Privacy
Last updated July 30, 2026
Summary
This site (sound.investments) and the Sound Investments client portal collect very little. We do not run analytics, advertising, or third-party trackers, and we do not set cookies for visitors who are not signed in.
When you sign in
Signing in sets __Secure-better-auth.session_token, a host-only authentication cookie with HttpOnly, Secure, SameSite=Lax, Path=/, and a seven-day Max-Age. If you select “Remember this device for 30 days” during two-factor verification, BetterAuth also sets __Secure-better-auth.trust_device. It is host-only with HttpOnly, Secure, SameSite=Lax, Path=/, and a 30-day Max-Age. BetterAuth refreshes that expiry after each accepted password sign-in while the trust record is valid. Signing out ends the current session and leaves device trust in place. We store the minimum information required to operate your account: your email address, encrypted password material, two-factor authentication enrollment state, and an audit record of actions you take within the portal. We do not store payment-card numbers; client billing runs through Stripe, which holds that data under its own terms.
Email correspondence
If you email hello@sound.investments, we retain your message and contact details only for as long as needed to respond and to keep a reasonable business record.
Where data lives
We do not sell, rent, or share personal information. The site and portal are hosted on Cloudflare. Billing for engaged clients runs through Stripe.
Requests
To request deletion of your account or correspondence, email privacy@sound.investments.