Auranser Consumer Privacy and Data Protection Policy

Version 1.0 | Effective August 1, 2026 | Last updated August 1, 2026

1. Purpose and scope

This Privacy and Data Protection Policy explains how Auranser Inc. (together with any affiliates it may have) collects, uses, shares, and protects personal information for our consumer products and services in the United States. It covers our core platform features, including financial education, behavioral engagement scoring, personal finance tools, deals and offers, and social features, as well as investment management services you may choose to use. Not all features described in this policy may be available to you at all times; we describe data practices for each category of service so you understand what applies when you use a particular feature.

This policy is designed to comply with United States laws including the Gramm-Leach-Bliley Act and its implementing privacy and safeguards rules (Regulation P, SEC Regulation S-P, and the FTC Safeguards Rule), the California Consumer Privacy Act and California Privacy Rights Act, the Electronic Fund Transfer Act and Regulation E, and the Fair Credit Reporting Act, as well as applicable state consumer privacy laws described in Section 9A.

Related disclosures. This policy is part of a set of privacy and regulatory documents. Consumer privacy documents include our Enrichment Score Disclosure and our Partner Privacy Index, each of which is available at auranser.com/disclosures or upon request at privacy@auranser.com. If you use our investment management features, additional disclosures will apply, including our Wrap Fee Program Brochure (Form ADV Part 2A, Appendix 1), Form CRS (client relationship summary), and the investment advisory agreement, each of which will be provided before you open an investment account. Where any of these documents provide more detail on a specific topic, we reference them from this policy.

This policy is available in accessible formats upon request. We are committed to accessibility and working toward WCAG 2.1 AA conformance.

2. How we maintain this policy

We review this policy periodically and update it as required by applicable law.

3. Interpreting timeframes

Unless stated otherwise, "days" means calendar days. Where a deadline falls on a weekend or United States federal holiday, performance is due on the next business day. "Business days" means Monday through Friday, excluding United States federal holidays. This definition is consistent with the Master User Agreement §14.9 and all other Auranser policy documents.

4. Eligibility and age

Our services are available to individuals age 18 and older who meet eligibility and verification requirements. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided information, contact privacy@auranser.com to request deletion.

We may offer additional services in the future, including deposit accounts, credit products, and services for users under 18. If we do, we will provide you with applicable agreements, disclosures, and privacy notices before those services become available.

5. Information we collect

We have collected the following categories of information within the preceding 12 months, where relevant to your use of our services. We collect personal information directly from you, from your devices and how you interact with our services, from financial institutions and services you connect to your account, and from our financial institution and custodial partners (including identity verification they perform in connection with opening and maintaining your account), and from publicly available sources where applicable.

Identifiers and contact information such as name, address, email, phone number, and date of birth.

Government identifiers where permitted by law for identity verification and compliance, such as driver license, passport, SSN or ITIN.

Financial information. The financial information we collect depends on which services you use. For core platform features, this may include information you provide about your financial goals, budgets, and spending categories. If or when banking products become available, this may also include linked bank and card details, account balances, and transactions. If you use our investment management features, this may additionally include investment objectives, risk tolerance, portfolio holdings, securities transaction history, and account statements provided by our custodial partner. If you subscribe to a paid Auranser plan, we also collect subscription and billing status (such as your plan, billing dates, and payment status) through our payment processor; we do not store full payment card numbers.

Account aggregation data. If you choose to link an external financial account, we use a third-party account aggregation service to retrieve your account and transaction data from your financial institution on your behalf. You authorize this access through the aggregation provider's secure connection interface, and you can revoke access at any time. The aggregation provider operates under its own privacy policy, which governs its collection, use, and retention of your data independently of this policy. We receive from the aggregation provider only the account and transaction data necessary to deliver the features you requested. See Section 8 for details on how we share information with our aggregation provider and Section 9 for your rights to manage or revoke aggregation connections.

Behavioral and usage data such as app activity, device information, log files, and cookie identifiers.

Educational and engagement data such as completion of financial education modules, behavioral finance settings, challenge participation, and behavioral scoring activity.

Customer support information such as messages and notes, and recordings where permitted.

Inferences derived from the above to personalize education, risk controls, and product experiences.

Sensitive personal information limited to what is necessary for identity verification, security, payments, fraud prevention, or required by law.

Images and documents you submit. If you submit images or documents through our platform (such as photos of receipts, bills, or statements), we use a cloud-based document extraction service to convert them into structured data. Submitted images are stored securely within our infrastructure for processing and are deleted when you delete the associated record or your account. We instruct our document processing provider not to retain images beyond the processing session. We store the extracted information, such as merchant names, dates, item descriptions, and amounts. We do not extract or retain payment card numbers or loyalty program details from submitted documents unless you enable optional rewards tracking, in which case we additionally store loyalty program details to help you monitor rewards across programs.

