2026 early-access offer: Double credits through end of 2026.

Legal & compliance

Privacy Policy

Last updated 2026-06

Last updated: June 2026

The short version: A2B2 does not sell your data, does not use your queries or portfolio to train AI models, and never shares your personal or financial information with third parties for commercial purposes. You control your data and can delete it at any time.

These policies are published in English. In the event of any discrepancy between the English version and any translated version on this website, the English version prevails.

01 About A2B2

Who we are

A2B2.ai is a wealth intelligence platform operated by Equora AI Limited (registered in Hong Kong SAR, company number 80313661) and Equora AI and Technologies Inc. (registered in Delaware, USA, company number 10608583), trading as A2B2.ai. References to "A2B2," "we," "us," or "our" mean Equora AI Limited, Equora AI and Technologies Inc. and any subsidiaries operating the platform.

The platform combines frontier AI models, agentic research tools, and verified human experts across four pillars: RESEARCH (multi-model intelligence), CONNECT (expert content), EXPLORE (market intelligence search), and OWN (portfolio consolidation).

A2B2 is not a financial institution. A2B2 does not execute trades or transactions, hold, manage, or advise on assets, or store your financial institution login credentials.

For privacy enquiries: privacy@a2b2.ai

02 Scope

What this policy covers

This policy covers how we collect, use, store, and delete your personal and financial data - including data received through third-party financial connectivity integrations such as the OWN module. It applies to all subscription tiers and both launch markets (US and Hong Kong). For current tier details see a2b2.ai/pricing.

Applicable privacy laws: CCPA/CPRA (California); Colorado CPA; Connecticut CTDPA; Virginia VCDPA; Utah UCPA; COPPA (users under 13); Hong Kong Personal Data (Privacy) Ordinance (PDPO).

03 Data we collect

What data we collect

CategoryWhat we collect
IdentityName, email address, date of birth, nationality, country of residence; professional credentials and licensing status (verified professional tiers - see a2b2.ai/pricing)
FinancialPortfolio values, holdings, balances, transaction history (via OWN module); asset classes, currencies, custodians; documents you upload for analysis (term sheets, fund proposals, reports)
AI interactionQueries submitted to RESEARCH; outputs delivered; expert content viewed, saved, or interacted with; research sessions; feedback on outputs
TechnicalIP address, approximate location, device type, OS, browser, session logs, access timestamps, feature usage patterns
CommunicationsSupport messages and survey responses
PreferencesCommunication preferences, content and asset class interests, consent records

How we collect: Directly from you (registration, queries, document uploads); via portfolio connectivity (Plaid for US) when you connect accounts; from third-party market data providers; automatically via session logs and cookies; from expert onboarding verification processes.

04 Legal basis

Why we're allowed to process it

Processing activityLegal basis
Account registration, authentication, core service deliveryContract performance
Portfolio data aggregation (OWN)Contract performance (requires your explicit authorisation)
Expert credential verificationContract performance; legal obligation
Fraud and abuse preventionLegitimate interests
Service and product improvementLegitimate interests
Platform security and access loggingLegitimate interests; legal obligation
AI interaction data - platform improvementConsent (opt-in; opt out at any time with no effect on service)
Marketing communicationsConsent (opt-in only)
Legal obligation compliance (record-keeping)Legal obligation

05 How we use your data

What we do with it

We use your data to deliver and personalise your subscription, run compliance checks on expert content before publication, detect and prevent fraud, improve the platform, communicate with you about your account, and meet our legal obligations.

We do not:

  • Sell your personal data to anyone
  • Generate personalised investment advice from your data
  • Share your query content with other users without your explicit consent
  • Use your financial connectivity data for targeted advertising
  • Make automated decisions with significant legal effects without human review

06 AI & data use

How AI uses your data

We do not share your queries or portfolio data with AI providers for general model training. Our agreements with all approved AI providers explicitly prohibit this.

Where your data is processed by an AI provider to generate a response, the provider may retain prompts, outputs, or related metadata for a limited period under its applicable DPA for purposes such as abuse monitoring, security, compliance, or operational integrity. This does not permit the provider to use your data for model training where a training prohibition applies. Until true Zero Data Retention is separately signed and confirmed for a specific provider, this limited operational retention is the applicable position.

