Privacy Policy

Last updated: August 17, 2026 · Effective: August 17, 2026

This policy explains what Hemisphere collects, why, who else ever sees it, and what you can do about it. It applies to the Hemisphere website and application operated by Arthur Avenue Technologies, LLC.

1. The short version

This summary is here to be read. It is not a substitute for the sections below, and where they differ, they control.

  • We do not sell your personal information, and we never have.
  • We do not show advertising, run advertising trackers, or share your information for cross-context behavioral advertising.
  • We never receive your bank username or password. If you connect a bank, Stripe handles the sign-in end to end.
  • Our application logs are built to exclude your financial details — no amounts, notes, merchant names, balances, email addresses, or phone numbers.
  • You can export everything you have entered, and you can delete your account from Settings.
  • AI features send summaries and, in some cases, transaction descriptions to Anthropic. Your data is not used to train anyone’s models.

2. Who this covers

Arthur Avenue Technologies, LLC (“Arthur Avenue Technologies”, “we”, “our”, “us”) operates Hemisphere, a personal budgeting service. This policy covers the information we handle when you visit our website, create an account, or use the application.

Hemisphere is offered to individuals in the United States who are at least 18 years old. It is a tool for managing your own money. It is not a bank, a broker, an investment adviser, a tax adviser, or a credit-reporting agency, and nothing in the service is a consumer report under the Fair Credit Reporting Act.

This policy does not cover what a third party does with information you give directly to them. When you pay us, Stripe collects your card details under Stripe’s own privacy policy. When you connect a bank, your bank and Stripe handle that sign-in under theirs.

3. What we collect

Information you give us

  • Account details. Your email address, your display name if you set one, and a password. The password is hashed by our authentication provider; we never see or store it in a readable form.
  • The financial information you enter. Budget categories and limits, transactions (amount, date, note, category), income sources and entries, bills, savings goals, accounts and their balances, tags, and any notes you attach to them.
  • Your phone number — only if you turn on SMS notifications, which is optional and Premium-only. It is encrypted with AES-256 before it is stored, and we return only the last four digits to the application.
  • Support messages. What you write to us, and what we write back.
  • Preferences. Theme, language, timezone, notification settings, and your saved dashboard and ledger layouts.
  • Reviews and feedback you choose to submit.

Information from your bank, if you connect one

Bank connections are optional and available on Premium. If you connect one through Stripe Financial Connections, we receive the institution name, the account type, the last four digits of the account number, balances, and transactions (amount, date, and description).

We never receive your bank username, password, security questions, or multi-factor codes. That exchange happens between you, Stripe, and your bank. You can disconnect a bank at any time from the application.

Information we generate or observe

  • Subscription status and a Stripe customer identifier, so we know which plan you are on. We do not store your card number.
  • Application logs for diagnosing errors and detecting abuse. These are deliberately built to carry identifiers and status codes only — a sanitizer strips amounts, notes, balances, account names, institutions, email addresses, and phone numbers before anything is written.
  • Notification records showing that a message was attempted, which template it used, which channel it went through, and whether it was delivered. These never contain the message text, your email address, or your phone number.
  • Security and administrative audit records — sign-in events, permission changes, and actions taken by our staff on an account.
  • Technical request data. Your IP address and browser user agent reach our servers with every request, as they do with any website. We use the IP address transiently to rate-limit abuse; it is held in memory for that purpose and is not written to our database alongside your account.

What we deliberately do not collect

  • Your Social Security number, government ID, or date of birth.
  • Your precise geolocation.
  • Biometric data.
  • Your card number, CVV, or bank credentials.
  • Anything from advertising networks, data brokers, or credit bureaus.

4. Where it comes from

There are only four sources, and you control all of them:

  • You — everything you type into the application or send to support.
  • Your bank, through Stripe — only after you connect it, and only balances and transactions.
  • Stripe — your subscription and payment status, so we know what you are entitled to.
  • Your browser — the technical request data described above.

We do not buy personal information, and we do not receive it from data brokers, advertising networks, credit bureaus, or social media platforms.

