1. Who this policy covers
This policy explains how NextGen Empowerment ("we", "us", "our") handles personal
information when you use thenextgenempowerment.com and the Empowerment Suite tools
(the "Services"). We are based in Charlotte, North Carolina, and the Services are
intended for people in the United States.
Capable Kids, our free in-person program for children, is run offline and is not part
of this website. Any information collected for that program is collected directly from
a parent or guardian and will carry its own notice at the time.
2. Information we collect
Account information
When you create an account we collect:
- Name - first and last, used to personalize your account.
- Email address - for sign-in, receipts, and service messages.
- Date of birth - to confirm you are 18 or older.
-
Password - handled entirely by Firebase
Authentication. It is stored only as a salted cryptographic hash.
We never see or store your actual password.
Financial information you enter
When you use the planning tools we store what you put in, which may include:
- Income amounts and pay frequency.
- Budget categories, planned amounts, and saved budget scenarios.
- Savings goals and financial priorities.
- Manually entered expenses, notes, tags, and category rules.
- Assets and liabilities you record in the Net Worth tool.
Subscription and billing information
If you subscribe to Premium, payment is processed by Stripe. We store your Stripe
customer and subscription identifiers, your plan, your subscription status, and your
renewal date so we can show you the right account information.
We never receive or store your full card number, CVC, or
expiry. Card details go directly to Stripe. The only card information shown in
your account is the brand and last four digits, which we read from Stripe when you
open your billing page and do not keep.
Technical and usage information
-
Server logs from our host, Netlify, which include
IP address, timestamps, and the pages or functions requested. These are used for
security, debugging, and abuse prevention.
-
Device and browser information such as browser
type, operating system, and screen size.
-
Usage analytics on our public pages, described in
section 9.
3. Bank data through Plaid
This is optional and off by default. Premium members
may connect a bank account so the Spending Tracker, Financial Insights, and Net Worth
tools can work from real data. The connection is handled by Plaid Inc.
What we never receive
- Your online banking username or password. You enter these with Plaid, not with us.
- Your full bank account number or routing number.
- Your debit or credit card numbers.
What we do store
-
A Plaid access token - a key that lets us request
your data. It is stored server-side and is never exposed to your browser.
-
Transaction records - date, amount, merchant or
description, and category.
-
Account balances - including the total value of any
investment or retirement accounts you connect, used for Net Worth. We do not request
individual holdings, securities, or cost-basis data.
-
Institution and account names - so you can tell your
connected accounts apart.
Transactions are automatically deleted after 90 days.
A scheduled job runs daily and removes anything older. You can also disconnect a bank
at any time from Profile Settings, which deletes the access token and stops all future
syncing.
Plaid handles your information under its own
end user privacy policy.
4. How we use your information
-
To run the Services - build your budgets, track
spending against plan, calculate net worth, and save your work across devices.
-
To generate insights - including AI-assisted
analysis, described in section 5.
-
To manage your subscription - process payments,
apply your tier, and show accurate billing information.
-
To communicate with you - service notices, billing
confirmations, security alerts, and replies to your support requests.
-
To keep the platform secure - detect abuse, prevent
fraud, enforce rate limits, and investigate problems.
-
To improve the product - understand which features
get used, using aggregated and de-identified information.
-
To meet legal obligations - such as tax and
accounting records for payments.
What we do not do: we do not sell your personal or
financial information, we do not share it with advertisers or data brokers, we do not
use it to target ads, and we do not use your financial data to build profiles for
anyone else.
5. AI processing
Some Premium features use Google's Gemini AI to summarize your finances and suggest
things to consider. When you run one of these features, the relevant financial
information is sent to Google's Gemini API, processed, and a written response is
returned to you.
-
AI analysis runs only when you ask for it. Nothing
is sent for analysis in the background.
-
We send the financial figures needed for the analysis. We do not send your password,
your payment details, or your Plaid access token.
-
Google processes this data under its own
Gemini API terms.
-
AI output is informational only and can be wrong. See our
Terms of Service.
6. Who we share data with
We share information only with the service providers that make the platform work, and
only as much as each one needs.
Google Firebase and Google Cloud
Accounts, authentication, and database storage for your budgets and financial data.
Firebase privacy
Netlify
Website hosting and the serverless functions behind our features. Processes server
logs including IP addresses.
Netlify privacy
Stripe
Payment processing, subscription management, and the billing portal where you
update your card or cancel. Receives your name, email, and payment details.
Stripe privacy
Plaid
Bank connectivity, only if you choose to connect an account.
Plaid privacy
Google Gemini, Analytics, and reCAPTCHA
AI analysis, website usage measurement on public pages, and bot protection on our
signup and checkout forms.
Google privacy
Slack
Our internal team channel receives an automated notification when someone signs up,
containing the new member's name, email, and plan, so we can provide support.
Slack privacy
Other limited situations
-
Legal requirements. If we are required by law, a
subpoena, or a court order, or where necessary to protect someone's safety or our
legal rights.
-
Business transfer. If the organization is ever
merged, acquired, or reorganized, your information may transfer as part of that. We
will notify you and this policy will continue to apply until replaced.
We do not share your data with advertisers, data
brokers, marketing companies, or credit bureaus, and we never sell your financial
information.
7. How long we keep data
Deleting your account is immediate and permanent.
When you confirm deletion we cancel any active subscription, remove your data from our
database, and delete your sign-in account. There is no grace period, so please export
anything you want to keep first.
8. Your rights and controls
What you can do yourself
-
See and correct your data. Everything you entered is
visible and editable inside the tool you entered it in.
-
Export from a tool. The budget tools offer CSV
export of your data.
-
Disconnect your bank. Profile Settings, Disconnect
Bank. Stops syncing and deletes the access token.
-
Cancel your subscription. Manage Subscription, then
complete cancellation in the Stripe billing portal.
-
Delete your account. Profile Settings, Delete
Account. Permanent and immediate.
What to email us for
A complete export of all your data is not yet a
self-service button. Email us and we will put it together for you. We aim to respond
within 30 days.
State privacy rights
If you live in California, Virginia, Colorado, Connecticut, Utah, or another state with
a comprehensive privacy law, you have the right to:
- Know what personal information we collect and why.
- Access a copy of it.
- Correct inaccurate information.
- Delete your personal information.
-
Opt out of sale or sharing for targeted advertising. We do not sell or share your
information this way, so there is nothing to opt out of, but the right exists.
- Not be treated differently for exercising any of these rights.
To make a request, email
thenextgenempowerment+service@gmail.com
with "Privacy Rights Request" in the subject line. We may need to verify your identity
before we act, usually by confirming control of your registered email address.
9. Cookies and analytics
We use a small number of cookies and similar technologies:
-
Essential. Firebase Authentication uses browser
storage to keep you signed in. Without this you cannot use an account.
-
Analytics. Our public marketing and article pages
use Google Analytics 4 to count visits and understand which content is useful. It is
not loaded on your account, billing, or tool pages.
-
Security. Google reCAPTCHA runs on our signup and
checkout pages to block automated abuse.
We do not use advertising or cross-site tracking cookies.
You can block or clear cookies in your browser settings, though blocking essential
cookies will prevent sign-in. You can also install the
Google Analytics opt-out add-on.
10. How we protect your data
-
Encryption in transit. All traffic uses HTTPS with
TLS.
-
Encryption at rest. Data stored in Firebase is
encrypted by Google Cloud.
-
Password handling. Firebase Authentication stores a
salted hash of your password. It never reaches our servers in readable form.
-
Access rules. Firestore security rules restrict each
account to its own data.
-
Server-side verification. Actions that touch billing
or personal data verify your identity token on the server before doing anything.
-
Secrets management. API keys and credentials are
held in server environment variables, never in the code sent to your browser.
-
Data minimization. We do not collect bank
credentials or card numbers at all, so there is nothing there to lose.
No system is perfectly secure. We use
industry-standard protections but cannot guarantee absolute security. Please use a
strong, unique password. If we ever discover a breach affecting your personal
information, we will notify you and the relevant authorities as required by law.
More detail is available on our
Security page.
11. Children's privacy
The Services are for adults. You must be 18 or older to create an account, and we do not
knowingly collect personal information from anyone under 18 through this website.
If you believe a child has provided us with personal information, contact us at
thenextgenempowerment+service@gmail.com
and we will delete it promptly.
12. Changes and contact
Changes to this policy
We will update this policy as the Services change or the law requires. The "Last
updated" date at the top always reflects the current version. For material changes,
such as collecting a new category of data or sharing with a new provider, we will notify
you by email before the change takes effect.
Contact us
Privacy and support:
thenextgenempowerment+service@gmail.com
Privacy rights requests: use the same address with
"Privacy Rights Request" in the subject line.
Business: NextGen Empowerment, Charlotte, North Carolina, USA
See also our Terms of Service.