Location-derived data. Certain features may use your device's location services. If you use location-based features (such as mileage tracking), we may receive and store location data you provide or authorize, including coordinates, within our infrastructure. This data is not shared outside our platform except as described in Section 8. If you opt in to enhanced tracking features, we may additionally store location-derived information from submitted documents, such as merchant addresses from receipts. We do not collect background location data or track your device location outside of features you actively use.

Biometric information. We do not collect biometric information.

6. Cookies and tracking technologies

We may use privacy-respecting, first-party analytics tools that we host or control and that do not track you across other websites or apps. We do not use advertising cookies, third-party ad-tech trackers, tracking pixels, or advertising SDKs, and we do not participate in advertising exchanges or data broker networks.

Strictly necessary cookies. We and our service partners use cookies required for authentication, security, session management, and cross-site request forgery (CSRF) protection. These include cookies set during account linking, sign-in flows, and authorization processes with partners such as identity verification, account aggregation, and payment processing providers. These cookies cannot be disabled without breaking core functionality and do not require separate consent.

Opt-out preference signals. We recognize browser-based opt-out preference signals, including the Global Privacy Control (GPC), as valid requests to opt out of the sale or sharing of personal information where applicable under state law. Because we do not sell or share personal information for these purposes (see Section 8), honoring these signals does not change your experience on our platform, but we process them as required by law. Our services do not track users across third-party websites over time, so we do not respond differently to browser Do Not Track signals; we honor the Global Privacy Control as described above.

7. How we use information

We use information to provide, personalize, operate, and improve our services; establish and service accounts; verify identity; prevent fraud; maintain security and integrity; meet legal and contractual obligations; perform analytics to improve education, behavioral features, and user experience; and communicate with you about your account and required notices. If you use our investment management features, we additionally use information to provide investment advisory services, facilitate securities transactions through our custodial partner, and fulfill our fiduciary obligations to you as an investment advisory client.

The primary purposes for each category of information we collect are: identifiers and contact information for account establishment, identity verification, communications, and required notices; government identifiers for identity verification, regulatory compliance, and fraud prevention; financial information for account servicing, transaction processing, and fraud prevention, and additionally for investment advisory services if you use investment features; account aggregation data for delivering the account linking features you request and, where applicable, for verifying financial information in connection with product applications; behavioral and usage data for service improvement, personalization, and security monitoring; educational and engagement data for content personalization, behavioral scoring, and service improvement; and inferences for personalizing education, product experiences, and risk controls.

Behavioral scoring and personalization. We use a behavioral engagement score (the Enrichment Score) to personalize your experience, including educational content and engagement rewards. This score is based on your engagement and verification activity within our platform, not on credit bureau data and not on protected characteristics such as race, religion, national origin, or sex. The Enrichment Score is not a credit score and is not used for credit decisions. Auranser does not use the Enrichment Score in credit decisions and will not do so. See the Enrichment Score Disclosure. As a matter of good practice, Auranser applies protections inspired by FCRA principles, including accuracy processes, consumer access to your score, and the right to dispute score errors (Section 6.2 of the Master User Agreement).

Education content analytics. If you subscribe to financial education content from a third-party content partner on our platform, we use your engagement data, such as which modules you view, complete, or rate, to generate aggregated, de-identified reports about content performance for that partner's subscriber base as a whole. These reports describe group patterns and trends, not individual users, and are only generated when a content partner's subscriber base meets a minimum size threshold sufficient to prevent individual identification. See Section 8 for how this information is shared with content partners.

Sensitive personal information (CPRA §1798.140(ae)). The categories of sensitive personal information we may collect include: (1) government-issued identifiers (Social Security number, ITIN, driver's license or state ID number); (2) financial account information (account numbers, routing numbers, debit card numbers) in combination with required access credentials; (3) account log-in credentials in combination with a password or security question; and (4) location-derived data such as merchant addresses from submitted receipts (only where you enable enhanced tracking features). We do not collect racial or ethnic origin, religious beliefs, genetic or biometric data for identification purposes, health information, sex life or sexual orientation data, or contents of private communications (other than communications you direct to us) as part of our financial services. We do not use sensitive personal information for purposes that require a right to limit under California law beyond what is necessary to provide services, ensure security and integrity, or meet legal obligations.

7A. CCPA/CPRA disclosure summary (§§1798.100, 1798.110, 1798.115)

The following table summarizes the categories of personal information we collect, the sources, business purposes, and categories of third parties to whom we may disclose each category. We do not sell personal information or share it for cross-context behavioral advertising.

