Trust · privacy
Privacy policy
Last updated: 2026-05-31. Effective for wealth.cosmos369.ai. Plain English. No surprises.
What Wealth is
Wealth is a personal-finance product run by Cosmos369 (a GalaxyZen AI initiative). Three AI specialists — Analyst, Planner, Guardian — help you see your picture, build your path, and protect your daily habit. We do not sell financial products or take commissions from third parties; we are paid only by our subscribers.
What we collect
- Account identity — name, email, account ID (managed by Clerk).
- Financial inputs you provide — accounts, balances, goals, transactions you upload or link. Stored in our database, encrypted at rest. Used only to power the Analyst / Planner / Guardian.
- Chat with the Coach — your questions and the Coach's responses. Retained 90 days then summarised, then raw chat deleted.
- Server logs — request method + path + status code + IP (rounded). 30-day retention.
What we never collect
- Bank credentials. We don't ask. We don't store them.
- Location data beyond country.
- Microphone, camera, or device sensors.
- Ad-tracking identifiers or third-party trackers. There are none.
- Card numbers — Stripe handles payments; we never see them.
GDPR + CCPA — your rights
You have the right to:
- Access — download every record we hold about your account as JSON. Email privacy@cosmos369.ai with subject "Wealth data export request" — we reply within 30 days.
- Rectification — correct anything wrong via Settings or by emailing us.
- Erasure — delete your account and all associated data. Email privacy@cosmos369.ai. Deletion within 30 days. Financial records required for tax compliance are retained per local law (typically 7 years).
- Portability — same channel as Access.
- Opt-out of "sale" — we do not sell your data, but if California law treats any sharing with sub-processors as a "sale", you may opt out by emailing us. (Spoiler: we still won't sell it.)
Who we share data with
- Clerk (authentication) · clerk.com/privacy
- Stripe (payments) · stripe.com/privacy
- Supabase (database) · supabase.com/privacy
- Vercel (hosting) · vercel.com/legal/privacy-policy
- Cloudflare (CDN/DNS/bot mitigation) · cloudflare.com/privacypolicy
We do not sell or rent your data. Ever. Coach reasoning runs on infrastructure we control; your financial data is not shared with third-party AI providers for training.
How long we keep it
- Active accounts: as long as the account is active.
- Cancelled accounts: 30 days, then deleted.
- Coach chat raw logs: 90 days, then summarised; raw deleted.
- Server logs: 30 days.
- Audit logs: 1 year.
- Financial / tax records: 7 years (legal requirement).
Where we are
Cosmos369 / GalaxyZen AI operates from Toronto, Canada. Data is stored in Supabase regions in the United States by default. EU/UK residency available on request.
Contact
privacy@cosmos369.ai for anything privacy-related. hello@cosmos369.ai for everything else.
See also: Terms · Security · Back to Wealth