AI Usage
Sumyfi AI Usage Policy
This page explains when Sumyfi uses artificial intelligence, what data may be processed, what safeguards we apply, and what choices you have as a user.
Purpose-limited AI
AI is used for budgeting support, explanations, summaries, and educational guidance. It is not a substitute for your judgment.
Minimal data sharing
We minimize, mask, aggregate, or omit sensitive financial details whenever possible before an AI request is made.
User control
You must consent before enabling AI features, and you can disable those features wherever product controls are provided.
AI Usage Terms
How AI is used in Sumyfi
Our commitment is simple: AI should make financial guidance clearer and more helpful without requiring unnecessary exposure of your personal or financial data.
When Sumyfi may use AI
- To summarize trends in your spending, saving, and budgeting activity.
- To answer natural-language questions about your financial dashboard.
- To generate personalized educational guidance, reminders, and planning suggestions.
- To improve clarity, not to make binding financial, lending, insurance, or tax decisions for you.
Data Minimization Principles
- Only send data strictly necessary to answer your current query.
- Never send full account histories, all transactions, or all account details by default.
- Prefer aggregated, categorized, or masked data whenever possible.
Prohibited Data
- Never send: account numbers, card numbers, government IDs, login credentials, exact internal user IDs, or unmasked personal addresses/phone numbers.
Sensitive Data Handling
- Mask or generalize merchant names (e.g., “Starbucks” → “Coffee Shop”).
- Round or bucket balances and amounts (e.g., $5,432.12 → “~$5.4K”).
- Remove or generalize account names (e.g., “TD Chequing 1234” → “Chequing Account”).
- Only include transaction details if your query specifically requires them.
Explicit User Consent
- You must be clearly informed that your financial data may be processed by AI providers to generate insights and responses.
- Consent is required before enabling AI features during signup or feature activation flows.
- If we expand AI functionality in a materially different way, we will update this page and the associated product disclosures.
Logging and Audit
- Never log or store raw AI prompts containing financial data.
- If logging is required for debugging, all sensitive data is redacted first.
- Maintain an audit log of: categories of data sent, intent/reason, timestamp, and anonymized user.
AI Providers and Data Transfers
- AI features may rely on carefully selected third-party model providers operating under Sumyfi instructions.
- Those providers should only receive the minimum context necessary to complete the requested task.
- Depending on the provider and hosting region, limited AI-processing data may be transferred across provincial, state, or national borders.
- Provider terms, retention controls, and security commitments may evolve over time, and Sumyfi will review material changes before continuing use.
Retention and Operational Handling
- We aim to avoid retaining raw financial prompts longer than operationally necessary to provide the feature, secure the service, or investigate abuse.
- Where product analytics or error monitoring is used, AI-related telemetry should be limited to redacted or non-sensitive metadata wherever possible.
- Retention periods may vary by provider, incident-response requirements, and applicable law, and those limits are reviewed during vendor and security assessments.
Important limitations
- AI outputs are informational and may be incomplete, generalized, or inaccurate.
- AI-generated responses are not legal, tax, accounting, credit, or investment advice.
- You remain responsible for reviewing your own financial decisions and account activity.
Human Review and User Rights
- AI features are designed to support users, not to make solely automated decisions that approve, deny, or materially restrict financial products or account access.
- If an AI-generated response seems wrong, incomplete, or risky, you should rely on human review and authoritative records before acting.
- You can stop using AI-powered features at any time, and you may contact Sumyfi support if you need help understanding how an AI feature handled your request.
- Additional privacy, access, correction, deletion, or complaint rights may be described in the Privacy Policy depending on your jurisdiction.
Review and Updates
- This policy is reviewed at least annually and after major product, vendor, or compliance changes.
- Continued use of AI-powered features after an update means the revised policy applies to those features.
Questions about AI usage?
This page is meant to provide a product-facing explanation of how AI features work in Sumyfi. It does not replace the full Privacy Policy, Terms of Service, security materials, or any legal advice specific to your situation.