Category of PISourcesBusiness/Commercial PurposesCategories of Third Parties To Whom PI Is or May Be DisclosedSold or Shared?
Identifiers (name, email, phone, address, date of birth)You; custodial partnerAccount establishment, identity verification, communications, required noticesService providers; broker-dealer custodian; legal/regulatory authoritiesNo
Government identifiers (SSN, ITIN, driver's license)You; custodial partnerIdentity verification, regulatory compliance, fraud preventionService providers; broker-dealer custodian; legal/regulatory authoritiesNo
Financial information (account balances, transactions, investment data)You; financial institutions; aggregation provider; custodial partnerAccount servicing, transaction processing, fraud prevention, investment advisory servicesService providers; broker-dealer custodian; aggregation provider; legal/regulatory authoritiesNo
Account aggregation dataAggregation provider (on your behalf, from your financial institutions)Delivering account linking features, verifying financial informationAggregation provider (see Section 8 for classification)No
Behavioral and usage data (app activity, device info, log files)Your devices and interactionsService improvement, personalization, security monitoringService providersNo
Educational and engagement data (module completion, challenge participation, behavioral engagement score)Your interactionsContent personalization, behavioral scoring, service improvementService providers; education content partners (aggregated, de-identified only)No
Inferences (derived profiles)Derived from other categoriesPersonalizing education, product experiences, risk controlsService providersNo
Customer support information (messages, notes, recordings)You; your interactions with supportProviding support, resolving disputes, improving service qualityService providersNo
Images and documents you submit (receipts, bills, statements)YouDocument extraction, transaction categorization, optional rewards trackingService providers (document processing; no image retention beyond processing session)No
Location data you provide or authorize (including coordinates and computed results such as trip distances)You; your devicesEnhanced tracking features you enable; service improvementNot disclosed to third parties, except as required by law or legal processNo
Sensitive PI (government IDs, financial account credentials, location-derived data where opted in)You; your devices; custodial partnerIdentity verification, account servicing, fraud prevention, enhanced tracking featuresService providers; broker-dealer custodian; legal/regulatory authorities (location-derived data is not disclosed to third parties except as required by law or legal process)No

Categories of PI disclosed for a business purpose in the preceding 12 months: identifiers, government identifiers, financial information, behavioral and usage data, educational and engagement data, inferences, customer support information, images and documents you submit, and sensitive PI, each disclosed only to the service providers and the broker-dealer custodian necessary to provide the services you use, and to legal or regulatory authorities where required. Location-derived data is not disclosed to third parties except as required by law or legal process. Categories of PI sold or shared: none. We do not sell personal information or share it for cross-context behavioral advertising as those terms are defined under CCPA/CPRA.

8. How we share information

We may share personal information with the following categories of recipients.

Service providers and processors under contract who perform services on our behalf and are bound by confidentiality and data protection obligations. This includes cloud-based document processing services that extract text from images you submit on our behalf and are contractually required not to retain image data beyond the processing session.

Identity verification. Opening a brokerage account requires identity verification and Know-Your-Customer screening under federal law, performed by our custodial partner (Alpaca Securities LLC) in connection with your brokerage account. What we transmit: the identifying information you supply during onboarding: your name, email address, phone number, date of birth, address, government-issued identifier (such as SSN or driver's license number), and, for brokerage account opening, your employment details and investment-profile information (such as employment status, annual income range, net worth range, and investment objectives) as required for suitability and Know-Your-Customer purposes. What is returned: a verification result (confirmed, not confirmed, or needs review) and, where applicable, watchlist-screening status. Auranser does not operate a separate biometric identity-verification service and does not collect or store biometric identifiers (biometric app-unlock, where you enable it, is processed on your device by your operating system and is not transmitted to Auranser). The custodian's data role is described in our Partner Privacy Index.

Broker-dealer custodian. If you use our investment management features, we share information necessary to open and maintain your brokerage account with a registered broker-dealer that serves as the qualified custodian for your securities. When you open an investment account, you establish a separate customer relationship with the broker-dealer custodian. The custodian opens and maintains your account subject to its own customer agreement and privacy policy, issues account statements directly to you, and is regulated by the SEC and FINRA independently of Auranser. Auranser provides investment advisory services as a registered investment adviser; the custodian provides brokerage and custody services. What we send to the custodian: we share with the custodian the information necessary to open your account, execute transactions, and fulfill regulatory requirements, including identity information, investment instructions, and account data. What we receive from the custodian: the custodian returns to us trade execution confirmations, account valuations, portfolio holdings, cost basis data, corporate action notifications, and account statements necessary for us to provide investment advisory services and fulfill our fiduciary and regulatory obligations. Regulatory classification: for purposes of CCPA and applicable state privacy laws, the broker-dealer custodian is a third party with respect to information it collects and uses under its own customer agreement with you, and a service provider with respect to data it processes solely on our instructions to execute advisory-directed transactions. Our Partner Privacy Index, available at auranser.com/disclosures or upon request at privacy@auranser.com, identifies our custodial partner and links to their privacy notice and customer agreement.

