Privacy notice
Your financial workspace stays private to your account.
Effective 18 August 2026. This notice explains the information Qubits Finance uses, the limited providers involved, and the controls available to you during the real-data pilot.
What we collect
- Account and access information, including your email address, profile, plan, approval state and security settings.
- Private portfolio information you choose to enter or import, including holdings, transactions, research notes, reports and notification preferences.
- KiwiSaver planning scenarios you save, including a scenario label, age, income, balance, contribution, retirement, first-home and fund inputs. Use non-identifying scenario labels wherever practical.
- Operational records needed to secure and run the service, such as delivery attempts, audit timestamps and error details.
Why we use it
- To provide the private research, portfolio monitoring, reporting and decision-support features you request.
- To authenticate users, enforce account isolation, deliver requested notifications, prevent abuse and investigate operational problems.
- Qubits Finance is a decision-support tool. It does not place trades and does not provide personalised financial advice.
Document-assisted holdings transcription
- When you explicitly consent in the Holdings import dialog, selected broker screenshots or PDFs are sent to OpenAI to transcribe holdings into structured data for your review.
- The request is sent with provider storage disabled. Limited security or abuse-monitoring logs may still be retained by the provider under its applicable service terms unless a separate zero-data-retention arrangement applies.
- Temporary import files are removed from Qubits Finance Storage after processing. CSV imports are parsed without sending the file to OpenAI.
Qubits research assistant
- When you use the in-app assistant, your question and the minimum necessary results from the Qubits read-only tools may be sent to OpenAI to generate a response. The assistant cannot query the database directly, place trades, move money, write records or fetch arbitrary URLs.
- Qubits Finance does not store the assistant conversation, prompt, answer, audio or transcript in Supabase, application logs, analytics or backups. The browser session is cleared when you clear the conversation or close the page. OpenAI's separate API data controls and abuse-monitoring terms apply to provider processing.
- If voice is enabled for your account, the browser requests microphone permission only after you start a session. Voice sessions are time-limited and are not recorded or stored by Qubits Finance. Qubits makes no New Zealand data-residency claim for provider processing.
Private Portfolio Briefing
- Portfolio Briefing is off by default. If you explicitly opt in, Qubits Finance creates a private, holding-by-holding issue for one portfolio using your current holdings, public market marks, dated Qubits Research context, confirmed corporate-action dates and, only if you choose it, imported Ledger activity.
- The full issue stays behind your authenticated account. If you consent to the current Portfolio Briefing email notice, Resend receives your first name, selected cadence, secure links and four aggregate highlights: holdings reviewed, research coverage, neutral review cues and upcoming events. It receives no portfolio name, ticker, units, values, performance or holding-level detail. Each email includes a one-click unsubscribe link, and you can also switch delivery off from Portfolio Briefing settings.
- Generated issues expire after 120 days. Opting out stops future briefing email and generation but does not delete issues that have not yet reached their expiry date; account deletion removes the remaining owner-scoped records.
Service providers and locations
- Supabase provides authentication, the Tokyo-region database and private object Storage. Vercel hosts the web application. Resend delivers operational and identity email. OpenAI processes document-assisted imports and assistant requests only where you explicitly use or approve those features.
- These providers may process limited information outside New Zealand. We restrict access through owner-scoped authorization, private Storage, server-only credentials and provider-specific controls.
Retention, backups and deletion
- Private records remain while your account is active or as needed to provide the service. Temporary import objects are removed after processing, and report inputs follow their documented purge schedule.
- KiwiSaver scenarios are stored as owner-scoped account records and can be deleted individually or all at once from the planner. An old browser-only workspace is not imported automatically; you can explicitly import it to your account or permanently delete the browser copy.
- You can request account deletion from Account settings. After administrator approval, the erasure workflow removes your private Storage objects and Auth identity, which cascades through owner-scoped database records.
- Older encrypted recovery copies expire under a 30-day rolling retention schedule. A minimal erasure audit is retained to prove completion and the date by which older backup copies expire.
Your choices and contact
- You can correct profile information in Account settings, change notification preferences, decline document processing and request account deletion.
- For privacy questions, access or correction requests, complaints, or an urgent security concern, contact info@qubits.co.nz.
The assistant-specific product terms are available at /assistant-terms. They supplement this privacy notice and do not replace any account or plan terms.
Qubits Solutions Limited is responsible for Qubits Finance during this pilot. Contact info@qubits.co.nz.