Privacy Policy

Last updated: March 10, 2026

Key Highlights

  • Your Data is Private: We never sell your data to anyone, and we never have!
  • Your Rights: Access, update, delete your data, and opt-out of communications at any time.
  • Security Measures: We protect your data using advanced security measures.
  • AI Data Protection: We do not use your personal financial data or AI conversation history to train AI models. We send scenario data to AI using generic identifiers (e.g. "User" and "Spouse") instead of your or your spouse's names. We may use only anonymized, aggregated usage statistics. Your conversations and inputs are not shared with third parties for marketing purposes.
  • Privacy modes: You can choose Local Mode (data on your device only; AI not available) or Cloud Mode (data synced on our servers; AI available). In Local Mode your data never leaves your device. Switching to Local does not delete data already on our servers.
  • Contact Us: For any privacy concerns, reach us at privacy@duskai.app.

1. Introduction

Welcome to Wealth Sandbox! We prioritize your privacy and we are dedicated to protecting it. At Dusk AI Inc. ("Wealth Sandbox", "we", "us", or "our"), we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains what data we collect, how we use it, and your rights as a user.

By using our Service, you agree to this policy. Please also review our Terms of Service to understand the complete agreement governing your use of our Services.

First and foremost: we never sell your data to anyone, and we never have!

2. Overview

Our policy is designed to inform you about:

  • The types of information we collect from you during your use of our services
  • How we use, maintain, and safeguard your information
  • Your privacy rights and how the law applies to you

This policy is relevant to information we collect:

  • On our Website and through our Service
  • In email, text, and other electronic messages between you and Wealth Sandbox
  • Through any mobile or desktop applications you download from our Website

We may update this Privacy Policy periodically, and we encourage you to review it regularly.

3. Information We Collect

We respect your privacy, and your data is NEVER sold to anyone.

Wealth Sandbox collects and uses your data to provide and enhance our services and respects your privacy at every step. Here are the categories of data we collect and key points about how each is handled:

Basic Account Information

Includes data like your name, email address, username, date of birth, marital status, country, and user preferences. This information helps us personalize and manage your experience with our Service.

Financial Planning Data

Encompasses all information you manually enter, such as:

  • Financial scenarios and projections
  • Account balances (savings, investments, real estate, physical assets)
  • Income and expense information
  • Debt and liability details
  • Future financial goals like home purchases, retirement planning, and other objectives
  • Tax information and filing status
  • Withdrawal strategies and financial planning preferences

All financial planning data is encrypted at rest and in transit. You control your data and can delete it anytime through your account settings.

AI Interaction Data

When you interact with our AI assistant (in cloud mode), we collect:

  • Your questions and queries to the AI assistant
  • AI-generated responses and scenario-based analysis
  • Chat session history and conversation context
  • AI interaction usage and patterns

When you use AI features, your inputs are processed by our third-party AI service providers (Anthropic Claude, OpenAI ChatGPT), whose servers are located in the United States. See Section 9 for how we handle international transfers. We do not use your personal financial data or AI conversation history to train AI models; we may use only anonymized, aggregated usage statistics. Your conversations and inputs are not shared with third parties for marketing purposes.

AI Processing Flow

  1. Your query is sent from our Canadian servers to our AI providers in the United States.
  2. The AI provider processes your query and generates a response.
  3. The response is returned to our Canadian servers.
  4. Your complete conversation history (sessions and messages) is stored on our servers in Canada. Our AI providers (Anthropic, OpenAI) do not retain your conversation data beyond the processing session, in accordance with our agreements with them.

Data Anonymization Before AI Processing

To protect your privacy, we do not include your name or your spouse's name in the scenario data sent to our AI providers. In the data we send for AI analysis we use generic identifiers—for example we refer to you and your spouse as "User" and "Spouse" (or "ME" and "SPOUSE" in data fields)—rather than personal names. This keeps personal identifiers out of AI processing while still allowing the assistant to answer questions about your scenario (e.g. "Spouse's income at 65"). Your chat messages are sent as you type them; if you include names or other personal details in a message, they will be sent to the AI. You can avoid including such information in messages if you prefer.

