Early-Access Privacy Notice
Version: privacy-early-access-2026-08-13
This notice explains what the current Continuum build can collect and why during the invitation-only early-access phase. Material changes to retention, deletion, export, account closure, processors, incident contacts, or supported jurisdictions require a new reviewed version.
Data the current build can handle
- Account profile, authentication, session, passkey, and security-event data.
- Connected financial-account identifiers, balances, transactions, liabilities, and read-only holdings snapshots.
- Manual accounts and imported transaction files or content a person chooses to provide.
- Budgets, goals, rules, alerts, assistant conversations, suggestions, and other in-app records.
- Operational logs, API usage, billing records, and support context when those features are used.
Receipt upload and extraction are currently frozen pending separate security and lifecycle controls.
Current purposes
The application uses data to authenticate users, display requested financial views, calculate planning summaries, evaluate local rules, provide support and security controls, and operate features a person explicitly invokes. Continuum does not currently submit bank transfers or trades.
Processors and integrations
Availability depends on deployment configuration and user choice. This table describes the current code paths; it is not a claim that every integration is live.
| Provider | When | Purpose |
|---|---|---|
| Plaid | Used when a person chooses to connect a supported account | Provides the account, balance, transaction, liability, or holdings data requested for that connection. |
| Anthropic | Used by the current AI categorization path when configured | Receives a bounded transaction batch containing description, counterparty, amount, type, and date to suggest categories. |
| Perplexity | Used by configured advisor, assistant, research, review, rule-parsing, and natural-language-search paths | Processes the user's question or instruction and the bounded financial summary, retrieved records, aggregate review statistics, account/category context, or conversation context assembled for that request. |
| Resend | Used when transactional email is configured | Delivers account messages such as email verification and password-reset links. |
| Stripe | Present in the billing implementation; live billing is not approved | Would process checkout, subscription, portal, invoice, and payment-event data if live billing is separately approved. |
AI processing and current limits
The Anthropic categorization path can send up to 50 transactions at a time with description, counterparty, amount, type, and date. Depending on the feature requested, Perplexity can receive an assistant or research question, conversation context, an aggregated advisor snapshot, up to five retrieved natural-language-search records in a bounded prompt, aggregate review statistics, or the account names, identifiers, types, and categories needed to parse a proposed rule. Generated output may be incomplete or wrong and should be checked against the underlying data.
The current build provides a per-user external-AI control that defaults off unless the stored value is explicitly true. Perplexity and Anthropic calls are skipped while it is off. This control does not set or promise processor retention periods, which remain subject to owner and legal review.
Retention, export, deletion, and closure
Owners and admins can request a household-wide JSON export; member and viewer roles cannot. The export excludes stored authentication secrets and raw provider credentials. Self-service closure is deliberately blocked while external banking connections, external billing identifiers, owned accounts, or receipt rows/files still need verified cleanup. There is no approved retention schedule, backup lifecycle, or vendor-deletion schedule. Those limits remain outside this phase approval.
Security and contact gap
Continuum includes authentication, household scoping, encryption for selected provider tokens, and audit/security controls, but no system can promise absolute security. A stable privacy contact and incident-contact process remain limited for this phase. During early access, use the same owner-controlled channel through which access was arranged.