Privacy Policy
Effective Date: July 22, 2026 · Previous versions: July 21, 2026 · March 7, 2026
Kite Lane Group LLC ("Company," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy describes how we collect, use, store, and disclose information when you use the NestMint web application (the "Service"). It also describes your rights and choices regarding your information.
By creating an account, accessing, or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described in this Privacy Policy, you should not use the Service.
This Privacy Policy should be read together with our Terms of Service, which govern your use of the Service.
1. Information We Collect
We collect only the information necessary to provide the Service. The categories of information we collect are described below.
1.1. Account Information
When you create an Account, we collect:
| Data | Purpose | Storage Method |
|---|---|---|
| Username | Account identification and authentication | Stored in plaintext |
| Password | Account authentication | Stored as a bcrypt hash with a unique per-password salt; we never store your plaintext password. Accounts created before our June 2026 security update retain a salted SHA-256 hash until the password is next changed. |
| Email address (required) | Account verification, password reset, and service messages about your Account | Stored on secure servers with a flag indicating whether it has been verified |
| Display name (optional) | Personalizing how the Service addresses you | Stored on secure servers |
| Date of birth (optional) | Age-dependent planning calculations, such as Required Minimum Distribution timing | Stored on secure servers |
| State of residence (optional) | Applying the correct state tax treatment to your projections | Stored on secure servers. We do not collect your street address. |
| Files you upload (optional) | Keeping your own spreadsheets and documents alongside your plan, for your reference | Stored on secure servers as part of your Account, exactly as you uploaded them. We do not read, parse, or analyze their contents, and they are never shared with other users. Like other stored data they are not separately encrypted at rest (see 3.1.1). They are removed when you delete the file or your Account. Please do not upload documents containing Social Security numbers, bank or brokerage account numbers, or other sensitive identifiers — the Service never needs them. |
| Feedback you submit (optional) | Improving the Service | Stored on secure servers with your Account |
| Google account identifier and email (only if you sign in with Google) | Authenticating you through Google Sign-In | Stored on secure servers. We receive only your basic profile and email from Google; we never receive your Google password. |
Note regarding email: An email address is required to create an Account. We use it to verify your Account, to let you reset your password, and to send you messages about your Account. We do not send marketing email, and we do not sell, rent, or share your email address. To deliver these messages we use a third-party email service provider, which processes your email address solely to send mail on our behalf.
Note regarding payment email: If you purchase a paid Subscription or Lifetime Access, our payment processor (Stripe, Inc.) will collect your email address as part of the payment flow. This email is processed and stored by Stripe in accordance with Stripe's Privacy Policy. The email address you give Stripe is handled by Stripe under its own policy; the email address stored by NestMint is the one you provide when you create your Account, as described above.
1.2. Financial Planning Data (User Data)
The Service allows you to enter financial planning data to generate retirement projections and estimates. This may include, but is not limited to:
- Account balances (e.g., 401(k), IRA, Roth IRA, taxable brokerage, savings)
- Income amounts (e.g., salary, pension, Social Security estimates)
- Spending and budget amounts
- Tax rates and tax-related assumptions
- Expected rates of return and inflation assumptions
- Retirement age and planning horizon
- Roth conversion amounts and scenarios
- Required Minimum Distribution (RMD) parameters
- Any other financial planning inputs you choose to enter
All User Data is entered manually by you. The Service does not connect to, link with, or aggregate data from any third-party financial institution, bank, brokerage, or external data source.
User Data is stored as JSON in our database on secure servers.
1.3. Information We Do NOT Collect
We want to be transparent about what we do not collect:
- No email address is currently required for account creation.
- No cookies or browser storage. The Service does not use browser cookies or local browser storage mechanisms. Authentication and session management are handled entirely through server-side sessions.
- No analytics or tracking. We do not currently use any third-party analytics services, tracking pixels, advertising trackers, or similar technologies.
- No third-party account linking. We do not connect to or retrieve data from any external financial accounts or services.
- No location data. We do not collect precise geolocation data.
- No device fingerprinting. We do not employ browser or device fingerprinting techniques.
1.4. Automatically Collected Technical Information
When you access the Service, our servers may automatically record certain technical information in server logs, including:
- IP address
- Browser type and version
- Operating system
- Date and time of access
- Pages or features accessed within the Service
This information is collected as a standard function of web server operations and is used solely for maintaining the security and operational integrity of the Service. It is not used for tracking, profiling, or advertising purposes.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Providing the Service: To operate the retirement planning tools, generate projections and estimates, and deliver the features you use.
- Account Management: To create and manage your Account, authenticate your identity, and facilitate account recovery.
- Service Improvement: To understand how the Service is used, identify bugs or errors, and improve the functionality, performance, and reliability of the Service.
