FUNDPILOT
Preparing your reserve model
Legal Documentation

Privacy Policy

Last Updated: August 8, 2026 · Document Version: 2026-08-08

Plain-language summary

We collect the minimum data needed to run the service: your email, your uploaded PDFs, your model settings, and security cookies. PDFs are processed by third-party AI providers under strict no-train contracts. We never sell your data. You can delete your account and all data at any time.


1. Introduction & Scope

This Privacy Policy describes how FUNDPILOT HOA Reserve Modeler (“Platform”, “we”, “our”, “us”) collects, uses, discloses, and protects information when you access, register for, or use the website, software, and related services (collectively, the “Service”). By using the Service you agree to the terms of this Policy. If you do not agree, do not use the Service.

We operate the Service as a software provider. We are not a certified reserve specialist firm, accounting practice, law firm, or engineering consultancy. Nothing in this Policy creates a fiduciary, advisory, or professional-client relationship.

2. Information We Collect

We collect the minimum information necessary to deliver 30-year capital reserve study modeling services:

  • Account Credentials Email address, full name, association name, and (for members) a username and password provided upon registration. Member passwords are bcrypt-hashed before storage; we never store plaintext passwords.
  • Uploaded PDF Documents Reserve study reports you upload for financial parsing and item extraction. PDFs are stored in private cloud storage buckets under strict access controls.
  • Extracted Financial Data Reserve line items, replacement years, useful life values, and estimated costs derived from your PDFs and stored in your private account.
  • Financial Parameters User-configured reserve start balances, monthly contributions, inflation rates, yield percentages, funding method, and target percent-funded goals.
  • Member & Community Data For HOA members, we store security question answers (bcrypt-hashed), member role/position, comments, preset configurations, and notifications. For treasurers, we store passcodes, member approvals, and audit trail entries.
  • Access Cookies & Tokens Session tokens, member tokens (hoa_member_token), and member view cookies used exclusively for access authorization. Member tokens are stored as SHA-256 hashes; the raw token is shown only once at issuance.
  • Usage & Diagnostic Data Aggregated, non-identifying analytics (page loads, feature usage) used to improve the Service. Error logs include a request trace ID and sanitized error messages; they are RLS-scoped so users only see their own errors.
  • Payment Data Subscription payments are processed by Dodo Payments as merchant of record. We do not collect or store your full payment card number, CVV, or bank account details. Dodo shares subscription status and customer identifiers with us via signed webhooks.
  • Communications If you contact us by email, we retain the message and our reply to handle your request.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide, operate, maintain, and improve the Service, including PDF extraction, financial modeling, scenario comparison, and report generation.
  • To authenticate users, prevent fraud, and enforce our Terms of Service.
  • To process subscription payments and manage Pro-tier entitlements.
  • To send you transactional emails (account confirmation, password reset, payment receipts, important security notices). Marketing emails are sent only with your consent, and you may unsubscribe at any time.
  • To respond to your support requests and comments.
  • To detect, prevent, and address security incidents, abuse, and technical issues.
  • To comply with legal obligations and respond to lawful requests from public authorities.

We do NOT use your uploaded PDFs or extracted data to train any AI model, ours or any third party’s. We do NOT sell, rent, or lease your personal information to third parties for marketing purposes.

4. AI Processing & Data Isolation

When you upload a reserve study PDF, our parsing pipeline processes text and table grids through secure artificial intelligence endpoints operated by independent providers: Nvidia NIM, OpenRouter, Google Gemini, and an OpenAI-compatible proxy. Only one provider is active at a time, selected by your configuration or our automatic fallback.

  • Your uploaded documents and extracted financial data are never used to train third-party AI models. All AI providers are accessed under commercial API agreements that prohibit training on submitted content.
  • All API data transmissions are encrypted using TLS 1.2 or higher.
  • Extracted reserve line items are isolated strictly within your private account schema secured by PostgreSQL Row Level Security (RLS). No other user, including other HOAs on the same database, can read your data.
  • A deterministic algorithmic extraction engine runs alongside the LLM as a safety net. If all AI providers are temporarily unavailable, the algorithmic engine still returns results.

5. Document Storage & Security

Uploaded PDF files are stored in private Supabase Storage buckets under strict access control policies. Only authorized account owners and approved read-only passcode holders can view generated signed URLs for document inspection.

