Nexor Vault Privacy Policy (DRAFT)
Version: 2026-08-12 Effective date: [DATE — set on publication; must not precede the date consent capture goes live] Last updated: 2026-08-12
TheVersionstring above is the canonical, machine-referenceable identifier for this policy. Consent capture must record this exact string against the accepting user. Any change to the substance of this document requires a newVersionvalue (YYYY-MM-DDof the change) and a fresh consent record; do not edit a published version in place.
1. Who We Are
Nexor Vault ("Nexor Vault," "we," "us") operates a financial management and trust-administration platform that lets clients view their accounts, holdings, and financial documents in one place, share scoped access with attorneys/advisors/family, and build trust instruments. This policy explains what personal and financial information we collect, why, and what rights you have over it.
[Insert legal entity name, state of incorporation, and registered address before publishing.]
2. Information We Collect
2.1 Information you give us directly
- Identity information about you: name, email address, and (optionally) phone number. We do not collect your date of birth for your own account record.
- A trust tax identifier, if you choose to enter one. When you create a trust in the trust builder, there is a single optional tax-identifier field. It is intended for the trust's Employer Identification Number (EIN), but if you enter a Social Security Number there instead, that is what we store. This field is optional and is the only place a personal tax identifier can be entered. It is encrypted at the application layer before it is written to the database, under a key held separately from the database, and it is decrypted only when the record is read back to you or used to draft your trust document (see §5, Anthropic). We do not use it for identity verification, and we do not collect an SSN for any other purpose.
- Financial account credentials, entered into Plaid's connection flow — we never receive or store your bank login credentials (see §3)
- Trust, estate, insurance, rental, and college-savings documents you upload
- Property addresses you enter to look up a property (see §5, RentCast)
- Beneficiary, grantee, and co-trustee information you enter about third parties — which may include their name, email, phone, postal address, and date of birth
2.2 Information collected automatically
- Third-party access logs. When someone you have granted access to views your shared vault dashboard, lists your documents, or downloads a document or tax document, that access is recorded in an audit trail (
AccessLog) with the viewer, the action, and the timestamp. This covers access by the people you share with. It does not currently record your own activity in your own vault, nor the creation, modification, acceptance, or revocation of an access grant. - Device/browser metadata, IP address, and session data, held by Clerk as our authentication provider
- IP addresses, used transiently to apply rate limits and abuse protection
- Application logs (error and diagnostic output) generated by the running service
- We do not currently operate any product analytics or behavioural tracking. No analytics or session-replay service is integrated into the application, and we set no advertising or cross-site tracking cookies. [CONFIRM: Clerk sets cookies necessary for authentication; the exact cookie inventory should be confirmed in the Clerk dashboard and listed here if a cookie disclosure is required.]
2.3 Information from third parties
- Plaid: from the institutions you link, we request transactions, liabilities, and — for investment accounts — holdings, together with the account details and balances that come with them. We do not request Plaid's identity product, so we do not receive your name, address, phone, or email from your bank through Plaid.
- Clerk: authentication and identity verification signals
- RentCast: property characteristics, tax history, and an estimated value, returned for a property address you enter
- Forwarded email statements: if you use your Nexor Vault forwarding address, we receive the emails you forward — including their body text and attachments — through our email provider, and extract account figures from them
- Attorneys, CPAs, or advisors you grant access to may add documents or notes visible in your vault
3. How We Use Financial Account Data (Plaid)
We use Plaid, Inc. to connect to your financial institutions. You enter your bank credentials into Plaid's own connection flow; we never see, receive, or store them. Plaid's own privacy policy governs its handling of them. Plaid issues us an access token for each linked institution, which we store encrypted at the application layer and never in plaintext.
We request the transactions, liabilities, and (for investment accounts) investments products only — not Plaid's identity product. We receive and store: institution and account details, balances, transaction history, holdings, and liability details, for as long as the institution is linked, so that we can display your consolidated financial picture and support trust-funding features.
Unlinking deletes the linked data. When you unlink an institution, we ask Plaid to remove the connection and we delete our stored record of that institution, which also deletes the accounts, balances, and transactions we had stored for it. [CONFIRM before publishing: historical net-worth snapshots (NetWorthSnapshot) hold aggregate figures derived from those accounts and are not removed by unlinking. If that remains true, say so here in one sentence rather than leaving the deletion claim unqualified.]
4. How We Use Your Information
- Provide the core service: aggregated financial dashboard, trust-builder tools, document vault, e-signatures
- Enable access-sharing you configure with attorneys, CPAs, family members, or advisors, at the section/level you choose
- Security: fraud detection, audit logging, incident response
- Communications: service notifications (Resend), required legal/regulatory notices, and — only with opt-in — product updates
- Comply with legal obligations: trust filings, IRS/state court submissions you initiate, tax reporting where applicable
4.1 Automated document reading and drafting (AI processing)
Several features work by sending your content to Anthropic, an AI provider, and using what it returns:
- Document extraction. When you upload a trust, insurance, rental, or college-savings document to be read automatically, the entire file is transmitted to Anthropic to extract the structured details.
