Peazy — Privacy Policy
Effective date: 2026-08-15
This Privacy Policy explains what personal information Peazy collects, why, who processes it, how long it's kept, and the rights you have over it. It forms part of, and should be read alongside, our Terms and Conditions. Terms defined there ("Service", "Your Content", "we"/"us") carry the same meaning here.
1. Who we are
Polaris Data Insights Ltd. (Ontario Corporation Number 1001167143), an Ontario corporation with
its registered office at Suite 516, 1 Belsize Drive, Toronto, Ontario M4S 0B9, Canada ("Peazy",
"we", "us", "our"), is the organization responsible for the personal information
described in this policy, for the purposes of the Personal Information Protection and Electronic
Documents Act (PIPEDA) and any applicable provincial equivalent. Our privacy contact is
privacy@peazy.cloud.
This policy covers the Peazy mobile applications (iOS and Android), the Peazy web application at
app.peazy.cloud, the site at peazy.cloud, and every related service, export, and message we
provide.
2. What we collect
We collect only what the Service needs to organize your financial documents and estimate what to set aside — nothing collected here is used for a purpose you wouldn't recognize from using the product.
- Account information. Email, full name, province/territory, incorporation status, and your profession. We do not collect a phone number. Profession is asked once during setup and is required, because the Service uses it to decide what to call things — whether the places that pay you are described as clinics, practices, or brokerages, and whether what you record is called production, billings, or gross commission. It is never used to calculate any tax, deduction, or other figure. You can change it at any time.
- Optional demographics. If you answer the optional in-app prompt, we also collect your gender and birth year. Neither is read by any calculation; they exist purely for an aggregate view of who uses Peazy, and answering is always optional and dismissible.
- Financial data via Plaid. Read-only transaction, balance, and account-name data, and the last four digits of a connected card or account number, for accounts you choose to connect. We never see or store your online banking credentials — Plaid handles that exchange, and the resulting access token is stored encrypted (Supabase Vault) and never exposed to the app. We cannot initiate payments or move money.
- Receipts you submit. Photographs or forwarded emails of expense receipts. We do not accept or process practice production reports, remittance statements, contracts, or other documents that would routinely carry patient- or client-identifying information — see §5.
- Production entries and payout rates — dentists only. Figures you type (not a document, not free text) — the work you recorded, and the payout-split percentage the clinic pays out (set when you add it, editable afterward) — used only to compare against deposits already visible from your connected accounts. This category is collected only if you selected dentist as your profession. For every other profession the Service does not offer these fields and holds neither figure. If it later becomes available to another profession, that is a change to what we collect about you and §14 (Changes to this policy) applies.
- Communications. If you email us for support, forward a receipt, or contact our privacy or security addresses, we keep that correspondence to respond to you and to meet our own record-keeping obligations (§9).
- Device and usage information. Ordinary technical data any app or web service collects to operate — device type, app version, crash diagnostics, and basic usage events — used to keep the Service working, not to build an advertising profile.
We do not collect information from anyone we know to be under 18 (see the Terms' eligibility section), and we do not knowingly collect more than the Service needs to function — a production entry, for example, was deliberately built with no free-text field, specifically because that is where a patient's or client's name would otherwise get typed (§5).
3. Why we collect it, and your consent
We collect and use your personal information only for the purposes described in this policy: running the Service you signed up for, computing your tax and deduction estimates, matching receipts to transactions, generating your monthly digest, presenting the Service in the vocabulary your profession actually uses, providing support, billing your subscription, and meeting our own legal and security obligations.
Profession is a presentation input, never a calculation input. It decides wording — clinic versus practice versus brokerage, production versus billings versus gross commission — and nothing else. It does not change any tax, CPP/QPP, or deduction figure, and it is not passed to the deterministic engine that produces those figures (§4). What does drive those figures is your province or territory of residence, your incorporation status, and how you're paid, all of which you set yourself.
Meaningful consent. Creating an account and connecting a financial account are both affirmative
actions you take with the relevant disclosure in front of you (this policy, and Plaid's own
disclosures at the point you connect an account, §6). Before you see your first tax estimate, the
Service also shows a dedicated, full-screen acknowledgement — not a pre-ticked checkbox — that you
must actively accept to continue; we log that acceptance (which version of the Terms and of this
policy, on which platform, and when) so both you and we have a durable record of it. You can
withdraw consent to non-essential processing at any time (for example, our marketing/product-update
emails have their own unsubscribe, per the Terms' CASL section) by contacting privacy@peazy.cloud;
withdrawing consent to processing the Service needs to function is equivalent to closing your
account (§10).
We will never use Your Content to train, fine-tune, develop, or evaluate any machine-learning or AI model, and we do not permit any service provider to do so either (see §6 and the Terms' §9.2).
4. How we use AI
Peazy uses AI to categorize transactions, extract receipt fields, and narrate your
monthly digest. The tax, CPP/QPP, and deduction figures themselves are never computed by an AI
model — they come from @peazy/tax-calc, a deterministic engine with no AI dependency at all.
Every AI output that touches a category, an extracted field, or a digest figure is validated,
clamped, or rejected by ordinary code before it's trusted; nothing an AI model produces is written
to your records raw. AI-proposed values are visually marked as such until you confirm them.
5. What we deliberately do not process
The Service is not a clinical records system. You must not enter, upload, or forward patient names, contact details, health numbers, chart numbers, clinical notes, or other patient-identifying information into any part of the Service.
The same prohibition applies to the people you serve, whatever your profession is called: if you are not in a clinical field, do not enter, upload, or forward client or customer names, contact details, file or matter numbers, or any other information identifying them. Peazy records what you earned and what you spent; it never needs to know who you earned it from beyond the clinic, practice, or brokerage that paid you.
