Privacy Policy Last updated: June 27, 2026 Maxed ("we", "our", or "us") operates the Maxed platform at app.maxed.life - an AI-powered financial intelligence platform for small and medium-sized businesses and their CPA / accounting firms. This Privacy Policy explains what data we collect, how we use it, who we share it with, and what rights you have over it. Two different roles. For some information, Maxed decides how and why the information is used — for example, your account and registration details, your use of the Site, and billing data. For that information, Maxed acts as a controller. For other information — in particular the financial records, taxpayer information, and personally identifiable information that a CPA or accounting firm uploads or syncs about that firm’s own clients — Maxed acts as a service provider (processor) that handles the information only on the firm’s instructions and under the firm’s agreement with us, and the firm remains responsible for that informatwner. Where this Policy and a written customer agreement or data processing agreement conflict as to such information, the customer agreement governs. By creating an account or using the platform you agree to the practices described here. 1. Information We Collect a) Account Information When you register we collect your name, email address, password (hashed - never stored in plain text), and your role (business owner or CPA / accountant). If you represent a firm or company we also collect the firm or company name. b) Financial Data If you connect a bank account via Plaid, we receive and store: Account balances (current and available) Transaction history (date, amount, merchant, category) Institution name and account type We store an encrypted access token provided by Plaid to keep your data synced. We never store your bank login credentials, those are handled entirely by Plaid. If you connect a Stripe account, we access revenue and payment data via Stripe's API to provide financial reporting and forecasting. We store only the connection reference - not your Stripe secret keys. c) Financial Records You Upload or Sync Revenue figures, expenses, invoices, bills, payroll data, and other financial records you enter or sync via accounting integrations (e.g. QuickBooks, Xero - where available) are stored to power your dashboards, reports, and AI analysis. Where you authorize the connection, these records may also include taxpayer identification numbers and tax return information within the meaning of Treasury Regulation § 301.7216-1(b)(3), and — through Microsoft 365 / Outlook and Microsoft Teams integrations — email archives and meeting transcripts. This information receives heightened handling consistent with our Written Information Security Program and our obligations under § 7216. d) Usage & Technical Data We automatically collect standard server logs including IP address, browser type, pages visited, and timestamps. This is used solely for security monitoring and platform ility. e) Communications If you use our AI chat, SMS, or call-scheduling features, message content is stored to maintain conversation history and generate AI responses. SMS messages are processed via Twilio. f) Payment Information Subscription and credit-pack payments are processed by Stripe. We store only your Stripe customer ID and subscription status - your card details are never transmitted to or stored on our servers. 2. How We Use Your Data Provide and operate the Maxed platform and all its features Generate AI-powered financial insights, reports, forecasts, and Monte Carlo simulations Display real-time dashboards populated with your financial data Send scheduled digests, alert notifications, and call-prep reports via email or SMS Process subscription payments and simulation credit purchases Allow your linked CPA or accountant to view your company data within the platform Detect anomalies and surface financial alerts relevant to your business Maintain security, prevent fraud, and ensure platform reliability Comply with applicable legal obligations We do not sell your personal or financial data to third parties. We do not use your financial data to train AI models sold to other parties. 3. AI Processing Maxed’s AI chat, financial analysis, and report-generation features are powered by open-source AI models that Maxed operates on its own infrastructure. Your financial data and messages are processed within the Maxed environment to generate AI responses and are not sent to any third-party large language model provider. Maxed does not use your data to train AI models, and does not share your data with any AI provider for that provider’s own model-training purposes. 4. Data Sharing We share data only in the following limited circumstances: Your CPA / Accounting Firm: If your account is linked to a CPA firm via an invite code, that firm's accountants can view your company's financial data and reports within the platform. You control this linkage at account creation.ervice Providers: We use the following sub-processors to operate the platform - Railway (application hosting and managed database services), Digital Ocean (per-firm hosting infrastructure), and Resend (transactional email). Each is bound by data processing agreements. Separately, when you choose to connect a third-party account, we exchange data with that provider as a data source you have authorized — for example Plaid (bank data), Stripe (revenue and payments), QuickBooks or Xero (accounting), and Microsoft 365 (email and calendar). Those providers handle your data under their own terms and privacy policies. Legal Requirements: We may disclose information if required by law, court order, or to protect the rights and safety of our users or the public. 