Skip to content

Finance90 Privacy Policy

Version 2026-10-05 · Effective 2026-10-05

This Policy describes how SAPIENSQ, Inc. collects, uses, stores and shares personal information through Finance90. Where the answer differs by kind of information, it is stated in a table rather than left to inference.

1Who We Are and What This Covers

  1. 1.1

    Finance90, the Finance90 Financial Simulator at finance90.ai, is supplied by SAPIENSQ, Inc., a Delaware corporation (“SAPIENSQ”, “we”, “us”), which is responsible for the personal information collected through it.

  2. 1.2

    SapiensQ Inc. (주식회사 사피엔스큐), a company incorporated in the Republic of Korea, develops and operates Finance90 and processes that information on SAPIENSQ’s behalf, as its service provider.

  3. 1.3

    This Policy applies to finance90.ai, the Finance90 workspace and its API, the simulation-of-record pages and the emails sent about them (the “Service”). It does not cover other SapiensQ websites or products, which have their own notices.

  4. 1.4

    Where you use the Service through an organisation that provisioned a workspace, that organisation decides what is put into its workspace and why. Business Customers and Processing Roles below sets out how its notice and this one fit together.

  5. 1.5

    Where a separate written agreement, order form or data processing addendum applies, it controls to the extent it conflicts with this Policy.

2Information We Collect

  1. 2.1

    We collect information you provide, information generated when you use the Service, and limited information from our service providers:

    • Account information: your name, email address, a hash of your password (never the password itself), your role in the workspace, whether your email address is confirmed, and the identifier Google returns where you sign in with Google.
    • Sign-up and agreement records: the version of the Terms you accepted and when, the plan you chose, the page you came from, and the IP address and browser of the request.
    • Workspace and membership records: the workspace’s name and plan, the email addresses of people you invite, and changes to who is a member.
    • Billing information: plan, billing contact, transaction records, country of residence for tax purposes, and a payment-method token held by Stripe. We do not receive or store complete payment-card numbers.
    • Usage records: the experiments and runs launched, credits used, timestamps and outcomes.
    • Calendar entries: the events you add to the workspace calendar and, if you choose to import from Google Calendar, a year of entries from your calendars — title, dates and times, location and description. We read your calendars only when you ask for an import, with read-only access, and do not keep Google’s access token afterwards.
    • Sign-in and security records: each sign-in attempt and its outcome with the email address used, IP address and browser; your sessions; and the request logs our hosting providers keep.
    • The simulation-of-record email list: your email address, when you asked and when you confirmed, and a keyed hash of the network address the request came from, kept only as evidence of your consent.
    • Support and correspondence: the messages you send us and our replies.
  2. 2.2

    The Service also processes the material you put into it and what it produces from that material: scenario premises, uploaded research documents, experiment configurations, model outputs, deliberation transcripts, reports, run history and credit ledgers.

  3. 2.3

    That material can contain personal information. We do not require it, the Terms restrict it, and we ask you not to submit special categories of personal data, government identifiers, financial account numbers, health records, children’s data or third-party confidential information unless we have agreed in writing to receive them.

3How We Use Information

  1. 3.1

    We use personal information to:

    • provide the Service: create and operate workspaces and run the simulations you launch;
    • authenticate users, enforce seat and plan limits, and record agreement to the Terms;
    • bill for paid plans, determine applicable tax and keep the accounting records the law requires;
    • send the simulation of record and its scorecard to the addresses that asked for them;
    • operate, secure, debug, measure and improve the Service;
    • prevent spam, abuse, fraud, security incidents and misuse of the Service;
    • send the service and administrative messages your account needs;
    • comply with law, enforce the Terms, and protect the rights and safety of SAPIENSQ, our users and the public.
  2. 3.2

    Where the law that applies to you requires a legal basis for processing, we rely on the following.

    PurposeTypical dataLegal basis
    Providing a workspace and running simulationsAccount, workspace content, usage recordsPerformance of a contract; legitimate interests for business users
    Authentication, security and abuse preventionSign-in records, sessions, technical logsLegitimate interests; legal obligation
    Billing, tax and accountingBilling contact, transaction records, country of residencePerformance of a contract; legal obligation
    Simulation-of-record emailsEmail address, request and confirmation times, keyed network-address hashConsent, given by confirming the address and withdrawn by unsubscribing
    Improving the Service and validating methodsAggregated, de-identified or limited usage dataLegitimate interests; consent or separate agreement where required
    Legal, compliance, safety and disputesRelevant records, communications, logs, account dataLegal obligation; legitimate interests; establishment or defence of claims

    Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before it.

