Privacy Policy

Last Updated: August 24, 2026

1. Who We Are and Scope

FriedmannAI Inc. ("FriedmannAI", "we", "us" or "our") provides AI-assisted financial-planning software for financial advisors and organizations. We are located at 407 Iroquois Shore Rd., Unit 8, Oakville, Ontario L6H 1M3, Canada.

This Privacy Policy applies to friedmann.ai and its subdomains, the FriedmannAI web application, and related services (the "Platform"). It explains how we collect, use, disclose, retain, and protect Personal Information. Our practices are designed to comply with Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") and other privacy laws that apply to us.

Platform use is also governed by our Terms of Service and any written agreement between FriedmannAI and you or your organization. If a written customer agreement contains different privacy or data-processing terms, that agreement controls to the extent of the conflict.

2. Our Role and Your Organization's Role

For information about our website visitors, account holders, billing contacts, and business relationships, FriedmannAI determines why and how the information is used.

Financial advisors and their organizations determine why Client Personal Information is entered into the Platform and how it is used in their advisory practice. For that information, FriedmannAI acts as a service provider or processor on their behalf. Clients should normally direct privacy requests to their advisor or the advisor's organization first.

Users must have the authority and any consent required by law to enter, upload, connect, or otherwise provide Personal Information about another person through the Platform.

3. Personal Information We Collect

"Personal Information" means information about an identifiable individual, including information that can identify a person when combined with other data. Depending on how the Platform is used, we collect the following categories.

Website and device information

  • IP address, browser, device, operating system, and approximate location;
  • pages viewed, referring pages, timestamps, interactions, and session events;
  • cookies, authentication events, error diagnostics, and security logs.

Account, organization, and billing information

  • name, business email, phone number, role, organization, and profile details;
  • account identifiers, authentication information, preferences, and permissions;
  • subscription, invoice, billing-contact, and transaction information. Payment-card details are submitted directly to Stripe and are not stored by FriedmannAI.

Advisor content and Client Personal Information

  • client identity, contact, household, family, employment, and residency details;
  • income, expenses, assets, debts, taxes, pensions, insurance, estate information, goals, risk preferences, and other financial-planning facts;
  • documents, notes, plans, reports, prompts, conversations, generated outputs, and feedback entered or created through the Platform;
  • insurance quote inputs, which may include age, sex, smoking or health class, province, coverage amount, and product criteria.

Connected accounts and communications

If a User chooses to connect an email or calendar account, we receive the authorization tokens and the messages, attachments, contacts, calendar events, and related metadata needed to perform the action the User requests. Connecting an account is optional and can be revoked through the applicable provider or Platform settings.

Support and business communications

We collect information included in support requests, security reports, meeting requests, surveys, feedback, and other communications with us.

4. How We Collect Personal Information

  • directly from Users, clients, website visitors, and business contacts;
  • from an organization or advisor that creates or manages an account;
  • from documents and information a User uploads or enters;
  • from services a User chooses to connect, such as Google or Microsoft email and calendar accounts;
  • automatically through logs, cookies, analytics, monitoring, and security tools;
  • from payment, scheduling, email-delivery, and other service providers.

5. Why We Use Personal Information

We use Personal Information to:

  • provide, secure, administer, support, and improve the Platform;
  • create and manage accounts, organizations, permissions, and subscriptions;
  • process documents, generate financial-planning outputs, run requested searches or quotes, and perform user-directed email or calendar actions;
  • process payments and send transactional or service communications;
  • measure product usage, diagnose errors, prevent abuse, and investigate security events;
  • send product or marketing communications where permitted by law and consistent with communication preferences;
  • comply with contracts, legal obligations, lawful requests, and regulatory or professional requirements;
  • establish, exercise, or defend legal claims.

We do not sell Personal Information. We do not use Client Personal Information to train or fine-tune FriedmannAI models or generalized models shared with other customers.

