Introduction
Truthifi, Inc. and/or its affiliates ("Truthifi," "we," "us," or "our") offers an investment-monitoring service through its website, Truthifi.com (the "Site"), and may offer additional products and services in the future (collectively, the "Services"). This Privacy Policy explains how Truthifi collects, uses, and protects your personal information when you use or evaluate our Services.
Important: Truthifi provides data-driven insights only. We are not an advisory service and do not provide investment, financial, or legal advice.
Information we collect
We may collect personal information that can identify you (such as your name, email address, and contact details) and other information that does not identify you directly. We collect and store personal information that you voluntarily provide, including: contact details; financial information related to your holdings, investments, and transactions when you use our Services; demographic information (such as age range or investment experience) where voluntarily provided; and communications you send to us. We may also automatically collect technical data such as IP address, browser type, device identifiers, and activity on our Site.
Connecting to your financial accounts
To deliver our Services, you may choose to connect your financial and investment accounts so we can retrieve factual information about your holdings and transactions. We use industry-leading, secure data-aggregation partners — including Morningstar (By All Accounts), Plaid, and Envestnet (Yodlee) — to connect to your accounts. When you connect a financial account, you directly authorize the relevant aggregator to share your account data with Truthifi. Truthifi receives that data; it does not send your personal data back to the aggregators.
Your passwords never reach our servers. Truthifi does not see, store, or have access to your financial institution usernames or passwords.
Tokenized, read-only access. Our aggregation partners use tokenized connections that let Truthifi retrieve your account information without storing or transmitting your credentials.
We can't move your money. Truthifi's access is strictly read-only.
We never sell your data. We do not rent, sell, or trade your personal information to anyone — ever.
We don't store payment-card numbers. If you subscribe, Stripe processes your payment securely; Truthifi does not store your card details.
Some account-connection screens (such as Plaid Link) are served directly by our partners. Any credentials you enter there are provided directly to that partner, not to Truthifi. Information retrieved through these connections is transmitted using bank-level encryption and securely stored on our systems and by our partners, subject to their respective privacy policies.
Your use of data obtained through a Data Aggregator or financial institution is also subject to that party’s requirements for end users, which may limit how that data — and insights derived from it — can be used, shared, retained, or provided to AI Features.
AI models & integrations
Truthifi offers optional connectivity to AI language models — both a Truthifi-provided AI experience and, via the Model Context Protocol (MCP), a connection to an AI assistant of your choice. This section describes how your data is handled when you use these features.
What happens when you connect via MCP (your own AI tool):
You authenticate to Truthifi through an OAuth flow.
When you run a prompt, Truthifi's MCP server retrieves the relevant financial data (such as holdings, performance, fees, transactions, or findings) from our systems and passes it to the AI model for that session only.
By default, AI features receive Truthifi-computed, derived information (scores, findings, allocations, summaries) rather than raw account records. Raw records are made available only where you have separately enabled that access.
Truthifi's MCP server does not store or log the contents of AI tool responses or conversation context.
Access to your financial data via MCP is fully logged by Truthifi — you have a complete, timestamped record of what data was requested and when.
Truthifi does not instruct AI models to retain your portfolio data between sessions. For how each AI provider handles session data, refer to their respective privacy policies.
You can disconnect any AI integration at any time from within the AI provider's connector or settings panel.
You can request deletion of your Truthifi data at any time by contacting support@truthifi.com, which will also terminate any active MCP access and revoke outstanding access tokens.
Truthifi-provided AI. Where Truthifi provides its own AI feature (rather than a Third-Party AI Tool you connect), any Model Provider we use to generate responses acts as our service provider, under confidentiality and data-minimization obligations. Where such terms are available, we require these Model Providers not to retain your data beyond the session and not to use it to train their models. The Model Providers we currently use for Truthifi-provided AI are identified in the Subprocessors list below.
Data-source restrictions. AI access to data obtained through a given data aggregator or financial institution may be limited or disabled — including by switching off a specific AI provider’s access to the MCP Server — to honor that aggregator's or institution's requirements, or at your request. Certain data — including any proprietary or licensed data provided through Morningstar | By All Accounts — may be excluded from AI Features.
