Privacy Policy

Last updated 2026-05-18

This Privacy Policy explains what personal data Capital Fortress, operated by Furni Systems SRL, collects when you use our Service, how we use and share that data, and what choices and rights you have. We act as the data controller for the personal data described below.

1. Who we are

Capital Fortress, a service operated by Furni Systems SRL, a company organized under the laws of Romania. For privacy questions write to support@capitalfortress.org.

2. What we collect

  • Account data: email address, password hash (we never see your plaintext password), display name if you provide one, tier, role, account creation date, last-active timestamp.
  • Billing data: Stripe customer ID, subscription status, plan, invoice history, payment-method metadata (card brand, last four digits, expiry month/year — never the full card number). Full payment-card data is collected and stored by Stripe, our payment processor.
  • App data you create: budget line items, custom categories, downturn plan, emergency-fund targets, readiness scores, investment audit holdings, notes, uploaded statements that you choose to import, watchlists, portfolio entries, and similar inputs.
  • Free educational scans: when you open a public educational scan (for example, the SAFE Vulnerability Scan) we create an anonymous session record identified only by a random value held in your browser for that visit. As you move through the questions we store the figures you enter and the results we compute from them — your score, your component breakdown, your portfolio-exposure reading and your prescribed moves — together with technical metadata (browser user agent, device type, approximate country and region derived from your IP address, the referring page, and any campaign parameters in the link you arrived through). This record is created and kept whether or not you ever give us your name or email address, and if you leave part-way through we keep what you had entered up to that point. Without contact details it is not linked to you as an individual and we make no attempt to identify you from it; we use it only to understand where the scan is unclear, which questions people abandon, and who our free tools are reaching, so that we can improve them. If you do ask for your full report, your first name and email are stored alongside that session record, and the whole record is then treated as personal data under the retention and deletion terms below.
  • Operational telemetry: request logs, error logs, IP address (hashed where used outside of immediate request handling), browser user agent, device type, language, approximate location derived from IP, time of access, pages viewed, and features used.
  • Communications: emails you send to us, support tickets, replies you submit to surveys we run.
  • Cookies and similar technologies: see our Cookies Policy.

We do not knowingly collect personal data from anyone under 18. If you believe we have, write to support@capitalfortress.org and we will delete it.

3. How we use your data

  • Provide the Service. Authenticate you, save your work, render dashboards, compute scores, deliver downloads, and process payments.
  • Operate and secure the Service. Investigate bugs, prevent fraud and abuse, enforce our Terms, and back up data.
  • Communicate with you. Send transactional messages (account, security, billing), respond to your messages, and — only with your consent or where permitted by law — send product updates and educational content.
  • Improve the Service. Aggregate and analyse usage to understand which features are used and how to make them better. We do not sell personal data.
  • Comply with law. Meet our tax, accounting, and legal obligations, and respond to lawful requests.

4. Legal bases (for users in the EEA, UK, and similar regimes)

  • Performance of a contract (Art. 6(1)(b)) — to deliver the Service you signed up for.
  • Legitimate interests (Art. 6(1)(f)) — to secure the Service, prevent abuse, and operate our business in a privacy-respecting way.
  • Consent (Art. 6(1)(a)) — for optional marketing emails, non-essential cookies, and any feature that requires explicit opt-in. You can withdraw consent at any time without affecting prior processing.
  • Legal obligation (Art. 6(1)(c)) — to retain invoices and tax records.

5. Who we share data with

We share personal data only with the following categories of recipients, and only as needed:

  • Service providers / processors. Stripe, Inc. (payments & invoicing), Supabase, Inc. (database, authentication, file storage), Vercel, Inc. (hosting and request routing), Resend, Inc. (transactional email delivery), Cloudflare, Inc. (DNS, email routing). Each acts under a written data-processing agreement and supports the EU-US Data Privacy Framework or equivalent transfer mechanism.
  • Advertising measurement. When our advertising campaigns are active, this site uses Meta advertising tools (the Meta Pixel and the Meta Conversions API). These tools share limited technical information about your visit with Meta Platforms, Inc. — pages viewed, actions such as starting or completing a free tool, your IP address and browser type, and, if you submit a form, a hashed (unreadable) version of your email address — so we can measure our advertising and reach people who are more likely to find it relevant. The financial details you enter in our tools are never shared with Meta. You can manage ad preferences in your Meta account settings.
  • Authorities. When we are legally required to disclose information, or when disclosure is necessary to protect rights, safety, or property.
  • Corporate transactions. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal data may be transferred as part of that transaction, subject to the protections in this Policy.

We do not sell personal data and we do not share it with advertising networks for cross-context behavioural advertising.

6. International transfers

Our infrastructure is hosted primarily in the United States (Vercel, Supabase, Stripe). When we transfer personal data of users in the EEA or the UK outside that region, we rely on Standard Contractual Clauses adopted by the European Commission, the UK International Data Transfer Addendum, or another lawful transfer mechanism, and we apply additional safeguards where appropriate. You may request a copy of the relevant mechanism by writing to support@capitalfortress.org.

7. Retention

  • Account and app data: for as long as your account is open. After account deletion, we retain a minimal record (hashed email, deletion timestamp, last tier) to enforce abuse policies and prevent recreation of suppressed accounts.
  • Billing records: retained for the period required by applicable accounting and tax law (typically up to 10 years in the EU).
  • Free-scan submissions: retained while your subscription to our list is active and for up to 5 years from your most recent submission, after which records are deleted or fully anonymised.
  • Marketing consent records: kept while consent is active and for up to 3 years after withdrawal as proof of compliance.
  • Logs and telemetry: up to 90 days, longer if needed for security investigations.
  • Backups: rotated under our standard schedule; deleted data may persist temporarily in encrypted backups until expiry.

8. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you and obtain a copy in a portable format.
  • Request correction of inaccurate data or completion of incomplete data.
  • Request deletion of your data (right to be forgotten) where applicable.
  • Object to or restrict certain processing (including marketing).
  • Withdraw consent at any time where processing is based on consent.
  • Lodge a complaint with your local data-protection authority. In Romania, the supervisory authority is ANSPDCP (dataprotection.ro); in the UK, the ICO; in California, the CPPA; in Canada, the OPC; in Australia, the OAIC; in New Zealand, the OPC.
  • For California, Virginia, Colorado, Connecticut, Utah, and similar US states: rights to know, delete, correct, and limit; opt-out of any sale or sharing (we do neither for cross-context advertising); and non-discrimination for exercising these rights.

To exercise your rights, write to support@capitalfortress.org. We may need to verify your identity before responding. See Data Processing Choices for the dedicated request form.

9. Security

We protect personal data with administrative, technical, and physical safeguards: encryption in transit (TLS 1.2+), encryption at rest on our infrastructure providers, password hashing using industry-standard algorithms, row-level security in our database, role-based access controls for staff, audit logging, and routine review of dependencies. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

10. Automated decision-making

We use deterministic, rule-based formulas (described in our course content and in the report itself) to compute scores and ranges shown in the Service. These outputs are educational and not used to take automated decisions about you with legal or similarly significant effect.

11. Changes to this Policy

We may update this Privacy Policy from time to time. The “Last updated” date above tells you when. For material changes we will use reasonable means to notify you, including via email to subscribers.

12. Contact

For any privacy question, request, or complaint, write to support@capitalfortress.org.