6. AI Processing

The Platform sends prompts and only the context needed for a requested feature to commercial AI and document-processing APIs. Depending on the feature, this can include conversation history, selected client facts, document text, images, or audio. The resulting output is returned to the User and may be stored in the Platform as part of the User's workspace.

FriedmannAI does not independently verify every AI-generated output. Users must review outputs for accuracy and appropriateness before relying on them or sharing them with clients. AI providers may retain limited request information for service operation, security, or abuse monitoring under their applicable business or API terms. Their current privacy notices are linked below.

7. Service Providers and Disclosures

We use service providers to operate specific parts of the Platform. A provider only receives the categories of information needed for the applicable service or feature; not every provider receives Client Personal Information for every User. This list reflects our production services as of August 24, 2026.

Application hosting and data infrastructure

These providers host the Platform or store and transmit information needed to operate it.

ProviderPurposeInformation involved
VercelApplication hosting, edge delivery, and server-side runtimeHTTP requests, application content, and operational logs
SupabaseDatabase, authentication, and application storageAccount information, advisor workspace data, and Client Data
IBM CloudObject storage and document-processing infrastructureUploaded documents, generated files, and document metadata
Redis CloudCaching, sessions, rate limiting, and temporary application stateSession identifiers, request metadata, and temporary cached data
RailwayHosting for FriedmannAI-managed memory and service-status componentsAssistant memory data, service requests, and operational telemetry

Artificial intelligence and document processing

These providers process only the information needed to perform the AI or document task requested through the Platform.

ProviderPurposeInformation involved
AnthropicPrimary AI model inferencePrompts, relevant conversation or client context, and generated responses
OpenAIFallback and auxiliary AI model inference, embeddings, transcription, and image generationPrompts, relevant context, documents or media submitted to the applicable feature, and outputs

Optional integrations and research tools

These providers are used when a User connects an account or requests the related feature.

ProviderPurposeInformation involved
ComposioConnection infrastructure for user-authorized email and calendar integrationsConnected-account tokens and the messages, attachments, contacts, or calendar data needed for a user-directed action
TavilyWeb-search results requested through the assistantSearch queries and associated request metadata
COMPULIFELife-insurance quote data and calculationsQuote inputs such as age, sex, smoking or health class, province, coverage amount, and product criteria

Monitoring and product analytics

These providers help us detect errors, secure the Platform, and understand product usage.

ProviderPurposeInformation involved
SentryError monitoring and diagnosticsError events, request and device metadata, and diagnostic context
PostHogProduct usage analytics and feature measurementProduct events, account or organization identifiers, and device or session metadata

Billing, email, and scheduling

These providers process payments and communications or help schedule meetings.

ProviderPurposeInformation involved
StripeSubscription billing and payment processingBilling contact, transaction, and payment information submitted directly to Stripe
Postmark (ActiveCampaign)Transactional and service email deliveryRecipient addresses, message content, and delivery metadata
LoopsLifecycle and marketing email deliveryContact information, communication preferences, and delivery or engagement events
ResendService-status subscription and alert email deliverySubscriber email addresses, message content, and delivery metadata
CalendlyMeeting scheduling on the FriedmannAI websiteContact details, scheduling selections, and meeting information provided by the visitor

Optional email and calendar integrations connect to Google or Microsoft at the User's direction. Information sent to or retrieved from those accounts is also governed by the User's relationship and settings with Google or Microsoft.

We may also disclose Personal Information to professional advisors, insurers, auditors, regulators, courts, law enforcement, transaction counterparties, or other parties when reasonably necessary to operate our business, complete a corporate transaction, comply with law, protect rights or safety, or with the relevant person's consent. These disclosures are limited to the information reasonably necessary for the purpose.

8. International Processing

FriedmannAI is based in Canada, but some service providers process information in the United States and other jurisdictions in which they operate. Information processed outside a person's province or country is subject to the laws of that jurisdiction and may be accessible to courts, law enforcement, or national-security authorities in accordance with local law.

FriedmannAI remains accountable for Personal Information transferred to service providers for processing on our behalf. We use contractual, organizational, and technical measures appropriate to the sensitivity of the information and the service being provided.