What Truthifi is not responsible for. Truthifi does not control the AI language models, APIs, or infrastructure of third-party AI providers. Once data is passed to a Third-Party AI Tool during a session, it is subject to that provider's privacy policy and terms. We encourage you to review the privacy policies of any AI provider you connect before enabling the integration.
Supported AI providers. Truthifi's MCP integration is compatible with any AI provider that supports the Model Context Protocol standard. Currently supported providers include Claude by Anthropic; additional providers may be supported over time and will be handled under the same principles described above. See the Subprocessors list below for the current AI providers we use.
Access is limited to approved agents. Your data is made available to AI Features only through Model Providers Truthifi has approved and engaged as service providers, and through Third-Party AI Tools Truthifi has reviewed and approved and that you authorize via OAuth. Only approved clients may connect to the MCP Server. We may add, refuse, or remove any client or provider at any time, and you can review and revoke authorized clients from your account settings.
Cookies and technologies
We use cookies and similar technologies to remember user preferences, improve performance, and analyze trends. We may use third-party analytics providers who may set their own cookies and are subject to their own privacy policies. We may collect log-file data including IP address, browser type, and referring pages. You can control cookies in your browser settings.
How we use the information we collect
We use your information to deliver the Services you request; provide customer support; analyze usage patterns to improve our offerings; and enforce our Terms and protect Truthifi and our users. We also process your information — including relevant financial account and portfolio data — through AI Model Providers that act as our service providers to generate the insights, answers, and content you request (see "AI models & integrations" and the Subprocessors list below). We may aggregate and anonymize user data for research or benchmarking, and take appropriate technical measures to minimize re-identification risk.
How we protect your personal information
We use bank- and military-grade security measures to protect your data. Transport Layer Security (TLS) encrypts information in transit; 256-bit AES encryption protects stored data; and access to personal data is restricted to authorized employees with a legitimate business need. No system is 100% secure, but we continuously monitor and improve our safeguards.
When we share information
We share personal information only as described in this Policy: with authorized service providers (such as those in the Subprocessors list below) who perform services on our behalf; to comply with law, subpoenas, or valid legal processes; to investigate or prevent fraud; and with your consent. If Truthifi undergoes a merger, acquisition, or sale, you'll be notified via email and/or prominent notice on our Site.
Third parties
Financial account data sources. When you connect your financial accounts, you directly authorize one or more independent data aggregators to share your account data with Truthifi. These aggregators are independent companies — not vendors engaged by Truthifi. Truthifi receives data from them; it does not send your personal data back. Each operates under its own privacy policy:
Data source Role Privacy policy Morningstar | By All Accounts Financial account data aggregation (user-authorized) morningstar.com/company/privacy-center/privacy-policy Plaid Inc. Financial account data aggregation (user-authorized) plaid.com/legal/privacy-statement/ Envestnet | Yodlee Financial account data aggregation (user-authorized) yodlee.com/legal/privacy-policy
Payment processing. If you subscribe, payment is processed by Stripe, Inc. Truthifi sends Stripe only what is necessary and does not store your card details. Stripe's privacy policy: stripe.com/privacy.
AI providers. When you use the MCP integration, the AI model provider you connect to also becomes a relevant third party. Please review their privacy policy before enabling the integration.
Subprocessors. In addition to the independent data aggregators above, we use a small number of trusted service providers ("subprocessors") that process personal data on our behalf or at your direction to operate, secure, and improve the Services. We update this list as our subprocessors change.
Subprocessor Purpose Data involved Amazon Web Services (AWS) Application hosting, storage, and infrastructure All Service data, encrypted MongoDB Atlas Managed database Application and account data, encrypted Stripe, Inc. Payment processing Billing/payment data (no card details stored by Truthifi) Twilio SMS / text notifications Phone number and message content Product analytics & monitoring providers Usage analytics, error tracking, and performance/log monitoring to help us operate, secure, and improve the Services Usage and technical/diagnostic data (no financial account credentials) AI model providers (Anthropic, OpenAI, Cohere) Generate AI answers, analysis, and search-result ranking — only when you use AI features Data you make available to AI, at your direction
AI providers receive your data only when you enable AI features, and only the data you choose to make available. When Truthifi runs the AI itself, we use providers under terms that, where available, prohibit retaining your data or training on it. When you connect your own AI tool, your data is handled under that tool's terms.