Account aggregation provider. If you link an external financial account, we use a third-party account aggregation provider to facilitate the secure connection between your financial institution and our platform. During the account linking process, you interact directly with the aggregation provider's connection interface, which is branded to identify the provider and link to their privacy policy. What we send to the aggregation provider: to initiate and maintain an account link, we transmit to the aggregation provider a unique account token, your Auranser user identifier, and the institution you select. We do not transmit your financial institution credentials; you enter those directly into the aggregation provider's secure interface. What we receive: the aggregation provider returns account and transaction data from your financial institution on your behalf. We do not access your financial institution's systems directly. The aggregation provider may independently collect device and interaction data during the linking flow under its own privacy policy. Regulatory classification: for purposes of CCPA and applicable state privacy laws, the aggregation provider acts as a third party with respect to data it independently collects during the account linking process (such as device identifiers and interaction data), and as a service provider with respect to account and transaction data it retrieves and transmits to us on your behalf under our contractual instructions. The aggregation provider's own privacy policy governs its independent collection, retention, and use of your data. You may manage or revoke your aggregation connections at any time through your account settings or through the aggregation provider's consumer portal. Our Partner Privacy Index, available at auranser.com/disclosures or upon request at privacy@auranser.com, identifies our aggregation provider and links to their consumer privacy policy and data management portal.

Consumer reporting agencies as authorized by you or as permitted by law to service accounts or fulfill regulatory obligations. Access to consumer reports is governed by the Fair Credit Reporting Act and is limited to permissible purposes.

Professional advisors, auditors, and examiners as reasonably necessary.

Legal and regulatory authorities as required by law or to protect rights, safety, and security.

Successors in the event of a business transfer, subject to continued protection of data.

Third-party applications and services you connect. You may authorize third-party applications or services to read information from your Auranser account, such as budgets, goals, or transaction summaries. Connected applications may also send you suggestions or proposed changes, which appear in your dashboard for you to review and accept or decline. You control what each application can access and can revoke access at any time in your account settings. Before any application is connected, we show you the specific data permissions being requested. Third-party applications that connect to our platform are contractually required to meet minimum data protection standards under our integration terms, but their handling of your data after they receive it is governed by their own privacy practices. We may limit the frequency or type of suggestions a connected application can send to protect your experience.

Education content partners. If you subscribe to content from a third-party financial education provider on our platform, that provider may receive aggregated, de-identified information about the engagement and financial wellness trends of their subscriber base as a whole. This information describes group patterns, not individual users, and cannot reasonably be used to identify you. Education content partners do not receive your name, account details, financial information, or individual activity unless you separately and directly share that information with them outside our platform.

We do not sell personal information as defined under the California Consumer Privacy Act or any other applicable state law. We do not disclose personal information to merchants in connection with offers surfaced on our platform. Deal matching is based on purchase goals you set, and merchants do not receive your personal information unless you independently choose to engage with a specific offer. We do not share personal information for cross context behavioral advertising. If our practices change, we will update this policy and provide required notices.

Named service partners. For a complete list of our data traffic partners, including the categories of data each partner may receive, whether their privacy policy applies to you directly or governs only their processing on our behalf, and links to their current privacy policies, see our Partner Privacy Index, available at auranser.com/disclosures or upon request at privacy@auranser.com, updated as partners are added or removed without requiring a revision to this policy.

9. Your privacy choices and rights

Depending on where you live and the services you use, you may have rights to know, access, correct, delete, and receive a copy of personal information, to opt out of certain sharing that is subject to opt out, to limit use and disclosure of sensitive personal information where that right applies, to opt out of profiling or automated decision-making that produces legal or similarly significant effects, and to appeal certain decisions.

How to submit a request: email privacy@auranser.com or call 888-311-9964. You may also submit requests through the Privacy Center in our application when available. We verify your identity before fulfilling requests. Unless a different period is required by law, we target 45 calendar days to respond, with a permitted extension where necessary.

Right to know: categories and specific pieces. You may request to know (a) the categories of personal information we have collected about you, or (b) the specific pieces of personal information we have collected about you. These are distinct request types under CCPA §1798.110(a), and we will fulfill your request based on which type you indicate. If your request does not specify, we will provide both categories and specific pieces.