9. Security

We maintain administrative, technical, and physical safeguards designed to protect Personal Information against unauthorized access, use, alteration, disclosure, or destruction. These measures include access controls, encryption in transit and at rest where supported, logging and monitoring, vulnerability management, personnel security practices, vendor review, incident response, and business-continuity procedures. FriedmannAI's relevant security controls have been examined in a SOC 2 Type 2 report.

No Internet transmission or storage system is completely secure. Users are responsible for protecting their credentials, using available security controls, and promptly notifying team@friedmann.ai of suspected unauthorized access.

We notify affected customers, individuals, and regulators of a security incident when and as required by applicable law or contract.

10. Retention and Deletion

We retain Personal Information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Platform and meet legal, regulatory, security, accounting, dispute-resolution, and contractual requirements. Retention depends on the category of information:

  • account and workspace data is retained while the applicable account or customer agreement is active;
  • after termination, authorized Users may request retrieval of Customer Data for 30 days, and Customer Data is scheduled for deletion or de-identification from active systems within 90 days;
  • payment, contract, audit, security, and compliance records may be retained for up to seven years, or longer where required by law or a legal hold;
  • provider backups and logs expire according to documented provider schedules and may remain for a limited period after deletion from active systems;
  • aggregated or de-identified information that cannot reasonably identify a person may be retained longer.

A verified deletion request may be refused or limited where retention is required by law, needed to protect another person's rights, necessary for security or fraud prevention, or otherwise permitted by applicable privacy law. When FriedmannAI processes Client Personal Information for an organization, deletion is subject to that organization's instructions and legal obligations.

11. Privacy Rights and Choices

Subject to applicable law, an individual may ask us to:

  • confirm whether we hold Personal Information about them;
  • provide access to that information and an account of its use or disclosure;
  • correct inaccurate or incomplete information;
  • withdraw consent where processing is based on consent;
  • delete information that we are not required or permitted to retain;
  • explain or review a decision about a privacy request.

Requests can be sent to team@friedmann.ai. We may verify identity and authority before responding. We normally respond to access requests within 30 days, subject to extensions and exceptions permitted by law. If a request concerns information an advisor or organization controls, we may refer the request to that organization or work with it to respond.

Marketing email recipients can unsubscribe using the link in the message. Withdrawing consent does not affect processing already completed and may prevent us from providing features that require the information.

Individuals may raise a concern with our Privacy Officer first and may also complain to the Office of the Privacy Commissioner of Canada or the applicable provincial privacy regulator.

12. Cookies and Analytics Choices

We use essential cookies for authentication, security, preferences, and Platform operation. We also use analytics technologies to understand feature use and website performance. Browser controls can block or delete cookies, although essential Platform features may then stop working. Where required by law, we obtain consent before using non-essential cookies.

13. Children's Privacy

The Platform is intended for adults and financial professionals and is not directed to children under 16. We do not knowingly create accounts for or collect Personal Information directly from children under 16. Information about a minor may be entered by an authorized advisor for legitimate financial-planning purposes, subject to the advisor's or organization's legal authority and privacy obligations.

14. Changes to This Policy and Service Providers

We update this Policy and the provider list when our practices change. The date at the top shows the latest revision. We will provide at least 30 days' advance notice by email or a prominent Platform notice before a material change that reduces a User's privacy rights or before a new provider materially processes Client Data, except where urgent security, legal, or operational circumstances make advance notice impracticable.

An organizational customer with a reasonable data-protection objection to a new provider may contact us during the notice period. We will work in good faith to address the concern, including by discussing available configuration options or the customer's right to stop using the affected service under its agreement.

15. Contact Us

Privacy questions, requests, and complaints may be directed to:
Privacy Officer, FriedmannAI Inc.
407 Iroquois Shore Rd., Unit 8
Oakville, Ontario L6H 1M3, Canada
Email: team@friedmann.ai

Privacy Policy - FriedmannAI | FriedmannAI