We employ industry-standard administrative, technical, and physical safeguards designed to protect your information, including encryption in transit (TLS), encryption at rest, role-based access controls, RLS-scoped database policies, HMAC-verified webhooks, and Cloudflare Turnstile CAPTCHA on all authentication endpoints.

No security measure is perfect We cannot guarantee absolute security. You acknowledge that any information you transmit to the Service is at your own risk. Where required by law, we will notify affected users of material data breaches without undue delay.

6. Cookies, Local Storage & Tracking

We use a minimal set of cookies and browser local storage keys, strictly to operate the Service:

  • Authentication cookies Supabase session cookie (managed by Supabase Auth) for treasurers; opaquehoa_member_tokencookie for members. Both are HTTP-only or SameSite=Lax and expire on logout.
  • Functional local storage hoa-demo-storage (guest demo persistence), hoa-dashboard-storage (in-flight upload job), hoa-walkthrough-done (onboarding tour), and hoa-legal-consent (your acceptance of these documents). All are scoped to the Service’s origin and contain no third-party trackers.
  • Cloudflare Turnstile CAPTCHA verification on every authentication flow. Turnstile sets its own cookies subject to Cloudflare’s privacy policy.
  • No advertising cookies We do not use third-party advertising networks, retargeting pixels, or cross-site tracking technologies.

7. Sharing of Your Information

We share information only in the following limited circumstances:

  • Service providers Cloud hosting (Supabase, Caddy reverse proxy, Docker), AI providers (Nvidia NIM, OpenRouter, Google Gemini, OpenAI-compatible proxy), payment processor (Dodo Payments), and email delivery (Resend). Each is bound by confidentiality and data-processing obligations.
  • Within your HOA If you are a treasurer, your data is visible to you and to any active members you explicitly invite. If you are a member, your comments and preset publications are visible to your HOA’s treasurer and other active members.
  • Legal compliance If required by valid law, regulation, court order, or to protect our rights, property, or safety (or that of others).
  • Business transfers In connection with a merger, acquisition, financing, or sale of assets, with confidentiality protections.
  • With your consent For any other purpose disclosed at the time of collection.

8. Data Retention

We retain your information for as long as your account is active or as needed to provide the Service. Specifically:

  • Account data, settings, and reports: retained while your account is active.
  • Uploaded PDFs and extracted line items: retained while your account is active, or until you delete them.
  • Audit log entries: retained for the life of your account to support HOA governance record-keeping.
  • Error logs: retained up to 180 days for debugging and abuse prevention.
  • Payment records: retained as required by tax and accounting law (typically 7 years).
  • Backup snapshots: up to 30 days after deletion.

9. Your Rights & Choices

You have the following rights regarding your personal information:

  • Access Request a copy of the personal information we hold about you.
  • Correction Update or correct inaccurate information through your account settings.
  • Deletion Delete your account and all associated data at any time from your User Settings page. Executing account wiping permanently deletes your user profile, stored PDF documents, financial models, line items, access passcodes, and authorization tokens from all databases and storage servers.
  • Export Download your data in common formats (PDF report, CSV, Excel).
  • Withdraw consent Where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing prior to withdrawal.
  • Complain Lodge a complaint with your local data protection authority if you believe we have violated your privacy rights.

10. Children’s Privacy

The Service is not directed to children under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will take steps to delete it.

11. International Data Transfers

We operate the Service from servers that may be located in different jurisdictions. By using the Service, you understand that your information may be transferred to, stored, and processed in countries other than your country of residence, including the United States and the European Union. We take appropriate safeguards to protect your information in accordance with this Policy.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The “Last Updated” date at the top of this page indicates when the Policy was last revised. Material changes will be communicated through the Service or by email. Your continued use of the Service after a change constitutes acceptance of the updated Policy.

13. Contact Us

If you have any questions regarding this Privacy Policy or your data privacy rights, contact us at .

14. Specific Notices for California Residents (CCPA/CPRA)

If you are a California resident, you have the right to know what categories of personal information we collect, the right to delete personal information we have collected, the right to correct inaccurate personal information, and the right to limit the use of sensitive personal information. We do not sell or share your personal information for cross-context behavioral advertising. To exercise these rights, contact us at the email above.


Document version 2026-08-08. This Privacy Policy is incorporated into and forms part of our Terms of Service.