4AI Processing and Model Training

  1. 4.1

    The Service sends the material a simulation needs, and the context to act on it, to the model provider listed under Sharing and Service Providers, which processes it to return the output under contractual terms that restrict other use.

  2. 4.2

    We do not use identifiable workspace content to train or fine-tune models for the benefit of other customers, unless you expressly opt in or a separate written agreement provides for it.

  3. 4.3

    We use aggregated or de-identified information to measure quality, validate methods and size capacity. Information used this way no longer identifies a person or a customer, and we do not attempt to re-identify it.

  4. 4.4

    Output is generated by an AI system and is identified as such. The simulated committee members are models built from public information; what they say is neither a statement by nor information about the real officials.

5Sharing and Service Providers

  1. 5.1

    We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose it only as follows:

    • to the service providers below, under contract and only for the purposes we specify, including SapiensQ Inc. as the operator of the Service;
    • to the organisation whose workspace you use, within the visibility its configuration and the roles it grants allow;
    • to regulators, courts, law enforcement and others where required by law or necessary to protect rights, safety, security or the integrity of the Service;
    • to parties to a merger, financing, acquisition, reorganisation or sale of assets, subject to appropriate confidentiality or notice obligations.
  2. 5.2

    The providers the Service currently uses are the following.

    ProviderUsed forTypical dataProcessing location
    VercelDelivery of the finance90.ai web applicationIP address, request metadata, session cookieUnited States and other provider-operated locations
    Google CloudThe application’s backend, its scheduled jobs and their logsAccount records, workspace content and usage records in processing; request logsUnited States
    SupabaseManaged Postgres holding Finance90’s dataAccount, workspace, billing references, sign-in and email-list recordsUnited States
    Google (Gemini)The models that run the simulated committeeScenario material, documents and context sent to the modelProvider-operated locations
    Google (Sign-In)Authentication where you choose to continue with GoogleEmail address, account identifier, sign-in metadataProvider-operated locations
    Google (Calendar)Reading your calendars when you ask for an importCalendar entries, read-onlyProvider-operated locations
    StripePayment processing and tax determinationBilling contact, payment-method token, transaction and location dataUnited States and other provider-operated locations
    ResendAccount, confirmation and simulation-of-record emailEmail address, message content, delivery metadataUnited States and other provider-operated locations

    Each simulation of record is also entered in Sigstore’s public transparency log as a hash, so anyone can check it has not changed. The hash and the record it identifies contain no personal information. We will update this table when the set of providers changes.

6International Transfers

  1. 6.1

    Finance90 is hosted in the United States. SapiensQ Inc. accesses Finance90 personal information from the Republic of Korea to develop, operate and support the Service on SAPIENSQ’s behalf, and some providers above process it in other countries.

  2. 6.2

    Transfers are made only on a basis permitted by the law that applies to them, which may include contractual protections such as standard contractual clauses, the consent or notice Korean law requires for overseas transfer, vendor due diligence, or another mechanism applicable law recognises.

  3. 6.3

    Countries receiving the information may have data protection laws different from those where you live. You may contact us for more about the safeguards applied to a particular transfer.

7Cookies and Similar Technologies

  1. 7.1

    The Service sets only the cookies and browser storage it needs to work: the session cookie that keeps you signed in, the short-lived security values a sign-in with Google needs, and two preferences — your light or dark theme, and whether the sidebar is collapsed.

  2. 7.2

    We do not use analytics, advertising or other non-essential cookies. If we add any, we will update this Policy and provide the consent or opt-out controls applicable law requires.

  3. 7.3

    We do not currently respond to browser “Do Not Track” signals, because there is no common standard for them.

8Retention

  1. 8.1

    We keep personal information only as long as reasonably necessary for the purpose it was collected for. The periods below apply unless the law or an order form requires a longer one.

    InformationRetention
    Account and workspace recordsFor the life of the account, then deleted or anonymised after closure
    Sign-up and agreement recordsFor the life of the account and for the period a claim about the agreement can be brought
    Experiment configurations, uploaded documents, run history and reportsFor the life of the workspace, exportable for up to 30 days after closure
    A workspace’s data left behind when it moves to another kind of storageDeleted automatically 30 days after the move
    Sign-in records90 days
    Simulation-of-record email listUntil you unsubscribe, or the address bounces or reports a message as spam. An address never confirmed is deleted once its 48-hour confirmation link has expired
    Billing and tax recordsFor the period required by tax and commercial law
    Security and technical logsFor as long as needed for security, debugging, reliability and legal purposes
    Aggregated or de-identified informationMay be retained indefinitely, as it no longer identifies a person

    We may retain information longer where reasonably necessary for legal, security, accounting, audit or dispute-resolution purposes. When a retention period ends, we delete the information or place it beyond use.