Local Mode: If you choose Local Mode, the AI assistant is not available. No financial data or queries are sent to our servers—projections and scenarios run in your browser. Your data never leaves your device.

Local Mode and Cloud Mode

Wealth Sandbox offers two data storage modes. When you use Local Mode (data stored only on your device, e.g. in browser storage):

  • Your financial data, scenarios, and projections remain on your device and are not transmitted to our servers
  • The AI assistant is not available in Local Mode—no queries or data are sent for AI processing
  • Projections and Monte Carlo simulations run in your browser; we do not receive or process this data

In Cloud Mode, your data is stored on our servers and synced across devices; AI features require Cloud Mode. You can switch between modes in Settings. Switching from Cloud to Local Mode means we stop syncing and displaying your cloud-stored data; we do not delete your data from our servers when you switch. To request deletion of cloud-stored data, contact support@wealthsandbox.com.

Usage Data

When you use our Service, we may collect usage-related information. Detailed analytics (e.g. IP address, browser type, pages visited, time spent, geographic location, referrer information, interaction patterns) are collected only when you consent to Performance/Analytics cookies—see Section 4. We may use minimal server-side data (e.g. request metadata) as necessary for security, fraud prevention, and operating the service, without relying on optional cookies.

Usage data we may collect (depending on your cookie choices) includes: IP address, browser type and version, device information, pages visited, time spent, navigation patterns, geographic location (country/city level), and referrer information. This helps us improve functionality and user experience, detect and prevent fraud, and ensure security.

Payment Information

Payments are processed through Stripe and other third-party payment processors. Your payment information is subject to the processor's terms and privacy policy. We do not store complete credit card information on our servers. Payment processing is handled by secure, PCI-compliant third-party services.

Remember, as a user, you control your planning data and can delete it anytime through your account settings.

4. Cookies and Tracking Technologies

Wealth Sandbox utilizes cookies and similar tracking technologies to enhance your experience on our website. Understanding how and why we use cookies will help you make informed decisions about your interaction with our site.

What Are Cookies?

Cookies are small text files stored on your device by websites you visit. They are widely used to improve your browsing experience, perform analytics, remember your preferences, and for advertising purposes.

Types of Cookies We Use

Strictly Necessary Cookies (Always Active)

These cookies are essential for the operation of our website and cannot be switched off. They enable basic functions only:

  • Authentication cookies that keep you logged in to your account
  • CSRF (Cross-Site Request Forgery) protection tokens for security
  • Session cookies that maintain your browsing session
  • Essential security cookies for fraud detection and preventing unauthorized access

We do not use strictly necessary cookies for analytics or visit tracking. Such tracking requires your consent and is described under Performance/Analytics below.

Functional Cookies (Optional)

Functional cookies enable our website to provide enhanced functionality and personalization, such as remembering your preferences and settings. These are set by us or third-party providers whose services we've added to our pages. If you do not allow these cookies then some or all of these services may not function properly.

Performance/Analytics Cookies (Optional)

We use performance and analytics cookies only when you consent. These cookies help us understand how visitors interact with our website and improve service performance. With your consent, they may include:

  • Visit tracking that logs IP address, browser type, pages visited, time spent, and referrer information
  • Geographic location (country/city level) for service optimization
  • User agent and interaction patterns for analytics
  • Usage tracking to measure site performance and identify popular content
  • Error tracking to help us identify and fix technical issues
  • Google Analytics and similar third-party analytics services (when you consent)
  • Server-side consent analytics: when you consent, we may store pseudonymous events (e.g. event type, page/section, timestamp) linked to your consent record, retained per our data retention policy (up to 13 months).

If you do not allow these cookies we will not use this data for analytics or performance monitoring. Essential security monitoring (e.g. fraud prevention) may still use minimal server-side request data as needed to operate the service.

Targeting/Marketing Cookies (Optional)

Targeting cookies are used to help measure the effectiveness of advertising campaigns, track referrals, and deliver marketing content or advertisements more relevant to you and your interests. They are only active when you consent to them and include:

  • Ad personalization cookies that help show relevant advertisements
  • Conversion tracking cookies that measure advertising effectiveness
  • Social media integration cookies for sharing functionality
  • Retargeting cookies that help us show relevant ads on other websites
  • Facebook Pixel and similar marketing tracking technologies

They do not store personal information, but are based on uniquely identifying your browser or internet device.

