Legal

Privacy policy

Last updated: September 2026

What we collect

Your email address (for your account), and the financial figures you type in: asset values, liability balances, income, expenses, and rental details. We never ask for — and cannot access — your bank or brokerage passwords. If you choose to connect a brokerage (e.g. Questrade), you provide a revocable read-only API token that you generate yourself; we store it to sync your account balances, only you can see it, and disconnecting removes it. If you subscribe to a paid plan we also keep the minimum billing metadata (your plan, renewal date, and Stripe customer reference).

Payments

Payments are processed by Stripe. Your card number goes directly to Stripe and never touches our servers; we receive only a customer reference and subscription status. Stripe's own privacy policy governs their processing.

The AI assistant

When you use the assistant, your messages and a snapshot of your household's figures are sent to our AI provider (Anthropic) to generate the reply, under an agreement that does not permit training on your data. We don't store your conversations on our servers. If you connect your own Claude or OpenAI API key in Settings, requests go to your provider on your key instead — your key is stored encrypted, visible only to you, and removable at any time. The assistant is optional; nothing is ever sent to an AI provider unless you open the chat and ask something.

Cookies

We use a session cookie to keep you signed in and a preference cookie for your language. There are no advertising trackers, no third-party analytics cookies, and no fingerprinting.

Who can see your data

Your household's data is visible only to the members of your household: you and, if you invite one, your partner. Access is enforced at the database layer (row-level security), not just in application code. There are no cross-household aggregates, leaderboards, or shared statistics.

What we don't do

We don't sell your data. We don't share it with advertisers. We don't use your financial figures for anything other than showing them back to you.

Where it lives

Data is stored with Supabase (Postgres) hosted in Canada (ca-central-1, Montréal). As a Canadian service handling personal financial information, we operate under PIPEDA.

Deletion and export

You can request a full export of your household's data, and you can request permanent deletion of your account and all associated data. Deletion is real deletion, not a soft-hide. Contact us from your account email to exercise either.

Tenant information

The rentals module is designed for minimal tenant data: labels like "Unit 2 tenant" rather than full names. We encourage keeping it that way — you are responsible for any personal information about tenants you choose to enter.

Calculators

The public calculators run entirely in your browser. Inputs are encoded in the page URL so you can share results; they are not stored on our servers.

Contact

Questions, corrections, or a request to delete your account and its data: email support@canadianfinhub.ca.

Not financial, tax, or investment advice.

Privacy policy — CanadianFinHub · CanadianFinHub