Analytics and monitoring providers receive only usage and technical data (never your financial account credentials) to help us operate, secure, and improve the Services.
We never sell your data.
Data Processing Agreement (DPA). Business and enterprise customers requiring a DPA for procurement, compliance, or regulatory purposes can request one at support@truthifi.com.
Your privacy rights
Depending on your location, you may have rights regarding your personal data, including the rights to access, correct, delete, and port your information, and to opt out of certain processing. To exercise a right or ask about your rights under applicable law (including the EU/UK GDPR and the California Consumer Privacy Act (CCPA)), contact support@truthifi.com.
Response time. We will verify your request and respond within the time required by applicable law — for example, within 45 days under the CCPA, with an extension of up to an additional 45 days where permitted and with notice to you.
No fee; verification. We do not charge a fee to process or respond to a verifiable request unless it is excessive, repetitive, or manifestly unfounded. To protect your data, we may need to verify your identity before acting on a request.
Non-discrimination. We will not discriminate or retaliate against you for exercising your privacy rights.
Appeals. If we decline your request, you may appeal by replying to our response or contacting support@truthifi.com; we will inform you of the outcome as required by applicable law.
We do not sell your personal information and do not "share" it for cross-context behavioral advertising as those terms are defined under applicable law.
Authorized agents. Where permitted by law, you may use an authorized agent to submit a request on your behalf; we may require verification of the agent's authority.
Professional Users and data submitted on behalf of others
If you use the Services as a Professional User (for example, a financial advisor or advisory firm) and submit, access, or analyze data relating to your clients or other individuals, you act as the controller of that data. You are responsible for the authority, lawful basis, and disclosures necessary to provide that data to Truthifi and to any AI Features or Third-Party AI Tools you use — including your own privacy notice and any required client consent. Truthifi acts as your service provider/processor for that client data under our Terms and any Data Processing Agreement or Enterprise Agreement. You are responsible for responding to your clients’ privacy requests; we will provide reasonable assistance as required. Your use of client data also remains subject to the applicable Data Aggregators’ and financial institutions’ requirements.
Third party websites
Our Site may link to other websites not operated by Truthifi. We are not responsible for their privacy practices. Review their policies before providing any personal information.
Subscription cancellation and data deletion
You may cancel your subscription online at any time. If you cancel, your access is discontinued, though your account and data remain securely stored unless you request deletion. To have your personal data removed, submit a deletion request to support@truthifi.com. Once verified, we will promptly delete your financial and transaction data. Deletion of your account also terminates all active MCP integrations and revokes any outstanding access tokens. We may retain limited information (such as your email address, account status, or past communications) for legal, fraud-prevention, or recordkeeping purposes as permitted by law.
Retention of information
We retain personal data until you request its deletion or as long as necessary to provide and maintain the Services, comply with legal obligations, prevent fraud, and enforce our Terms. After a verified deletion request, we permanently remove the associated financial and transaction data from our systems and from our aggregation partners.
Choices about communication
You may unsubscribe from marketing emails using the link in each message or by contacting support@truthifi.com.
Children's privacy
Truthifi's Services are not intended for individuals under 18 years of age, and we do not knowingly collect information from children. If such data is discovered, we will delete it promptly.
International users
If you access our Site from outside the United States, your data may be transferred to and processed in the U.S. or other countries. We take reasonable steps to protect your information consistent with applicable law.
Changes to this privacy policy
We may update this Policy periodically. The latest version will always be available at Truthifi.com/privacy with an updated "Effective" and "Last updated" date, and posting the updated Policy is how we provide notice of changes. We determine, in our reasonable discretion, whether a change is material. If we make a change we consider material, we will provide additional notice before it takes effect by a reasonably appropriate method, such as email or a prominent Site notice.
Contact us
If you have questions about this Privacy Policy or our data practices, contact us at support@truthifi.com, or by mail at:
Truthifi, Inc. 174 Nassau St. #417 Princeton, NJ 08542
Self-serve finalization prepared 2026-06-30; v1.2.0 (2026-07-08) embeds the named subprocessor list directly into "Third parties," matching how comparable consumer-finance apps disclose subprocessors. The standalone FIX-06 page remains available if you prefer a separate /subprocessors URL. Not legal advice.