Privacy Policy
Last updated: September 7, 2026. Covers this website and summarizes how FinSeek AI handles data.
1. Scope
This policy explains how PanMAS LLC handles information on the PanMAS company website at panmas.finseekai.com, and summarizes how our product FinSeek AI handles your data.
FinSeek AI has its own full Privacy Policy, published on finseekai.com. That document governs the product. Sections 4 through 15 below summarize it for readers who arrive here first; if the two ever differ, the FinSeek policy is the controlling one.
2. Who we are
PanMAS LLC ("PanMAS", "we", "us") is an Arizona limited liability company and the developer and operator of FinSeek AI. We are the controller of the personal information described here. Privacy questions and data requests: privacy@finseekai.com.
3. This website
This is a static informational website. It has no accounts, no login, no forms, and no analytics or advertising trackers. It sets no cookies.
Two things are still collected as a normal part of serving a web page:
- Server logs. Our hosting provider records standard request data including your IP address, the page requested, the time, and your browser type. This is used for security and reliability.
- Web fonts. Typefaces on this site are served by Google Fonts, so loading a page sends a request to Google's servers that includes your IP address. Google's handling of that request is governed by Google's own privacy policy.
Nothing you do on this website is linked to a FinSeek account.
4. What FinSeek AI collects
Information you provide directly: your email address (for account creation, waitlist registration, or communication), an optional display name, an optional phone number, your password (stored only as a cryptographic hash by our authentication provider — we never see or store the plaintext), and any feedback or support messages you send.
Information collected automatically: device type and browser, IP address giving an approximate location, anonymized usage data such as pages visited and features used, and error diagnostic data with personal information scrubbed before transmission.
5. Financial information — two separate paths
Financial information reaches FinSeek in one of two ways. Each is entirely user-initiated, and either can be used without the other.
- Statement upload. When you upload a bank statement file — CSV, Excel, TXT, or PDF — the transaction data is extracted from the file in memory on our backend and the raw file is immediately discarded. Uploaded statement files are not stored at any stage.
- Bank connection through Plaid. If you choose to connect a bank account, you authorize Plaid Inc. to share transaction data with FinSeek. Plaid provides an access token, which we store encrypted with AES-256-GCM at the application layer on top of our database provider's own encryption at rest. You can disconnect at any time from the Profile page, which revokes the Plaid connection and deletes the stored token.
Whichever path you use, the transaction data retained is: date, merchant name with identifying details masked before storage, amount, type (income or expense), and category.
6. Where your data is stored
Your financial data is stored in our encrypted database and is accessible only through your authenticated account.
FinSeek does not persist financial data on your device. Only your authentication token is kept in your browser's local storage so you stay signed in between visits; it contains no financial data and is cleared when you sign out. Uploaded files are held briefly in browser memory during upload and are not written to persistent storage.
7. Third-party AI processing
FinSeek's AI features — AI Copilot, Insights, and Forecast — are powered by Groq, Inc.
Consent comes first
Consent to third-party AI processing is required before AI features are enabled on your account. It is off by default, and you must actively opt in through the in-app consent flow. Nothing is sent to Groq until you do.
Declining does not affect any other feature. The dashboard, transaction management, subscription detection, and bank connectivity all work without AI. You can withdraw consent at any time from the Profile page; withdrawal is immediate and takes effect on your next AI request, and historical AI interaction records are deleted.
What is sent
A summary of your financial context: aggregate income and expense totals for a defined date range, spending totals by category, subscription totals, and — for the chat feature — the message you type.
What is masked before transmission
Automated masking is applied to identifying details before any transaction-derived data is sent, including bank account numbers, ACH beneficiary names, reference identifiers, email addresses, phone numbers, and Social Security numbers.
Merchant names are transmitted after masking. Specific merchants may still be recognizable, so we treat this data as personal information and protect it accordingly. Masking is automated and we cannot guarantee it removes every identifier in every case.
Groq's commitments
Under Groq's Services Agreement, Groq does not access, use, store, or retain inputs or outputs except as strictly necessary to provide inference services, and does not use customer inputs to train or fine-tune any AI model. Groq processes data in Google Cloud Platform data centers in the United States. FinSeek has Zero Data Retention enabled on its Groq account, which prevents even temporary retention for platform reliability purposes.
