← Sextant

Privacy Policy

Last updated: 2026-07-06

DRAFT — pending legal review. This page is a structural placeholder. The final text must be prepared and approved by counsel before launch.

How Sextant handles your data (in plain terms)

  • Documents you upload are read and stripped of personal details in your browser before anything is sent.
  • There is no bank-login connection and no account aggregation — Sextant never holds your banking credentials.
  • Your saved profile and history are isolated per user (row-level security).
  • We do not sell your data, and we do not train AI models on it.
  • You can export all your data, and delete your account and data, at any time from your account settings.

1. Information we collect

[Counsel to complete: account info, user-entered financial figures, documents, usage/telemetry, cookies.]

2. How we use it

[Counsel to complete: to run computations, provide the service, meter usage/billing, secure the service.]

3. Sub-processors & sharing

[Counsel to complete: hosting (Vercel), database/auth (Supabase), AI/model providers, error telemetry (Sentry), and their roles; note IP/user-agent sent to error telemetry.]

4. Data retention

[Counsel to complete: retention periods per data type; deletion on account closure.]

5. Your rights

[Counsel to complete: access, export, correction, deletion; CCPA (do-not-sell — N/A) and GDPR rights; how to exercise them.]

6. Security

[Counsel to complete: encryption in transit, RLS isolation, access controls, in-browser document redaction.]

7. Children

[Counsel to complete: not directed to children under the applicable age.]

8. Changes & contact

[Counsel to complete: how updates are notified; privacy contact address.]