Authorized agents. You may designate an authorized agent to submit privacy requests on your behalf. If you use an authorized agent, we require the agent to provide one of the following: (a) a power of attorney executed under applicable state law, or (b) your signed written authorization specifically designating the agent to act on your behalf for privacy requests, accompanied by verification of the agent's identity. Even when you use an authorized agent, we may directly verify your identity before fulfilling the request, as permitted by CPRA regulations §7063. To submit an authorized agent request, email privacy@auranser.com with "Authorized Agent Request" in the subject line.

Financial data portability, access, and aggregation management. You have the right to access your financial data and to authorize third parties to access it on your behalf, consistent with applicable law. You may revoke authorizations at any time. Where technically feasible, we provide data in commonly used, machine readable formats or through secure APIs. To request a copy of your financial data or to authorize third-party access, contact privacy@auranser.com or use your account settings.

If you have linked external financial accounts through our account aggregation provider, you may manage those connections, including revoking access or viewing what data is shared, through your account settings within our application. You may also manage connections directly through the aggregation provider's consumer portal. We honor revocations promptly and cease collecting new data from revoked connections. Aggregation connections that remain active may require periodic reauthorization consistent with applicable law and the aggregation provider's policies; we will notify you in advance if reauthorization is needed.

Automated decision-making and profiling. We use automated tools, including behavioral engagement scoring, to personalize your experience. The behavioral engagement score is visible to you in the app, is calculated using transparent, deterministic rules applied to your own engagement data, and does not produce legal or similarly significant effects on your access to financial products or services. Where applicable state law grants you the right to opt out of profiling that produces legal or similarly significant effects, or the right to request an explanation of how automated processing affected your experience or eligibility, you may exercise those rights by contacting us using the methods described above. Specific state rights include:

  • Connecticut (CTDPA), Colorado (CPA), Virginia (VCDPA): You may opt out of profiling in furtherance of decisions that produce legal or similarly significant effects. To opt out, contact privacy@auranser.com or use your privacy settings.
  • Minnesota (MCDPA): You have the right to challenge any profiling decision that produces legal or similarly significant effects. You may challenge the result, receive the reason, correct your data, and request human reevaluation. Auranser will assign the request for human review with authority to change the outcome. We will respond to challenge requests within the same timeframe that applies to other privacy requests, as described above. Contact privacy@auranser.com with "MN Profiling Challenge" in the subject line.
  • Where required by applicable law: Where your state grants a right to human review of consequential decisions that materially affect your access to financial products or services, you may request human review by contacting compliance@auranser.com.

Our Enrichment Score Disclosure, available at auranser.com/disclosures or upon request at privacy@auranser.com, explains what the score is and is not, how it works, the inputs it excludes, and how to request review or correction.

Non-discrimination. We will not discriminate against you for exercising your privacy rights. We will not deny you services, charge you different prices, provide a different quality of service, or suggest that you will receive a different level of service because you exercised a right under applicable law. This is required by CCPA §1798.125(a) and similar provisions in other state privacy laws.

Appeals. If we deny a privacy request in whole or in part, we will explain our reasons. You may appeal the decision by contacting us at privacy@auranser.com with "Privacy Appeal" in the subject line. We will respond to your appeal within 45 days, or the period required by applicable law, and inform you of any further rights, including the right to contact your state attorney general or applicable regulatory authority.

9A. Your state privacy rights

We provide the privacy rights required by the consumer privacy law of your state of residence, where and to the extent that law grants them. As of the effective date of this policy, comprehensive consumer privacy laws are in effect in California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. If additional states enact comprehensive consumer privacy laws during the term of this policy, we will comply with those laws as they take effect.

California (CCPA/CPRA). If you are a California resident, you have the right to: (1) know what personal information we collect and how we use it; (2) request deletion of your personal information; (3) opt out of the sale or sharing of personal information (we do not sell personal information or share it for cross-context behavioral advertising, so no opt-out action is required, but we honor opt-out requests if submitted); (4) limit the use and disclosure of sensitive personal information (we use sensitive PI only for purposes permitted under §1798.121(a) and do not use or disclose it for purposes that would require providing you a right to limit); (5) non-discrimination for exercising your rights; (6) correct inaccurate personal information. Sensitive personal information we collect: government-issued identifiers (Social Security number, ITIN, driver's license or state ID number), financial account information (account numbers, routing numbers, debit card numbers), account log-in credentials in combination with security questions or passwords, and, where you enable enhanced tracking features, location-derived data (such as merchant addresses from receipts). We use this information only as necessary to provide our financial services, verify your identity, prevent fraud, and comply with legal requirements. Authorized agents: You may designate an authorized agent to submit requests on your behalf with appropriate documentation.

Connecticut (CTDPA). You have the right to access, correct, delete, and obtain a copy of your personal data. You may opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects. Universal opt-out: We recognize browser-based universal opt-out preference signals, including the Global Privacy Control (GPC), as valid requests to opt out of targeted advertising and the sale of personal data under Connecticut law.

Colorado (CPA; Colorado AI law effective January 1, 2027). You have the right to access, correct, delete, and obtain a copy of your personal data in a portable format. You may opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects. We recognize universal opt-out mechanisms including Global Privacy Control (GPC). Data protection assessments: We conduct data protection assessments where required by applicable law. Where the Colorado Privacy Act requires it, such assessments are available to the Colorado Attorney General upon request. Colorado AI law: No Colorado AI-specific statute is currently in force. Colorado's automated-decision-making law takes effect January 1, 2027. Auranser will update its practices and this policy as the law takes effect.

Virginia (VCDPA). You have the right to access, correct, delete, and obtain a copy of your personal data. You may opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects.

Minnesota (MCDPA). You have the right to access, correct, delete, and obtain a copy of your personal data. You have the right to challenge any profiling decision that produces legal or similarly significant effects as described in Section 9 above.

Maryland (MODPA). You have the right to access, correct, delete, and obtain a copy of your personal data. Maryland's definition of "sale" includes any exchange of personal data for monetary or other valuable consideration. We do not sell personal information. See Section 8.

Florida (DBOR). You have the right to access, correct, delete, and obtain a copy of your personal data, to the extent applicable.

Other states. If you reside in a state with specific privacy rights not listed here, contact us and we will work with you to address your request consistent with applicable law. We monitor state privacy legislation and will update this section as new laws take effect.

Service provider contracts. Our service provider contracts include the requirements of California Civil Code §1798.100(d) and comparable provisions under other state privacy laws, including: (a) prohibition on selling or sharing personal information received from us; (b) prohibition on retaining, using, or disclosing personal information for purposes other than performing services under the contract; (c) prohibition on combining personal information from us with personal information from other sources except as permitted; and (d) our right to monitor compliance with these requirements.

Privacy Preference Center. We are building a Privacy Center within our application where you can view what data categories we hold about you, manage marketing and communication preferences, submit access, correction, deletion, and portability requests, exercise applicable opt-out rights, and view current data sharing status. Until the Privacy Center is available, you may exercise all rights by email or phone as described above.

10. Marketing preferences

You may manage email and in app marketing preferences in your account or by using the unsubscribe instructions in our messages. Transactional and service communications are required for the operation of your account.

11. Financial privacy notices and advisory disclosures

Auranser is an investment adviser registered with the U.S. Securities and Exchange Commission (CRD# 340833). We comply with applicable state privacy laws. Where the law of your state provides greater protection, we apply that standard for you.

This Privacy Policy serves as Auranser's GLBA initial privacy notice for platform services. Its content addresses the initial-notice requirements of Regulation P (12 CFR 1016) and, for advisory-client information, SEC Regulation S-P (17 CFR 248), including the categories of nonpublic personal information collected and disclosed, categories of affiliates and nonaffiliated third parties receiving such information, and the consumer's right to opt out where applicable. A summary of our information-sharing practices in the federal model-form ("FACTS") format is available in our Financial Privacy Notice.

GLBA financial privacy notice mapping. Different GLBA financial privacy notices apply depending on which Auranser product or service you use:

Product/ServiceGLBA Notice ProviderNotice Location
Investment advisory servicesAuranser Inc. (as RIA)Financial Privacy Notice (auranser.com/financial-privacy-notice)
Brokerage/custody servicesAlpaca Securities LLC (as BD)Alpaca privacy notice, provided at account opening
Platform services (personal financial management, education)Auranser Inc.This Privacy Policy

Each entity's GLBA notice describes that entity's information-sharing practices and your opt-out rights for that relationship. If you use multiple Auranser products, multiple GLBA notices may apply.

Should you enter into an Investment Advisory Agreement with Auranser, Auranser will act as a registered investment adviser and owe you a fiduciary duty under the Advisers Act. Before you open an investment account, we provide you with the Wrap Fee Program Brochure (Form ADV Part 2A, Appendix 1, delivered in lieu of the standard Part 2A brochure, which describes our advisory services, fees, conflicts of interest, and privacy practices for advisory clients), our Form CRS (a client relationship summary), and the investment advisory agreement governing our relationship. We deliver updated brochures annually or when material changes occur. These advisory disclosures describe how we handle information in our capacity as your investment adviser, including information shared with our broker-dealer custodian to service your account. If there is any conflict between the advisory disclosures and this privacy policy regarding the handling of investment account information, the advisory disclosures govern for that information.

