Privacy Policy
PRIVACY POLICY
Effective Date: September 1, 2026
1. Introduction
Welcome to ChartFI.
This Privacy Policy explains how Good Trajectory LLC ("Good Trajectory," "Company," "we," "our," or "us") collects, uses, stores, shares, and protects information when you use the Services. "ChartFI" refers to the Services, which include:
- the ChartFI website;
- the ChartFI web application;
- any future mobile applications;
- customer support services;
- AI-powered features; and
- any related services
(collectively, the "Services").
This Privacy Policy applies whenever you access or use the Services.
Capitalized terms used but not defined in this Privacy Policy have the meanings given to them in the Terms of Service.
Please read it carefully. If you do not agree with this Privacy Policy, you should not use the Services.
2. Scope of this Privacy Policy
This Privacy Policy describes:
- what information we collect;
- how we collect it;
- why we collect it;
- how we use it;
- when we disclose it;
- how we protect it;
- how long we retain it;
- your privacy choices; and
- your legal rights.
This Privacy Policy does not apply to third-party websites, services, or applications that are not operated by Good Trajectory LLC.
3. Information We Collect
We collect information in several different ways.
3.1 Information You Provide Directly
You may voluntarily provide information including:
Account Information
- name;
- email address;
- authentication credentials;
- account preferences.
Account authentication is handled through our authentication provider (currently Supabase). We do not store your account password in plain text.
Financial Planning Information
Depending on how you use ChartFI, you may voluntarily enter information such as income, salary, bonuses, retirement savings, investment balances, checking and savings balances, debt balances, mortgage information, expenses, tax filing assumptions, retirement goals, withdrawal assumptions, expected rates of return, inflation assumptions, Social Security assumptions, pension assumptions, retirement ages, financial notes, and planning scenarios.
This information is used solely to perform the calculations you request.
We do not require you to provide Social Security numbers, driver's license numbers, passport numbers, tax returns, bank login credentials, brokerage usernames or passwords, or financial account passwords.
We strongly discourage entering highly sensitive personal information that is not requested by the Services. We do not intentionally collect "sensitive personal information" as that term is defined under applicable state privacy laws.
3.2 Payment Information
Payments are processed by our payment processor (currently Stripe, Inc.).
We do not store complete payment card numbers on our own servers.
Depending upon your subscription, our payment processor may provide us with limited billing information such as subscription status, billing dates, payment confirmation, payment method type, and transaction identifiers.
3.3 Communications
If you contact us, we may collect emails, customer support requests, feature requests, survey responses, feedback, and bug reports.
3.4 AI Conversations
When you use AI features, the prompts you submit and the AI's responses are processed to generate the response you request.
We do not store your AI conversations on our systems. Prompts and responses are not saved to our database; your conversation history is held in your browser session and is not retained by us once you clear or leave it.
We do record limited, non-content usage metering for each AI request — such as the number of messages, token counts, and estimated cost — so we can apply usage limits and manage costs. This metering contains no prompt or response text.
We do not use AI conversations to provide individualized financial advice. We do not use your AI conversations or financial planning information to train artificial intelligence models. AI functionality is currently provided through the Anthropic API, and under Anthropic's commercial terms your inputs and outputs are not used to train Anthropic's models. (See Section 8 of our AI Use & Transparency Policy for more detail.)
4. Information Collected Automatically
When you access the Services, certain information may be collected automatically. This may include:
- IP address;
- browser type;
- operating system;
- device information;
- language preferences;
- pages visited;
- features used;
- referring URLs;
- approximate geographic region;
- dates and times of access;
- session identifiers;
- diagnostic information;
- marketing attribution information (such as the campaign, link, referral, or waitlist through which you reached or were invited to the Services); and
- information about how you signed up for the Services (for example, by invitation, referral, or waitlist).
We collect this information primarily to operate the Services, improve performance, detect fraud, troubleshoot technical issues, monitor reliability, and maintain security.
4.1 Cookies
ChartFI uses cookies and similar technologies.
Cookies help us authenticate users, maintain login sessions, and improve security. We do not use cookies for advertising, analytics, or cross-site tracking.
