8 Total
0 High severity
6 Medium severity
2 Low severity
Summary

This document establishes Wealthfront's data collection, use, and retention practices across its investment, cash account, and lending products. The policy distinguishes between Users of planning tools and Clients under a Client Agreement: Clients' personal data is retained indefinitely due to regulatory recordkeeping obligations and generally cannot be deleted upon request, whereas Users may request deletion of their data. The policy permits data sharing with service providers, affiliates, and business partners for operational purposes, and establishes opt-out mechanisms for marketing communications and location tracking through account settings or support contact.

Technical / Legal Breakdown

This Privacy Policy, effective December 19, 2025, is jointly issued by five Wealthfront entities (Wealthfront Corporation, Wealthfront Advisers LLC, Wealthfront Brokerage LLC, Wealthfront Home Lending LLC, and Wealthfront Software LLC) and governs the collection, use, retention, and disclosure of Personal Information for Users of free financial planning tools and Clients who enter into formal service agreements, with Financial Privacy-Covered Data additionally governed by the Gramm-Leach-Bliley Act and Wealthfront's separate Financial Privacy Notice. The policy states that Wealthfront will 'never rent, sell, or trade your Personal Information to anyone,' while the terms authorize sharing with affiliated entities, service providers performing business functions, business partners offering joint products, and third parties in connection with mergers or asset transfers; the terms also authorize periodic re-access of linked third-party financial account credentials for as long as an ACH link remains active, and disclose that biometric data (selfie photographs for identity verification) is collected from Clients with destruction required within 90 days by vendor contract. The policy asserts a distinction between Users (who may request data deletion) and Clients (whose data generally cannot be deleted due to regulatory recordkeeping obligations), which is operationally significant and narrows deletion rights considerably for most active account holders; the policy also states that cross-device tracking and browsing activity matching across devices is conducted, and that the site does not respond to Do Not Track signals. The policy engages the Gramm-Leach-Bliley Act (GLBA) and its implementing Regulation S-P, CCPA for California residents, biometric privacy laws in applicable jurisdictions (including Illinois BIPA), and FCRA in connection with home lending credit information; the policy's assertion that federal privacy laws may render state privacy laws inapplicable in certain situations is a legally contested area requiring evaluation under applicable state law, and the adequacy of international transfer protections is described only generally without specifying mechanisms such as Standard Contractual Clauses.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial

1 important change detected

3 versions captured · Last updated: June 2026

June 2, 2026

unknown
What changed Wealthfront updated their Wealthfront Privacy Policy on June 02, 2026. Change detected: 6 sentence(s) added, 4 sentence(s) modified. Document contained 276 sentences after update.
View full change record →

Recent Provision Changes Jun 2, 2026

Added (2)
Ongoing Third-Party Account Credential Re-Access Authorization Medium

This addition explicitly documents ongoing re-authorization for continuous account access beyond initial aggregation, which is a material expansion of credential access permissions.

No Response to Do Not Track Signals Low

This new provision clarifies Wealthfront's non-compliance with DNT signals and provides conditional reassurance about third-party tracking authorization, which is important for privacy-conscious users.

Removed (5)
No Sale or Trade of Personal Information

This provision was replaced with a more emphatic version titled 'No Selling or Trading of Personal Information' with strengthened language ('Ever'), suggesting the prior version lacked sufficient emphasis.

Third-Party Account Aggregation (Plaid and Yodlee)

This provision was consolidated and replaced with the more detailed 'Ongoing Third-Party Account Credential Re-Access Authorization' provision, reducing the high-severity rating by narrowing focus to credential handling rather than service provider names.

Marketing Communications Opt-Out

This provision was entirely removed from the current version, suggesting Wealthfront either consolidated it elsewhere or deprioritized explicit marketing opt-out disclosures.

Children's Data Prohibition

Removal of this provision eliminates explicit contractual language protecting children's data, which may reflect either consolidation into general terms or a deliberate de-emphasis of child protection commitments.

California CCPA Rights

Removal of state-specific CCPA rights language suggests Wealthfront may have relocated these rights to a separate California-specific privacy notice or consolidated them into general privacy disclosures.

Modified (5)
Client Data Deletion Restriction

Severity downgraded from high to medium, and specific regulatory justification language was added explaining the rationale for deletion restrictions.

Biometric Data Collection and Vendor Destruction Requirement

Provision expanded with specific details about vendor destruction requirements and conditional consent mechanisms for biometric data.

Data Transfer in Merger or Acquisition

Renamed from 'Data Transfer in Merger or Acquisition' to include 'Asset Sale,' and expanded to include additional scenarios like financing due diligence, bankruptcy, and transition of service.

Cross-Device Tracking and Browsing Activity Matching

Provision renamed and significantly expanded with concrete examples and specific technical methods (geo-location, device identifiers, browsing pattern analysis) used for cross-device matching.

Home Lending Expanded Data Sharing

Severity downgraded from high to medium, and provision expanded to explicitly include onward transfer rights by third-party service providers with enumerated data types (SSN, financial and credit information).

1 provision unchanged.

View full change record →
Medium — 6 provisions
Low — 2 provisions

Monitoring

Wealthfront has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle Bank Login Credential Sharing with Yodlee and Plaid and similar clauses.

Compare across platforms →
Archival ProvenanceSource & Archival Record
Last Captured June 2, 2026 09:50 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000367
Version ID CA-V-003307
SHA-256 e2aed4086f35683f3e4abb15885a3059f3ec733740c3a6519002f35b75c3db0f
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans