Privacy Policy

Last updated: October 9, 2026

This Privacy Policy explains how Mount Si Labs LLC (“Mount Si Labs,” “we,” “us,” or “our”) collects, uses, and protects information when you use Summitward (the “Service”).

1. Information We Collect

We collect the minimum information necessary to provide our service:

  • Account information: email address, name (optional), and hashed password.
  • Financial data: net worth figures, asset allocations, portfolio tickers, and configuration preferences you enter into the dashboard.
  • Usage data: page views, feature usage, and error logs for improving the product.
  • Payment information: billing details are collected and processed by Stripe. We do not store your credit card number on our servers.
  • Assistant connections: if you connect an AI assistant such as Meta Muse to your account, we store a fingerprint (hash) of the connection token, never the token itself, along with the name you give it, the permissions you chose, when it was created, when it was last used, when it expires, and a record of which Summit tools it called.

2. How We Use Your Information

  • To provide, maintain, and improve the Summitward dashboard and analysis tools.
  • To authenticate your account and secure your data.
  • To process payments and manage subscriptions via Stripe.
  • To monitor application performance and diagnose errors via Sentry.
  • To analyze usage patterns and improve the product via analytics services.
  • To communicate important service updates, billing notifications, and security alerts.

3. Data Storage and Security

Your financial data is encrypted in transit (TLS) and encrypted at rest at both the database and application layers, so it is stored as ciphertext rather than readable figures. We do not write your individual financial values to our application logs. We do not sell, rent, or share your personal or financial data with third parties for advertising or marketing purposes. Access to decrypted financial data is restricted and limited to authorized personnel for support and operational purposes only.

4. Data Retention

Your data is retained as long as your account is active. You can export all your data via CSV at any time from Settings. Upon account deletion, all data is permanently removed within 30 days. Aggregated, anonymized usage statistics may be retained indefinitely for product improvement purposes. An assistant connection token stays active until you revoke it or it expires (90 days by default); revoked and expired tokens stop working immediately and are deleted with your account.

5. Cookies and Tracking Technologies

We use the following cookies and tracking technologies:

  • Essential cookies: Required for authentication, session management, and security. These cannot be disabled.
  • Analytics cookies: Used by Google Analytics 4 (GA4), PostHog, and Microsoft Clarity to understand how visitors interact with Summitward. These collect anonymized usage data such as pages visited, features used, session duration, and interaction patterns (clicks, scrolls, and mouse movements).
  • Local storage: Used to store user preferences (e.g., dark mode, onboarding state) in your browser. This data never leaves your device.

You can opt out of analytics tracking by enabling “Do Not Track” in your browser settings or by using a browser extension that blocks analytics scripts. Disabling essential cookies may prevent you from using Summitward.

6. Third-Party Services

Summitward uses the following third-party services that may collect or process your data in accordance with their own privacy policies:

  • Stripe (stripe.com/privacy) — Payment processing and subscription management.
  • Google Analytics 4 (policies.google.com/privacy) — Website analytics and usage tracking.
  • PostHog (posthog.com/privacy) — Product analytics and feature usage tracking.
  • Microsoft Clarity (clarity.microsoft.com/terms) — Session recordings, heatmaps, and interaction analytics to improve user experience.
  • YouTube (policies.google.com/privacy): Some Learn guides include videos. Before you press play, the page loads only a thumbnail image from YouTube. Pressing play loads the player from youtube-nocookie.com, and from then on Google's privacy policy applies to that video.
  • Sentry (sentry.io/privacy) — Error monitoring and performance tracking.
  • Google Gemini API (policies.google.com/privacy) — Optional AI insights. When you use the built-in AI insights, summary financial metrics (computed totals, ratios, and growth rates, never your account credentials or transaction history) are sent to Google's Gemini API under our API account, subject to a daily per-user limit. If you supply your own Gemini API key in Settings, these requests are made under your own Google account instead. AI insights are optional and can be disabled in Settings. Gemini can also answer Summit plan questions when you select it with your own key.
  • Anthropic API (anthropic.com/legal/privacy): Optional. Used for Summit plan questions only when you supply your own Anthropic API key. See “Summit plan questions” below.
  • Meta Muse (facebook.com/privacy/policy): Optional. Used only if you connect Muse to Summitward, either through our public connector (no account data) or with a connection token you create in Settings. See “Assistants you connect” below.
  • Google Cloud (cloud.google.com/terms/cloud-privacy-notice): Application hosting (Cloud Run) and database (Cloud SQL).

The “Export to AI” feature is different from the built-in Gemini insights above. It builds a summary of your data in your browser and copies it to your clipboard. Summitward does not transmit that text anywhere. If you then paste it into ChatGPT, Claude, Gemini, or another tool, you share it with that provider under their own terms.

Summit plan questions (beta). The invitation-only Summit feature sends your retirement plan inputs from the simulator (such as ages, spending, contributions, Social Security timing, and allocation), your total investable balance, and your question to the AI provider you select, Anthropic or Google. For a follow-up question it also sends up to five earlier questions from the same conversation and the plan changes proposed for them, but not their results. These requests use your own API key and are governed by that provider's terms. The names you give your accounts and your transaction history are not sent; balances are grouped by account type, such as Roth IRA or taxable brokerage. Summitward stores your questions, the proposed changes, the computation receipts (inputs, assumptions, and simulation results), token counts, and a log of each session so you can review how an answer was produced. Prompts sent to the provider are stored only as fingerprints (hashes), not as text. Your API keys are stored encrypted and are never logged. This history is deleted when you delete your account.

Assistants you connect (beta). Summitward offers two ways to use its tools from an AI assistant such as Meta Muse. The public connector at summitward.com/mcp needs no account and returns only public content: Learn guides, calculators that use the numbers you or the assistant supply, and published market rates. It sends no information about you. If you are invited to the Summit beta, you can also create a connection token in Settings. With that token, the assistant can call Summit tools that read your saved plan (such as ages, spending, contributions, Social Security timing, filing status, and account balances) and run calculations on it. The results of each tool call, including those plan figures, go to the assistant, and the assistant's provider processes them under its own terms and privacy policy, which Summitward does not control. The names you give your accounts and your transaction history are not sent; balances are grouped by account type. Summitward keeps the computation receipts for those calls so you can check any figure the assistant quotes. You can revoke a connection at any time in Settings, and connecting an assistant is optional.

7. Children's Privacy

The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13 without parental consent, we will take steps to delete that information promptly. If you believe a child under 13 has provided us with personal information, please contact us at support@summitward.com.

8. California Privacy Rights (CCPA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):

  • Right to know: You may request disclosure of the categories and specific pieces of personal information we have collected about you.
  • Right to delete: You may request deletion of your personal information, subject to certain exceptions.
  • Right to opt-out of sale: We do not sell your personal information. If this changes, we will provide a “Do Not Sell My Personal Information” link.
  • Right to non-discrimination: We will not discriminate against you for exercising your CCPA rights.

To exercise these rights, contact us at support@summitward.com with the subject line “CCPA Request.”

9. International Data Transfers

Mount Si Labs LLC operates the Service from the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States. By using Summitward, you consent to the transfer of your information to the United States, which may have different data protection laws than your country of residence.

10. Your Rights

You have the right to:

  • Access and export all your data via the Settings page or CSV export.
  • Correct inaccurate data via the Settings page.
  • Delete your account and all associated data.
  • Request a copy of the personal information we hold about you.
  • Revoke any AI assistant connection at any time in Settings.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email or an in-app notification. Your continued use of Summitward after such changes constitutes acceptance of the updated policy.

12. Contact

For privacy-related inquiries, contact us at support@summitward.com.