- Security: To detect, prevent, and address fraud, unauthorized access, security incidents, and other harmful or illegal activities.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
- Communications: To respond to your inquiries, support requests, or other communications you send to us.
We do not use your information for advertising, marketing profiling, or selling to third parties.
3. How We Store and Protect Your Information
3.1. Data Storage. Your information is stored on secure servers operated on our behalf. User Data (financial planning inputs) is stored as JSON in our database. Your password is stored as a bcrypt hash with a unique per-password salt — we never store or have access to your plaintext password. Accounts created before our June 2026 security update retain a salted SHA-256 hash until the password is next changed, at which point it is upgraded.
3.1.1. What encryption we do and do not use. We want to be precise rather than reassuring here. All traffic between your browser and the Service is encrypted in transit using industry-standard TLS (HTTPS). Your password is protected by one-way cryptographic hashing, as described above. However, User Data stored in our database is not separately encrypted at rest — it is protected by server access controls, not by application-level encryption. The same is true of any files you upload: they are stored as you provided them, protected by access controls rather than application-level encryption. We describe this plainly because a privacy policy should state what is actually true. Note also that the Service never asks for and never stores Social Security numbers, bank or brokerage account numbers, or credentials to any financial institution, and it does not connect to any external financial account.
3.1.2. NestMint Workplace (employer program). If you use NestMint through your employer's program, we store your employer's configuration only — company name, branding, benefits-team contact, retirement-plan details such as the employer match formula and plan provider, and the sign-on settings your employer's IT team provides. This employer configuration contains no personal data about you. Your employer never sees your individual data: your plan inputs, results, saved scenarios, and everything else in your Account remain yours alone, exactly as for every other user, and there is no mechanism by which an employer can view, query, or export any individual employee's information. If you sign in through your employer's program, your Account records which employer program it belongs to — the program's identifier only, used to show your employer's branding and plan details; it grants your employer no access of any kind. If employer-level reporting is ever offered in the future, it will contain only aggregated, anonymized statistics computed over groups large enough that no individual can be identified, and this policy will be updated first.
3.1.3. Account type and planning view. Every Account records its account type — whether it is a personal Account you created yourself at nestmint.ai, or a NestMint Workplace Account created through an employer program. The two are separate Accounts with separate data, even when they use the same email address; neither can read the other's information. Workplace Accounts also record your planning view preference — whether you are currently using the Employee or Retiree view, and which view you last used — so that we can return you to the same view the next time you sign in. The planning view is a display preference that you control and can change at any time; it is not a statement about your employment status, it is never reported to your employer, and it does not change what data you can see or save.
3.1.4. Interface preferences. We store a small set of interface preferences on your Account — for example, a record that you have dismissed a one-time explanatory message. These preferences contain no financial or personal information and exist only so the Service does not repeat itself across your devices.
3.1.5. Workplace invitations. NestMint Workplace Accounts cannot be self-created; they exist only by invitation from your employer. When your employer invites you, we store an invitation record containing the email address your employer supplied, optionally your first name for the greeting on the invitation page, the planning view you are assigned to start in, the employer program the invitation belongs to, a single-use invitation token, and its expiry and status. Invitations expire automatically, and accepting one creates your Workplace Account. Your employer supplies the email address and name in these records; we do not obtain them from any other source.
3.1.6. Employer single sign-on. If your employer's program uses single sign-on, you sign in through your employer's identity provider rather than with a NestMint password. When you do, the identity provider sends us your work email address (and, if your employer's system provides it, your name) so we can create or match your Workplace Account. We also keep a short-lived technical record of each sign-in — the identifier of the sign-in message and when it was used — solely to reject replayed or duplicated sign-in messages; this record contains no plan data and is not used for any other purpose. We never receive your employer password, and your employer's identity provider does not receive your plan data.
3.2. Security Measures. We implement reasonable technical and organizational measures designed to protect your information from unauthorized access, disclosure, alteration, and destruction. These measures include, but are not limited to:
- Cryptographic password hashing with per-password salting (bcrypt)
- Encryption of all traffic in transit using TLS (HTTPS)
- Rate limiting on sign-in, registration, and password-reset attempts
- Single-use, time-limited password reset links
- Server-side session management (no client-side token storage)
- Secure server infrastructure
- Access controls limiting who can access user data
3.3. No Guarantee of Security. While we strive to protect your information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee the absolute security of your information. You acknowledge and accept this inherent risk when using the Service.
4. Sharing and Disclosure of Information
We take your privacy seriously and do not sell, rent, or trade your personal information or User Data to third parties for their marketing or commercial purposes.
We may share your information only in the following limited circumstances:
- Service Providers: We share information with third-party service providers who perform services on our behalf, including:
- Hosting providers — for server infrastructure and data storage.