With your explicit consent, anonymised and aggregated interaction data may be used to improve our own validation architecture only - not for general model training. You can opt out at any time via Account Settings → Privacy → Data use preferences with no effect on service quality.

Anonymisation process

Before any interaction data is used for platform improvement: (1) all direct identifiers removed; (2) query text assessed for indirect identifiers and generalised; (3) data aggregated so individual patterns are not visible. Anonymised data is not re-identifiable.

AI interaction data retention: 12 months from the date of interaction, then securely deleted. Request early deletion at privacy@a2b2.ai.

All AI outputs pass through an automated pre-delivery compliance check before reaching you. If any output appears to constitute a personalised investment recommendation, use the [Flag this output] button immediately and do not act on it without independent verification.

07 OWN module

Your portfolio data (Plaid connection)

We are not your financial institution. A2B2 is not a bank, broker-dealer, or custodian. It does not hold or control your assets. Financial data shown in OWN is read-only and aggregated from your institutions. For discrepancies, verify with your institution directly.

What we receive via Plaid

Data typeDescriptionSensitive (CPRA)?
HoldingsBrokerage positions: securities, quantities, market values, cost basisYes
TransactionsInvestment transaction historyYes
Account metadataInstitution name, account type, account ID (non-financial identifier)No

We never receive or store your financial institution username or password. Plaid uses OAuth token-based access - you enter credentials into Plaid's own interface and they are never transmitted to us.

Token storage

TokenStorageEncryptionRetention
link_tokenFrontend memory onlyN/ANever persisted
public_tokenTransient server-side exchangeN/ANever persisted
access_tokenServer-side database onlyAES-256-GCM at restUntil disconnect + purged within 90 days
item_idServer-side databaseN/A (non-sensitive identifier)Until disconnect + purged within 90 days

Revoking your Plaid connection

Disconnect at any time via Account Settings → OWN → Disconnect, or by revoking access directly at your financial institution. On disconnection: Plaid access token revoked immediately; all derived holdings, transaction data, and associated tokens purged within 90 days; financial connectivity access logs retained for 90 days then auto-purged.

Plaid's privacy policy and your consent

A2B2 integrates Plaid's financial connectivity services to power OWN. Before you connect a financial account, Plaid's own consent interface is presented to you, which includes notice of Plaid's privacy policy. As Plaid's client, A2B2 warrants that it will provide all notices and obtain all consents required under applicable law before your data is processed through Plaid's services.

Plaid's privacy policy governs how Plaid processes data within Plaid's own systems independently of A2B2. A2B2 will not make representations about your data that are inconsistent with Plaid's privacy policy, and will not interfere with any independent notice or consent efforts by Plaid.

How we use OWN data

PurposeBasis
Display portfolio holdings and transactions in OWN moduleContractual necessity (user-authorised)
Enable portfolio-aware context in RESEARCH module (contextualisation only; no personalised advice)Contractual necessity
Fraud and abuse preventionLegitimate business interest

We do not: use financial connectivity data to train AI models; sell or share portfolio data with third parties for commercial purposes; generate personalised investment advice from portfolio data; target advertising using your financial information.

08 Data sharing

Who we share with

We don't sell or share your personal or financial data with any third party for commercial, advertising, or any other non-service purpose.

RecipientPurposeSafeguard
Plaid Inc.Investment data connectivity (OWN module)Plaid's privacy policy and DPA apply; Plaid processes data within their systems independently
AWS (us-east-1)Hosting and encrypted data storageAWS DPA; AES-256-GCM encryption at rest; TLS in transit
DatadogObservability and loggingAggregated / pseudonymous; Plaid tokens and credentials excluded from all log output
AI model providers - Group 1 (OpenAI, Anthropic/Claude, Google/Gemini)Generate query responses for personal and financial data queriesDPAs in place; general model training prohibited; ZDR where provider amendments confirmed. See AI Transparency Policy
AI model providers - Group 2 (DeepSeek, Qwen, Kimi) - China-basedNon-personal, non-financial contexts onlyNot cleared for personal or financial data. Restricted pending legal clearance and DPA confirmation. See AI Transparency Policy
Professional advisorsLegal, financial, technical supportConfidentiality obligations apply
Law enforcement / regulatorsLegal obligation or good-faith harm preventionCase-by-case basis; legal review required

