Privacy Policy
What data Sovereign HNI (operated by Confiable Tech, DIFC, Dubai) collects, why, where it goes — including what each AI provider receives and when — how long it is kept, and the rights you have over it.
1. Who is responsible for your data
The data controller is Confiable Tech (DIFC, Dubai), a company registered in the Dubai International Financial Centre, Dubai, United Arab Emirates, which operates Sovereign HNI at sovereignhni.com. Privacy requests: admin@sovereignhni.com.
Pending counsel review: the full registered office address will be published here. We have not appointed a Data Protection Officer, and we have not appointed a representative in the EU or the UK under Article 27 GDPR / UK GDPR; whether either is required for a DIFC controller serving EU and UK residents is part of the review. We do not claim to have them.
2. What we collect
- Account data — your email address, a hashed password held by our authentication provider (Supabase), and any profile information (name, avatar) returned by an OAuth provider you sign in with (Google). We also record the date and version of the Terms and Privacy Policy you accepted.
- Portfolio data — everything you enter or import: holdings, units, prices, currencies, purchase dates, notes, business and real estate metadata, loans you have made, liabilities, income streams, expenses, your watchlist, transactions, and hourly snapshots of all of the above over time.
- Preferences — display currency, tax residence, nationality (if set), timezone, digest schedule and delivery address, theme and layout choices.
- Connection data — read-only exchange and broker API keys you choose to add (encrypted at rest), the read-only Flex Web Service token and query id for Interactive Brokers, the identifiers SnapTrade issues for a broker you sign in to through it, bank-linking access tokens issued by Plaid / Salt Edge / Lean (all encrypted at rest), public wallet addresses you add, and the positions and balances we sync from those sources.
- Second Brain — notes, tasks, goals, journal entries, contacts and files you save, the groups they are sorted into, and the memories the Hermes assistant keeps about your preferences (you can view, edit and forget them in the Hermes tab).
- Presence and sovereignty inputs — the countries and date ranges you log in the days-in-country tracker, and your answers to the Sovereignty Index questionnaire (citizenships, residences, banking jurisdictions, and similar).
- Assistant conversations — messages you exchange with Hermes in the app or over Telegram, and, if you link the Telegram bot, your Telegram chat identifier.
- Transient uploads — screenshots you import, travel documents you scan, and voice clips you record. They are processed in memory to produce the result and are not written to our database; the extracted proposals (holdings, stays, text) are.
- Operational data — request logs (timestamp, route, status code) and error reports (stack traces, page URL, browser type). We do not attach holdings or balances to error events.
3. What we don't collect
- We do not run marketing or advertising trackers, on the dashboard or on this site.
- We do not use Google Analytics, Meta Pixel, or similar third-party analytics.
- We do not collect device fingerprints beyond what your browser sends with normal HTTP requests.
- We do not collect precise location. The presence tracker records only the countries and dates you enter.
- We do not knowingly collect data from anyone under 18. Sovereign HNI is a financial tool for adults and is not directed at children.
4. Why we use it, and the legal basis
Under the DIFC Data Protection Law 2020 and, where they apply to you, the GDPR / UK GDPR, each purpose needs a lawful basis. Ours are:
- Providing the service you signed up for (performance of a contract) — storing your portfolio, rendering charts, taking snapshots, running the tax engine on your numbers, syncing connected accounts, answering your questions in Hermes, generating the Monitor brief, and the Second Brain features you use.
- Opt-in deliveries (consent, withdrawable at any time in Settings) — the daily brief and weekly digest by Telegram or email, Telegram linking, and every exchange, bank or wallet connection you add.
- Keeping the service secure and working (legitimate interests) — request logs, error reporting, rate limiting, abuse prevention.
- Legal obligations — responding to valid legal process, keeping the record that you accepted the Terms.
We do not use your data for marketing, profiling, advertising, or training AI models — ours or anyone else's — and we make no decisions about you by solely automated means that have legal or similarly significant effects. Tax and relocation outputs are models you run; nothing acts on them.
5. Where your data goes: every provider, what they receive, and when
We do not sell your data and never will. The list below is the complete set of third parties that can receive data from Sovereign HNI, with the trigger for each transfer. “Automatic” means it happens without you asking for it in the moment.
- Supabase (database and authentication; hosted in Frankfurt, EU) — all account and portfolio data at rest, encrypted; login sessions; confirmation and password-reset emails.
- Render (backend API; Frankfurt, EU) and Vercel (frontend; global edge network) — process every request you make.
- Anthropic (Claude models; United States) — the AI provider behind Hermes, the Monitor desk and the Second Brain features. What is sent, and when. Nothing is sent to Anthropic automatically or on a schedule unless you have switched on “Automatic AI analysis” (Settings, or the “Enable AI desk” card on the Monitor). It is off by default for every account, including accounts created before this setting existed, and you can switch it off again at any time — it takes effect immediately and any stored AI-written brief is discarded. The flows marked opt-in below only run while it is on; everything else runs only when you press the feature yourself.
