DRAFT — PENDING LEGAL REVIEW. This document is an engineering- and product-grounded draft prepared to support a privacy lawyer's review. It has not been reviewed or approved by counsel and is not legal advice. Keel must not publish it until a qualified Canadian privacy lawyer (PIPEDA + Quebec Law 25) has signed off. Items marked [DECISION NEEDED: …] require a business or legal decision before publication.
Keel Privacy Policy
Effective date: [DECISION NEEDED: effective date]
Last updated: [DECISION NEEDED: last-updated date]
Keel helps you see your whole financial picture in one place and understand what your own decisions could mean for your money. To do that, we handle some of your most sensitive information — your transactions, balances, holdings, and debts. We take that seriously. This policy explains, in plain language, what we collect, why, who we share it with, where it goes, and the choices and rights you have.
This policy is governed by Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, for Quebec residents, Quebec's Law 25 (An Act respecting the protection of personal information in the private sector).
A note on what Keel is. Keel is a decision-support tool, not an investment advisor, dealer, or portfolio manager. We are not registered with any securities regulator. Keel shows you the projected consequences of allocations and strategies you choose — "if you do X, here is Y." The decision always stays yours. Keel does not tell you what to buy, sell, or do with your money. This shapes how we use your data, including how we use AI (see §7).
1. Who we are (and who is accountable)
Keel is operated by [DECISION NEEDED: legal entity name] ("Keel," "we," "us"), located at [DECISION NEEDED: business / Quebec mailing address].
We are accountable for the personal information in our care, including information we transfer to the service providers listed in §6 for processing. We require those providers, by contract, to protect your information to a standard comparable to this policy.
Privacy Officer (designated and published — required by Law 25)
We have designated a person responsible for protecting your personal information. You can reach them about anything in this policy — to ask a question, request access to or deletion of your data, withdraw consent, or make a complaint.
- Name / title: [DECISION NEEDED: privacy officer name + title]
- Email: [DECISION NEEDED: privacy officer email]
- Mail: [DECISION NEEDED: privacy officer mailing address]
2. The information we collect
We try to collect only what we need to run Keel for you. Here is everything, by category.
2.1 Account and identity information
- Email address and, if you sign up with a password, a securely hashed password (we never store your password in readable form).
- If you sign in with Google, the identity Google returns to us — your email and name.
- Profile details you provide or that come from your sign-in: your full name, your province, and an optional marginal tax rate and strategy preferences you set in Keel.
2.2 Financial information from your linked bank and investment accounts
When you connect a financial institution through Plaid (see §5), we receive and store:
- Transactions — date, description, amount, currency, and a category.
- Account balances and details — account name, type (for example chequing, TFSA, RRSP, FHSA, RESP, or a mortgage), and currency.
- Investment holdings — your securities, quantities, and cost basis.
- Liabilities / debts — balances on things like credit cards, mortgages, and student loans.
- Recurring charges we detect from your transaction history (for example subscriptions).
To verify accounts and fund balances, Keel also requests Plaid's auth product. Through it, Plaid may transiently return to us account and transit/routing numbers for a linked account. We do not retain those account or transit/routing numbers for our own use — they are not stored as part of your Keel financial record. We hold only the data described above plus the Plaid access token (see §5).
You can also enter accounts and balances manually, or import entries from a screenshot you choose to upload (read by AI and confirmed by you — see §7), in which case that information comes directly from you.
2.3 What we deliberately do not collect
- No Social Insurance Number (SIN). We never ask for or store it.
- No raw bank login credentials. When you link a bank, you enter your credentials with Plaid, not with Keel. We never see or store your banking username or password.
- No government-ID / "identity" profile pulled from your bank. We do not request Plaid's
identityproduct. We only request the banking data we need to run the product (see §5), and we do not retain the account or transit/routing numbers that Plaid'sauthproduct may transiently return (see §2.2).
