Privacy Notice
Updated October 1, 2026 · Version 2026-10-01-v8
Questions about your account or these documents? Email contact@amicus.ai or use our contact form. Amicus’s published mailing address is Palo Alto Research Campus, 2100 Geng Rd, Ste. 210, Palo Alto, CA 94303.
Optional household statistics
Help us understand who the planning service serves. This account-wide choice is separate from browser cookies and is off by default.
Checking your account preference…
What we collect and why
Google sign-in supplies your verified email, name and an account identifier. When email sign-in is available, we use your email address to deliver a one-time code and authenticate your planning account. We store a keyed hash of the code, a browser-bound challenge, attempt counts and short-lived security limits; the raw code is not retained in the application database or analytics. We do not request access to Gmail, Drive, bank accounts or passwords. If you save a household, we store the household details, ages, residence, account balances and basis, income, spending, assumptions, scenarios, optional stock-award and option inputs, 401(k) plan provisions, home and inheritance assumptions, and previous saved versions you enter to provide your plan. Your consent and notice acknowledgment records document your choices. Please do not enter Social Security numbers, account numbers, passwords or tax documents.
Contacting a human
Our contact form collects the name, email, US state, topic and message you provide, plus your permission, a receipt and delivery status. It shows the recipient email addresses before submission. With your affirmative permission, we store and email the entered fields to those recipients; an introduction request names Wayne Tam. Your financial plan is not attached. Our transactional email provider and the receiving mailboxes process the message to deliver and handle your request. Email-service acceptance does not guarantee inbox arrival or a reply. Pending requests remain queued; failed or uncertain deliveries are held for review. Earlier requests submitted under a storage-only notice are not automatically forwarded. A request does not book a meeting, create a professional engagement or subscribe you to marketing. Do not include financial documents or account numbers. You can withdraw a pending request or request deletion through the privacy contact, quoting your receipt. Delivered messages cannot be recalled; applicable retention may continue.
Scenario sharing and invitations
Public scenario links use fictional examples and never read your saved household. A personal snapshot requires a separate preview and affirmative sharing permission. We store the named recipient email, exact calculation results, financial assumptions, rules, expiry and permission receipt you confirm. Account names, your other scenarios and your household identity are excluded. Only you and a user signed in with the selected verified email can view or download an active snapshot. You send the link; we do not automatically email invitations or enroll anyone in marketing. Links expire after 1, 7 or 30 days. You can revoke future access at /shared. Revocation removes the stored snapshot and recipient email immediately; expiry blocks access immediately and daily cleanup removes that content. Minimal permission evidence is removed 30 days after the original expiry, unless a lawful retention requirement applies. Encrypted backups expire under the backup retention policy. Downloaded images or PDFs can be kept or forwarded and cannot be recalled. These choices do not create an advisory engagement or authorize investment contact.
Public economic references
We retrieve public national CPI and Federal Reserve inflation projections from FRED to help you select assumptions. These requests contain only fixed public series identifiers and dates; no household inputs or identifiers are sent to FRED. Choosing an inflation path saves its dated reference and your adjustments with your plan. Later economic releases do not automatically change your saved assumptions.
Saved market simulations
Monte Carlo simulations are currently unavailable. If you previously requested a run, we retain its private planning input snapshot, selected assumptions, random seed, model versions, queue information and results. These records are not sent to external AI, market-data or advertising services. Existing records remain subject to the access, export and deletion request process described below; removing the feature does not delete your saved records.
Contacting the investment team
The separate investment-team contact form asks for your name, email, US state, message and a required acknowledgment that you meet the SEC definition of an accredited investor. With your affirmative permission, we store those fields, your self-attestation text, version and time, the recipient, a consent receipt and delivery status and email the request to investor@amicus.ai. We do not attach your plan, balances, return assumption or account profile. Our transactional email provider and the receiving mailbox process the message to deliver and handle your request. If delivery is unavailable, the request is held for later delivery; uncertain delivery is held for review. The acknowledgment is self-reported and unverified; we do not derive it from planning balances, and it does not replace any required verification. Contact is optional and does not add you to newsletters, authorize a professional referral, establish investor qualification or create an investment engagement. You may withdraw a pending request or request deletion through the privacy contact form, quoting your receipt. Already delivered messages cannot be recalled; applicable retention may continue. These requests follow the retention and access policies below.