- Forwarded statements. When you forward a financial statement to your Nexor Vault address, the email body and its attachments are transmitted to Anthropic to extract the account figures.
- Trust drafting. When you generate a draft trust document, we send a structured summary of the trust — including the people named in it, their contact details, the asset schedule, and the trust tax identifier if you entered one — so the draft can be written from your actual data.
These features are used only when you initiate them; we do not send your documents for automated reading unless you ask for it. Drafts produced this way are not legal advice and are presented for your review.
[CONFIRM: Anthropic's API data-retention and model-training terms for our account, and whether zero-retention applies, before publishing this section. Do not state or imply that content is not retained or not used for training without confirming the contractual position — this needs both the vendor terms and counsel.]
We do not sell your personal information, and we do not disclose it to advertisers or data brokers.
5. Who We Share Information With
| Recipient | What they get | Why |
|---|---|---|
| Plaid, Inc. | Your bank credentials, entered directly into Plaid's own connection flow and never seen by us; the account access token Plaid issues to us, which we hold encrypted; and the account, balance, transaction, liability, and holdings data Plaid returns | Account aggregation |
| Clerk | Your email address, name, authentication identifiers, session and device metadata, IP address | Authentication and session management |
| Microsoft Azure — Database for PostgreSQL Flexible Server | All application data at rest: your account record, trusts, beneficiaries, properties, holdings, balances, transactions, insurance, and audit logs | Primary database hosting |
| Microsoft Azure — Blob Storage | Every document you upload, in full | Document storage |
| Microsoft Azure — Key Vault | Our own service credentials and encryption keys. No customer data is stored in Key Vault. | Secrets management |
| Anthropic | Document and record contents you submit for automated reading or drafting. Specifically: (a) the full contents of trust, insurance, rental, and college-savings documents you upload for extraction; (b) the body text and attachments of financial statements you forward to your Nexor Vault email address; (c) when you generate a trust document draft, a structured summary of that trust — including grantor and co-grantor names, emails and phone numbers, beneficiary names, relationships, contact details and shares, the asset schedule with values, and the trust tax identifier if you entered one. | Automated document reading and trust-document drafting |
| RentCast | The full property address you type into the property lookup, sent to their valuation API | Property details, tax history, and value estimate |
| Resend | Outbound: your email address and the contents of notifications we send you. Inbound: any email you forward to your Nexor Vault forwarding address, including attachments, which Resend receives and holds on our behalf. | Transactional email and inbound statement forwarding |
| Yahoo Finance (unauthenticated market-data endpoint) | The ticker symbols in your portfolio, when we fetch a live price for a holding. No name, account identifier, or credential is sent; the request carries no authentication and is not tied to your account by us. The set of symbols is nonetheless derived from your holdings. | Live prices and price history |
open.er-api.com (exchange-rate API) | Nothing about you. A single request for USD reference rates, containing no user data. | Currency conversion |
| Attorneys/CPAs/advisors you invite | Whatever vault sections and access levels you explicitly grant, for as long as the grant is active | Access-sharing feature you control |
| Government agencies (IRS, state courts, county recorders) | Filing information you submit through the platform | Trust/estate filings you initiate |
| Law enforcement / legal process | Minimum required | Only in response to valid legal process |
We use no advertising, marketing, or analytics processors, and we do not disclose your information to any.
Verified against the codebase on 2026-08-12 by tracing every configured third-party credential and every outbound network call. The list above is the complete set of external recipients as of that date.
[Vendor DPAs with each processor above must be executed before this table can be represented as accurate/binding — none has been executed as of 2026-08-12. This is an open item for counsel, not a resolved one.]
[CONFIRM: the data-residency region of each Azure resource, and whether any processor above stores or processes data outside the United States, before publishing §10 (International Users).]
6. Security
We maintain administrative and technical safeguards appropriate to the sensitivity of financial and trust data. Specifically, and stated no more broadly than is true today:
- In transit: all application traffic is served over TLS only, with HSTS. Connections to our object storage enforce a TLS 1.2 minimum, and database connections are TLS-encrypted.
- Application-layer encryption: two values are encrypted by our application with AES-256-GCM before being written to the database, under a key held in a separate secret store: the access token for your linked financial institution, and your trust tax identifier. Neither is ever written in plaintext.
- Other data at rest relies on the platform-level encryption provided by our cloud provider rather than on additional application-layer encryption. [CONFIRM: encryption-at-rest state and key type (platform-managed vs. customer-managed) for the Azure Postgres server and the storage account, in the Azure portal, before publishing.]
- Network isolation: our production database has no public network endpoint and is reachable only from within our application's private network. There is no direct browser-to-storage path; every document read and write is proxied through our server.