User Consent and Preferences

We respect your right to privacy. Therefore, aside from strictly necessary cookies, we will only use other types of cookies if you consent to them. You can manage your preferences via our Cookie Consent Manager, accessible on our website or through your account settings at Privacy Settings.

Cookie Storage and Retention

Cookies are stored locally on your device. We use the following maximum retention periods:

  • Session cookies: Deleted when you close your browser
  • Authentication cookies: Up to 30 days
  • Security cookies: Up to 2 years
  • Analytics cookies (with consent): Up to 13 months
  • Marketing cookies (with consent): Up to 13 months
  • Cookie preference settings: Until you change them or up to 12 months

Server-side visit logs and security data may be retained for up to 2 years for fraud prevention and security analysis.

Local Mode Cookie Handling

When you use Local Mode (data stored only on your device):

  • Strictly necessary cookies for authentication and security are still used when you are logged in
  • Analytics and marketing cookies (if you have consented) may continue to function for website optimization
  • No financial or scenario data is transmitted via cookies or to our servers—your projection data is stored only in your browser's local storage, not in cookies

Managing Cookies

You can control and manage cookies through:

  • Our cookie consent banner when you first visit our site
  • The cookie settings page in your account preferences
  • Your browser settings (though this may affect website functionality)
  • Clearing your browser's stored data (note: this will not affect necessary cookies which are required for functionality)

Keep in mind that removing or blocking cookies can impact your user experience and parts of our website may no longer be fully accessible.

Third-Party Cookies

We may use third-party services that set their own cookies, including:

  • Analytics providers for website performance monitoring
  • Payment processors for subscription management
  • Content delivery networks for improved performance
  • Customer support platforms

These services may collect information about you according to their own privacy policies. We encourage you to review the privacy policies of any third-party services you access through our platform.

Changes to Our Cookie Practices

We may update our cookie practices from time to time to reflect changes in our practices, technology, or legal requirements. If we make significant changes to how we use cookies, we will notify you through our cookie consent mechanism and may request renewed consent. We encourage you to periodically review this policy for the latest information on our cookie practices.

5. How We Use Your Information

We use your information to provide, maintain, and improve our Services.

Service Provision

  • To create and manage your account
  • To process your subscriptions and payments
  • To provide financial planning tools, projections, and simulations
  • To deliver scenario-based analysis and projections
  • To respond to your inquiries and provide customer support
  • To send service-related notices, including updates about our Services and information about your account

AI Services

  • To process your queries and generate AI responses
  • To provide scenario-based analysis and projections (informational only)
  • To run what-if simulations and scenario analyses
  • To generate charts and visualizations based on your data
  • To improve AI accuracy and performance (using anonymized and aggregated data only, with your consent)

We do not use your personal financial data, scenarios, or AI conversation history to train AI models. We may use anonymized, aggregated usage statistics to improve our Services. Your data is not sold to third parties.

Security and Fraud Prevention

  • To detect and prevent fraud, abuse, and security threats
  • To monitor for suspicious activity and unauthorized access
  • To ensure compliance with our Terms of Service
  • To analyze user behavior patterns for security purposes

Service Improvement

  • To analyze usage patterns and improve our Services
  • To develop new features and functionality
  • To optimize website performance and user experience
  • To conduct research and analytics (using anonymized data)

Communication

  • To send you service-related communications (with your consent for marketing communications)
  • To notify you about changes to our Services or policies
  • To respond to your requests and inquiries

Cookie Data Usage

Cookie data is used to remember your preferences, maintain your login session, analyze site performance (with consent), and provide personalized experiences (with consent). Visit tracking data (collected via necessary cookies) is used for security monitoring, fraud detection, service optimization, debugging, and ensuring compliance with our terms of service.

7. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy.

You can request deletion of your account and associated data at any time by contacting our support team at support@wealthsandbox.com. Upon termination or account deletion, all your data (including AI conversation history and scenario data) will be permanently deleted within 60 days, except where we are required to retain data by law or for legitimate business purposes (e.g., fraud prevention, legal compliance).

Free tier users have the same data deletion and data portability rights as paid users. We may delete inactive free accounts (no login for 12 months or longer) after providing 30 days' notice to the account email address.

We may retain certain information in anonymized or aggregated form, which cannot be used to identify you, even after you delete your account.

Specific Retention Periods

  • Account data: Retained while your account is active; permanently deleted within 60 days after account deletion
  • Financial planning data: Retained while your account is active; permanently deleted within 60 days after account deletion
  • AI interaction data: Retained while your account is active; permanently deleted within 60 days after account deletion
  • Visit logs and security data: Up to 2 years for fraud prevention and security analysis
  • Payment information: Transaction records and billing history are retained for 7 years for tax compliance. Complete credit card numbers are not stored on our servers; card data is handled by Stripe in accordance with their retention policies.
  • Marketing data: Until you unsubscribe or withdraw consent
  • Analytics data: Anonymized and retained indefinitely for service improvement
  • Cookie preferences: Stored until you change them or clear your browser data. Necessary cookies are retained as long as needed for security and functionality.

8. Data Security

Ensuring the security of your data is a top priority. We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.

While no online service is entirely secure, we implement advanced measures to protect your data, including:

  • Data encryption in transit (TLS/SSL) and at rest
  • Continuous review and updating of our security practices
  • Access controls restricting data access to authorized personnel
  • Secure software development practices
  • Regular security audits and monitoring
  • Secure cookie handling and encrypted data transmission

We continuously upgrade our security practices to prevent unauthorized access. Access to personal data is restricted to authorized personnel who need it for their job functions.

Both free and paid tier users receive the same level of data security protection, including encryption in transit and at rest. Your data protection does not depend on your subscription level.

In the event of a data breach, we will notify affected users and relevant authorities as required by law.

9. Disclosure, Retention, and Transfer of Personal Data

Your data is handled with the utmost care and discretion.

Service Providers

We engage third-party companies for tasks like data hosting, analytics, payment processing, and customer support. These providers are bound by strict data protection agreements and confidentiality requirements. Personal data is only shared with service providers as necessary and under confidentiality agreements.

Legal Compliance

We may disclose data in accordance with law enforcement or legal obligations, including court orders, subpoenas, or other legal processes. We comply with major privacy regulations like GDPR and CCPA.

Where We Store and Process Data

User data is stored on servers located in Canada. When you use AI features, your inputs are processed by our AI service providers (Anthropic Claude, OpenAI ChatGPT), whose servers are located in the United States. We ensure all such transfers comply with applicable data protection laws, including PIPEDA.

International Data Transfers

When we transfer personal data outside of Canada (including to our AI providers in the United States), we ensure appropriate safeguards are in place to protect your information. For EU/UK users, we ensure adequate protection through Standard Contractual Clauses or adequacy decisions. We comply with applicable cross-border data transfer requirements in all jurisdictions where we operate.

Business Transfers

In the event of a merger, acquisition, or sale of all or part of our business, your personal information may be transferred to the new owner. We will provide notice of such transfer and any choices you may have regarding your information. The new owner will be required to honor the commitments made in this Privacy Policy.

We retain data only as long as necessary for providing our services and as required by law.

10. Your Rights and Choices

As a Wealth Sandbox user, you have certain rights regarding your personal data. Depending on your location, you may have additional rights under applicable privacy laws.

General Rights

  • Access and Update: You can access and update your personal data within your account settings
  • Deletion: You have the right to request the deletion of your data
  • Opt-Out: You may opt out of marketing communications and set preferences for how we contact you
  • Data Portability: You may request an export of your data at any time by contacting support@wealthsandbox.com. We will provide your data in a machine-readable format (e.g., JSON or CSV) within 30 days of your request.
  • Cookie Preferences: You have the right to control your cookie preferences at any time, including the ability to withdraw consent for optional cookies

Canadian Residents (PIPEDA)

Canadian residents have rights under PIPEDA, including the right to access their personal information and challenge the accuracy of that information. You may file a complaint with the Office of the Privacy Commissioner of Canada: www.priv.gc.ca or 1-800-282-1376.

EU/UK Residents (GDPR/UK GDPR)

EU/UK residents have additional rights under GDPR/UK GDPR, including:

  • Right to access: Request a copy of your personal data
  • Right to rectification: Correct inaccurate or incomplete data
  • Right to erasure: Request deletion of your data (subject to legal requirements)
  • Right to restrict processing: Limit how we use your data
  • Right to data portability: Receive your data in a machine-readable format
  • Right to object: Object to processing based on legitimate interests
  • Right to withdraw consent: For processing based on consent
  • Right to lodge a complaint: With a data protection authority. For a list of EU data protection authorities, visit edpb.europa.eu. UK residents can contact the Information Commissioner's Office (ICO) at ico.org.uk.

California Residents (CCPA)

California residents have specific rights under the CCPA, including:

  • The right to request information about data collection
  • The right to opt out of data sales—we do not sell your personal information. See our Do Not Sell My Personal Information page for details.
  • The right to request deletion of personal information
  • The right to non-discrimination for exercising privacy rights

Exercising Your Rights

To exercise your rights, please contact us at privacy@duskai.app. For data protection inquiries from EU/UK residents, please include 'GDPR Request' in your subject line. We will respond to your inquiries within 30 days (or as required by applicable law).

You can also access and modify your cookie settings through your account preferences at Privacy Settings.

11. Automated Decision-Making and AI Processing

We do not use your data for automated decision-making or profiling that has legal or significant effects on you without your explicit consent.

Our AI features are powered by third-party AI service providers (Anthropic Claude, OpenAI ChatGPT). When you use AI features, your inputs are sent to these providers for processing; their servers are located in the United States. Our AI services process your data to provide analysis and scenario-based outputs, which are informational and educational in nature. We do not use retrieval-augmented generation (RAG); instead we use on-demand, tool-based access to your scenario data so that only the data needed to answer your question is sent to the AI provider when you ask.

We do not use your personal financial data, scenarios, or AI conversation history to train AI models. We may use anonymized, aggregated usage statistics to improve our Services, but never your specific financial information or identifiable data.

12. Children's Privacy

Wealth Sandbox is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@duskai.app.

We do not set cookies on devices of users we know to be under 13 years of age. Users between 13 and 18 should have parental consent before using our Services.

If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information promptly.

13. Third-Party Services and Links

Our Services may contain links to third-party websites, applications, or services that are not owned or controlled by us. We are not responsible for the privacy practices of these third parties.

Third-party services we integrate with may include:

  • Stripe for payment processing and subscription management (we do not store complete credit card information)
  • Anthropic (Claude) for AI assistant features (Privacy Policy); OpenAI (ChatGPT) for AI assistant features (Privacy Policy)—inputs are processed on their servers in the United States
  • Analytics providers for website performance monitoring
  • Content delivery networks for improved performance
  • Customer support platforms
  • Email service providers

These services may collect information about you according to their own privacy policies. We encourage you to review the privacy policies of any third-party services you access through our platform.

Links to Other Websites: Our service may contain links to external websites. We are not responsible for the privacy practices of these external sites.

14. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the 'last updated' date.

You are advised to review this Privacy Policy periodically for any changes. If we make significant changes to how we use cookies or process your data, we will notify you through our cookie consent mechanism and may request renewed consent.

Material changes will be communicated via email to registered users where required by law. Your continued use of our Services after changes are posted constitutes acceptance of the updated policy.

15. Governing Law and Disputes

This Privacy Policy is governed by the laws of the Province of British Columbia and the federal laws of Canada applicable therein. Any disputes relating to this policy or our handling of your personal data are subject to the exclusive jurisdiction of the courts of the Province of British Columbia.

16. Contact Us

If you have any questions about this Privacy Policy, our cookie practices, or wish to exercise your privacy rights, please contact us:

Dusk AI Inc.

Privacy Inquiries: privacy@duskai.app

Support: support@wealthsandbox.com

For cookie-specific inquiries or to exercise your cookie preferences, you can also reach us at the same email address.

For data protection inquiries from EU/UK residents, please include 'GDPR Request' in your subject line.

We will respond to your inquiries within 30 days (or as required by applicable law).

Thank you for trusting Wealth Sandbox with your financial planning!