Separate investment-information requests
An investment-information form is available only when its offering and marketing route has been recorded as approved. If you choose to submit that form, it identifies the receiving entity and requests separate permission to store your name, email, state and consent receipt for that contact purpose. It does not attach your planning balances, return assumptions, Google profile or financial documents, and an inquiry does not establish investor qualification. Requests enter a separate private review queue; we do not automatically email, forward or add them to a marketing list. You can withdraw a pending request or ask for deletion through the privacy contact form, quoting your receipt; the team handles verified requests manually. Previously downloaded records cannot necessarily be recalled. The retention and access policies below also apply to these requests.
Optional usage analytics
Usage analytics is off until you allow it in Cookie preferences. With permission, a random browser cookie lets us count public visits, selected feature clicks, named field interactions, new account registrations, completed intake steps, saved plans, comparisons, exports and contact submissions. Field interactions record the field name, never what you typed. Fixed source, campaign and creative labels from our campaign links attribute events to the last recognized campaign within 30 days; direct visits do not replace that campaign. We do not store arbitrary campaign text, search terms, full URLs, query strings, referrers or advertising click identifiers in these records. A registration event is recorded only when a new account is created, without copying its account ID, name or email into analytics. A hashed browser identifier, event labels and times remain pseudonymous, not anonymous. These records are not joined to saved households or supplied to ad platforms. Consented page views also record mobile/tablet, desktop or unknown; raw user agents, device models, IP addresses, screen dimensions, financial values, free text and session recordings are excluded. Updated purposes require a new choice before collection resumes; earlier permitted counts remain until withdrawal or expiry.
Optional advertising measurement
When configured, a separate opt-in enables Google Ads and Meta (Facebook and Instagram) tags on public marketing landings and a generic new-account completion page only. These providers receive public page and event information, their click and cookie identifiers, and browser/network information including IP address and potentially a referring page. A random event ID deduplicates an account-completion event; it is not your account ID. Tags do not run in sign-in, onboarding, the sample or private planning workspace, contact forms, investment forms or the operator dashboard. We do not supply email addresses, names, financial facts, investor qualification, or private planning activity. Enhanced conversions, automatic form capture, customer-list uploads and Google advertising personalization are disabled by this implementation. Meta event data is processed according to its platform terms. Allowing first-party usage analytics alone does not enable advertising tags. Review Google’s privacy policy at https://policies.google.com/privacy and Meta’s at https://www.facebook.com/privacy/policy/ for their processing, retention and controls. Declining this purpose does not reduce planning access.
Optional household statistics and internal reports
A separate account setting in this Privacy Notice lets you choose whether your completed household contributes its primary age band, state, broad US region and filing-status category to internal aggregate service reports. This setting is off by default and is not enabled by accepting terms or allowing browser analytics. Reports exclude names, emails, exact ages, balances, income and messages; demographic breakdowns with groups smaller than five are withheld. No household is linked to browser event history or advertising audiences. We retain an immutable receipt of your choice. Turning the setting off excludes your household from subsequent live demographic reports without reducing planning access. Authorized operators can also see aggregate registration/completion counts and counts of received planning and investment inquiries by submission week, entered state and delivery status, to operate the service and manage requests. Inquiry reports do not include contact details or message content. State and region in these reports are entered residence, not IP-derived visitor location or advertising attribution. The calculation service keeps bounded in-memory duration and error counts for fixed operations to diagnose performance; these contain no financial inputs or user identifiers and reset on restart.
