Privacy Policy
Last updated: December 17, 2025
Version 1.0.0
Important Notice About Financial Data
1. Introduction
This Privacy Policy describes how Vexton AI ("we," "us," or "our") collects, uses, discloses, and protects your information when you use our wealth intelligence platform and related services (collectively, the "Service").
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, do not use the Service.
2. Definitions
- Account: A unique account created for you to access our Service.
- Company: Refers to Vexton AI.
- Device: Any device that can access the Service such as a computer, mobile phone, or tablet.
- Financial Data: Portfolio holdings, transactions, account balances, investment theses, performance metrics, and related financial information.
- Personal Data: Information that relates to an identified or identifiable individual.
- Service: The VextonAI wealth intelligence platform, accessible from https://vexton.ai
- Usage Data: Data collected automatically through your use of the Service.
- You: The individual or entity accessing or using the Service.
3. Information We Collect
3.1 Personal Information
When you create an account, we collect:
- Full name
- Email address
- Password (encrypted)
- Profile information (optional)
3.2 Financial Data
To provide our core service, we collect and process:
- Portfolio Holdings: Securities, cryptocurrencies, and other assets you own
- Transaction History: Buy/sell transactions, transfers, dividends, and corporate actions
- Account Information: Brokerage/bank account names, types, and balances (we DO NOT store account numbers or credentials)
- Investment Theses: Your written investment rationale, notes, goals, and strategy documentation
- Performance Metrics: Returns, allocations, drift analysis, and related calculations
- Financial Goals: Investment objectives, risk tolerance, time horizons
3.3 Data Collection Methods
You provide financial data through:
- CSV Upload: Manually uploaded transaction and holdings files
- Manual Entry: Data you input directly into the platform
- Account Aggregation (Future): With your explicit consent, we may connect to financial institutions via Plaid or similar services
3.4 Usage Data
We automatically collect:
- IP address and device information
- Browser type and version
- Pages visited and time spent
- Feature usage patterns
- Error logs and diagnostic data
- Referring URLs and navigation paths
3.5 Cookies and Tracking
We use cookies for:
- Essential Cookies: Authentication, security, and basic functionality (required)
- Functional Cookies: Remember your preferences and settings
- Analytics Cookies: Understand how you use the Service to improve it
You can control cookies through your browser settings, though disabling essential cookies may limit functionality.
4. How We Use Your Information
4.1 Core Service Operations
We use your information to:
- Track and analyze your portfolio performance
- Calculate investment returns, allocations, and drift
- Link investment theses to portfolio positions
- Generate automated alerts and notifications
- Create performance reports and visualizations
4.2 AI-Powered Features
AI Processing Transparency
4.3 Communications
We may send you:
- Service announcements and updates
- Security alerts and account notifications
- Performance summaries and reports
- Educational content (with your consent)
5. Third-Party Services and Data Sharing
5.1 Service Providers
We share data with trusted service providers who assist us:
- Hosting & Infrastructure: Amazon Web Services (AWS), Vercel
- Analytics: PostHog (privacy-focused analytics)
- Email: Plunk
- Payments: Stripe (we do not store payment card details)
- AI Models: OpenAI, Anthropic (data anonymized where possible)
5.2 We Do NOT Sell Your Data
We do not sell, rent, or trade your financial data to third parties for marketing purposes. Your investment information stays confidential.
6. Data Security
We protect your data through:
- Encryption: All data encrypted in transit (TLS/SSL) and at rest (AES-256)
- Access Controls: Role-based access, two-factor authentication
- Monitoring: Automated threat detection and security logging
- Regular Audits: Periodic security assessments and penetration testing
- Data Isolation: Multi-tenant architecture with data segregation
7. Data Retention and Deletion
We retain your data for as long as your account is active. You may request deletion at any time:
- Account data deleted within 30 days of request
- Backups purged within 90 days (retention for disaster recovery)
- Legal/regulatory data retained as required by law (up to 7 years)
8. Your Privacy Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and data
- Portability: Export your data in a machine-readable format
- Opt-Out: Unsubscribe from marketing communications
- Withdrawal: Revoke consent for data processing (may limit functionality)
9. International Data Transfers
Your data may be transferred to and processed in countries outside your residence, including the United States. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.
10. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.
11. Do Not Track Signals
Some browsers support "Do Not Track" (DNT) signals. We currently do not respond to DNT signals, as there is no universal standard for interpretation.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the Service at least 30 days before taking effect. Your continued use constitutes acceptance of the updated policy.
13. Contact Us
For privacy-related inquiries, contact us at:
- Email: privacy@vexton.ai