Our Privacy Promise
Your financial data is personal. We treat it that way.
"We don't need your sensitive data. We explicitly tell you: don't enter SSNs, account numbers, or bank passwords. Broad strokes are all the math requires. We'll never ask for more because we don't need more."
"No ad network. No third-party analytics. No data brokers. We do count whether setup actually works — on our own servers, with no outside company involved. Your trust is what sustains us."
"Your data is always exportable. If we ever shut down, you leave with everything."
What we store
Only what is necessary to make Enuf work for you:
- Email address (for login and account recovery)
- Hashed password (we never see your actual password)
- Financial-plan inputs (approximate balances, income, spending, goals, and assumptions)
- Simulation results and plan checkpoints
- Chat history (your conversations with the AI advisor)
- Monthly check-ins and streak
- Subscription status and account preferences
- Which setup steps you reached, and browser errors (see “How we measure whether Enuf works” below)
What we DON'T store
We go out of our way to avoid collecting things we don't need:
- Your real name — we never ask for it
- Financial account numbers or transaction history
- Social Security numbers or government IDs
- Bank or brokerage passwords
- Third-party analytics, advertising or cross-site tracking of any kind
- The pages you visit anywhere else on the web
- Data from any external financial account
How we measure whether Enuf works
We need to know whether people can actually finish setting up a plan, and whether the app is breaking in anyone's browser. So we count a short list of steps: the site opened, the setup sentence was started, it was submitted, the dashboard loaded, a result came back, an account was created, a plan was saved. We also record browser errors, so a blank screen reaches us instead of nobody.
These events go to our own servers and nowhere else — no Google Analytics, no PostHog, no Sentry, no advertising or cross-site tracking, and no cookies for any of it. The one exception is Cloudflare Web Analytics, which counts page views and page speed; Cloudflare already serves every page of this site, so no new company sees your visit, and it sets no cookies either.
What is never included: anything you typed, any of your figures, the page addresses you visit (we keep the section of Enuf you were in, never the full link), and any page you visit anywhere else. Timings are stored as ranges like “1–3 seconds”, not exact numbers. Error messages are stripped of anything that looks like an email address or a long number before they are saved.
Events carry a random identifier your browser generates for itself. If you are signed in, they also carry a one-way keyed hash of your account id — not your email, and not the account id itself. It is a different hash from the one used for plan storage, so the two cannot be matched up against each other.
We keep these events for 180 days and then delete them automatically, and they are erased with everything else if you delete your account. If your browser sends “Do Not Track” or Global Privacy Control, we send nothing at all — those are not binding on us everywhere, and we honour them anyway.
Third-party services
We use a small set of infrastructure services. Each has a narrow, specific purpose:
Account deletion
A couple of clicks in Settings. No emails to confirm and nothing to wait for — your account closes there and then, and you are signed out everywhere.
We then keep it recoverable for 30 days, so that a deletion you regret within the hour is not final; contact us inside that window and we can bring it back. After 30 days we erase your email, financial plans, simulations, check-ins, chat history and all associated data for good, and nothing can restore it. Before deleting, you can export everything in JSON format so you leave with your data.
Legal compliance
The human promise comes first, but we also meet the legal bar:
- GDPR – Right to access, rectify, and erase your data. Data export available anytime.
- CCPA – We do not sell personal information. Period. California residents can request full data disclosure at any time.
- No data brokers – We have zero relationships with data aggregators, advertisers, or information resellers.
Questions about our privacy practices? Contact us at privacy@enuf.ai