Most browsers allow you to control cookies through browser settings. Disabling cookies may affect certain functionality of the Services. See Section 14 regarding browser-based opt-out preference signals.
4.2 Analytics
We use first-party analytics — collected and processed within our own application infrastructure — to understand feature usage, application performance, error rates, and user engagement. We do not use third-party advertising analytics or cross-site tracking technologies.
Analytics information is used to operate and improve the Services and to understand how users discover and adopt them. If we adopt a third-party analytics provider in the future, we will add it to our subprocessor list and update this Privacy Policy.
5. How We Use Information
We use information for legitimate business purposes, including to:
- provide the Services;
- create and manage accounts;
- authenticate users;
- process subscriptions;
- perform financial calculations;
- generate reports and charts;
- operate AI features;
- provide customer support;
- improve software functionality;
- fix defects;
- analyze usage trends to prioritize product improvements;
- understand how users discover the Services and measure the effectiveness of our communications and marketing;
- maintain security;
- detect fraud;
- enforce our Terms of Service;
- communicate with users;
- comply with legal obligations; and
- protect the rights of the Company and our users.
We process only the information reasonably necessary to perform these purposes.
6. Legal Bases for Processing
Depending upon applicable law, we process personal information based upon one or more of the following legal grounds:
- performance of a contract;
- compliance with legal obligations;
- our legitimate business interests;
- your consent where required by law; and
- protection of legal rights.
We limit processing to purposes reasonably related to providing and improving the Services.
7. When We Share Information
We do not sell your personal information.
We do not sell your financial planning information.
We do not sell your AI conversations.
We share information only in the limited circumstances described below.
Service Providers
We may disclose information to service providers that assist in operating the Services, such as providers of cloud hosting, authentication, databases, payment processing, email delivery, AI services, and monitoring. A current list of the key service providers (subprocessors) we use is available upon request and, where we publish one, on our website.
These providers receive only the information reasonably necessary to perform services on our behalf, and they are contractually required to protect information in accordance with applicable law. We host and process personal information in the United States.
7.1 Legal Requirements
We may disclose information if we believe in good faith that doing so is necessary to:
- comply with applicable law;
- comply with a subpoena, court order, or other legal process;
- respond to lawful requests from governmental authorities;
- enforce our Terms of Service;
- investigate fraud or security incidents; or
- protect the rights, property, or safety of Good Trajectory LLC, our users, or others.
We will disclose only the information reasonably necessary to satisfy the applicable legal obligation.
7.2 Business Transactions
If Good Trajectory LLC is involved in a merger, acquisition, financing transaction, asset sale, corporate restructuring, bankruptcy, dissolution, or similar business transaction, your information may be transferred as part of that transaction, subject to applicable law.
Any successor entity will remain bound by applicable privacy obligations unless you are notified otherwise.
8. Data Retention
We retain information only for as long as reasonably necessary to:
- provide the Services;
- maintain your account;
- comply with legal obligations;
- resolve disputes;
- enforce our agreements;
- detect and prevent fraud;
- maintain security; and
- satisfy legitimate business purposes.
Retention periods vary depending on the type of information involved. Examples include:
| Information | Typical Retention |
|---|---|
| Account information | While the account is active and for a limited period thereafter |
| Financial planning data | Until deleted by you or your account is deleted, subject to backups and legal obligations |
| AI conversations | Not stored on our systems. Your prompts and the AI's responses are processed to generate the response you asked for and are not saved to our database; conversation history lives in your browser session and is gone when you clear or leave it. Our AI provider processes them under its own terms (see our AI Use & Transparency Policy) |
| Billing records | As required by tax, accounting, and legal requirements (generally up to 7 years) |
| Support communications | As reasonably necessary for support and legal purposes (generally up to 2 years after the matter is resolved) |
| Usage and product-event data | Retained at event level for up to 12 months to analyze trends and improve the Services, then deleted automatically; anonymized aggregates may be kept longer |
| Marketing and attribution data | While relevant to our relationship with you, or until you unsubscribe or object |
| Security and access logs | For security, fraud prevention, and operational purposes, generally up to 90 days. Some logs are held by our infrastructure providers under their own retention schedules (see our Subprocessor List) |
| Change/audit records | We keep an append-only record of changes made to saved plans (for example, that a scenario was created, updated, or deleted, and when). These records identify the account by an internal identifier and contain no financial figures. We keep them as an integrity and security record while your account is open, and for up to 730 days after an account is deleted, after which they are deleted automatically. We keep them for longer only where reasonably necessary for a legal claim or legal hold, a fraud or abuse investigation, a security incident, or another legally recognized retention obligation |
| Consent records | We keep a record of your acceptance of our Terms of Service and policies — the document, the version accepted, the method of acceptance, and a timestamp. These records are retained after account deletion as evidence of the agreement that was in force |
| Email opt-out / suppression records | Retained on an ongoing basis so we can continue to honor your opt-out |
| Backup copies | We keep encrypted backup copies of our database on a tiered schedule: weekly copies for up to 180 days, and one copy per month for up to 365 days. Information you delete may remain in a backup copy until that copy expires |
To honor an unsubscribe or opt-out request, we retain a limited suppression record (such as a hashed identifier). This means that even after we delete other information at your request, we keep the minimum information necessary to avoid contacting you again.
Deletion requests may not immediately remove information from backup systems or archived disaster recovery copies.
Backup copies are not edited in place. Each copy expires automatically on the schedule described above, so information you delete may persist in a backup copy for up to 12 months before it ages out. We do not use backups to restore information you have asked us to delete.
9. Data Security
Protecting your information is important to us.
We implement commercially reasonable administrative, technical, and organizational safeguards designed to protect information from unauthorized access, disclosure, alteration, and destruction. These safeguards may include:
- encrypted communications using TLS;
- encrypted storage where appropriate;
- authenticated user access;
- role-based administrative access;
- monitoring and logging;
- routine software updates and security patches;
- infrastructure monitoring; and
- access controls.
No method of transmitting information over the Internet or storing electronic information is completely secure. Accordingly, we cannot guarantee absolute security.
In the event of a data security incident affecting your personal information, we will notify you and applicable authorities where required by, and in accordance with, applicable law.
You are responsible for maintaining the confidentiality of your account credentials.
10. Your Choices
Depending on how you use the Services, you may be able to:
- update your profile information;
- modify financial planning information;
- change account settings;
- manage subscription preferences;
- cancel your subscription;
- delete planning scenarios; and
- close your account.
You are responsible for ensuring that information you provide remains accurate and current.
10.1 Marketing Communications
If we send marketing emails, you may unsubscribe at any time using the unsubscribe instructions included in those communications.
We use first-party attribution information (such as how you found or were invited to the Services) to understand how users discover ChartFI and to measure our communications. If you unsubscribe or ask us not to send you marketing messages, we honor that choice; to make sure we continue to honor it, we keep a limited suppression record even if you later delete other information.
You may continue to receive transactional or legally required communications, including billing notices, account security notifications, service announcements, legal notices, and updates regarding your account.
10.2 Cookies and Opt-Out Preference Signals
Most web browsers allow you to delete cookies, block cookies, or receive notifications before cookies are stored.
Disabling cookies may reduce the functionality of certain portions of the Services.
For information about how we respond to browser-based opt-out preference signals such as the Global Privacy Control (GPC), see Section 14.
11. Your Privacy Rights
Depending on your jurisdiction and applicable law, you may have certain rights regarding your personal information. These rights may include the ability to:
- know what personal information we collect;
- access personal information;
- correct inaccurate information;
- request deletion of personal information;
- obtain a copy of certain personal information;
- object to certain processing;
- withdraw consent where processing is based on consent; and
- appeal certain privacy decisions where required by law.
These rights are subject to applicable legal exceptions.
Rights we provide to everyone. Regardless of where you live, and whether or not a privacy law requires it, we voluntarily provide every user with the ability to access the personal information we hold about them, correct it, request its deletion, and obtain a copy of it. The other rights described above, and any additional rights conferred by a particular state's law, apply where that law applies.