5. How we use it

  • To run the service you signed up for and show you your own data.
  • To calculate budgets, balances, net worth, goal progress, and the other figures the app displays.
  • To process your subscription through Stripe and give you the features of your plan.
  • To sync transactions and balances, if you connected a bank.
  • To send the notifications you have turned on, and the transactional messages we must send (receipts, security alerts, renewal notices, and account-deletion confirmations).
  • To provide the AI features described in section 6.
  • To answer your support requests.
  • To keep the service secure — detecting abuse, rate-limiting, investigating fraud, and enforcing our Terms.
  • To diagnose errors and improve reliability and performance.
  • To meet our legal, tax, and accounting obligations.

We do not use your financial information to build advertising profiles, to score you, or to make any decision about you that produces a legal or similarly significant effect. We do not engage in automated decision-making of that kind, and we do not profile you for it.

6. AI features

Some features use AI models operated by Anthropic. Where you are interacting with an AI rather than a person, we tell you so in the interface.

AI features and what data each one sends
FeatureWhat is sentAvailability
The “Fin” budgeting coach and AI chatAn aggregated summary of your finances — totals, category rollups, and goal progress. Not your transaction notes, merchant names, or account names.Premium
Transaction categorization suggestionsThe transaction description only, when our built-in merchant matching cannot categorize it.Premium, optional
Support triage and draftingThe text of your support message and relevant knowledge-base articles.All plans
Display translationAI-generated text being translated. On-device translation runs entirely in your browser, and in that mode nothing is sent anywhere.All plans

What this means for you

  • Your data is not used to train models. Our agreement with Anthropic prohibits it.
  • We do not retain AI conversations. Chat history with the coach lives in your browser, not on our servers. What we do keep is a per-day message count, so we can enforce usage limits.
  • The coach’s long-term memory is deliberately non-specific. It stores qualitative themes — what you are working toward, what tone you prefer — and not amounts, merchants, or account details.
  • AI output can be wrong. It is informational, it is not financial, investment, tax, or legal advice, and it is not a substitute for a licensed professional. See the Terms for the full disclaimer.
  • You can avoid it. The AI features are optional; the budgeting, tracking, and reporting features work without them.

7. Who we share it with

We share your information with the service providers below, each under a written contract that limits them to processing it on our instructions for the stated purpose. This is the complete list.

Service providers who process your information
ProviderWhat they do for usWhat they receive
SupabaseDatabase hosting, authentication, and file storageAll account and financial data you enter or sync, stored under row-level security
VercelApplication hosting, content delivery, and scheduled jobsRequest metadata (IP address, user agent, timestamps) and server logs
StripeSubscription payments, and bank connections via Financial Connections if you enable themBilling details, payment method (held by Stripe, never by us), and — only if you connect a bank — your bank sign-in, which Stripe handles end to end
AnthropicAI features: the budgeting coach, chat, categorization suggestions, and support triageAggregated summaries of your finances, and — for categorization and support — transaction descriptions or the text of your support messages. Not used to train models.
ResendSending transactional and notification emailYour email address and the content of the message being sent to you
TwilioSending SMS notifications, only if you opt inYour phone number and the content of the message being sent to you
Logo.devDisplaying the logo of a bank you have connectedThe institution name only. Never your identity, balances, or transactions.

The only other times we disclose anything

  • When you ask us to — for example, exporting your data or connecting a bank.
  • When the law requires it — a valid subpoena, court order, or legal process. We review every request, disclose no more than it compels, and will notify you unless we are legally prohibited from doing so.
  • To protect people — where we reasonably believe disclosure is necessary to prevent fraud, a security incident, or physical harm.
  • In a business transfer — if the company is acquired or merges, your information may transfer with it. Any acquirer would be bound by this policy for information collected before the transfer, and we will notify you before your information becomes subject to a materially different policy.

8. We do not sell your data

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined by the California Consumer Privacy Act and the other state privacy laws. We have never done either. We have no advertising business, no advertising trackers, and no data-broker relationships.

We also do not use or disclose your sensitive personal information — which for our purposes means your financial account information — for any purpose other than providing the service you asked for and the security and legal purposes in section 5. You therefore do not need to exercise a right to limit its use, because we already operate within that limit.

We do not knowingly sell or share the personal information of anyone under 16. The service is not offered to anyone under 18.