2.4 Usage and diagnostic information
- Product analytics and performance — when you use Keel on our hosting platform (Vercel), we collect basic, cookieless usage and page-performance measurements (via Vercel Web Analytics and Speed Insights). These do not use tracking cookies and do not build an advertising profile of you.
- Error and diagnostic data — our error-monitoring tool (Sentry) is integrated in the codebase but is inert unless a production error-reporting key (
NEXT_PUBLIC_SENTRY_DSN) is configured. When it is active, every report is scrubbed before it leaves the app: under our current configuration it does not collect your IP address, authentication headers or cookies, or a user identifier. See §6 for detail.
2.5 No anonymous or guest access
Keel does not offer anonymous or guest access — using Keel requires an account. Anonymous sign-in is disabled across the product, and any residual anonymous session left over from earlier testing is signed out automatically and cannot access the product. As a result, Keel does not hold a separate category of "guest" data: everything described in this section is tied to an account.
3. Why we use your information (purposes)
We use each category of information only for the purposes below. We tie purposes to data so you can see the connection.
- Email, password / Google identity — to create and secure your account and sign you in.
- Province, marginal rate, strategy preferences — to run Canada-specific budgeting, tax, and strategy projections for you.
- Transactions — to show your spending and cash flow and group them into categories (with optional AI assistance — see §7).
- Balances and account details — to build your net-worth picture and let you see all accounts in one place.
- Investment holdings — to track your portfolio and project the outcomes of allocations you choose.
- Liabilities / debts — to show what you owe and project the debt and strategy outcomes you ask about.
- Recurring charges — to help you see and label your subscriptions.
- Usage and performance data — to keep Keel reliable and fast and understand which features are used.
- Error / diagnostic data — to find and fix problems.
We will not use your information for a new purpose without telling you and, where required, asking for your consent.
What we do not do: We do not sell your personal information. We do not use it for third-party advertising. And, as described in §7, we do not use it to make automated financial decisions about you or to give you investment advice.
4. Your consent and your choices
4.1 How you give consent
- Linking an institution through Plaid is your express consent for us to import and store that institution's data, for the purposes in §3.
- Signing in with Google is your consent to use that Google identity to authenticate you.
- Entering data manually is consent to store what you enter.
4.2 Necessary vs. optional
Some processing is necessary to run Keel at all — for example, storing your linked transactions so we can show your cash flow. You can't use those features without it.
Other processing is optional in principle and is not bundled into the necessary consent — for example, product analytics, performance measurement, and error diagnostics. Today, the analytics and performance measurement described in §2.4 are cookieless and always on, and Keel does not yet offer an in-product control to turn them off; you can raise any concern with our Privacy Officer (§1). Consistent with Law 25, our intent is to default non-necessary analytics and diagnostics to the most privacy-protective setting and to seek separate, specific consent before activating any non-necessary collection. [DECISION NEEDED: confirm opt-in vs default-on for Vercel Analytics / Speed Insights, and whether an in-product opt-out control ships at launch — align this section with the actual behaviour. Law 25 expects the most privacy-protective option by default and separate, specific consent for non-necessary purposes.]
4.3 Withdrawing consent
You can withdraw consent at any time, and it should be as easy as giving it:
- Disconnect an institution in Keel. We tell Plaid to remove the connection so it can no longer be used, we stop importing new data from it, and — by default — we delete the financial history already imported from that institution (its accounts and their transactions, holdings, and debts). If you would rather keep that history in Keel, the disconnect dialog offers an explicit "keep my imported data" choice; keeping it is an opt-in, never the default. See §8 for exactly what each path retains.
- Delete your account to remove your personal information (see §9).
Withdrawing consent may mean some features stop working — for example, disconnecting your bank removes live transaction syncing.
5. How bank linking works (Plaid)
Keel uses Plaid Inc. ("Plaid") to securely connect to your financial institution. Plaid is a third-party service, hosted in the United States.