As of 2026-08-09, Peazy does not accept or process production, billing or collections reports,
remittance or pay statements, or other operational documents from a business that pays you, at
all — that pipeline was removed outright rather than
hardened, on the view that nothing-to-redact beats redacting well. Your Peazy forwarding address
classifies inbound mail before any extraction runs, and discards anything recognized as a practice
document without parsing it. If patient information reaches us despite this, tell us at
privacy@peazy.cloud and we will delete it; we will not use it for any purpose and will not disclose
it except as required by law.
6. Who we share it with
We share personal information only with service providers who need it to help us run the Service, under contractual confidentiality and security obligations, and — for cross-border transfers — you should assume your information may be processed outside Canada, including in the United States, where it is subject to that country's laws (including lawful access by its authorities).
| Provider | Purpose | Country |
|---|---|---|
| Supabase | Database, authentication, file storage, edge functions | United States |
| Plaid Inc. | Bank/card account connection and read-only transaction data | United States |
| Stripe | Subscription billing | United States |
| Anthropic | AI categorization, extraction, and digest narration | United States |
| Apple / Google | Sign-in (if you use it), app distribution | United States |
We do not sell personal information, and we do not share it for the recipient's own marketing purposes. We may disclose aggregated, anonymized statistics (for example, "the median associate connects two financial accounts") produced from data aggregated across many users, in a form from which no individual can reasonably be identified — we will not attempt to re-identify it.
We may also disclose personal information where required by law, to protect the rights or safety of any person, or in connection with a merger, acquisition, or sale of assets (on notice to you, as described in the Terms).
7. Security safeguards
We maintain safeguards appropriate to the sensitivity of the information we hold, including:
- Row Level Security on every database table, no exceptions — every table scopes access to the authenticated owner, with an additional trigger-enforced check on every cross-table reference so a user cannot point their own record at someone else's.
- Encryption. Plaid access tokens are stored in an encrypted secrets vault, never in a plain database column, and are never exposed to the app. Data is encrypted in transit and at rest.
- Minimal, logged staff access. A small number of authorized personnel can access accounts to provide support, investigate a problem, or administer billing. Every such access — including simply looking up an account, not only actions that change something — is logged, with who, when, and which account.
- No credential handling. We never see or store your online banking credentials; Plaid handles that exchange entirely.
No safeguard is perfect, and we cannot guarantee absolute security. See §9 for what happens if something goes wrong.
8. How long we keep information
- While your account is open, we keep your data to provide the Service.
- Raw forwarded documents (the original email payload behind a submitted receipt) are kept only as long as needed to extract the receipt, then purged automatically on a short, fixed window — not retained indefinitely.
- On account closure, we delete or anonymize Your Content within 30 days (in practice, our in-app "Delete account" flow does this immediately: it cancels your subscription, disconnects every connected bank account, purges your uploaded files, and removes your account, cascading through every table that references it), except for (i) routine backups, which age out on their own cycle, and (ii) records we are legally required to keep, such as billing records and the breach register described in §9.
- Support correspondence and compliance records (including the breach register) are kept for as long as applicable law requires — PIPEDA requires our breach record specifically to be kept at least 24 months and producible to the Office of the Privacy Commissioner on request.
9. If something goes wrong
If we become aware of unauthorized access to, or unauthorized use or disclosure of, Your Content, we will notify you without undue delay at your registered email address, tell you what we know, and tell you what we're doing about it. We keep an internal record of every such incident — reportable to the Office of the Privacy Commissioner of Canada or not — for at least 24 months, as PIPEDA requires.
If you are a health information custodian, an agent of one, or otherwise subject to your own statutory or contractual breach-notification duty, that duty is yours; we will give you the information reasonably available to us so you can meet it, but we do not notify patients, custodians, practices, regulators, or professional colleges on your behalf (see the Terms' §8.6).
10. Your rights
Subject to limited exceptions in applicable law, you have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information — most of your profile is editable directly in
the app, including your profession and your province or territory; for anything that isn't,
contact
privacy@peazy.cloud. - Withdraw consent to non-essential processing, or close your account entirely (§3, §8).
- Export your data at any time your account is open. Export it before you close your account — closing it deletes your data immediately and permanently (§8), and we cannot reproduce or restore it afterwards.
- Complain to the Office of the Privacy Commissioner of Canada (
priv.gc.ca) if you believe we've handled your personal information improperly, ideally after raising it with us first atprivacy@peazy.cloudso we have the chance to fix it.
11. Cookies and similar technology
The web application uses only the technical storage (local/session storage, authentication cookies) needed to keep you signed in and remember your preferences. We do not use third-party advertising trackers.
12. Children
The Service is not directed at, and we do not knowingly collect personal information from, anyone
under 18. If you believe a child has provided us personal information, contact privacy@peazy.cloud
and we will delete it.
13. Quebec residents
The Service is not currently offered to residents of Quebec. This is a deliberate, temporary scope decision (not a technical limitation) made because Loi 25 and Bill 96's requirement that a contract of adhesion and the software interface itself be offered in French cannot yet be met — see the Terms' §22.9. Quebec-specific rights (including under Loi 25, such as a designated and published privacy officer, and Commission d'accès à l'information notification) will be built out and disclosed here before the Service opens to Quebec residents; they are not asserted in this version of the policy because they don't yet apply to anyone using the Service.
14. Changes to this policy
We may update this policy. For a material change, we'll give at least 30 days' notice by email or in-app before it takes effect, the same way the Terms describe for changes to that agreement.
15. Contact us
Polaris Data Insights Ltd. (operating as Peazy)
Suite 516, 1 Belsize Drive, Toronto, Ontario M4S 0B9, Canada
Privacy: privacy@peazy.cloud
Security: security@peazy.cloud
Support: hello@peazy.cloud