To exercise available rights, please contact us using the information provided at the end of this Privacy Policy. You may also use an authorized agent to submit a request on your behalf where permitted by applicable law.
We may request reasonable information necessary to verify your identity before responding to a request. We will respond within the timeframe required by applicable law (generally within 45 days, subject to any extension the law permits).
12. U.S. State Privacy Rights
Residents of certain U.S. states may have additional privacy rights under applicable state privacy laws.
Where required by law, we will honor qualifying requests regarding access, correction, deletion, portability, and appeals.
The availability of these rights depends upon applicable law and your state of residence. Nothing in this Privacy Policy limits any rights that cannot legally be waived.
12.1 California Privacy Notice
If the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"), applies to your personal information, California residents may have additional rights, including the right to:
- know the categories of personal information collected;
- know the categories of sources;
- know the categories of disclosures;
- request access, correction, and deletion; and
- request information portability.
We do not sell personal information.
We do not knowingly share personal information for cross-context behavioral advertising as those terms are defined under California law.
If our data practices change in the future, we will update this Privacy Policy accordingly.
12.2 Other U.S. State Privacy Laws
A growing number of U.S. states (currently around twenty and increasing) have enacted comprehensive consumer privacy laws. Residents of states with applicable consumer privacy laws may exercise the rights available under those laws to the extent they apply, and we will process qualifying requests in accordance with applicable legal requirements.
Several of these laws require opt-in consent before processing "sensitive" personal information. As noted in Section 3, we do not intentionally collect sensitive personal information.
13. Children's Privacy
The Services are intended only for individuals who are at least eighteen (18) years of age.
We do not knowingly collect personal information from children under the age of 18.
If we become aware that a person under eighteen has created an account, we may suspend or terminate the account and delete associated information, subject to applicable law.
If you believe that a minor has provided information to us, please contact us promptly.
14. Do Not Track and Opt-Out Preference Signals
Some web browsers transmit "Do Not Track" ("DNT") signals. Because there is currently no universally accepted standard governing how websites should respond to DNT signals, ChartFI does not respond differently based solely upon receipt of a DNT signal.
Separately, some browsers and extensions transmit opt-out preference signals such as the Global Privacy Control ("GPC"). These signals are intended to communicate a consumer's choice to opt out of the "sale" or "sharing" of personal information as those terms are defined under applicable state privacy laws.
Because we do not sell personal information and do not share personal information for cross-context behavioral advertising, there is no such sale or sharing for these signals to opt out of. Where applicable law requires us to recognize a valid opt-out preference signal, we will treat it as a request to opt out to the extent required and, where required, provide confirmation that the request has been honored.
If an industry or legal standard develops further in the future, we may revise this practice.
15. United States Only
The Services are offered only to individuals located in the United States and are not directed to individuals in other countries. We host and process personal information in the United States.
If you choose to access the Services from outside the United States, you do so on your own initiative, and you understand that your information will be processed and stored in the United States.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, changes in applicable law, new features, new service providers, changes to our business operations, or improvements in privacy practices.
If we make material changes, we will provide notice by one or more reasonable methods, including updating the Effective Date, posting the revised Privacy Policy within the Services, and sending an email where required by law.
Your continued use of the Services after the updated Privacy Policy becomes effective constitutes acknowledgment of the revised Privacy Policy.
17. Contact Us
If you have questions regarding this Privacy Policy or our privacy practices, you may contact us at:
Good Trajectory LLC
Mailing Address: 533 E Girard Ave STE 76861, Philadelphia, PA 19125
Phone: 445-294-3517
Email: privacy@chartfi.com
Website: https://chartfi.com
If we designate an updated privacy contact or mailing address in the future, that information will replace the contact information above upon publication.
18. Policy Integration
This Privacy Policy forms part of the legal framework governing your use of the Services.
Your use of ChartFI is also governed by our:
- Terms of Service;
- AI Use & Transparency Policy;
- Financial Disclaimer; and
- other policies expressly incorporated by reference.
To the extent of any conflict between this Privacy Policy and the Terms of Service regarding contractual obligations, the Terms of Service shall govern unless otherwise required by applicable law.