- When you link an account, you enter your bank credentials directly with Plaid, not with Keel. We never see them.
- Through Plaid, we request the data we need to run Keel: your transactions (core), plus account/balance details, investment holdings, and liabilities where your institution supports them, and the
authproduct to verify accounts and fund balances. Throughauth, Plaid may transiently return account and transit/routing numbers; Keel does not retain those numbers for its own use (see §2.2). We do not request Plaid'sidentityproduct, and we never receive your SIN or your bank login. - Plaid gives us a secure access token that lets us sync your data. We store that token encrypted at rest using AES-256-GCM encryption (see §10). We never store your bank login.
- Your use of Plaid is also governed by Plaid's End User Privacy Policy, available at https://plaid.com/legal/#end-user-privacy-policy. Please review it to understand how Plaid handles your data.
- You can disconnect an institution at any time in Keel; we then ask Plaid to remove that connection and, unless you explicitly choose to keep it, we delete the data imported from it. See §8.
Plaid is currently the only bank-connection provider Keel uses. If we add another connection provider, we will update this policy before it goes live.
6. Who we share information with (service providers / sub-processors)
We share personal information with the service providers below, only as needed to run Keel, and under contracts requiring them to protect it. Where a provider is located in the United States, your information is transferred outside Canada — see §11 for what that means under Law 25. We do not sell your information to anyone, and we do not share it with data brokers or advertisers.
Active sub-processors
- Supabase — database and user authentication, where your account, profile, and financial data live. Receives all stored account, profile, and financial data. Hosted in Canada (region
ca-central-1). Not outside Canada. - Plaid — connects your bank and syncs transactions, balances, holdings, and liabilities. Receives your linked-account financial data and holds the Plaid access token; may transiently handle account/transit numbers via the
authproduct (not retained by Keel). Located in the United States (outside Canada). - Anthropic (Claude) — AI assistance for categorizing transactions, finding similar funds, and reading rows out of screenshots you choose to import. For transaction categorization: a transaction's description, amount, and currency, plus a small batch of your recent categorized transactions as examples. For fund discovery: only fund-catalog data — no personal financial data. For screenshot import: the image you choose to upload, processed within that request only and not stored by Keel. See §7 for detail. Located in the United States (outside Canada).
- Vercel (hosting) — runs and serves the Keel app. Receives the standard request data needed to serve the app. Located in the United States (outside Canada).
- Vercel Web Analytics + Speed Insights — cookieless usage and performance measurement. Receives aggregate, cookieless usage and page-performance data. Located in the United States (outside Canada).
- Google — "Sign in with Google" authentication. Receives your Google sign-in identity (email, name). Located in the United States (outside Canada).
- Finnhub — market data (quotes and security details). Receives only ticker symbols / search terms — no personal data. Located in the United States (outside Canada).
- EODHD — market data for the research area (price history and dividend schedules), active when its API key is configured. Receives only ticker symbols / search terms — no personal data. Located in the United States (outside Canada).
- Frankfurter — a public exchange-rate API we use to convert values between currencies. Receives only currency codes (for example CAD, USD) — no personal data. Hosted in the European Union (outside Canada).
Conditional sub-processor
- Sentry — error and performance monitoring. Sentry is integrated in our codebase but is inert unless a production error-reporting key (
NEXT_PUBLIC_SENTRY_DSN) is configured. When active, Sentry is a United States sub-processor (outside Canada) that receives technical error and diagnostic context. Under our current configuration that context is scrubbed before it is sent: the SDK is set to not collect default personal information (sendDefaultPii: false), IP addresses, authentication and cookie headers, and user context are stripped from every event, free-text values that look like emails, tokens, amounts, or account identifiers are redacted, no user identifier is attached, and session replay is disabled. [DECISION NEEDED: confirm whether Sentry is turned on at launch; if it stays off, say so here.]
7. How we use AI — and how we don't (automated processing disclosure)
This section matters, so we want to be precise. Law 25 requires us to tell you when we use automated processing on your personal information.
What our AI does. We use an AI service (Anthropic's Claude) for three narrow, helpful tasks:
- Suggesting a category for a transaction (for example "Groceries"). The AI chooses from a fixed list of categories; it can't invent new ones.
- Finding similar funds in our existing fund catalog when you ask it to — surfacing matches, never ranking or recommending.
- Reading rows out of a screenshot you choose to import — for example, a screenshot of transactions, a dividend notice, or a holding from another app. The AI reads the visible rows into draft entries that you review, edit, or discard; nothing is saved unless you confirm it.
What we send the AI, depending on the feature:
- Transaction categorization: the transaction's description, amount, and currency, plus a small batch (roughly 10–20) of your own recent categorized transactions — each as a description, amount, and category — to show the model how you categorize. The AI returns a category drawn from a fixed list, a confidence score, a one-line rationale, and optional tags.
- Fund discovery: only the characteristics of funds in our catalog — no personal financial data.
- Screenshot import: the image you choose to upload. The image exists only inside that request — Keel does not store it.
By default the text-based tasks run on the claude-haiku-4-5 model and screenshot reading runs on the claude-sonnet-5 model (both configurable for cost/quality tuning).
These are suggestions you control.
- An AI-suggested transaction category is only a suggestion. You can change it, and we never overwrite a category you set yourself.
- The fund-similarity feature is information retrieval — it surfaces matches; you decide.
- Rows read from a screenshot are drafts for your review — you can edit or discard any row, and nothing is written to your Keel data until you confirm it.
What our AI does not do — and your right to a human review.
- The AI does not make financial decisions about you. It does not decide your allocations, choose investments for you, or give investment advice.
- Our strategy projections, tax calculations, and dividend forecasts are not AI. They are deterministic, rule-based calculations that show the consequences of allocations you choose. They produce the same result every time from the same inputs.
- The AI features above use automated processing of your personal information to suggest a category or label that you can review and change; they do not place trades, move money, or set your allocations. Regardless of how this processing is ultimately characterized under Law 25, you always have the right to be informed about it, to share your observations with us, and to ask a person at Keel to review or correct any AI-generated suggestion. Contact our Privacy Officer (§1).
Training. Our intent is not to allow your personal information to be used to train third-party AI models, and we configure our use of the AI service to that end. [DECISION NEEDED: confirm and cite Anthropic's commercial-API no-training / data-retention terms for the API tier Keel uses, so this statement can be made specific and verifiable.]
8. How long we keep your information (retention)
We keep your personal information only as long as we need it for the purposes in §3, or as required by law.
When you disconnect or remove an institution: we tell Plaid to remove the connection and we delete the stored access token. By default, we also delete the financial history imported from that institution — its accounts and their transactions, holdings, and debts. Keeping that history is an explicit, informed choice: the disconnect and remove dialogs offer a "keep my imported data" option, and only if you select it does the imported history stay in Keel, as records no longer linked to a live connection that remain part of your financial picture until you delete them or delete your account (see §9).
When you delete your account: we delete your personal information (see §9).
[DECISION NEEDED: set concrete retention periods — e.g., how long history a user explicitly chose to keep after disconnecting is retained if the account stays open; how long backups persist after deletion; any legal/tax record-keeping minimums. Law 25 and PIPEDA require destroying or anonymizing personal information once the purpose is fulfilled, so a defined schedule is required before launch.]
9. Your rights: access, correction, portability, and deletion
You have the right to:
- Access the personal information we hold about you.
- Correct information that is inaccurate or incomplete (you can also edit much of it directly in Keel — for example, recategorizing a transaction or fixing manual entries).
- Portability — receive the personal information you provided to us, or that we collected automatically, in a structured, commonly used technical format (a Law 25 right). This is self-serve: Settings → Export data downloads everything Keel stores about you as a single machine-readable JSON file.
