Privacy Policy
Plain-language summary (not a substitute for the policy below): We collect your account info (name, email), your questions and the tutor’s answers, and payment info (handled by Stripe — we never store your card number). We use Clerk for login, Stripe for billing, PostHog for product analytics including session recordings, OpenAI to generate tutor answers, and Anthropic to review conversation quality behind the scenes. We run Google ads and measure whether they lead to signups. Email support@financebrain.ai anytime to access, correct, or delete your data.
Table of contents
- Who we are and what this policy covers
- Information we collect
- Who we share information with (service providers)
- How we use your information
- Chat content: what happens to your questions and answers
- Cookies and tracking
- Session replay and analytics
- Data retention
- Your rights and how to exercise them
- California privacy rights (CCPA/CPRA)
- Visitors from outside the United States
- Children’s privacy
- Security
- Changes to this policy and version history
- Contacting us
1. Who we are and what this policy covers
This policy describes how Finance Brain (“we,” “us,” “our”) collects, uses, and shares information when you use financebrain.ai and the Finance Brain tutoring service (the “Service”). It is written to reflect what our systems actually do — every vendor and data category named below is one we actually use as of this policy’s effective date. Finance Brain is based in the United States, and your data is processed and stored in the United States.
2. Information we collect
| Category | Examples | Source |
|---|---|---|
| Account information | Name, email address, authentication identifiers | You, via Clerk (our authentication provider) at signup |
| Payment information | Billing details and subscription status. We do not store your full card number — Stripe handles and stores that. | You, via Stripe Checkout |
| Chat content | The questions you ask and the tutor’s answers | You, when you use the Service |
| Usage data | Pages visited, features used, session activity, on-screen interactions (see Section 7) | Automatically, via PostHog |
| Attribution/advertising data |
How you found us — ad click IDs (Google
gclid/gbraid/wbraid), UTM
campaign parameters, and (for advertising measurement only) a hashed
version of your email
|
Automatically, from URL parameters and, after signup, matched to your account for conversion measurement |
| Device/technical data | IP address, browser type, general location (country/region, from your IP) | Automatically |
3. Who we share information with (service providers)
We use the following service providers to run Finance Brain. Each receives only the data it needs to do its job, and none of them are permitted to use your data for their own independent marketing purposes.
| Provider | What they do | What they receive |
|---|---|---|
| Clerk | Authentication (sign-up, sign-in, session management) | Name, email, authentication data |
| Stripe | Payment processing, subscription billing, and the self-service billing portal | Payment/billing details, email, subscription status |
| PostHog | Product analytics and session replay (see Section 7) | Usage events, on-screen interaction data, session recordings |
| OpenAI | Generates the tutor’s answers to your questions | The text of your questions and the conversation context needed to answer them |
| Anthropic | Reviews conversations behind the scenes to analyze topic trends and answer quality — an internal quality process, not a second tutor you interact with | Conversation content (question/answer pairs), analyzed in batches |
| Google Ads | Advertising measurement — tells us whether an ad click led to a signup or subscription so we can measure and improve our marketing | Ad click identifiers, a hashed (not plaintext) version of your email for conversion matching, and whether/when you subscribed |
| Vercel | Hosts our website and web application | Standard web request/technical data |
| Heroku | Hosts our backend servers | Standard web request/technical data |
| MongoDB Atlas | Our database — stores account, chat, and subscription records | All of the above data categories, at rest |
We do not sell your personal information for money. Depending on your state, sharing data with an advertising partner like Google Ads for conversion measurement may legally count as a “share” for cross-context advertising purposes even though no money changes hands — see Section 10 for your opt-out rights if you are a California resident.
We may also disclose information if required by law (for example, a subpoena or similar legal process) or to protect the rights, property, or safety of Finance Brain, our users, or others. If Finance Brain goes through a business transition such as a merger, acquisition, or sale of assets, your information may be among the assets transferred.
4. How we use your information
- To provide and operate the Service — answer your questions and manage your account and subscription.
- To improve the Service — product analytics, understanding what’s confusing, fixing bugs (see Section 7).
- To process payments and manage billing.
- To measure whether our advertising is working (Google Ads conversion tracking).
- To communicate with you about your account, billing, or material changes to our terms or policies.
- To detect and prevent fair-use abuse, fraud, or security incidents.
5. Chat content: what happens to your questions and answers
When you ask Finance Brain a question:
- Your question (and relevant conversation context) is sent to OpenAI to generate the tutor’s answer. This happens for every message, in real time.
- Separately, conversations may be reviewed in batches by Anthropic’s Claude as part of our internal quality process — analyzing topic trends and whether answers were helpful. It is not a live feature you interact with; it runs behind the scenes.