- Hermes chat (in the app, over Telegram, or from an agent you connect via MCP) — on every message: your message and recent conversation, your full holdings list (names, tickers, units, live prices, values, section), all liabilities, live net worth with 24h and 30d changes, and up to eight Hermes memories relevant to the question. The whole portfolio is sent regardless of what you asked, because Hermes needs the identifiers to act on it.
- Monitor AI brief — opt-in (Automatic AI analysis), then automatic: when you open the Monitor tab, and again roughly every 45 minutes while it stays open (sooner on a market-regime flip or a net-worth move over 1.5%, or when you press Regenerate). While the setting is off the Monitor shows only figures computed on our own servers (your 24h P&L and what drove it) and nothing is sent. Sent when on: net worth and its 24h / 30d change, asset mix, your eight largest holdings with tickers and values, total liabilities, tax residence, nationality, watchlist tickers, the titles of your goals, open tasks and last week's notes, your saved digest preferences and feedback (free text, exactly as you gave it to Hermes), prior briefs, and public market data. No chat is needed to trigger this once the setting is on.
- “From your Second Brain” feed on the Monitor — opt-in (Automatic AI analysis), then automatic when you open the Monitor and your Second Brain has changed since the last run: your group names and the titles and tags of your 40 most recent notes, so topics can be extracted. Those topic names are then used as search terms against Google News (see below). You can mute topics; muted ones stop being searched. While the setting is off no topics are extracted; topics you type in by hand are still searched.
- Daily brief — opt-in, then automatic on your schedule, whether or not you are logged in: the same context as the Monitor brief. It is written by the AI only while Automatic AI analysis is on; with it off, a scheduled brief is a numbers-only version composed on our servers and nothing goes to Anthropic.
- Weekly digest — opt-in, then automaticon your chosen weekday, whether or not you are logged in: your net worth and its change over the week, the week's trades (type, name, ticker, value and date), the titles of tasks you completed, how many notes you filed, the week's daily-brief headlines, your watchlist tickers with their performance, and your saved digest preferences and feedback. Like the daily brief, it is AI-written only while Automatic AI analysis is on (otherwise a numbers-only version). Both can also be pulled on demand by an agent you connect via MCP — the same setting applies to those pulls.
- Second Brain — when you press the button: Ask (your question and the notes that match it), Auto-sort, Consolidate and Recolor (note titles and short snippets, group names).
- Screenshot import — when you upload: the image, plus your current holdings and section names so the result can be reconciled with what you already hold.
- Presence import — when you upload: the boarding pass or itinerary image, or the location strings from a calendar file.
- Citizenship desk — when you ask: your question and the applicant details you type.
- Desk track record— nightly, only while Automatic AI analysis is on: the desk's own past forecast statements and public market data, to grade them. No portfolio data.
- OpenAI (Whisper speech-to-text; United States) — only when the voice feature is enabled and you use it: the audio clip you record in the Second Brain ask bar or send as a Telegram voice message, to turn it into text. Nothing else.
- Resend(transactional email; United States) — only if you opt into email digests: your digest email address and the email body, which contains the brief's headline and summary and your net-worth movement.
- Telegram — only if you link the bot: your Telegram chat identifier, the messages you exchange with Hermes there (including whatever portfolio detail Hermes answers with), and opt-in digests. The Signals panel reads public Telegram channels and sends nothing about you.
- Sentry (error monitoring; United States) — crash reports and stack traces from the site and the API, the page URL and browser type, and a 10% sample of performance timings. We do not attach holdings or balances to error events and do not enable session replay.
- CoinGecko and Yahoo Finance (price data) — ticker symbols only, fetched in batches across all users with no account identifier.
- Google— Google News RSS receives search queries made of the country names on your Monitor exposure map and the topic names extracted from your Second Brain (see above), with no account identifier. The Monitor's Live TV panel embeds YouTube players; while it is showing, they load from youtube.com and set Google's cookies in your browser.
- Open-Meteo (weather) — the coordinates of the capital cities of the countries on your Monitor map. No account identifier.
- CitizenX (citizenship-by-investment quotes) — only when you request a quote: applicant count, roles, ages, nationalities and routes you enter. Anonymous; no account identifier.
- Exchanges, brokers, banks and blockchain data providers — only for connections you add. Exchange/broker API keys you supply are used against that provider's API to read balances; for Interactive Brokers that is the Flex Web Service, which can only return the report you configured (open positions and cash). Brokers you connect through SnapTrade work differently: you sign in on the broker's own page (or in SnapTrade's window), SnapTrade holds that broker session, and we receive an opaque user id plus your positions, balances and account names — never your broker password or 2FA. SnapTrade learns which broker you use, under an opaque id, not your email. Bank links go through Plaid (US), Salt Edge (EU) or Lean (MENA): you authenticate on their widget, we receive balances and an access token. Public wallet addresses you add are sent to the chain-data services needed to read them: Bitcoin — mempool.space; Ethereum and other EVM chains — Alchemy (or Infura / public JSON-RPC endpoints when Alchemy is not configured), Zerion, and the relevant DeFi protocol APIs (e.g. Aave, Morpho); Solana — Shyft, the Solana public RPC (or a dedicated provider such as Helius when configured), Alchemy, and DeFi protocol APIs (e.g. Jupiter, Kamino, Raydium, Orca, Meteora, Solend, marginfi); Hyperliquid — Hyperliquid's API. All connections are read-only.