5. Data Retention We retain your account and financial data for as long as your account is active. If you delete your account, we will delete your personal data and financial records within 30 days, except where we are required to retain records for lal or compliance purposes. Where Maxed processes a firm’s data under a customer agreement, return and deletion of that data on termination are governed by that agreement. Security and audit logs are retained for a limited period (generally 12 to 24 months) for security and reliability purposes. Tax return information and related workpapers may be subject to longer retention required by law. A legal hold suspends deletion until released. Bank connection tokens (Plaid access tokens) are deleted when you disconnect your bank account or close your account. 6. Data Security Maxed maintains an administrative, technical, and physical safeguards program (its Written Information Security Program) designed to protect the security, confidentiality, and integrity of the data it holds. Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256). Each customer’s data is logically isolated from other customers’ data through database-level access controls. Access to data is restricted to authorized personnel and sub-processors, who are bound by confidentiality obligations; high-risk actions require multi-factor authentication. Sensitive credentials, such as bank-connection and integration tokens, are stored server-side only and are never exposed to the browser. No system is 100% secure. In the event of a data breach we will notify affected users in accordance with applicable law. Where Maxed processes data on a firm’s behalf, Maxed will notify the firm of a security incident affecting that data without undue delay and, in any event, within the time required by the applicable customer agreement, so that the firm can meet its own notification obligations. Maxed will also make any regulator notifications required of it by law. 7. Your Rights Depending on your location you may have the right to: Access the personal data we hold about you Correct inaccurate data Delete your account and associated data Export your data in a portable format Disconnect bank or Stripe integrations at any time Integrations page Opt out of non-essential communications To exercise any of these rights, email us at [email protected]. Categories and purposes. The categories of personal information we collect, the sources we collect it from, and the purposes for which we use and disclose it are described in Sections 1, 2, and 4. We disclose personal information to the service providers and integrations identified in Section 4 for the purposes described there. No sale or sharing; sensitive information. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information — including financial-account information and, where applicable, taxpayer information — for any purpose other than providing the Services and other purposes permitted by law. State privacy rights. Depending on your state of residence, you may have some or all of the following rights, in addition to those listed above: to confirm whether we proceour personal information and to access it; to correct or delete it; to receive a portable copy; to opt out of the sale or sharing of personal information, targeted advertising, and certain profiling (we conduct none of these); and to limit our use of sensitive personal information. We will not discriminate against you for exercising any of these rights. Appeals. If we decline your request, you may appeal by replying to our response or emailing [email protected] with “Appeal” in the subject line. We will respond within the time required by applicable law, and if we deny your appeal you may contact your state attorney general. Verifying requests; authorized agents. Submit requests to [email protected]. To protect your information, we will take reasonable steps to verify your identity before acting on a request and may ask for information that matches what we already hold. You may use an authorized agent to submit a request on your behalf if we can verify the agent’s authority and your identity. ial data subject to the GLBA. Personal information we process that is subject to the Gramm-Leach-Bliley Act is exempt from these state privacy laws and is handled under our obligations in that Act. The state rights above apply to personal information that is not within that exemption — for example, your account and registration details, business contact information, and information about how you use the Services. 8. Cookies We use first-party session cookies to keep you logged in. We do not use third-party advertising cookies or tracking pixels. You can clear cookies at any time via your browser settings, which will log you out of the platform. 9. Children's Privacy The Maxed platform is intended for business use only and is not directed at anyone under the age of 18. We do not knowingly collect personal information from minors. 10. Changes to This Policy We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top and, for material changesnotify you by email or an in-app notice. Continued use of the platform after changes constitutes acceptance of the updated policy. 11. Contact Us If you have questions about this Privacy Policy or how we handle your data: Maxed Life, Inc. Email: [email protected]