Privacy Policy
The short version
Norrith is a personal finance app for Canada. We need certain information to make the product work: your email, the bank connections you choose to link, and your transaction history once linked. Everything we collect is described below. We do not sell your data. We do not share it with advertisers. We store it encrypted in Canadian infrastructure. You can leave any time with a full export of everything we have.
- We collect: your email, account data from linked institutions, the budgets/goals/bills and split records you create, a contact you choose to import when you add a split partner, app usage data, device metadata for security.
- We do not collect: banking passwords (Plaid handles authentication; we never see them).
- We never sell or rent your data.
- AI features (Insights and the Ask Norrith chat) are off by default and consent-gated. What they send to our AI provider is described in §5, and a separate "detailed mode" is required before any balances or itemized transactions are shared.
- You can delete your data, including a 30-day recovery window before permanent erasure.
What this policy covers
This Privacy Policy applies to information collected through the Norrith iOS application, this website (norrith.com), and any communications you have with us. By using Norrith you confirm you have read and understood this policy.
Who controls your data
Norrith Labs Inc. (referred to as "Norrith", "we", or "us") is the data controller for personal information processed through the app and website. Norrith is incorporated in Ontario, Canada, with its principal place of business in Toronto.
Our designated Privacy Officer can be reached at privacy@norrith.com.
Information we collect
From you directly. Email address (when you join the waitlist, create an account, or contact support); your name if you provide it; subscription preferences; and the financial content you create in the app: budgets, goals and goal contributions, savings targets, recurring bills, transaction notes, tags, categorization rules, and shared-expense (split/IOU) records. If you use the split feature, you can add someone from your contacts: Norrith asks for Contacts permission and reads your address book on your device to show you a searchable list. Only the person you tap is saved or sent to us (their name and, if present, an email or phone handle); the rest of your address book never leaves your device. Any feedback you send.
From your bank, with your consent, via Plaid. Account names, balances, transactions, merchant names, dates, amounts, account type (chequing, credit, RRSP, TFSA, FHSA, RESP, brokerage, etc.), and institution metadata. Plaid handles authentication. Your banking password is sent only to Plaid and your bank, and is never visible to Norrith.
From your device. Operating system version, device model, app version, IP address (used for security and abuse detection), a push-notification token (to deliver alerts you enable), and crash and performance diagnostics. We do not access your photos, precise location, or calendar. Contacts access is used only for the split-partner importer described above: the reading happens on your device, and only the contact you choose is saved or sent to us.
Inferred or derived. Spending categories assigned by our classifier; budget calculations and goal progress; net-worth snapshots; subscription and anomaly-detection signals (e.g., a subscription price increase); and your Financial Health Score. This data is generated on your device or on our servers from the transaction data above.
Ask Norrith conversations. If you enable the AI chat, your conversation history is stored on your device (capped to recent turns) so you can pick up where you left off. It is cleared automatically when you sign out or a different account signs in on the device. What is sent to our AI provider to answer a question is described in §5.
On-screen summaries (home-screen widget). If you add the Norrith widget, the app stores a small financial summary of your net worth, budget status, top goals, and upcoming bills in a protected, backup-excluded app-group container on your device so the widget can render. This file is wiped on sign-out, and an amount-hiding option lets you keep figures off your home and lock screen.
Web analytics. When you visit norrith.com we use two analytics providers. Vercel Analytics records anonymous, aggregated page views and performance metrics, with no cookies and no individual visitor identification. Google Analytics 4, loaded through Google Tag Manager, sets first-party cookies (_ga, _ga_*) and assigns a persistent client ID so we can see how visitors move through the site, which pages convert to waitlist signups, and roughly where in the world traffic comes from. Google Analytics anonymizes IP addresses by default. We do not enable Google Signals or any advertising features, and we do not use Google Analytics data for retargeting. This is off until you consent: the Tag Manager container (and every tag in it, Google Analytics included) loads only after you accept in the cookie banner shown on your first visit, and you can withdraw or change that choice any time from “Cookie preferences” in the footer. You can also opt out globally with Google’s Analytics opt-out browser add-on.
How we use your information
We use your information only for the following purposes:
- Provide the service. Show you your accounts, categorize transactions, calculate budgets, track goals and bills, compute your net worth and Financial Health Score, and, when you enable them, generate AI insights and answer your questions in Ask Norrith.
- Maintain security. Detect fraud, abuse, and unauthorized access attempts.
- Customer support. Respond to your questions and resolve issues.
- Improve the product. Aggregate, de-identified analysis of feature usage. No individual user is identified in this work.
- Communicate with you. Service notices, security alerts, product updates you opted into.
- Comply with law. Respond to lawful requests from regulators or courts.
We do not use your data for advertising, profiling for marketing purposes outside Norrith, or hand it to third parties for model training.
How long we keep it
Active accounts. Your data is retained for as long as you have an active Norrith account.
On your device. Data cached on your device for the app to work is wiped when you sign out or a different account signs in, so the next person on a shared device cannot see it. This includes your accounts and transactions, your Ask Norrith chat history, your recent in-app searches, the home-screen widget summary, and your consent selections.
Deletion request. When you delete your account from inside the app, Norrith enters a 30-day soft delete window. During this window your account is recoverable. After 30 days, all personal data is permanently erased from production systems within 7 days.
Backups. Encrypted backups are retained for up to 90 days for disaster recovery. Personal data in backups is purged on the next backup rotation following permanent deletion.