12. Automated tools

The Enrichment Score is not used for credit decisions. See the Enrichment Score Disclosure.

If we deploy models or automated tools that influence financial product eligibility or terms, we will apply oversight to help ensure fairness and monitor for unintended bias. You may request information about the principal factors that affected a decision and, where applicable under state law, an explanation of how automated tools were used.

13. Data minimization, retention, and disposal

We collect and retain only what we need for the purposes described in this policy and to satisfy legal, regulatory, tax, accounting, and reporting requirements. The following provides general guidance on retention periods by data category.

Account identification data such as name, contact information, and government identifiers: retained for the life of your account and for at least 5 years after account closure (7 years for tax records), as required by BSA/AML, tax, and other regulatory obligations.

Transaction records including payment and investment activity: retained for at least 5 years (7 years for tax records) as required by BSA/AML, tax, accounting, and reporting obligations.

Investment advisory records including investment advice provided, portfolio compositions, trading records, client communications related to advisory services, and compliance documentation: retained for at least 5 years as required by SEC books and records rules (Rule 204-2 under the Investment Advisers Act), kept in an easily accessible place for the full period, with the first 2 years maintained in an appropriate office of the adviser.

Algorithmic decision records including algorithm decision logs and override audit trails for the advisory algorithm: retained for at least 5 years.

Account aggregation data retrieved from linked external accounts: retained for the life of your account and for up to 2 years after account closure or connection revocation for service improvement and dispute resolution purposes, then deleted. If the CFPB's Personal Financial Data Rights Rule (Section 1033) imposes a shorter maximum retention period for data obtained through authorized third-party access (see Section 9), the shorter period governs and we will delete the data accordingly. If you revoke an aggregation connection, we stop collecting new data from that connection promptly; previously retrieved data is retained per this schedule unless you request earlier deletion.

Behavioral scoring data including behavioral engagement score calculations, factor history, and scoring methodology inputs: retained for the life of your account and for 5 years after account closure; upon a verified deletion request, retained only in de-identified form as described immediately below.

Deletion and de-identification of behavioral scoring data. When you request deletion, we de-identify the behavioral data used in your score, severing the link between your identity and historical score calculations. De-identified data cannot be used to reconstruct your identity or affect any future score. Auranser's own scoring methodology and internal algorithms are proprietary business records and are not subject to a consumer deletion right.

Educational and engagement data such as module completion and challenge participation: retained for the life of your account and for up to 2 years after account closure for service improvement purposes, then deleted.

Behavioral and usage data such as app activity, device information, log files, and cookie identifiers: retained for the life of your account and for up to 2 years after account closure for security and service-improvement purposes, then deleted or de-identified.

Customer support records, including messages and any recordings where permitted: retained for up to 5 years after the interaction, or longer where related to a dispute, claim, or regulatory obligation.

Inferences derived from other categories: retained while the underlying source data is retained, and deleted or regenerated when the source data is deleted.

Subscription and billing data for any paid Auranser plan (such as plan, billing dates, and payment status): retained per the Transaction records schedule above for tax and accounting purposes. We do not store full payment card numbers.

Marketing preferences: retained until you change them, and deleted upon account closure.

Submitted images and documents: extracted data retained per the transaction records or engagement data schedules above as applicable. Source images are stored securely within our infrastructure and deleted when the associated record is deleted or upon account deletion.

Location-derived data: location data you provide or authorize (including coordinates and computed results such as trip distances) retained within our infrastructure for the life of your account and available for export. Deleted upon account closure unless you request earlier deletion. Location data is not shared outside our platform except as required by law or legal process.

Data from closed accounts. If you close your account, we delete your personal information consistent with this retention policy and applicable law.

We securely dispose of personal information when it is no longer needed and no legal retention requirement applies.

14. Security and data storage

Written Information Security Program (FTC Safeguards Rule): Auranser maintains a written Information Security Program ("ISP") that includes administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, use, or disclosure. This Section 14 summarizes the consumer-relevant elements of Auranser's written Information Security Program, which Auranser maintains internally, consistent with the FTC Safeguards Rule (16 CFR Part 314) and SEC Regulation S-P (17 CFR §248.30). We store and process personal information primarily within the United States using data centers operated by SOC 2-audited providers. We do not transfer personal information outside the United States except to provide specific services you request or as disclosed at collection.