9. How we protect it

We maintain a written information security program with administrative, technical, and physical safeguards appropriate to the sensitivity of financial information. It includes:

  • Encryption in transit and at rest. All connections use TLS. Data is encrypted at rest by our database host. Phone numbers are additionally encrypted at the application layer with AES-256 and a versioned key.
  • Row-level isolation. Database policies enforce that a session can reach only its own rows, so isolation does not depend on application code being written correctly.
  • Column-level restrictions on internal fields, so that even a direct database read from a signed-in browser cannot return our internal notes about an account.
  • Secrets are server-side only. No key that can read another user’s data is ever sent to a browser.
  • Optional two-factor authentication (TOTP), available on every plan at no cost.
  • Session hygiene. Idle sessions are revoked automatically, and you can sign out other devices from Settings.
  • Logged and monitored access. Administrative actions are recorded in an append-only audit trail, and security events raise alerts.
  • Payment isolation. Card details are tokenized by Stripe, a PCI-DSS Level 1 service provider, and never reach our servers.

No system is perfectly secure, and we cannot guarantee that a determined attacker will never succeed. If a breach affects your personal information, we will notify you and the appropriate regulators as required by applicable law, without unreasonable delay.

If you believe you have found a vulnerability, please report it to security@hemisphere.money. We will not pursue legal action against researchers who report in good faith, act in proportion, and do not access, alter, or retain data belonging to anyone else.

10. How long we keep it

Retention periods by type of information
InformationHow long we keep it
Your account and the financial data in itUntil you delete your account
Routine operational logsAbout 30 days
Error and security logsAbout 180 days
Notification delivery records (status only, never content)About 90 days
Support conversationsRetained after account deletion with your identity removed, so we can improve support quality
Security and administrative audit recordsRetained after account deletion, for fraud and abuse prevention
Payment and tax recordsRetained by Stripe and by us as required by financial record-keeping and tax law, typically seven years
Proof of your agreement to our Terms and of subscription consentAt least three years, or one year after your account closes, whichever is longer
Data exports you generateDeleted automatically after a short expiry window

Deleting your account

You can request deletion in Settings. We email you to confirm it is really you, then wait seven days — during which you can cancel — and then delete. Deletion removes your financial data, preferences, and stored files, and cancels any active subscription.

The rows in the table above marked as retained after deletion are the exceptions, and they are narrow: de-identified support content, security audit records, and the payment and consent records we are legally obliged to keep. We do not keep a shadow copy of your budget.

11. Your rights and choices

We extend the following rights to every Hemisphere user, regardless of which state you live in:

Your privacy rights and how to use them
RightHow to use it
Know and accessEverything we hold is visible in the app. Settings → Export produces a complete ZIP archive.
CorrectEdit any record directly in the app, or ask support.
DeleteSettings → Delete account. See section 10.
PortabilityThe same export, in CSV, XLSX, and JSON.
Opt out of sale, sharing, and targeted advertisingNothing to opt out of — we do none of these. See section 8.
Limit use of sensitive informationWe already operate within that limit. See section 8.
Opt out of profilingWe do not profile you for decisions with legal or similarly significant effects.
Withdraw consentTurn off notifications, disconnect a bank, or disable SMS at any time in Settings.
Non-discriminationWe will never degrade your service, raise your price, or deny you a feature for exercising a privacy right.

Making a request

Most rights are exercised directly in the app, immediately and without asking us. If you would rather write to us, email support@hemisphere.money or use the in-app support page. We will respond within 45 days, and will tell you if we need a permitted extension.

We will need to verify that the request is really yours before we act on it, usually by confirming control of the email address on the account. For a deletion request we require confirmation from that address. We cannot fulfil a request we cannot verify.

You may use an authorized agent. We will ask for written proof of their authority and for you to verify your own identity directly.

If we say no — your right to appeal

If we decline your request, we will tell you why. You may appeal that decision by emailing support@hemisphere.money with “Privacy Appeal” in the subject line. A different person will review it, and we will respond in writing within 45 days with our decision and the reasoning behind it. If we deny the appeal, we will give you a way to complain to your state Attorney General.

12. State-specific disclosures

California

In the twelve months before this policy’s effective date we collected the following categories of personal information under the CCPA/CPRA, for the business purposes in section 5, from the sources in section 4, and disclosed them for a business purpose only to the service providers in section 7:

  • Identifiers — name, email address, account identifier, IP address.
  • Customer records (Cal. Civ. Code §1798.80) — phone number, and the financial information you enter or sync.
  • Commercial information — your subscription and purchase history.
  • Internet or network activity — how you use the application, and error logs.
  • Sensitive personal information — your financial account information and account log-in credentials. Used only to provide the service, as described in section 8.
  • Inferences — budget suggestions and spending patterns the app computes from your own data, and shows only to you.