- Stripe, Inc. — for payment processing. Stripe receives your payment card details and billing email address directly. NestMint does not store your full card number, CVV, or payment credentials. Stripe processes payments in accordance with PCI-DSS standards and its own Privacy Policy.
- Legal Requirements: We may disclose your information if required to do so by law, or in the good faith belief that such action is necessary to (a) comply with a legal obligation; (b) protect and defend the rights or property of the Company; (c) prevent or investigate possible wrongdoing in connection with the Service; (d) protect the personal safety of users of the Service or the public; or (e) protect against legal liability.
- Business Transfers: If the Company is involved in a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of its assets, your information may be transferred as part of such transaction. We will notify you of any such change in ownership or control of your information.
- With Your Consent: We may share your information for any purpose with your explicit consent.
5. Cookies, Tracking, and Similar Technologies
The Service does not currently use:
- Browser cookies (first-party or third-party)
- Local or session browser storage
- Tracking pixels or web beacons
- Third-party analytics services (e.g., Google Analytics)
- Advertising or retargeting technologies
- Device fingerprinting
Session management is handled entirely through server-side sessions. If we introduce any tracking or analytics technologies in the future, this Privacy Policy will be updated to reflect such changes, and you will be notified as described in Section 11 below.
6. Data Retention
6.1. We retain your Account information and User Data for as long as your Account is active and you maintain an active Subscription.
6.2. If you request deletion of your Account, we will delete your Account information and User Data within thirty (30) days of receiving your verified request, subject to any legal obligations requiring us to retain certain information.
6.3. Server logs containing automatically collected technical information are retained for up to ninety (90) days for security and operational purposes and are then deleted or anonymized.
6.4. Following Account deletion, certain information may be retained in anonymized or aggregated form that cannot be used to identify you individually.
7. Your Rights and Choices
You have the following rights regarding your information:
7.1. Access and Data Export
You may request a copy of the personal information and User Data we hold about you. To make a data export request, please contact us at admin@nestmint.ai. We will respond to your request within thirty (30) days.
7.2. Correction
You may update or correct your User Data at any time through the Service. If you need to update your Account information (e.g., username), please contact us at admin@nestmint.ai.
7.3. Deletion
You may request deletion of your Account and all associated data by contacting us at admin@nestmint.ai. Upon receiving and verifying your request, we will delete your Account and User Data within thirty (30) days of receiving and verifying your request, subject to any legal retention obligations.
7.4. Subscription Cancellation
You may cancel your Subscription at any time. Cancellation does not automatically delete your Account or data. To delete your data, you must submit a separate deletion request as described above.
8. Children's Privacy (COPPA Compliance)
8.1. The Service is not directed at, marketed to, or intended for use by children under the age of thirteen (13). We do not knowingly collect personal information from children under 13.
8.2. If we become aware that we have collected personal information from a child under 13, we will take immediate steps to delete such information from our servers.
8.3. If you are a parent or guardian and believe that your child under 13 has provided personal information to us, please contact us at admin@nestmint.ai so that we can take appropriate action.
8.4. Users must be at least eighteen (18) years of age to create an Account, as stated in our Terms of Service.
9. California Privacy Rights (CCPA/CPRA)
If you are a resident of California, the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA"), provides you with certain additional rights regarding your personal information.
9.1. Right to Know
You have the right to request that we disclose to you (a) the categories of personal information we have collected about you; (b) the categories of sources from which the personal information is collected; (c) the business or commercial purpose for collecting the personal information; (d) the categories of third parties with whom we share personal information; and (e) the specific pieces of personal information we have collected about you.
9.2. Right to Delete
You have the right to request that we delete any personal information about you that we have collected, subject to certain exceptions provided by law.
9.3. Right to Correct
You have the right to request that we correct inaccurate personal information that we maintain about you.
9.4. Right to Opt-Out of Sale or Sharing
We do not sell or share your personal information as those terms are defined by the CCPA. Therefore, there is no need to opt out of sale or sharing.
9.5. Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights. We will not deny you goods or services, charge you different prices, provide you with a different level of quality, or suggest any of the foregoing as a result of your exercising your rights under the CCPA.
9.6. Categories of Personal Information Collected
Under the CCPA framework, we collect the following categories of personal information:
| Category | Examples | Collected? |
|---|---|---|
| Identifiers | Username, IP address | Yes |
| Financial information | Self-reported account balances, income, spending (not linked to external accounts) | Yes |
| Internet or network activity | Server logs (browser type, pages accessed) | Yes |
| Protected classifications | Age (inferred from retirement planning inputs) | Indirectly |
| Geolocation data | Precise location | No |
| Biometric information | Fingerprint, face recognition | No |
| Sensory data | Audio, visual | No |
| Professional or employment information | Job title, employer | No |
| Education information | School, degree | No |
9.7. How to Exercise Your California Privacy Rights
To exercise any of your CCPA rights, please contact us at admin@nestmint.ai with the subject line "CCPA Request." We will verify your identity before fulfilling your request. We will respond to verifiable requests within forty-five (45) days.
