# Privacy Policy & Air-Gapped Zero-Cloud Architecture - ProjectionPlan

Canonical URL: https://projectionplan.in/privacy

> Effective Date: September 2026. Last Updated: September 2026.
> Our fundamental covenant: We do not, cannot, and will never collect, access, sell, or monetize your financial data.

## 1. Zero-Cloud Privacy Architecture
ProjectionPlan operates with an air-gapped local architecture. Unlike conventional personal finance applications that route your bank accounts through third-party intermediaries:
- **No Remote Databases**: No financial accounts, balances, transactions, net worth figures, debt schedules, or simulation parameters are ever transmitted to any remote server.
- **Hardware-Backed Encryption at Rest**: The local SQLite database is encrypted at rest using native operating system security: Android File-Based Encryption (FBE) and iOS Data Protection APIs.
- **No Identity Linking**: You are not required to create an account, verify a phone number, or provide biometric data to use ProjectionPlan's simulation engines.

## 2. In-Memory Bank Statement Parsing
- ProjectionPlan includes a zero-cloud, client-side RFC 4180 streaming statement parser.
- When you import a CSV statement from your bank or credit union, parsing and delimiter sniffing occur entirely in volatile device memory inside your device's isolated application sandbox.
- No transaction data is sent over the internet, and no unencrypted temporary files are left on disk.

## 3. Website & Waitlist Privacy Practices
When you visit our public marketing website at `https://projectionplan.in`:
- **Waitlist Registration**: If you choose to join our early access waitlist, we collect your email address. This is used solely to notify you of launch milestones and provide your early-bird discount. Waitlist emails are managed securely via Loops with instant one-click unsubscribe links.
- **Web Analytics**: We utilize privacy-preserving, cookie-less web analytics (via Vercel Analytics) to measure aggregate page visits, browser platforms, and Core Web Vitals. We do not use third-party tracking pixels (such as Meta Pixel or Google Ads Remarketing) and do not track users across websites.
- **Server Logs**: Minimal operational HTTP request logs (IP address, user agent) are processed transiently for DDoS mitigation and edge routing, retained for standard short retention periods.

## 4. Global Privacy Rights & Regulatory Compliance
We respect privacy rights under the European Union GDPR, California Consumer Privacy Act (CCPA), and India's Digital Personal Data Protection Act (DPDPA):
- **Right to Access & Portability**: Because your financial data is stored 100% locally on your device, you possess total ownership and can export your entire database as standard JSON/CSV files at any time.
- **Right to Erasure**: Deleting the ProjectionPlan mobile app or clearing application data from your OS settings permanently purges all local data. To remove your email from our waitlist, click unsubscribe in any email or contact `privacy@projectionplan.in`.

## 5. Data Controller Contact
- **Data Controller**: ProjectionPlan
- **Privacy Officer Contact**: privacy@projectionplan.in
- **Postal Address**: Outer Ring Road, Bellandur, Bengaluru, Karnataka 560103, India

## Machine-Readable Links
- [Home Page](https://projectionplan.in/)
- [About Us](https://projectionplan.in/about)
- [Contact Support](https://projectionplan.in/contact)
- [Agent Guide (llms.txt)](https://projectionplan.in/llms.txt)
- [XML Sitemap](https://projectionplan.in/sitemap.xml)