08b Enterprise & advisor visibility

What enterprise admins and advisors can and cannot see

Enterprise administrators (an employer, firm, or institution managing a bulk seat plan) have access to: seat utilisation counts, billing records, and aggregate usage statistics. They cannot see individual query content, uploaded documents, AI output history, portfolio data, or individual usage patterns for any user under their plan.

Shared advisor sessions are always user-initiated. During a shared session, both you and your advisor see the same real-time output. When the session ends, the advisor retains no access to your query history, documents, portfolio data, or any activity outside that session.

No query you submit on A2B2 is visible to your employer, plan administrator, or advisor outside of a shared session you explicitly start.

09 Security

How we protect it

MeasureStandard
Encryption in transitTLS 1.2+ (all client↔server and server↔third-party communications)
Encryption at restAES-256-GCM (all persistent storage; third-party access tokens encrypted before storage)
Access controlGoogle Workspace SSO + MFA enforced for all staff; least-privilege principles throughout
Token isolationAccess tokens accessible only to the relevant BFF service layer
MonitoringDatadog; 90-day log retention; automated purge
Secrets managementAWS KMS + AWS Secrets Manager

If you suspect your account has been compromised, contact security@a2b2.ai immediately.

For our full security posture, see the Security Policy →

10 Data retention

How long we keep it

Data typeRetention periodDeletion method
Account identity dataAccount duration + 7 years post-closureSecure deletion
Financial data (portfolio, transactions via OWN)Account duration + 7 years post-closureSecure deletion
Documents uploaded for analysis (RESEARCH)90 days post-querySecure deletion
AI interaction data (queries and outputs)12 months from interactionSecure deletion
Expert-published content (CONNECT)Account duration + 3 years post-closureSecure deletion / anonymisation
Marketing preferences and consent recordsAccount duration + 3 yearsSecure deletion
Technical / access logs90 daysAutomated purge
Support and complaint correspondence5 yearsSecure deletion
Account closure records7 years from closureSecure deletion

Retention periods may be extended for live legal claims, regulatory investigations, or court orders.

11 Your rights

Your rights over your data

Know & Access

Request details of personal information collected and how it is used

Delete

Request deletion of personal information (subject to legal retention obligations)

Correct

Request correction of inaccurate personal information

Portability

Receive your data in a structured, machine-readable format

Limit use of SPI

Limit use of Sensitive Personal Information (including portfolio data) to necessary service purposes (California users - CPRA)

Opt-out of sale/sharing

A2B2 does not sell or share personal information - this right is inherent to our model

Withdraw consent

Withdraw consent at any time; does not affect prior lawful processing

Appeal

Appeal a denied rights request within 45 days of denial (CO, CT, VA, UT users)

How to exercise: Email privacy@a2b2.ai or use Account Settings → Privacy. Response time: 45 days (extendable by 45 days with written notice for complex requests).

Authorised agents (California): Written authorisation required; A2B2 may verify identity directly with you.

Supervisory authorities

California: California Privacy Protection Agency (CPPA); California AG - oag.ca.gov
US federal: Federal Trade Commission - ftc.gov
Hong Kong: Office of the Privacy Commissioner for Personal Data (PCPD) - pcpd.org.hk

California: Notice at Collection (CPRA)

Notice at Collection - California residents. At the time we collect your personal information (including at signup), we disclose the following as required by the California Privacy Rights Act (CPRA):

  • Categories collected: Identity, financial, AI interaction, technical, communications, preferences (see Section 3)
  • Purposes: Service delivery, personalisation, security, platform improvement, legal compliance (see Section 5)
  • Sold or shared: We do not sell or share personal information as defined under CPRA
  • Retention: See Section 10 (Data retention schedule)
  • Sensitive Personal Information: Portfolio holdings, balances, and transaction history qualify as SPI under CPRA. Used only for service delivery (OWN module). You have the right to limit use of SPI to necessary purposes

To exercise rights: privacy@a2b2.ai or Account Settings → Privacy.