- Your own AI agent — only if you create a personal access token in Hermes → Connections: whatever your agent requests over MCP, within the scope you granted (read, or read+write). You control and can revoke the token.
- Stripe — not yet in use. When paid tiers open, card details will go directly to Stripe and never touch our servers; this page will be updated first.
We will disclose data to authorities only if compelled by a valid legal process, and only the specific data scope demanded. If we receive a subpoena or court order targeting your account, we will notify you unless legally prohibited from doing so.
6. International transfers
Your data at rest lives in the EU (Supabase and Render, both in Frankfurt). The controller is in the DIFC. The AI, email and error-monitoring providers above process data in the United States, and Vercel serves the site from edge locations worldwide. Each processor is bound by its standard data-processing terms; the specific transfer mechanism to rely on for EU and UK residents (the DIFC is not on the EU adequacy list) is a pending counsel item and will be stated here once settled. If you do not want any US-based processing of your portfolio, do not use the Hermes, Monitor brief, Second Brain AI, digest or voice features — everything else works without them.
7. How long we keep it
- Account, portfolio, Second Brain, presence and preference data — for as long as your account exists. Deleting your account removes it from the live database immediately and from backups within 30 days.
- Net-worth snapshots — hourly for the last 7 days, daily beyond that, kept indefinitely. The nightly pruner keeps the first snapshot of each older day and deletes the rest.
- Per-holding value history — the same rule, except the rows created by your own edits are never pruned.
- AI briefs— the cached brief is replaced within 45 minutes; delivered briefs are archived into your Second Brain, and the desk's graded forecasts are kept as your track record, both for the life of the account.
- Assistant conversations — the last 20 messages of an in-app chat are held in server memory only, for context, and are not written to the database (Telegram keeps its own copy of messages exchanged there). Hermes memories are kept for the life of the account; you can delete them individually in the Hermes tab.
- Connection data — kept while the connection exists. Removing a connection deletes its keys or tokens and everything it synced immediately, and a SnapTrade connection is revoked at SnapTrade at the same time. Exchange and broker syncs run every six hours from one fixed address (5.75.170.180) so you can restrict your keys to it.
- Transient uploads (screenshots, travel documents, voice clips) — not stored; processed and discarded.
- News pool — the shared, non-personal Wire keeps 30 days of stories.
- Demo sessions — deleted automatically after 24 hours.
- Terms acceptance record — for the life of the account, plus as long as needed to evidence it.
- Bug reports you send — stored with your account id for the life of the account (deleted with it, included in your export). A report contains only what you typed plus the technical details the form shows you before sending (page, browser, last failed request) — never your amounts or holdings — and is emailed to our team through Resend.
- Operational logs and error reports — request logs for a short rolling window at our hosting provider; error events at Sentry for 90 days.
8. Cookies and browser storage
Sovereign HNI uses your Supabase login session (a first-party cookie) and stores UI state — theme, sidebar state, privacy mode, collapsed sections, tour progress and similar — in your browser's local and session storage. We do not use tracking, advertising, or analytics cookies. The only third-party cookies come from YouTube players on the Monitor's Live TV, and only while that panel is showing.
9. Your rights and how to use them
Under the DIFC Data Protection Law 2020 (Articles 32–40) and, where they apply, the GDPR / UK GDPR (Articles 15–22), you can:
- Access and port — download your full dataset as JSON at any time from Settings (this is your Article 15 / 20 right, self-served).
- Rectify — every field on every record is editable from the dashboard.
- Erase — delete your account and all associated data from Settings. Deletion is immediate and irreversible. You can also delete individual notes, memories, connections and holdings.
- Restrict and object — every automatic AI flow is off until you enable it, and one switch (Settings → Automatic AI analysis) turns them all off again, immediately. You can also disable digests and unlink Telegram in Settings, and disconnect integrations. Email us to restrict processing you cannot switch off yourself.
- Withdraw consent — at any time, for anything you opted into, with the same toggles.
- Complain— to the DIFC Commissioner of Data Protection (Dubai), and, if you are in the EU or UK, to your national data protection authority or the UK Information Commissioner's Office. We would appreciate the chance to fix it first.
To exercise a right you cannot self-serve, email admin@sovereignhni.comfrom your account's email address. We will respond within one month. We may ask you to verify your identity before acting.
10. Security
Encryption in transit and at rest, read-only integrations, per-user row isolation, and what we deliberately cannot do are described on the security page. If we suffer a breach that puts your data at risk we will notify you and the relevant authorities as the DIFC law and, where applicable, the GDPR require.
11. Children
You must be at least 18 to hold an account. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, contact admin@sovereignhni.com and we will delete it.
12. Changes to this policy
We update this page whenever a data flow changes. Material changes are announced in-app and the “Last updated” date at the top is revised; the app records the version you have seen. Continued use of the service after a change constitutes acceptance.
13. Contact
Privacy questions and requests: admin@sovereignhni.com. Security reports: admin@sovereignhni.com. General contact: admin@sovereignhni.com.