9Security

  1. 9.1

    We protect personal information with administrative, technical and organisational measures, including encryption in transit, role-based access control, workspace separation enforced in the database, restricted internal access, secrets kept in a managed secret store, and logging.

  2. 9.2

    No online service can be guaranteed to be completely secure. You are responsible for keeping your credentials confidential.

  3. 9.3

    If a security incident affects personal information and applicable law requires notice, we will notify affected individuals, customers, regulators or other parties within the period that law requires.

10Your Rights and Choices

  1. 10.1

    Depending on where you live, you may have the right to request access to your personal information, correction, deletion, a copy in a portable form, restriction of or objection to processing, withdrawal of consent, information about how we disclose it, and to complain to a supervisory authority.

  2. 10.2

    To make a request, contact finance90@sapiensq.com. We may need to verify your identity before acting, and we will respond within the period applicable law requires. Where we decline a request we will tell you why and how to appeal.

  3. 10.3

    Every simulation-of-record email carries a link that unsubscribes you in one step, and unsubscribing deletes your address from the list.

  4. 10.4

    Where an organisation provisioned your workspace, we will refer a request about that workspace’s content to the organisation and help it respond. We will not delete an organisation’s records at one user’s request without its instruction, unless applicable law requires us to.

  5. 10.5

    We will not discriminate against you for exercising a privacy right.

11Business Customers and Processing Roles

  1. 11.1

    For material an organisation puts into its own workspace, the organisation is the controller, or in Korean terms the personal information controller, and we act as its processor on its instructions.

  2. 11.2

    For the information we need to run the Service itself — registration, authentication, billing, security, support and the simulation-of-record emails — we are the controller and this Policy describes that processing.

  3. 11.3

    A data processing addendum, including the terms for sub-processing and international transfer, is available to eligible business customers on request. Where one is executed, it governs the processing it covers.

12Automated Decision-Making

  1. 12.1

    We do not use account or usage records to make solely automated decisions producing legal or similarly significant effects about a person.

  2. 12.2

    Simulation output describes a simulated committee and its scenario, not a person. We use automated signals to detect abuse, fraud and plan misuse; they can lead to a review or a request for evidence, and a person reviews the case before an account is closed for misuse.

13Children

  1. 13.1

    The Service is not directed to children, and account holders must be at least 18 years old. We do not knowingly collect personal information from a child, and we do not process the personal information of children under 14 within the meaning of the Korean Personal Information Protection Act.

  2. 13.2

    If you believe a minor has given us personal information, contact us so we can review it and delete it where appropriate.

14Regional Notices

  1. 14.1

    The following apply only where the corresponding law applies to SAPIENSQ or to your use of the Service.

  2. 14.2

    Republic of Korea. This Policy is the personal information processing policy for Finance90. It states the purposes of processing, the items processed, retention and destruction, provision to third parties, entrustment of processing, overseas transfer, the rights of data subjects and how to exercise them, and our safety measures. You may also raise a dispute with the Personal Information Dispute Mediation Committee, the Korea Internet and Security Agency privacy call centre, or the Personal Information Protection Commission.

  3. 14.3

    European Economic Area, United Kingdom and Switzerland. The legal bases we rely on are in the table under How We Use Information. You have the rights described under Your Rights and Choices, including the right to object to processing based on legitimate interests and to complain to your local supervisory authority.

  4. 14.4

    United States. The categories of personal information we collect, their sources and purposes, the categories of recipient and our retention practice are described above. We do not sell personal information or share it for cross-context behavioural advertising, and we do not use sensitive personal information for purposes that require a right to limit. Residents of California and of states with comparable laws may exercise those rights by contacting us.

  5. 14.5

    Other regions. Where local law grants rights relating to notice, consent, access, correction, deletion, withdrawal of consent, overseas transfer or complaint handling, we will honour them as that law requires.

15Changes to This Policy

  1. 15.1

    We may update this Policy to reflect changes in the Service, our providers or applicable law. The version and effective date are stated at the top.

  2. 15.2

    Where a change materially affects how we process personal information, we will give notice by email, through the Service or by another method applicable law accepts, and where consent is required we will obtain it before the change applies to you.

16Contact

  1. 16.1

    Privacy questions and requests may be sent to the address below, which is the contact point for the person responsible for personal information protection for Finance90.

    • Legal name: SAPIENSQ, Inc.
    • Place of incorporation: Delaware, United States
    • Email: finance90@sapiensq.com
    • Operated by: SapiensQ Inc. (주식회사 사피엔스큐), Republic of Korea