Do Not Sell or Share My Personal Information

A2B2 does not sell or share your personal information as defined under the CPRA. This right is therefore inherently satisfied by our business model. California users wishing to confirm this in writing may contact privacy@a2b2.ai. We will respond within 45 days.

Hong Kong: PDPO rights

Users in Hong Kong have the following rights under the Personal Data (Privacy) Ordinance (PDPO, Cap. 486):

  • Access: Request a copy of personal data we hold about you. We will respond within 40 days and may charge a reasonable fee for access requests
  • Correction: Request correction of inaccurate personal data. We will correct or annotate the data within 40 days
  • Objection to direct marketing: You have the right to opt out of use of your personal data for direct marketing at any time
  • Data breach notification: If a data breach affects your personal data, we will notify you and the PCPD as required under the PDPO

To exercise PDPO rights: email privacy@a2b2.ai with subject "PDPO Rights Request". Identity verification may be required.

Supervisory authority (HK): Office of the Privacy Commissioner for Personal Data (PCPD) - pcpd.org.hk

12 Children

Children & minors

A2B2.ai is not for users under 18. We don't knowingly collect personal information from anyone under 13 (COPPA). You must confirm you're 18 or older when you sign up. If we discover an account belongs to someone under 13, we'll disable it and delete all associated personal information immediately. Contact privacy@a2b2.ai if you believe we've collected a minor's data.

13 Data residency

Where your data is stored

A2B2's production infrastructure runs on AWS us-east-1 (US East - N. Virginia) as the sole production cloud provider. All persistent user data - including portfolio data, AI interaction logs, uploaded documents, and account information - is stored and processed within this region.

Third-party AI providers process query data to generate responses. The data residency and retention practices of these providers are governed by their own data processing agreements with A2B2. A maintained list of AI providers and sub-processors is referenced in our AI Transparency & Data Use Policy.

No user data is stored in or transferred to any region other than us-east-1 without explicit disclosure in an updated version of this policy. Where third-party AI providers process queries, data is transferred to that provider's infrastructure under their applicable DPA. Chinese AI providers (DeepSeek, Qwen, Kimi) are not used for queries involving personal or financial data - their use is restricted to non-personal contexts pending legal clearance. Cross-border transfer restrictions per provider are maintained in the AI Provider Vendor Register (available on request at security@a2b2.ai).

14 Wind-down

If A2B2 closes

In the event of a wind-down or discontinuation of the A2B2 platform, we will provide users with:

  • Reasonable notice: At least 30 days' notice by email where feasible, depending on the circumstances of wind-down
  • Data export window: A period to export your data before service discontinuation, via Account Settings → Privacy → Export my data
  • Deletion on closure: Your personal data will be securely deleted or anonymised following the export window, subject to mandatory legal retention obligations (see Section 10)
  • Continued security: Security controls will be maintained through the wind-down period - your data will not be left unprotected

If A2B2 is acquired or its data is transferred to a successor entity, users will be notified before any such transfer and given the option to delete their account and data before it proceeds.

15 Changes

When this policy changes

Material changes (data use, fees, liability, user rights, AI training opt-out) come with at least 30 days' notice via email and in-app banner before they take effect. Material changes include: new data collection categories; new third-party processors; changes to AI training opt-out; pricing changes; governing law changes.

Non-material changes (corrections, clarifications) take effect on publication with the version date updated.

Continuing to use the platform after a material change takes effect counts as acceptance. If you don't accept, close your account before the effective date.

Related policies: For cookie and tracking details, see the Cookie & Tracking Policy. For AI transparency and data use, see the AI Transparency & Data Use Policy. For data retention details, see the Data Retention Policy.

16 Contact

Reach us

Privacy enquiries

privacy@a2b2.ai

Security concerns

security@a2b2.ai

OWN / Plaid discrepancies

privacy@a2b2.ai

Legal

legal@a2b2.ai

A2B2 is not your financial institution and is not the source of truth for your holdings or transactions. Verify discrepancies with your institution directly.