Privacy Policy
Last updated: April 2, 2026
1. Information We Collect
Account data: When you create an account, we collect your email address and store a securely hashed password. We never store plaintext passwords.
Estate planning inputs: You voluntarily provide financial data including estate value, income, beneficiary count, trust details, charitable intent, and state of residence. This data is used solely to generate your estate optimization analysis. Free-tier inputs are processed in your browser session and are not persisted server-side.
Usage data: We collect API request logs including timestamps, endpoints accessed, and response codes for billing and abuse prevention. These logs do not contain your estate planning inputs.
2. How We Use Your Information
We use your information to provide estate tax modeling, gift strategy analysis, and wealth transfer optimization. We use account data for authentication and subscription management. We use anonymized, aggregated usage data to improve the accuracy of our optimization models. We do not sell, rent, or share your personal or financial information with third parties for marketing purposes.
3. Email Communications
If you create an account, we may send transactional emails related to your subscription, password resets, and important service updates. We do not send unsolicited marketing emails. You may opt out of non-essential communications at any time.
4. Cookies
Voritanel uses only essential cookies for session management and authentication. We do not use third-party tracking cookies, advertising pixels, or behavioral analytics scripts. No cookie consent banner is required because we do not perform cross-site tracking.
5. Third-Party Services
We use Stripe for payment processing. Stripe receives your email and subscription tier for billing purposes and is governed by Stripe's Privacy Policy. We use Cloudflare for hosting and infrastructure. No estate planning data is shared with any third party.
6. Data Retention
Account data is retained while your account is active plus 30 days after deletion. API request logs are retained for 90 days. Anonymized usage statistics may be retained indefinitely for product improvement. Upon account deletion, all personally identifiable data is purged within 30 days.
7. CCPA Rights (California Residents)
If you are a California resident, you have the right to know what personal information we collect and why, to request deletion of your personal information, and to opt out of the sale of personal information. We do not sell personal information. To exercise your deletion rights, use the DELETE /v1/account API endpoint or email privacy@smarttechinvest.com. We process CCPA requests within 45 days.
8. Security
All data is encrypted in transit via TLS 1.3 and at rest via AES-256. Passwords are hashed with bcrypt. API keys are generated using cryptographically secure random functions. We employ parameterized database queries to prevent SQL injection and enforce secure HTTP headers across all endpoints.
9. Contact
For privacy-related inquiries, contact privacy@smarttechinvest.com.