15. Incident Response Program and Data Breach Notification

What This Means for You. If we discover that sensitive customer information, such as your Social Security number or financial account numbers, was accessed without authorization, we will investigate promptly, work to contain the issue, and notify you as soon as practicable and no later than 30 days after becoming aware, consistent with SEC Regulation S-P, with details about what happened, what information was involved, and what you can do to protect yourself, including changing your passwords, monitoring your account statements, and placing a credit freeze. If your Social Security number or financial account numbers were involved, we will provide credit monitoring and identity protection services as required by applicable law. We also report qualifying incidents to state attorneys general and other regulators as required by law.

This section summarizes the consumer-relevant elements of Auranser's written Incident Response Program ("IRP"), which Auranser maintains internally under Regulation S-P (17 CFR §248.30). The IRP is designed to detect, respond to, and recover from unauthorized access to or use of customer information, and to provide timely notification to affected individuals and regulators. Regulation S-P does not preempt state breach notification laws; where state law imposes shorter timelines or additional requirements, we comply with the more protective standard.

For purposes of this IRP, "customer information" includes nonpublic personal information as defined in Regulation S-P, investment account data (including trade history, portfolio holdings, and investment preferences), and any category of personal information that triggers breach notification obligations under applicable state law, including, if ever collected, biometric identifiers, health insurance information, and login credentials. "Sensitive customer information" means any component of customer information, alone or in conjunction with other information, the compromise of which could create a reasonably likely risk of substantial harm or inconvenience to an identified individual.

Response Procedures. Upon detection of a potential incident, we assess, contain, investigate, remediate, and notify affected individuals and regulators as described below.

Consumer Notification. For incidents involving unauthorized access to or use of sensitive customer information that has occurred or is reasonably likely to have occurred, we notify affected individuals as soon as practicable and no later than 30 days after becoming aware of the unauthorized access, consistent with Regulation S-P (§248.30). This obligation applies regardless of the number of individuals affected. For purposes of state law compliance, the notification clock begins on the earliest applicable trigger event under each state's law, whether described as "discovery," "determination," "becoming aware," or "notification." We may forgo individual notification only where, after a reasonable investigation, we determine that the sensitive customer information has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience to the affected individual. Our notification to you will include: a description of the incident; the types of information involved; steps you can take to protect yourself, including changing passwords, monitoring account statements, considering a credit freeze, and contacting Auranser support; information about how to contact the Federal Trade Commission and relevant credit reporting agencies; and our contact information for questions. Where the incident involves Social Security numbers or financial account numbers, we will provide affected individuals with credit monitoring and identity protection services as required by applicable law. For incidents involving investment account data, notifications include instructions for reviewing account activity and placing account restrictions through our brokerage partner.

Service Provider Incident Notification. Under Regulation S-P, our service providers are required to notify us as soon as possible after becoming aware that a breach of customer information maintained on our behalf has occurred or is reasonably likely to have occurred, and we seek notification as soon as possible, consistent with SEC Regulation S-P requirements as applicable to us. Upon receiving such notification, we activate our IRP, independently assess the impact to our clients, and issue our own client notifications as required, regardless of whether the service provider issues its own notifications. We promptly notify brokerage and custodial partners of incidents originating in our systems that may trigger their independent regulatory reporting obligations, including applicable FINRA notification, cybersecurity, and business-continuity obligations.

State Attorney General and Regulator Notification. We notify the attorney general or other designated state official in each state where affected individuals reside, concurrent with or before consumer notification as required by the applicable state's law. For states with numerical thresholds, such as 500 or more affected residents, we provide notice when those thresholds are met.

Third-Party and Service Provider Coordination. Our incident response procedures include notification to our brokerage partners (including our custodial partner, whose own regulatory notification obligations may be independently triggered by the same incident) and service providers as soon as reasonably practicable, consistent with SEC Regulation S-P requirements as applicable to us, where an incident may affect their customers, operations, or contractual obligations. Partner-specific notification timelines and escalation procedures are governed by the applicable service agreement. We maintain current contact information for all service providers with access to customer information.

16. Changes to this policy

We may update this policy from time to time. If we make material changes, we will provide notice through our application, by email, or as otherwise required. For material changes to the categories of information we collect, how we share information, or how automated tools affect your experience, we will provide notice in advance and identify the effective date of the change. Where a change would newly permit sharing of nonpublic personal information that gives you a right to opt out under the Gramm-Leach-Bliley Act, we will provide that notice and opt-out opportunity before the change takes effect. Your continued use of our services after the effective date of the updated policy constitutes acceptance of the updated policy.

17. Contact us

For questions about this policy or our privacy practices:

Email: privacy@auranser.com

Phone: 888-311-9964

Mail: Auranser Inc., Attn: Privacy, 3160 Hwy 21, STE 103-873, Fort Mill, SC 29715

This policy is effective as of the date shown above and supersedes all prior versions.