This policy explains how North Memory collects, uses, discloses, protects, and retains personal information when you use North Memory.
Effective July 29, 2026Version 2026-07-29.1
Read-only connections
North Memory can retrieve supported financial data. It cannot trade, withdraw, transfer, or make payments.
Owner-scoped records
Connected records, preferences, labels, and notes are scoped to the authenticated user.
AI only when invoked
AI analysis uses a minimized financial summary after you ask a question or select a clearly labeled AI action.
No targeted advertising
North Memory does not sell connected financial data or use it for cross-context behavioral advertising.
1. Scope and operator
This policy applies to North Memory websites, progressive web app features, account services, and support interactions.
The service is intended only for adults age 18 or older in Canada, excluding Quebec, and the United States during early access.
Operator
North Memory
Registration status
Incorporation pending
Jurisdiction
British Columbia, Canada
Business address
1190 Pacific Street, Coquitlam, British Columbia V3B 6Z2, Canada
Privacy officer
North Memory Privacy Contact
2. Information North Memory collects
Identity and authentication. Name, email, phone when provided, Clerk identifiers, session information, account metadata, and legal-acceptance time when express consent is enabled.
Early-access requests. Email address, whether your financial accounts are in Canada, the United States, or both, a bounded campaign attribution source when present, and the privacy-notice version shown when you submit the request.
Public beta enrollment. Self-declared country and province or state, adult attestation, accepted policy versions, and consent time.
Bank and transaction information. Institution, account name and type, masked identifiers, balances, pending status, transactions, merchant descriptions, categories, and connection health from Plaid.
Brokerage information. Institution, account metadata, balances, holdings, cost basis, cash, dividends, interest, fees, and reported activity from SnapTrade or Plaid Investments when enabled. Brokerage credentials and multi-factor authentication codes are entered only in provider-controlled connection flows and are not received by North Memory.
Your additions. Notes, merchant names, categories, labels, splits, recurring items, account purposes, preferences, profile context, priorities, and feedback.
AI interactions. Prompts, recent conversation context, and minimized financial summaries sent for the request. North Memory does not currently persist AI prompts or responses in Neon, though they remain visible in the active browser session and providers may retain them under their policies.
Billing. Stripe customer and subscription identifiers, plan, billing interval, status, consent record, and limited payment metadata. Full card numbers are handled by Stripe and are not stored by North Memory.
Technical information. Device, browser, IP address, security events, request and error logs, PWA state, and browser-local display preferences.
Optional public-site measurement. After you allow measurement, Google may receive public page paths and titles, referrers, campaign parameters, browser and device information, and a generic successful waitlist conversion event. North Memory does not send Google the waitlist form fields, connected financial data, account identifiers, authenticated financial-page activity, or AI prompts.
Communications. Support requests, privacy requests, and related correspondence.
3. Sources and purposes
Information comes from you, Clerk, Plaid, connected financial institutions, SnapTrade, Stripe, your browser, North Memory's deterministic calculations, and Google only when you allow optional public-site measurement.
Authenticate users, secure accounts, and prevent abuse.
Manage early-access requests, enforce beta eligibility and capacity, and send the invitation and service updates you requested.
Import, synchronize, normalize, categorize, and display financial information.
Apply owner-approved category rules, account purposes, notes, and transaction details.
Generate AI explanations at your request using the selected financial scope.
Process subscriptions, provide support, resolve disputes, and comply with law.
Measure which public pages and campaigns lead to successful waitlist requests when you allow optional measurement.
Improve reliability using aggregated or appropriately deidentified information that is not used to identify you.
4. AI processing and automated indicators
North Memory sends selected totals, category summaries, limited merchant patterns, bounded transactions, and relevant portfolio aggregates to Anthropic or an OpenRouter-routed provider only when an AI feature is invoked.
North Memory excludes bank credentials, access tokens, full account numbers, and complete raw histories from the AI context.
AI and anomaly outputs can be inaccurate, incomplete, delayed, or misclassified. They are informational and are not financial, investment, tax, accounting, credit, or legal advice.
Anthropic and OpenRouter providers may retain request data according to their commercial terms and routing configuration. Do not include unnecessary sensitive information in a prompt.
5. Service providers and disclosure
North Memory discloses information only as needed to operate the requested service, protect users, complete billing, comply with law, or complete a business transaction subject to appropriate safeguards.
Information may be processed in Canada, the United States, and other locations where these providers operate. North Memory remains responsible for selecting and overseeing service providers as required by applicable law.
6. Sale, advertising, and marketing
North Memory does not sell personal information and does not share connected financial information for cross-context behavioral advertising.
With your optional consent, North Memory uses Google Analytics and, when configured, Google Ads conversion measurement only on public marketing pages. Consent defaults to denied, the Google tag does not load until you allow measurement, and ad personalization remains disabled.
Google measurement is excluded from authenticated financial pages. North Memory does not enable enhanced conversions, send form contents to Google, or use connected financial data for remarketing or audience creation.
Submitting the early-access form requests emails about waitlist status, eligibility, invitations, and essential early-access updates. Broader promotional marketing remains separate and optional.
Marketing email or SMS consent, if introduced, will be separate and optional. Transactional security, billing, and service messages are not marketing.
7. Security and incidents
Financial provider tokens are encrypted on the server and are not sent to the browser.
Transport encryption, owner-scoped queries, least-privilege service credentials, administrative access controls, and vendor safeguards are used to reduce risk.
No system is completely secure. North Memory maintains incident-response procedures and will notify regulators and affected people when required by applicable law.
8. Retention, disconnection, and deletion
Financial access tokens. Kept until the institution is disconnected or the North Memory account is deleted, then revoked and deleted from active systems.
Synced records and user additions. Kept while the account is active and targeted for deletion from active systems within 30 days after a verified full-account deletion request.
AI prompts and responses. Not currently stored in Neon. Provider-side copies follow the disclosed provider configuration and policy.
Security logs. Normally kept for up to 24 months unless an investigation or law requires longer.
Billing, consent, tax, and dispute records. Kept for up to seven years or the period required by law and professional advice.
Early-access requests. Kept while the early-access program is active and for up to 24 months after the last related interaction, unless you request deletion sooner or law requires longer.
Public-site measurement. Your choice is kept in browser storage until you change it or clear site data. Google measurement cookies and event data follow the configured Google account retention controls. Withdrawing consent stops future measurement and removes recognized Google measurement cookies from the current browser where possible.
Public beta enrollment. Kept while the account is active and deleted from active systems through the verified account-deletion workflow.
Backups. Expire through the hosting provider's rolling recovery cycle, normally within 90 days.
Canceling Pro stops future renewal but does not delete the account. Disconnecting an institution stops future access but does not automatically delete every mirrored record. Full account deletion is a separate verified request.
9. Your choices and privacy rights
Access, correct, export, or request deletion of personal information.
Withdraw consent where the processing depends on consent, subject to legal and service limitations.
Allow, decline, or later withdraw optional Google measurement through the Privacy choices control on any public marketing page.
Disconnect a financial institution and revoke future provider access.
Request information about service providers and cross-border processing.
Appeal a denied request where applicable and complain to the relevant privacy regulator.
Receive equal service without discriminatory treatment for exercising a privacy right.
North Memory may verify identity before completing a request. A Canadian access request is normally answered within 30 days unless a lawful extension applies.
10. Children and policy changes
North Memory is not directed to anyone under 18. If North Memory learns that an underage person created an account, the account and associated information will be deleted.
Material policy changes will be posted with a new effective date. Fresh consent will be requested before introducing a materially different use when required by law.
Contact the privacy officer
Send privacy questions, access or correction requests, consent withdrawals, complaints, and deletion requests to the privacy contact below. North Memory may verify your identity before acting on a request.
North Memory Privacy Contactyourthought2020@gmail.com1190 Pacific Street, Coquitlam, British Columbia V3B 6Z2, Canada
Email is not a secure channel. Do not include financial-account credentials, multi-factor authentication codes, provider tokens, full account or card numbers, or government identification numbers.
For general support and security reports, use the Contact page.
Institution, security, and issuer marks may be supplied by connected data providers or Logo.dev. All third-party marks remain the property of their respective owners.