How long we keep it, and how we let go.
Keep data only as long as it serves a legitimate purpose, dispose of it securely when that purpose ends, and give users clear control over their own data.
Purpose and scope
This policy defines how long Carlo Finance, Inc. (“Carlo”) retains each category of user data and how that data is disposed of when it is no longer needed. It applies to all data collected through the Carlo application, including data received from third-party services like Plaid.
The goals are straightforward: keep data only as long as it serves a legitimate purpose, dispose of it securely when that purpose ends, and give users clear control over their own data.
Data categories and retention periods.
The following table summarizes retention periods for each category of data we handle. These periods describe how we operate in the ordinary course; where an exception in Section 07 applies (legal holds, regulatory requirements, fraud prevention), data may be retained longer.
| Category | Retention | Disposal method |
|---|---|---|
| Plaid account data Account info, balances, transactions | Duration of active account + 30 days | Database deletion + backup rotation |
| Financial projections and scenarios Simulation results, what-if outputs | Duration of active account | Database deletion |
| User profile and goals Income, savings targets, retirement timeline | Duration of active account + 30 days | Database deletion |
| Authentication credentials Hashed passwords, session tokens, Plaid access tokens | Duration of account; immediate on deletion | Cryptographic erasure |
| Usage and analytics data Pages visited, features used, interaction patterns | 24 months rolling | Automated purge |
| Session recordings How you interact with Carlo, which may include content viewed and information entered | 90 days rolling | Automated purge |
| Server logs IP addresses, request logs, error logs | 90 days | Automated purge |
| AI prompts and responses Natural-language requests, model-generated text and structured outputs stored in your account | Duration of active account + 30 days | Database deletion + backup rotation |
| AI request metadata Model used, latency, error state, token counts, request ID | Duration of active account + 30 days | Database deletion + backup rotation |
| Uploaded raw documents Financial documents uploaded for account import and extraction | Encrypted in Carlo-controlled Amazon S3 for the active account, until the user deletes the file | File deletion purges every stored object version; account deletion purges all associated originals, subject to legal and security retention constraints |
| AI inference payloads Transient prompts, uploaded documents, and responses processed by our AI providers’ model infrastructure | Carlo does not store transient provider request payloads as standalone records; encrypted originals remain governed by their document/account record and normalized product facts by the surface that owns them | Per our AI providers’ published policies, inference content is retained transiently plus any limited service-operation and abuse-monitoring period (windows vary by provider and configuration) before deletion (longer only if required by law or legal process), and is not used to train their models (see Section 06); Carlo-controlled product copies follow the retention schedule in this table |
| Billing and consent records Invoices, transaction identifiers, subscription history, tax records, and proof of acceptance | Up to 7 years after the transaction or account closure, or longer when required for a legal hold or payment dispute | Restricted archival retention at Carlo and Stripe, then secure deletion under provider retention schedules |
| Support communications Email threads, in-app support messages | 2 years after resolution | Manual deletion |
User-initiated deletion
You have the right to request deletion of your data at any time. Here is how it works:
How to request deletion
- In-app — use the account settings page to request account deletion directly (available at launch).
- Email — send a request to privacy@carlo.finance from the email address associated with your account.
What happens next
- We verify your identity and acknowledge the request within 5 business days.
- All information associated with your account, including personal data, financial data, uploaded documents, and extracted account records, is deleted from production systems, typically within 30 days of the verified request, subject to legal, security, and fraud-prevention retention constraints.
- Plaid access tokens are revoked immediately, severing the connection to your financial institutions.
- Backups containing your data are purged as backup rotation completes, typically within 30 days of the deletion request (see Backup Retention below).
- The natural-language prompts and AI-generated responses tied to your account are deleted from Carlo-controlled systems on the same schedule. On the provider side, per the providers’ published policies, inference content is retained transiently plus any limited service-operation and abuse-monitoring period (windows vary by provider and configuration) before deletion (longer only if required by law or legal process) and is not used to train their models (see Section 06).
- We send you a confirmation email once deletion is complete.