10. Other State and International Privacy Rights
10.1. Nevada Residents
Under Nevada law, certain consumers may opt out of the sale of "covered information." We do not sell your covered information as defined by Nevada law. If you have questions, please contact us at admin@nestmint.ai.
10.2. Virginia, Colorado, Connecticut, and Other U.S. States
Residents of states with comprehensive privacy laws (including but not limited to Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and Iowa) may have additional rights, such as the right to access, correct, delete, and obtain a copy of personal data, and the right to opt out of targeted advertising and the sale of personal data. Because we do not sell personal data or engage in targeted advertising, many of these rights are already addressed by our practices. For any privacy-related request, please contact us at admin@nestmint.ai.
10.3. International Users
The Service is currently intended for use by residents of the United States only. We do not actively market the Service to residents of the European Union, United Kingdom, or other jurisdictions with comprehensive data protection laws beyond those described in this Privacy Policy.
The Service is operated from and is intended for users in the United States. If you access the Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those of your jurisdiction. By using the Service, you consent to the transfer and processing of your information in the United States.
11. Changes to This Privacy Policy
11.1. We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will notify you by posting a prominent notice within the Service and updating the "Effective Date" at the top of this page.
11.2. Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the updated policy. If you do not agree with the revised Privacy Policy, you should discontinue use of the Service and request Account deletion.
11.3. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
11.4. Revision history. For transparency, material changes to this Privacy Policy are recorded here rather than made silently.
| Effective date | What changed |
|---|---|
| August 5, 2026 | Added section 3.1.6 describing employer single sign-on: what we receive from your employer's identity provider (your work email, and your name if provided) and the short-lived technical sign-in record we keep solely to prevent replayed sign-ins. Also noted that plan inputs now include an optional Retirement Age alongside Current Age, mirroring the existing spouse fields; like every plan input, it is yours alone and never visible to your employer. |
| August 3, 2026 | Disclosed the account model behind NestMint Workplace: the account type that separates a personal nestmint.ai Account from an employer-program Account (sections 3.1.3), the planning-view preference that remembers whether you are using the Employee or Retiree view (3.1.3), interface preferences such as dismissed one-time messages (3.1.4), and the invitation records your employer creates before your Workplace Account exists (3.1.5). No new financial data is collected; these entries describe information already required to operate the employer program. |
| July 29, 2026 | Added section 3.1.2 for the NestMint Workplace employer program: we store employer configuration only (branding, benefits contact, plan rules, sign-on settings), which contains no personal data, and employers never see any individual employee's data. |
| July 22, 2026 | Disclosed two categories that were in use but undocumented: files you upload in the Files area (stored as provided, never read or analyzed by us, removed with the file or the Account) and feedback you submit. Added a caution against uploading documents containing sensitive identifiers, and extended the encryption statement to cover uploaded files. |
| July 21, 2026 | Updated to match current practice: an email address is now required to create an Account (previously it was not collected) and is used for verification, password reset, and Account messages; disclosed optional display name, date of birth, and state of residence, and the identifier and email received when signing in with Google; described password storage accurately as bcrypt, noting that accounts created before the June 2026 security update retain a salted SHA-256 hash until the password is next changed; stated plainly which data is and is not encrypted; removed the retired security question and answer, which is no longer collected or stored; added rate limiting and single-use time-limited reset links to the list of security measures. |
| March 7, 2026 | Initial publication. |
12. Data Security Incident Response
12.1. In the event of a data breach or security incident that compromises the confidentiality or integrity of your personal information, we will:
- Investigate the incident promptly and take steps to contain and remediate the breach;
- Notify affected users as required by applicable law;
- Notify relevant regulatory authorities as required by applicable law;
- Provide information about the nature of the breach and steps you can take to protect yourself.
13. Third-Party Links
The Service may contain links to third-party websites or services that are not owned or controlled by the Company. This Privacy Policy applies only to the Service and does not govern the privacy practices of any third-party website or service. We encourage you to review the privacy policies of any third-party websites or services you visit.
14. Do Not Track Signals
Some browsers include a "Do Not Track" (DNT) feature that signals to websites that you do not want your online activity tracked. Because the Service does not currently employ any tracking technologies, we do not respond to DNT signals — not because we disregard your preferences, but because no tracking occurs regardless of your DNT setting.
15. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Kite Lane Group LLC
Email: admin@nestmint.ai
Subject Line: "Privacy Inquiry"
We will respond to all privacy-related inquiries within thirty (30) days of receipt.