Privacy Policy
Effective August 10, 2026 · Version 1.0
We collect as little as we can and we do not make money from your data. This policy explains, specifically, what we hold and what we do with it.
1. Who this covers
This policy applies to findmyFA.app and describes how we handle information about three groups: visitors who look things up, users who sign in and submit content, and financial advisors whose public registration records appear on the Site.
2. What we collect
- (a) Public registration records about advisors. Names, CRD numbers, firm affiliations, registration status and scope, examinations, employment history, city and state, and related fields, reproduced from the SEC's Investment Adviser Public Disclosure (IAPD) system and FINRA's BrokerCheck.
- (b) Account data for users who sign in. Your email address and the account identifier supplied by your sign-in provider (Google or Apple), plus the sign-in method and timestamps. We do not receive or store your password.
- (c) Review submissions and attestations. The text you submit, your chosen display-name setting, and the relationship, compensation, and conflict attestations described in the Review & Testimonial Policy.
- (d) Technical data. IP address, user-agent and device signals, request logs, error logs, and coarse security and abuse-prevention signals.
- (e) Nothing else. We do not buy personal information from data brokers, we do not build advertising profiles, and we do not track you across other websites or apps.
We use Google Analytics to collect aggregate usage statistics (pages viewed, referring site, approximate location derived from IP address, browser and device type). We do not use Google Analytics advertising features such as remarketing, and we do not use analytics data for ad targeting. You can block analytics with common browser tools or Google's opt-out add-on. Beyond that: no advertising trackers, no cross-context behavioral advertising, no sale of personal information. The Site runs no third-party ad tags, no ad-network pixels, and no cross-site advertising identifiers.
We do not sell or share personal information, as those terms are defined under the California Consumer Privacy Act. We do not participate in cross-context behavioral advertising.
3. How we use what we collect
- To operate the Site: serving lookups, publishing content, and displaying registration records.
- To authenticate you and prevent duplicate, automated, or fraudulent submissions.
- To apply and enforce our published moderation criteria, and to handle disputes and corrections.
- To keep the Site secure and available: rate limiting, abuse detection, and debugging.
- To comply with law and respond to valid legal process.
We do not use your information for advertising, profiling, or automated decision-making that produces legal or similarly significant effects.
4. Cookies and local storage
We use your browser's local storage to remember your display-theme preference, and a session cookie to keep you signed in if you choose to sign in. That is all. We set no advertising or analytics cookies that identify you across sites.
5. Advisor data
Registration information about advisors is sourced from government records that are lawfully made available to the public by the SEC and FINRA. Under the California Consumer Privacy Act and the California Privacy Rights Act, publicly available information of that kind is excluded from the definition of "personal information," and comparable exclusions exist in other state privacy laws.
We will still respond to every request we receive from a listed advisor. Where a request asks us to delete fields drawn from those public records, we may decline, and if we do we will tell you plainly which fields we are declining to delete and why. We will delete anything we hold about you that is not drawn from those records. You may also ask us to re-pull your record from the primary source at any time, and we will. See Data Corrections for the fastest route to fixing a factual error in how we reproduce your record, and section 5 of our Legal Disclosures for the limits of what we can change.
6. Reviewer data
If you submit a review, we retain the categories of information listed in section 12 of the Review & Testimonial Policy: review text and all versions, submission timestamp, IP address, device signals, sign-in method and account identifier, attestations, verification artifacts, moderation decisions and the criterion applied, and dispute correspondence.
We do not share your identity or your email address with the advisor you reviewed, and we do not share it with anyone else except as described in section 8. We will disclose a reviewer's identity only in response to valid legal process, or where we believe in good faith that disclosure is necessary to prevent imminent physical harm. If we receive a subpoena or court order seeking a reviewer's identity, we will notify that reviewer at the address on file, provide a copy of the demand and plain-language information about moving to quash, and give them at least 14 days to respond before we produce anything, unless we are legally prohibited from giving notice.
7. Uploaded relationship documents
If you choose to support a documented-relationship badge by uploading a document, we review it, record only a non-reversible verification artifact (such as a hash) and the outcome, and then delete the uploaded document within 30 days. We never retain client statements, account documents, or their contents. Please redact account numbers and balances before uploading anything.
8. When we disclose information
- Service providers. Hosting, content delivery, error monitoring, and email delivery vendors that process data on our instructions and are contractually barred from using it for their own purposes.
- Legal process. When we are required to by valid legal process, subject to the notice commitments in section 6.
- Safety. Where we believe in good faith that disclosure is necessary to prevent imminent physical harm.
- Business transfer. If the Site is ever acquired or merged, information may transfer to the successor, which will remain bound by this policy or give you notice and a choice before any materially different use.
We do not disclose personal information to advertisers, data brokers, or advisors.
9. Your rights and how to exercise them
Regardless of where you live, you may ask us to:
- Access the information we hold about you, and learn the categories, sources, purposes, and recipients;
- Correct information that is inaccurate;
- Delete information we hold about you;
- Port a copy of the content you submitted, in a portable format;
- Opt out of any sale, sharing, targeted advertising, or profiling — noting that we do none of those, so there is nothing to opt out of;
- Appeal any decision we make on a request.
To exercise a right, email [CONTACT_EMAIL] with enough detail for us to find your records — for advisors, the CRD number; for account holders, the email address you signed in with. We will verify your request in a way proportionate to its sensitivity, and we will not ask you for more information than we need to do so.
We respond within 45 days, and we will tell you if we need a permitted extension. If we deny a request in whole or in part, we will explain why and how to appeal; we decide appeals within 45 days of receiving them. We will not discriminate against you for exercising any of these rights — and since the Site is free and has no paying customers, there is no service level to lose. You may also authorize an agent to make a request on your behalf.
10. No GLBA relationship
findmyFA.app is not a financial institution and does not provide financial products or services. We do not collect nonpublic personal financial information, and we ask you never to send us account numbers, balances, or statements.
If you send us that kind of information anyway, we will delete it rather than store it, and we will tell you that we did.
11. Children
The Site is not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it promptly. If you believe a minor has provided us information, contact us at [CONTACT_EMAIL].
12. Retention
We keep account data for as long as your account is active, and for a limited period afterward to handle disputes and meet legal obligations. Published review content and its moderation record are retained while the review is published and archived afterward for accountability. Technical logs are retained for a short operational window and then deleted or aggregated. Uploaded relationship documents are deleted within 30 days, as described in section 7.
13. Security
We use transport encryption for all traffic, encrypt data at rest with our hosting providers, restrict administrative access to the smallest number of people who need it, use federated sign-in so that we never hold your password, and log administrative actions. No system is perfectly secure, and we do not claim otherwise.
14. Breach notification
If we discover a breach of security that compromises personal information we hold, we will investigate promptly, take steps to contain it, and notify affected individuals and the applicable regulators as required by law, without unreasonable delay. Our notice will describe what happened, what information was involved, what we have done, and what you can do.
15. International transfers
We operate in the United States, and information we hold is processed in the United States and in other countries where our service providers operate. If you access the Site from outside the United States, you understand that your information will be transferred to and processed in the United States, where data-protection law may differ from the law of your country. Where a lawful transfer mechanism is required, we rely on standard contractual clauses or another approved mechanism with our providers.
16. Changes to this policy
We may update this policy. When we do, we will change the version number and effective date at the bottom of this page and keep prior versions available. If a change materially expands how we use information about you, we will give notice on the Site before it takes effect.
17. Contact
Privacy questions, requests, and appeals: [CONTACT_EMAIL]. For a factual error in a registration record, Data Corrections is faster.