AI-generated output can be inaccurate or incomplete. FinSeek's insights are informational and are not financial, investment, tax, or legal advice.
8. Service providers
PanMAS does not sell your personal data. To operate FinSeek we share limited data with these providers:
- Supabase, Inc. — database and authentication. Stores your account, transactions, and AI interaction records, encrypted at rest.
- Plaid Inc. — bank connectivity, used only if you connect an account. Governed by Plaid's own privacy policy.
- Groq, Inc. — AI inference. Receives masked summaries only after you consent. See section 7.
- Vercel, Inc. and Render Services, Inc. — application hosting. Process requests; do not persist financial data.
- Resend Inc. — transactional email, such as verification, password reset, and security notifications.
- Sentry Software, Inc. — error monitoring. Personally identifying information is scrubbed from error reports before transmission.
All of these providers are contractually bound to protect your data in accordance with the standards described in this policy, and each provides equivalent or greater safeguards under its own certified privacy and security programs. None may use your data for its own purposes, sell it, or use it for advertising.
We may also disclose data when required by law, legal process, or to protect the rights, property, or safety of PanMAS, our users, or the public.
9. Security
- All data encrypted in transit using TLS 1.2 or higher.
- All data encrypted at rest at the database level using AES-256.
- Plaid access tokens receive additional application-layer encryption using AES-256-GCM.
- Row-Level Security policies ensure your data is reachable only through your authenticated account.
- Passwords are hashed with bcrypt by our authentication provider; we never see or store plaintext passwords.
- All administrative access to production systems requires multi-factor authentication.
No system is completely secure.
10. Retention and deletion
- Account and transaction data — retained until you delete it. Deletion is immediate and permanent.
- Anonymized usage logs and AI interaction records — up to 12 months, then removed by a daily scheduled retention job.
- Database backups — retained by our infrastructure provider for up to 7 days on a rolling basis.
- Plaid access tokens — retained only while your bank connection is active; deleted immediately on disconnection.
- Uploaded statement files — not retained at any stage.
You can delete individual statements, all transactions, or your entire account from the Profile page. Instructions, including a route that does not require the app, are on our account deletion page.
11. Your rights
You may access your data through the app, correct it from the Transactions page, delete any part or all of it from the Profile page, export your transactions as a CSV file, withdraw AI consent, and withdraw bank connectivity consent — all from within FinSeek. You can also email privacy@finseekai.com.
California residents have the rights to know, delete, correct, opt out of sale or sharing, limit use of sensitive personal information, and non-discrimination, under the CCPA and CPRA. We do not sell or share personal information for cross-context behavioral advertising. We respond within 45 days.
EU, UK, and EEA residents have rights of access, rectification, erasure, restriction, portability, and objection, and rights relating to automated decision-making. FinSeek does not use your data for automated decisions producing legal or similarly significant effects. Our legal bases are your consent (AI processing and bank connection), performance of a contract, and our legitimate interests in operating and improving the service. Transfers to the United States rely on Standard Contractual Clauses where applicable. You may complain to your local data protection authority. We respond within 30 days.
12. Cookies
FinSeek uses essential cookies only, for authentication sessions. It does not use advertising trackers or cross-site tracking cookies and does not sell browsing data. You can disable cookies in your browser, though some features will not work as expected. This website sets no cookies at all.
13. Age requirement
FinSeek is not intended for anyone under 18. We do not knowingly collect personal information from minors. If we become aware that a minor has created an account, we will delete it.
14. International users and business changes
The service is operated from the United States and your data is processed and stored on servers located in the United States. By using the service you consent to that transfer, subject to the safeguards described in section 11.
PanMAS LLC may change its legal structure, or may merge with, acquire, or be acquired by another entity. In such cases personal data may transfer as part of the business assets, subject to this policy or a successor policy providing substantively equivalent protection. We will notify you before any such transfer.
15. Breach notification
If a security incident affects your personal data, we will notify you within the timeframes required by applicable law — typically 72 hours for GDPR-scope users, and as required by applicable state law for users in the United States.
16. Changes to this policy
We may update this policy as the service evolves. Material changes will be communicated in-app or by email, and the updated date will be posted at the top of this page.
17. Contact
PanMAS LLC, an Arizona limited liability company. Privacy questions and data requests: privacy@finseekai.com. General inquiries: hello@finseekai.com.