Catalyst

Catalyst Privacy Policy

Catalyst Finance, Inc.

Version 2.2 — Effective: September 12, 2026

Last Updated: September 12, 2026

1. Introduction

Catalyst Finance, Inc. ("Catalyst," "we," "us," or "our") provides the Catalyst mobile application and web platform (the "Service"). This Privacy Policy explains how we collect, use, share, and retain information when you use the Service. The Service is offered to residents of the United States, is operated from the United States, and your information is processed and stored in the United States.

By using the Service, you consent to the practices described in this policy. If you do not agree, please do not use the Service.

2. Information We Collect

2.1 Information You Provide

2.2 Information from Linked Financial Accounts

With your authorization, you may connect brokerage, financial, or crypto-exchange accounts through third-party account aggregation services — Plaid Inc. ("Plaid") and SnapTrade — which retrieve, on a read-only basis: account identifiers and institution names; portfolio holdings (securities and digital assets, quantities, prices, and values); account balances; and investment transaction history (such as buys, sells, and dividends).

Your financial-institution login credentials are entered only on the aggregation provider's own pages — we never receive or store them. Access credentials issued to us by the aggregation providers are stored in encrypted form.

We use third parties to gather your data from financial institutions. By using the Service, you grant our third-party providers the right, power, and authority to act on your behalf to access and transmit your personal and financial information from the relevant financial institution according to the terms of our third-party provider's privacy policy. Plaid's handling of your data is governed by Plaid's End User Privacy Policy, available at https://plaid.com/legal. SnapTrade's handling of your data is governed by its privacy policy, available on SnapTrade's website. Each aggregation provider also presents its own end-user terms to you during the connection process, before you authorize access.

2.3 Information Collected Automatically

3. How We Use Information

We use the information we collect to:

4. AI Features

The Service's AI chat and content features are powered by third-party artificial intelligence service providers. When you use the AI chat, the content of your messages, your prior messages in the same conversation, and related context — such as ticker symbols you select or that appear in your watchlists or linked holdings, and content you attach — are transmitted to those providers to generate responses. If you ask portfolio-related questions, that context may also include information from your linked or manually entered accounts, such as holdings and quantities, cost basis, position and account values, institution and account names, and transaction history. Portfolio-based features such as the portfolio brief similarly transmit information about your holdings, watchlist, and account activity to our AI providers to generate your summaries. We do not provide these providers with your name, email address, or account credentials.

Your conversations are stored with your account in our systems, and chat interactions may be logged and reviewed — including through automated compliance checks and internal quality review — for quality, safety, and compliance purposes. Copies of content processed by our AI providers, including any portfolio information included in it, are retained by those providers under their own policies, and deleting a conversation or your account does not delete the copies they hold. Do not submit sensitive personal information through chat.

4A. Connecting an External AI Assistant (Including MCP Connections)

You may be able to connect the Service to an artificial-intelligence assistant, agent, or client that you choose — for example through an API or a Model Context Protocol ("MCP") connection. This is optional and off unless you set it up. Before a connection is established, we ask you to review and accept disclosures describing what follows; you give that acknowledgment once, and it applies for as long as the connection exists.

What can be sent. Access to your financial information is off unless you turn it on, and you approve it separately for each assistant. Once you do, that software can request information about your accounts — such as holdings, quantities, cost basis, valuations, and institution labels — as well as Catalyst market content. The exact fields a connection can and cannot retrieve, and the scope you approve (for example, all of your holdings or only selected accounts), are shown to you when you authorize the connection. Additional detail about the current API and assistant integration is published separately at https://api.catalystfinance.ai/portfolio-privacy.html.

Who receives it, and what we can and cannot control. When a request is made, we transmit the requested information to the software you connected and, through it, to the artificial-intelligence provider and any other services that software relies on. You choose that software and provider; we do not. We do not operate, control, vet, audit, or endorse them, we have no agreement with them about your information, and we cannot impose security, retention, or confidentiality requirements on them.

Once information leaves Catalyst:

Your choices. Review a provider's terms and privacy settings before connecting, and decide whether you are willing to send financial information to it. Where we offer scope controls, you can limit what a connection may request. You can disconnect at any time in the Service's settings or in the external software; disconnecting stops future transmissions but does not affect information already sent.

5. How We Share Information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only:

6. Data Security

We use reasonable administrative, technical, and organizational safeguards designed to protect your information, including encrypted storage of financial access credentials and role-based access controls. No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Data Retention and Deletion

We retain your information while your account is active. You may delete your account at any time in the App's settings. When you delete your account, we revoke our connections at the account aggregation providers, delete stored access credentials, your profile photo, and push tokens, and delete your account data. Limited records may persist after deletion — including archived records retained for security, dispute-resolution, and legal-compliance purposes, derived records used to operate the Service, and backups — until removed in accordance with our retention practices, or longer where required by law; aggregated or anonymized data that no longer identifies you may be retained. Copies of chat content and related context held by our AI providers are subject to their retention policies, as described in Section 4.

You may also disconnect a linked financial account at any time in settings, which stops further syncing and deletes the holdings and transactions synced from that account from our systems, and revokes our access authorization for that account at the aggregation provider. Separately, we may automatically pause or disconnect a linked account after prolonged inactivity or persistent connection errors, with advance notice where reasonably possible; after an automatic disconnection we stop syncing and revoke our access, and previously synced holdings and transactions remain visible in the App until you remove them or delete your account.

8. Your Choices and Rights

9. Children's Privacy

The Service is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.

10. Changes to This Policy

We may update this policy from time to time. We will post the updated policy in the Service, update the "Last Updated" date, and notify you of material changes through the Service or by email. Continued use after changes are posted constitutes acceptance.

11. Contact Us

Catalyst Finance, Inc.

501 Knights Run Ave Apt 1302, Tampa, Florida 33602

Email: contact@catalystfinance.ai