Operational logs and aggregated analytics may be retained longer in de-identified form.
Your rights
Under PIPEDA (Personal Information Protection and Electronic Documents Act) and Quebec's Law 25, you have the right to:
- Access the personal information we hold about you.
- Correct information that is inaccurate or out of date.
- Withdraw consent for processing. Norrith uses granular, opt-in consent: separate toggles in Settings → Privacy control AI Insights, AI detailed mode, Analytics (including crash diagnostics), Marketing, Financial Sync, and Data Sale ("Do Not Sell or Share"). You can turn any of them off at any time, revoke a bank connection, or delete your account from inside the app.
- Receive a copy of your data in a portable, machine-readable format. CSV and JSON exports are available directly from the app.
- Delete your account and have your personal data erased (subject to the 30-day soft delete window above).
- Lodge a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, for Quebec residents, the Commission d'accès à l'information du Québec.
Norrith does not sell personal information; the "Do Not Sell or Share" control is provided so the right is exercisable regardless. To exercise any of these rights, email privacy@norrith.com. Our default response target is 15 business days. PIPEDA and Quebec Law 25 allow us up to 30 calendar days (extendable to 60 with written notice). We aim to stay well inside that window.
How we protect your data
Our security overview is published at norrith.com/security. The highlights:
- Encryption in transit. TLS-protected connections with certificate pinning, so a hostile network can't intercept your data.
- On-device encryption. The local store is encrypted, with the master key secured by the iOS Keychain: device-only and non-exportable. The store stays unreadable while your device is locked.
- Shared-device isolation. Signing out or switching accounts wipes locally cached data (accounts, transactions, Ask Norrith chat, recent searches, the widget summary, and consent state) so one person's data can't surface in another's session.
- Lock-screen minimization. By default, notifications hide dollar amounts and merchant names, and health or medical merchant names stay redacted even if you turn on lock-screen previews.
- iCloud sync is disabled. Your data does not leave the device except via authenticated API calls to our backend.
- Authentication. Sign in with Apple, Google, or email + password. Two-factor authentication (TOTP) with backup codes is available for every account. Face ID / Touch ID gate the app, with abuse protection on failed attempts.
- Read-only bank access. Plaid handles authentication directly with your bank. Your password never reaches Norrith. Access tokens never leave the server and are stored encrypted. Webhook signatures are cryptographically verified.
- Database-layer isolation. Per-user row-level access is enforced at the database itself, so even an application-level bug cannot expose another user's data.
- Audit log. Security events (multi-factor enrollment, credential and email changes, deletion scheduling) are logged and viewable in Settings → Security inside the app.
- Abuse protection. Sensitive operations (export, deletion, account connections, login attempts) are throttled to prevent abuse.
- PII redaction in logs. Email addresses are masked; account numbers and access tokens are never logged.
- Device-integrity signals: jailbreak-detection heuristics run on the device and are reported to our backend.
- No custom cryptography. We use only Apple frameworks and standard libraries.
- Breach notification. If a breach materially impacts your data, we will notify affected users and the Office of the Privacy Commissioner of Canada without unreasonable delay (and within timeframes required by PIPEDA), measured from the point at which we become aware of unauthorized access, alteration, or disclosure.
International users & cross-border transfers
Where your core data lives. Your account information, financial data, and authentication records are stored encrypted in a Canadian region. Backups remain in Canada.
Cross-border processing. A narrow set of subprocessors listed in §5 operate outside Canada, primarily in the United States. The main cross-border flows are:
- Apple: App Store billing and push-notification tokens.
- AI model provider (Google, Gemini API): only when you opt in to Insights or the Ask Norrith chat. AI Insights sends category-level summaries; Ask Norrith additionally sends top-merchant names, upcoming bills, goal and budget names, and net worth; and, only if you also enable detailed mode, per-account balances, an itemized recent-transaction list (which the assistant can query back about three years), holdings, and split-partner names. Processed in the United States on Google's paid API tier (inputs not used to train Google's models).
- Crash diagnostics: only when you opt in to Analytics; receives crash data with personal-information capture turned off.
- Marketing site infrastructure: hosting, DNS, and email delivery for norrith.com.
- Google Analytics 4: website page-view and conversion measurement; data is processed by Google in the United States.
For each of these we rely on contractual data-protection commitments (data-processing agreements and standard contractual terms) consistent with PIPEDA's cross-border transfer requirements and Quebec Law 25 art. 17.
Geographic availability. Norrith launches in Canada in 2026 and is offered only in Canada at that time. If you are a resident of the European Union, the United Kingdom, or another jurisdiction we have not opened to, this policy and the Norrith service are not directed at you, and we do not knowingly process your personal data. When we open Norrith in additional countries, we will update this policy with the applicable local privacy rights and re-confirm consent before processing any data from users in those countries.
Children's privacy
Norrith is designed for adult personal-finance management and requires users to be at least 19 years old. We do not knowingly collect personal information from children. Age affirmation is included in our Terms of Service, which you accept during onboarding; the App Store age rating reflects the same intent.
If you believe a child has signed up and provided us with personal information, contact privacy@norrith.com and we will delete the account and underlying data.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced through the app and via email to registered users at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent change.
Contact us
Privacy questions, requests to exercise your rights, or complaints:
Norrith Labs Inc.
Privacy Officer
Toronto, Ontario, Canada
privacy@norrith.com