<← Back to Apexa

Privacy Policy

Apexa Web App LLC · Effective April 6, 2026 · Version 2026-04
Short version: We collect only what we need to run the service. We don't sell your data. You can export or delete everything at any time. Your biometric data never leaves your device.

1. Who We Are

Apexa Web App LLC ("Apexa", "we", "us") operates the Apexa financial platform accessible at apexa.com. We are incorporated in Puerto Rico, EIN 41-5230947.

For privacy questions: privacy@apexa.com

2. What Data We Collect

CategoryWhat exactlyWhy
Account dataFull name, email address, account type (creator/agency)To create and identify your account
AuthenticationBcrypt password hash, WebAuthn public key (not biometric data), session JWTsTo securely verify your identity
Financial preferencesTax %, invest %, spend % split settings, risk profileTo automate your income splitting
SubscriptionPlan tier, Stripe customer ID, subscription statusTo manage your billing
Consent recordsCheckbox state, timestamp, IP address at signupLegal compliance (CCPA, GLBA)
Access logsLogin timestamps, IP addresses, device user-agentSecurity — detect unauthorised access
Usage dataScreen views, feature usage (anonymised)Product improvement

3. What We Do NOT Collect

4. How We Use Your Data

5. Third Parties We Share Data With

ServiceWhat they receiveTheir privacy policy
StripeName, email, payment method for billingstripe.com/privacy
PlaidBank connection initiation (credentials handled entirely by Plaid)plaid.com/legal
DriveWealthName, DOB, SSN for brokerage account opening onlydrivewealth.com/privacy
AnthropicChat messages you send to Apexa AI (no PII injected)anthropic.com/privacy
AirtableName, email at signup for CRM (optional, can opt out)airtable.com/privacy

We do not sell, rent, or trade your personal data to any third party for advertising or marketing purposes.

6. Your Rights

Regardless of where you live, you have the following rights:

7. California Residents (CCPA)

California residents have additional rights under the California Consumer Privacy Act (CCPA):

To exercise your CCPA rights, use the in-app controls or contact privacy@apexa.com. We will respond within 45 days.

8. Financial Privacy (GLBA)

As a financial technology company, we are subject to the Gramm-Leach-Bliley Act (GLBA). We collect and use nonpublic personal financial information only to provide the Apexa service. We do not share your financial information with unaffiliated third parties for marketing. Our security program includes encryption at rest and in transit, access controls, and audit logging.

9. Data Retention

10. Security

11. Cookies & Tracking

Apexa uses only functional cookies required to keep you logged in (JWT stored in localStorage). We do not use advertising cookies, tracking pixels, or third-party analytics that profile you.

12. Children's Privacy

Apexa is not directed to children under 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us data, contact privacy@apexa.com and we will delete it promptly.

13. Changes to This Policy

We will notify you of material changes via email and in-app notice at least 14 days before they take effect. The current version date is always shown at the top of this page.

14. Contact

For privacy questions, data requests, or concerns: