cedarwiseHome

Privacy Policy

Effective: August 2026 · Cedarwise is operated by Cedarwise, Inc.

1. Who we are

Cedarwise, Inc. is a Delaware corporation. This policy covers the Cedarwise website (including the free diagnostic, the waitlist, and the blog) and the Cedarwise app, which is in development. Questions and data requests: support@cedarwise.ai.

2. The website and the diagnostic

The diagnostic asks band-level questions about your workplace benefits: ranges and choices, never your name, credentials, account numbers, Social Security number, balances, or exact salary. While you answer, your responses stay in your browser’s session storage under a randomly generated session ID, which is not derived from and is not linked to your identity. When you complete the diagnostic, your answers are stored under that same random ID so we can improve employer coverage. Unfinished questionnaires are never stored. An employer name we don’t recognize goes into our research queue.

If you ask us to email you a copy of your results, we store the address you provide with those results and use it to send you that report and occasional product updates. You can opt out at any time by replying to any message.

We record anonymous usage events keyed to that same random session ID, and aggregate page analytics (visits, referring site, country, device type) that set no cookies and receive no answers or email addresses. We use no advertising trackers or pixels. Data is stored on servers located in the United States with industry-standard security measures; the site is served over TLS.

3. The Cedarwise app (in development)

The app connects to financial accounts you choose to link, through Plaid. It accesses balances, transactions, and holdings to show your financial picture; Plaid access tokens are stored server-side only, and your institution credentials are never held by Cedarwise. We collect your email address for authentication.

AI features (chat, reports, and summaries) run on Cedarwise servers. To generate a response, the relevant portions of your financial data are sent to our AI model provider under API terms that prohibit training on customer content and provide for processing without retention. Credentials and Plaid tokens are never shared with any AI provider.

If product analytics are enabled (you can opt out in the app at any time), we collect anonymous usage events identified by a randomly generated device ID. Your email, account identifiers, balances, and transactions are never sent to our analytics provider.

4. Storage and security

Data is stored on encrypted infrastructure hosted in the United States (AES-256 at rest, TLS 1.2+ in transit). Sensitive values on your device are stored in the iOS Keychain.

5. Retention and deletion

App data is retained while your account is active; deleting your account permanently removes it. Disconnecting a linked account stops future syncs. For website data, email support@cedarwise.ai to access, export, or delete your stored answers or waitlist entry.

6. Third-party services

We use Plaid to connect the financial accounts you choose to link; Plaid’s handling of that data is governed by its own end user privacy policy. We also rely on service providers for cloud hosting and data storage, email delivery, analytics, subscription management, and the AI model features described above. Each receives only what its role requires, acts on our instructions, and none receives data for advertising. These providers process IP addresses as necessary to deliver and secure the service and to maintain short-term operational logs. We do not associate IP addresses with your responses.

7. What we never do

We do not sell your data, share it for marketing or advertising, or move money. AI output in Cedarwise is educational; see the disclaimer below.

8. Changes

Material changes to this policy will be announced by email or in-product notice before they take effect.