Cookies and browser storage
Essential, host-only cookies support sign-in (up to 7 days), Google and email-code handshakes (up to 10 minutes), and cookie preferences (180 days). Separate optional usage and advertising permission cookies last up to 180 days after opt-in. Campaign attribution lasts 30 days; usage events expire after 90 days. If you permit advertising measurement, Google and Meta may set their own advertising cookies under their policies; our first-party Google cookie lifetime is configured for up to 90 days. Our browser session storage may retain vendor click identifiers for up to 30 days or until the tab session ends, and a one-use registration measurement receipt expires within 10 minutes. Neither contains financial inputs. Rejecting optional cookies creates no analytics identifier. Cookie preferences apply to this browser; another browser has its own choices. The sample workspace can store demo inputs and scenarios locally until you clear them. Personal saved plans use your account storage.
Your privacy choices
Rejecting optional measurement leaves all planning features available. Cookie preferences lets you separately disable usage analytics and advertising measurement. Turning usage analytics off deletes this browser’s live events and campaign attribution. Withdrawing advertising permission stops future advertising tags, invalidates unused registration receipts and clears advertising storage we can access. Previously transmitted data and third-party cookies cannot be recalled or deleted by this control; Google and Meta provide their own privacy controls. Global Privacy Control and Do Not Track signals disable both optional purposes. Browser-data disclosures to advertising providers may be considered sharing under applicable state privacy laws; to opt out of sale or sharing, reject optional advertising measurement in Cookie preferences. No financial profiles, contact messages, emails, investor status or customer lists are uploaded for advertising. Measurement permission is separate from terms, marketing subscriptions, referrals and investment contact.
Who can process information
Authorized members of the Amicus Planning team and the infrastructure used to operate the service can process stored information for the purposes described here. Google handles its own sign-in service under its privacy policy. Our configured transactional email provider processes recipient addresses and messages to deliver requested sign-in codes and separately authorized planning-contact and investment-team inquiries. When Cloudflare Turnstile is enabled, Cloudflare processes browser and network signals to verify sign-in, planning-contact and investment-inquiry security checks. No saved financial profile is attached to emails or sent to Turnstile; these essential security and delivery functions are separate from optional usage analytics. The application does not automatically disclose household profiles to professionals, fund operations, advertisers or AI services. Browser requests necessarily expose connection information to the serving infrastructure; the application analytics store does not retain IP addresses. Access to stored plans is restricted to authorized service operations; signing in does not grant access to Amicus investment systems. With separate advertising permission and configured integrations, Google and Meta process the limited public-page measurement information described above under their respective privacy policies.
Retention and deletion
Email codes expire after 10 minutes and can be used once. Expired challenges are removed on a subsequent code request or daily cleanup. Hashed abuse-prevention counters expire within 48 hours and are removed on the same cleanup schedule. Email sign-in associations are retained for the account and removed when its verified Google email changes or the account is deleted. Analytics events expire after 90 days and are removed by a daily cleanup while the service is running. Analytics permission records expire after 180 days; withdrawing permission immediately stops new events and removes linked events from the live store, with a minimal permission record retained until expiry. Account data, saved versions, simulation inputs and results, notice receipts and contact requests are retained unless you make a verified deletion request. These records do not currently have an automatic expiration. We review deletion requests manually and explain any information that must be retained. Deleting live records does not itself erase existing backup copies.
Access, correction and other requests
You can export your saved household and update its inputs in the workspace. Use the contact form’s Privacy or data request topic for access, correction, deletion, a copy of your notice receipt or a complaint. The team may need to verify account ownership before disclosing or deleting information. Requests are handled manually; submitting a request is not confirmation of deletion. Depending on applicable law, you may have additional rights, including an appeal or a complaint to a regulator. Declining optional analytics does not reduce free planning access.
Audience, security and changes
Amicus Planning is intended for adults residing in the United States and is not directed to children. Registration may be open or limited by the displayed access policy. Protect your email and Google accounts, never share sign-in codes, and sign out on shared devices. No system is perfectly secure. Material changes to these documents will be shown before further account edits and recorded with a new acknowledgment. A change to the analytics purposes will require a new choice.
