Security & Privacy

Security & Privacy

Last updated: April 28, 2026

ClearPlan is a planning tool for financial advisors. We help advisors generate one-page client summaries from financial inputs. We are not a custodian, not a financial advisor, and not a data aggregator. This page describes how we handle data, where it lives, and what we do (and don't) do with it.

What data ClearPlan handles

Your account data (advisor)

Plan content you enter

What we do not collect

The following fields do not exist anywhere in the ClearPlan interface and have no place to be entered:

Where data is stored

DataProviderRegion
Account, profile, plans, firm settingsSupabase (Postgres on AWS)United States
Application hosting and request handlingVercelUnited States
Subscription billing and paymentStripeUnited States

All data is encrypted in transit using TLS 1.2 or higher. All data is encrypted at rest by the underlying provider (Supabase via AWS-managed encryption; Stripe via PCI-DSS compliant infrastructure).

Access controls

Data retention and deletion

AI and third-party APIs

ClearPlan does not currently send any plan content to third-party AI services such as Claude or OpenAI. Plan generation, calculations, and PDF rendering happen entirely in your browser or in our own server. If we add AI-assisted features in the future, this page will be updated and the relevant subprocessor added before any plan data leaves ClearPlan's infrastructure.

Subprocessors

The current list of third parties that process customer data on our behalf — and what each one does — is available on request. Email hello@getclearplan.com and we will respond within two business days.

Breach notification

In the event of a confirmed data breach affecting customer data, ClearPlan will notify affected customers by email within 72 hours of confirmed discovery, with a description of the data involved, the cause, and the steps being taken to remediate.

Compliance posture

ClearPlan is designed for advisors operating under SEC Regulation S-P and state-equivalent privacy rules. The product's data minimization — no SSNs, no account numbers, no client contact details — is a deliberate design choice to reduce your firm's regulatory exposure when using the tool.

We are a small, focused team and do not currently hold SOC 2 or ISO 27001 certification. We maintain documented security practices appropriate to the data we hold and are happy to provide additional documentation for vendor due diligence on request.

Documents available on request

For vendor due diligence, the following are available on request — typically within two business days:

Email hello@getclearplan.com with the subject line "Vendor due diligence — [your firm name]" and we will respond promptly.

Questions

For any security or privacy questions, contact us at hello@getclearplan.com.