- Access controls: authentication is required by default on every non-public route, and access you grant to third parties is enforced per request, scoped to the sections and levels you chose, and honoured as revoked immediately once you revoke it.
- Audit trail: views and downloads of your shared vault content by the people you grant access to are recorded, and the person recorded cannot alter or delete their own access records through the application. This audit trail covers third-party access to shared content; it does not cover your own activity or grant-lifecycle events, and we do not describe it as a complete record of all access.
- Rate limiting and abuse protection are applied centrally.
The list above is intended to be exhaustive as to the safeguards we currently operate. We are not SOC 2 attested and do not claim to be. No safeguard eliminates risk, and we do not represent that our systems are impenetrable.
See our Incident Response Plan for our breach-response process. [Once GLBA Safeguards Rule applicability is confirmed, this section needs to reference the specific required elements: written risk assessment, named Qualified Individual, access controls, encryption, MFA, secure disposal, incident response, and annual reporting to the board.]
7. Your Rights and Choices
- Access/portability: request a copy of your data
- Correction: update inaccurate information via your profile
- Deletion: request deletion of your data through the account deletion flow. This deletes your linked financial institutions and their tokens, your properties, net-worth snapshots, stock holdings and sales, tax documents, notifications, and the access grants you issued, and anonymizes your account record. Two limits we state plainly: trust records co-owned with other stakeholders (e.g., co-trustees, beneficiaries) are not deleted by this flow, since deleting them would destroy other people's legal records, and documents you uploaded are attached to those trust records and therefore also survive it. A joint-deletion process for co-owned records is not yet built; until it is, ask us and we will handle the request manually. [Some record types — including insurance policies, rentals, college-savings accounts, bonds, liabilities, and forwarded email messages — are not yet covered by the automated flow either. Either extend the deletion transaction (
src/app/api/account/delete/route.ts) or keep this sentence; do not publish a broader deletion claim than the code performs.] - Unlink financial accounts at any time
- State-specific rights (CCPA/CPRA, VCDPA, CPA, and others): [to be completed per-state once counsel maps applicability — likely includes the right to opt out of "sale/sharing" even though we do not sell data, the right to limit use of sensitive personal information (financial account data, and a tax identifier where one has been entered, would both qualify), and a non-discrimination guarantee]
8. Data Retention
- Financial and trust data: retained while your account is active and for the period required by applicable trust/estate and tax recordkeeping law after closure [counsel to specify retention periods per document type]
- Audit logs (
AccessLog): retained for [X years] to support security investigations and GLBA/state recordkeeping requirements - Deleted-account data: purged per §7 deletion flow, except where retention is legally required
Stated accurately: we do not currently delete data automatically on a schedule. Retention today means data is kept until you delete it through the account-deletion flow or ask us to remove it. No period in this section is enforced by an automated process, and this policy should not be read as promising automatic expiry. [Do not fill in the bracketed periods above until either a scheduled deletion job exists or the wording makes clear the period is a maximum-retention commitment honoured manually. Publishing a numeric retention period with no implementing code would be an unbacked claim — the same failure this pass exists to prevent. See docs/compliance/policies/data-retention-policy.md, where every period is still a placeholder.]
9. Children's Privacy
Nexor Vault is not directed at individuals under 18. We do not knowingly collect data from minors, except where a minor is named solely as a beneficiary in a trust document uploaded by an adult account holder.
10. International Users
[Confirm whether the service is US-only at launch. If any non-US users are in scope, GDPR/UK-GDPR applicability needs separate counsel review — not addressed in this draft.]
11. Changes to This Policy
We will notify you of material changes to this policy by email and/or in-app notice before they take effect.
12. Contact Us
[Insert: privacy contact email, mailing address, and — once assigned — the name/title of the GLBA-required security/privacy officer.]
Drafting checklist before publication
- Attorney review for GLBA Privacy Rule + Safeguards Rule accuracy
- State-by-state consumer privacy law addendum (CCPA/CPRA at minimum given financial-data sensitivity)
- Insert real entity name, addresses, retention periods, contact info
- Set the Effective date at the top; keep
Version: 2026-08-12unless the substance changes again - Resolve every
[CONFIRM: ...]marker in this document — each is a fact only a vendor or Azure console can settle - Subprocessor list in §5 verified against the codebase (2026-08-12): every configured third-party credential and every outbound network call traced
- Re-verify §5 whenever a new outbound integration or third-party credential is added — a new subprocessor is a new disclosure, and the check is
grep-cheap - Counsel review of the §4.1 AI-processing disclosure specifically (trust contents and tax identifiers are transmitted to Anthropic)
- Execute vendor DPAs referenced in §5 before claiming those safeguards are contractually binding — none executed as of 2026-08-12
- Wire consent capture to record the
Versionstring above against each accepting user, and keep prior versions archived and retrievable