- Deletion / erasure — delete your personal information. This is also self-serve: Settings → Delete account permanently erases your account and all of its data — including any history you chose to keep after disconnecting an institution (see §8) — and tells Plaid to remove your bank connections.
How to make a request: data export and account deletion are self-serve in your settings — no request needed. For anything else — an access question, or a correction you can't make directly in the product — email our Privacy Officer (§1). We will respond within 30 days (the PIPEDA standard), and we will verify your identity first to protect your account.
10. How we protect your information (safeguards)
We use technical and organizational safeguards appropriate to the sensitivity of financial data, including:
- Encryption at rest of your Plaid bank access tokens using AES-256-GCM.
- Encryption in transit (TLS) for data moving between you, Keel, and our service providers.
- Row-level security (RLS) in our database, enforced on every table, so each user's data is isolated and only reachable by that user.
- Tightly controlled administrative ("service-role") access, used only by automated backend jobs, never exposed to the browser.
- No storage of raw bank credentials or your SIN.
No system is perfectly secure, and we don't overstate ours: today our token encryption uses a single key and automated key rotation is planned for a later phase. We continue to improve our safeguards over time.
11. Information that leaves Canada (cross-border transfers + Law 25 assessment)
Your account and financial data are stored in Canada with Supabase, in the ca-central-1 region. However, some processing happens with providers outside Canada — in the United States: Plaid (bank data), Anthropic / Claude (limited transaction data, as described in §7), Vercel (hosting and cookieless analytics), Google (sign-in), Finnhub and EODHD (ticker symbols only, no personal data), and Sentry (scrubbed error diagnostics, if turned on — see §6); and in the European Union: Frankfurter (currency codes only, no personal data). See §6 for exactly what each receives.
This means some of your personal information is transferred outside Quebec and Canada and may be subject to the laws of those jurisdictions — including, for the U.S. providers, lawful-access requests by U.S. authorities.
Law 25 requires us to conduct a privacy impact assessment before transferring personal information outside Quebec, to confirm the information receives adequate protection, taking into account its sensitivity, the purposes, the safeguards in place, and the legal framework of the destination. This assessment is required and will be completed before we serve Quebec residents, and once it is complete this policy will state its conclusion. [DECISION NEEDED: PIA completion — complete and document the cross-border privacy impact assessment, then update this section to state its conclusion before serving Quebec residents.]
12. If there is a data breach
If a confidentiality incident occurs that poses a real risk of significant harm (PIPEDA) or a risk of serious injury (Law 25), we will:
- notify affected individuals and the relevant regulator — the Office of the Privacy Commissioner of Canada (OPC) and, for Quebec residents, the Commission d'accès à l'information du Québec (CAI) — without unreasonable delay; and
- keep a register of confidentiality incidents, as Law 25 requires.
Separately, and as required by PIPEDA (s. 10.3), we keep records of all security breaches involving personal information — not only those that trigger notification — and we will make those records available to the Office of the Privacy Commissioner of Canada on request.
13. Children
Keel is intended for adults who are the age of majority in their province or territory. It is not directed at children, and we do not knowingly collect their personal information.
14. Changes to this policy
We may update this policy as Keel evolves or the law changes. If we make a material change, we will update the "last updated" date and notify you through Keel or by email. The current version is always available publicly, without needing to sign in.
15. Contact us and how to complain
Questions, requests, or concerns? Contact our Privacy Officer (§1).
If you are not satisfied with our response, you may complain to:
- the Office of the Privacy Commissioner of Canada (OPC) — www.priv.gc.ca; and
- if you are a Quebec resident, the Commission d'accès à l'information du Québec (CAI) — www.cai.gouv.qc.ca.
This is a draft for legal review and does not constitute legal advice. A qualified Canadian privacy lawyer must review and approve it before Keel publishes it or onboards a real user.