BOREXIA does not sell, rent, or trade your personal financial intelligence. Read our comprehensive Privacy Policy below to understand exactly how we collect, sanitize, and obliterate your state memory.
The foundation of our privacy policy is rooted in our architecture. By refusing to implement Open Banking APIs (such as Plaid or Yodlee), we physically prevent ourselves from accessing data you do not explicitly wish to share.
We only collect the cryptographic hash of your email address for authentication, and the exact ledger strings you manually input into the dashboard.
To provide actionable intelligence, BOREXIA must process your manual ledger entries through Large Language Models (LLMs). We employ a strict data sanitization pipeline to ensure absolutely no Personally Identifiable Information (PII) is included in the inference prompts.
We do not sell your data to marketers, ad networks, or data brokers. However, to run an enterprise-grade web application, we must utilize world-class infrastructure partners. We have strict Data Processing Agreements (DPAs) with the following sub-processors.
Used exclusively for AES-256 encrypted database storage (Firestore) and secure cryptographic authentication routing. Data is stored in US-Central region.
Used exclusively for stateless inference. Prompts are transmitted via TLS 1.3, processed in memory, and immediately discarded. Zero training retention.
In strict adherence to GDPR and CCPA, BOREXIA provides programmatic, instantaneous tools for data export and permanent deletion.
You have the right to request a complete, machine-readable copy of your entire state memory. This includes all ledger entries, categorical tags, and AI-generated insights.
This triggers an immediate cascading delete across our Firestore clusters. It permanently obliterates your user collection, all sub-collections, and invalidates your authentication token. There are no "soft deletes."
BOREXIA does not utilize third-party advertising pixels (such as Meta Pixel, TikTok Pixel, or Google Ads tags). We utilize strict, first-party functional cookies exclusively for maintaining your secure cryptographic session (JWTs) and preventing Cross-Site Request Forgery (CSRF) attacks.
Our Data Protection Officer is available to discuss our architecture, audit reports, or individual data requests.