- Your conversation history is stored in our database (MongoDB Atlas) so you can pick up where you left off.
We access both providers through their commercial APIs, which by their standard terms do not use API-submitted content to train the providers’ general-purpose models.
6. Cookies and tracking
| Cookie | Purpose | Duration |
|---|---|---|
fb_consent |
Records your cookie/advertising consent choice (shown to EEA/UK visitors — see below) | 180 days |
fb_geo |
Short-lived region tag used only to decide whether to show the cookie consent banner | Short-lived |
| Clerk session cookies | Keep you signed in | Session-based, per Clerk’s defaults |
| Stripe cookies | Fraud prevention during checkout | Set by Stripe during checkout |
| PostHog cookies/local storage | Analytics and session identification (see Section 7) | Per PostHog defaults |
If you are visiting from the EEA or UK, you will see a cookie consent banner, and analytics and advertising cookies stay off until you accept. If you are visiting from anywhere else, including the United States, analytics (including session replay) runs by default without a banner. California residents: see Section 10 for your specific opt-out right, which applies regardless of the banner.
7. Session replay and analytics
We use PostHog for product analytics, including session replay — recordings of how you interact with the Service (clicks, scrolling, and on-screen content, including the spreadsheet workspace) so our team can see what’s confusing and improve the product.
To protect your sensitive information, recordings automatically mask:
- Anything typed into sign-in, sign-up, and account-management screens.
- Email address and password fields anywhere in the product.
Other on-screen text and typed input are not masked — if you type a question or work in the spreadsheet, that content may appear in a session recording our team can review for product improvement. Network request and response bodies, URL query parameters, and browser console logs are never recorded.
8. Data retention
We keep your account and conversation data for as long as your account is active, plus a reasonable period after that to handle support requests, enforce our Terms of Service, and meet legal obligations. If you request deletion (see Section 9), we will delete your personal information within a reasonable timeframe, except where we are required to keep records (for example, payment records for tax and accounting purposes) for longer. Deletion requests are currently handled manually by our support team.
9. Your rights and how to exercise them
Regardless of where you live, you can ask us to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your account and associated personal information.
- Export your data in a portable format.
To exercise any of these, email support@financebrain.ai from your account’s email address. We may ask you to verify your identity before completing the request.
10. California privacy rights (CCPA/CPRA)
If you are a California resident, in addition to the rights in Section 9, you have the right to:
- Know what categories of personal information we have collected and shared, and with whom (see Section 3).
- Opt out of “sale” or “sharing” of your personal information. We do not sell personal information for money. We do share hashed-email and ad-click-ID data with Google Ads for advertising conversion measurement, which California law treats as “sharing” for cross-context behavioral advertising purposes even without a sale. To opt out, email support@financebrain.ai with “California opt-out” in the subject line — we will disable Google Ads conversion tracking for your account.
- Not be discriminated against for exercising any of these rights.
11. Visitors from outside the United States
Finance Brain is a US-based product built primarily for US students, and your data is processed and stored in the United States. If you access the Service from the EEA, UK, or elsewhere, the rights in Section 9 apply to you as well, and our cookie consent banner (EEA/UK) governs analytics and advertising cookies for your visits.
12. Children’s privacy
The Service requires users to be at least 18 years old (see our Terms of Service, Section 2). We do not knowingly collect personal information from anyone under 18, and in particular not from children under 13. If you believe a child has provided us personal information, email support@financebrain.ai and we will delete it.
13. Security
We use industry-standard safeguards (encryption in transit, access controls) to protect your information. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we experience a data breach that puts your information at risk, we will notify you as required by applicable law.
14. Changes to this policy and version history
We may update this policy. When we do, we will update the version number and effective date at the top of this page. Material changes will be disclosed in-product or by email before they take effect.
| Version | Effective date | Summary |
|---|---|---|
| 2.0 | July 8, 2026 | Full rewrite: named every service provider we actually use (Clerk, Stripe, PostHog, OpenAI, Anthropic, Google Ads, Vercel, Heroku, MongoDB Atlas), disclosed session replay exactly as implemented, documented the cookie/consent behavior and the California opt-out email path, and added retention/deletion and chat-content sections. Kept the 18+ posture from the Terms of Service. Published with conservative resolutions of open legal questions (manual CCPA opt-out path, replay scope, US-only consent-banner geography) — pending a one-time counsel review. |
| 1.0 | April 16, 2023 | Original privacy policy. Superseded. |
15. Contacting us
Questions about this policy, or to exercise your privacy rights: support@financebrain.ai