requires us to tell. The notification will say what happened, which fields were involved, what we have done and what you should do. We would rather tell you about an incident that turns out to be minor than have you learn about a serious one from somebody else.
Security
Traffic is served over HTTPS, the application sets strict transport, framing, content-type and content-security headers, and the database is a managed service reached over an encrypted connection. Access to production is limited to the people who operate the service. No system is perfectly secure, and we make no claim to any formal certification we do not hold. If you find a vulnerability, email admin@infinidatum.net before publishing it and a good-faith report will not be treated as an attack.
Children
Fin360AI is a business research product intended for use by professionals in the course of their work. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has created an account, tell us and we will delete it.
Where the data is
The service is operated from the United States and the data is stored there. If you access it from outside the United States, you are sending your information to the United States, where privacy law differs from the law where you live.
Changes to this policy
If this policy changes materially, the revision date at the top changes with it and signed-in users are notified by email before the change takes effect. The date is not rolled forward on deploys that do not change the text, because a revision date that moves for nothing tells you nothing.
Contact
Privacy questions and requests go to admin@infinidatum.net. The contact page lists the other subject lines, and the Terms of Use cover the agreement itself.