Trust is not a marketing word here.
This page exists so you can decide whether to give Wade.Tech access to anything sensitive in your life — your bank, your home, your calls. Every claim here is something we hold ourselves to in code, in policy, and in audit.
The lock on a door isn't decoration. Neither is this page. Every claim below is something we hold ourselves to in code, in policy, and in audit.
trust · live posture
Three things we will never do with your data.
No passwords. No account numbers.
Plaid's read-only tokens. We never see what you type.
scope: read-only
Read only. Never move.
Our software cannot move money or send anything in your name.
writes: 0
Isolated. Encrypted. Yours.
Walled off per person. No casual review. No partners.
tenant-isolated
What we collect, and do not
We collect
- Bank transaction data (via Plaid read-only tokens)
- Account types and balances you've opted to sync
- The information you give Higgins (face/voice recognition data — local on your device)
- Your travel route searches (for the watch feature, if you opt in)
- Site analytics (page views, anonymized, GA4)
We do not collect
- Bank passwords or login credentials (Plaid handles these — we never see them)
- Card numbers or CVVs
- Continuous home audio/video (Higgins listens/watches for what you asked)
- Your contacts list, location history, or microphone outside Higgins-specific use
How bank connections work
Plaid is the financial-data gateway. You log in to your bank inside Plaid's secure flow — Plaid issues a token to Wade.Tech. The token can read transactions but cannot move money, change account settings, or initiate transfers. We can revoke our access; you can revoke our access; nothing happens to your money without you triggering it on your bank's side.
How AI conversations are handled
When a product uses Aspen to think, your prompt is sent to an intelligence provider. We strip personally-identifiable information before transmission. We never retain prompt content in long-term storage. We do retain routing metadata (what kind of question, what tier responded, latency) for analytics on what works — without the words.
Multi-tenant isolation
Every customer's data lives behind a tenant boundary. No cross-tenant queries are possible in the data layer. Aggregated public-website data (the live counters you see on this site) is gated to cohorts of 5+ tenants so no individual can be inferred.
Encryption posture
At rest: AES-256 on databases and backups. In transit: TLS 1.3 only. Keys: AWS KMS with rotation; access logged.
Auditing & accountability
Internal review monthly. We are working toward annual third-party SOC 2 Type II audit (in progress). Any security incident is disclosed to affected users within 72 hours.
Your rights
Export everything we have on you, anytime. Delete everything we have on you, anytime. Correct anything that is wrong. Email privacy@wade.technology and we respond within 5 business days.
Contact for security questions
Security questions or responsible disclosure: security@wade.technology. We honor responsible disclosure and acknowledge within 48 hours.