every model spec’d & versioned · Concordance-tested changelog →

Legal

Data Processing Addendum

Effective date: August 29, 2026 · Version 2026-08-29 · Accepted together with the Terms of Service at checkout

1. Scope and roles

This Data Processing Addendum (the “DPA”) forms part of the Terms of Service and applies whenever you submit Customer Data to the Services — above all when you store household records through the Household Engine. For that data, you are the controller (you decide what is submitted and why) and Worthune is the processor: we process it only to provide the Services you invoke, and on no other basis.

Customer Data” means the data you submit to the API: household documents (members, accounts, liabilities, income and expense streams), the labels you attach to them, computed projections and decision records derived from them, and your configuration (webhooks, tenant branding, assumption inputs).

2. What the household schema deliberately excludes

The household document format is designed to be pseudonymous. It has no fields for names, Social Security numbers, dates of birth, addresses, phone numbers, or email addresses of household members — a member is a birth year, a relationship, and optionally a sex; the rest is amounts, rates, and dates. The engine computes the same answer whoever the household is, so the Services never need to know.

The one free-text field, the household label, is caller-supplied. If you place identifying information there (“The Alvarez family”), you are choosing to do so; use your own internal identifiers if your compliance posture requires pseudonymity end to end.

3. Processing instructions

Your API calls are your processing instructions: we store what you store, compute what you ask computed, deliver webhooks where you register them, and render tenant embeds you mint tokens for. We do not use Customer Data to train models, build cross-customer profiles, or for advertising. Aggregate, non-identifying operational telemetry (daily request counts per endpoint) is described in the Privacy Policy.

4. Confidentiality and tenancy

Customer Data is scoped to your organization. Every read and write on household resources carries your organization id in the query itself; API keys are stored as SHA-256 hashes; webhook payloads are signed with a per-endpoint secret; tenant embeds render only behind tokens signed with a per-tenant secret. Access by Worthune personnel is limited to what operating and supporting the Services requires.

5. Subprocessors

We use the following subprocessors to operate the Services, each bound by its own data-protection terms: Vercel (application hosting), Neon (database hosting; data encrypted at rest by the provider), Stripe (payments — Stripe processes your billing details directly and independently), and Resend(transactional email). Household documents live in Neon and are processed in Vercel functions; they are not shared with Stripe or Resend.

We will update this list before adding a subprocessor that touches Customer Data; continued use after an update is acceptance of the revised list.

6. Security

We maintain technical measures appropriate to the data’s pseudonymous design: TLS on every connection, hashed credentials, org-scoped tenancy enforced at the query level, signed webhooks with SSRF-guarded destinations, fail-closed production configuration, and input validation that rejects rather than repairs. Our security posture and its evidence are documented for customers in the due-diligence materials available on request.

7. Retention, return, and deletion

Household records persist until you archive them; archived records remain readable to you and leave the active-household meter. Decision records are append-only computation evidence and persist with the household they describe.

On termination of your subscription, you may export your Customer Data through the API before your key is revoked (it remains readable through the end of the billing period). On written request to support@worthune.com after termination, we will delete your organization’s household and decision records within 30 days, except where a record must be retained to evidence a computation already relied on or to meet a legal obligation — and we will tell you which records those are.

8. Incident notice

If we become aware of unauthorized access to Customer Data, we will notify affected customers at their organization’s billing email without undue delay after confirming the incident, with what we know: what was accessed, when, and what we have done about it.

9. Your responsibilities

You are responsible for the lawfulness of the data you submit — for having the right, under your own regulatory obligations (including, where applicable, GLBA and Regulation S-P), to process your clients’ financial information through a service provider; for honoring your clients’ privacy rights; and for not placing data in the Services that the schema does not ask for.

10. Order of precedence and changes

If this DPA conflicts with the Terms, this DPA controls for Customer Data processing. Material changes bump the version shown below; continued use of the household endpoints after a version bump — or re-acceptance where a flow asks for it — is acceptance of the revised DPA.

Questions about this DPA: support@worthune.com.