We did not sell or share any category for cross-context behavioral advertising. California residents have the rights listed in section 11 and may designate an authorized agent.

Under California Civil Code §1789.3, you may also contact the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs in writing at 1625 North Market Blvd., Suite N 112, Sacramento, CA 95834, or by telephone at (800) 952-5210.

Colorado, Connecticut, Virginia, Texas, Oregon, Montana, and other states with comprehensive privacy laws

You have the rights in section 11, including the right to appeal a denial, described there. Some of these laws exempt information handled by a financial institution subject to the Gramm-Leach-Bliley Act. Rather than rely on that exemption, we extend these rights to everyone.

Nevada

Nevada residents may direct us not to sell certain personal information. We do not sell it, but you may submit a verified request to support@hemisphere.money.

13. Financial privacy notice

This section is our privacy notice under the Gramm-Leach-Bliley Act. It is delivered to you when you open an account and made available annually thereafter.

What we collect

The nonpublic personal information described in section 3: what you give us on applications and forms, information about your transactions with us, and — if you connect a bank — information from that institution.

What we disclose, and to whom

We do not disclose your nonpublic personal information to anyone except as permitted by law: to the service providers in section 7 who perform services for us under contract, to complete a transaction you requested, with your consent, and as required by legal process.

We do not disclose your nonpublic personal information to nonaffiliated third parties for their own marketing purposes. Because we do not, there is no opt-out for you to exercise — but you may still contact us with any question about this notice.

We have no affiliates with whom information could be shared. If that changes, we will update this notice and give you any opt-out the law then requires before sharing anything.

Former customers

If you close your account, we continue to apply this notice to the limited records described in section 10.

How we protect it

We maintain the safeguards described in section 9, and restrict access to employees and contractors who need it to provide the service to you.

14. Cookies and tracking signals

We use functional cookies only. There are no advertising cookies, no third-party analytics trackers, no advertising pixels, and no session-replay recording on any page of this site or application.

Cookies we set
CookiePurposeLifetime
Authentication sessionKeeps you signed in. Set by our authentication provider and not readable by page scripts.Until you sign out or it expires
LanguageRemembers whether you want English, Spanish, or French.One year
Theme and colour preferenceRenders the app in your chosen appearance without a flash.One year
Interface stateRemembers small layout choices, such as a collapsed sidebar.One year

Stripe sets its own fraud-prevention cookies during checkout, governed by Stripe’s privacy policy. That is the only third party that sets a cookie on our pages, and it does so only on the checkout flow.

Do Not Track and Global Privacy Control

We honour these signals by construction rather than by configuration: there is no cross-site tracking, no sale, and no targeted advertising here to opt out of. A Global Privacy Control or Do Not Track signal therefore does not change how the service behaves, because the behaviour it asks us to stop is behaviour we never had.

15. Children

Hemisphere is not directed to children, and you must be at least 18 to create an account. We do not knowingly collect personal information from anyone under 18. If you believe a minor has given us information, contact support@hemisphere.money and we will delete it promptly.

16. Where your data is processed

Hemisphere is operated from the United States, and your information is stored and processed on infrastructure located in the United States. Our service providers may process limited technical data elsewhere in the course of operating global infrastructure.

The service is intended for use in the United States. If you access it from another country, you are transferring your information to the United States, where privacy laws may differ from your own. We do not currently offer the service to residents of the European Economic Area, the United Kingdom, or Switzerland, and this policy is not written to satisfy the GDPR.

17. Changes to this policy

We may update this policy as the service changes. When we do, we will change the “Last updated” date at the top.

If a change materially reduces your privacy protections or materially expands how we use your information, we will give you notice by email or a prominent in-app notice before it takes effect, and — where the law requires your consent for that change — we will ask for it rather than assume it.

18. Contact us

For any question about this policy, to exercise a privacy right, or to file an appeal:

Arthur Avenue Technologies, LLC

920 Pierremont Dr., Ste 407, Shreveport, LA 71106

support@hemisphere.money

You can also reach us from the in-app support page, which is the fastest route if you are signed in.