What we cannot delete
Aggregate, de-identified data that has been stripped of all personal identifiers and cannot be linked back to you may be retained and used internally as described in our Privacy Policy — for example, for product analytics and for improving Carlo’s own models, features, and services. This data cannot identify you, and it is never sold or licensed to third parties.
We may also retain limited billing, tax, fraud-prevention, dispute, and consent records when needed to comply with law, establish or defend legal claims, or document a transaction. These records are restricted from ordinary product use and are deleted when the applicable retention purpose ends.
Account closure process
When you close your Carlo account:
- Immediate — your account is deactivated. You can no longer log in or access simulations.
- Immediate — any paid subscription is canceled so it cannot renew. Account deletion ends access immediately and does not produce a prorated refund except where required by law.
- Immediate — all Plaid access tokens are revoked. Your financial institutions are disconnected from Carlo.
- Typically within 30 days — all personal data, financial data, projections, and profile information are deleted from production databases.
- Typically within 30 days — your data is purged from backup systems as backup rotation completes.
- Confirmation — you receive an email confirming that account closure and data deletion are complete.
Backup retention and disposal
Database backups are an essential part of our disaster recovery plan. Here is how they interact with data deletion:
- Backup schedule — production databases are backed up daily. Backups are encrypted at rest using the same encryption standard as the production database.
- Backup rotation — backups are retained on a rolling basis. Older backups are automatically replaced as new ones are created.
- Deletion requests — when a user requests data deletion, their data is purged from backups as the backup rotation cycle completes, typically within 30 days. We do not selectively delete individual records from encrypted backups; instead, we rely on the rotation cycle to ensure complete removal.
- Restoration safeguard — if a backup containing deleted user data must be restored for disaster recovery purposes, we re-apply pending deletion requests immediately after restoration.
AI provider retention.
The retention periods above describe data Carlo holds. Carlo uses third-party AI models — from providers such as OpenAI and Anthropic, accessed directly or through hosting platforms such as Amazon Bedrock, Microsoft Foundry, or OpenRouter — for natural-language and document-import features. Inference requests are sent from Carlo’s servers to these providers, and their handling of that content is outside Carlo’s direct control.
- Region — our AI providers and platforms generally process requests in the United States, and some do not offer a data-residency or region commitment for our accounts.
- Data minimization — prompts include the user request and only the account, transaction, goal, document, or model context needed for that request.
- Provider-side retention — we prefer providers and configurations that limit retention. Under the providers’ published policies, content sent for inference is retained transiently plus any limited service-operation and abuse-monitoring period (windows vary by provider and configuration) before deletion, unless a provider is required to retain it longer to comply with a law, court order, or legal process (for example, a litigation preservation order). Carlo does not control these providers’ systems and cannot guarantee provider-side retention or deletion beyond each provider’s own terms.
- Not used to train the providers’ models— we select and configure our AI providers so that your content is not used to train or improve their models. Carlo may use de-identified or aggregated data that cannot reasonably be linked back to you to research, develop, and improve Carlo’s own models and services.
When you delete your Carlo account, Carlo deletes stored prompts and AI-generated responses from Carlo-controlled systems according to the schedule above. On the provider side, under the providers’ published policies, inference content is retained transiently plus any limited service-operation and abuse-monitoring period (windows vary by provider and configuration) before deletion, unless required to be retained longer by law or legal process. Carlo does not control these providers’ systems and cannot independently guarantee deletion of provider-side copies.
Exceptions
In limited circumstances, we may retain data beyond the periods listed above:
- Legal holds — if we receive a legal preservation request (litigation hold, government investigation), we will retain relevant data for the duration of the hold, even if it exceeds our standard retention period.
- Regulatory requirements — certain financial regulations may require us to retain specific categories of data for longer than our standard periods. If this applies, we will retain only the minimum data required and delete it as soon as the regulatory obligation ends.
- Fraud prevention — data associated with accounts flagged for fraud or abuse may be retained for up to 3 years after account closure to support fraud prevention and investigation.
In all exception cases, we apply the same security controls to retained data as we do during normal retention.
Policy review
This Data Retention & Disposal Policy is reviewed at least annually. Reviews assess:
- Whether retention periods remain appropriate for current product functionality and regulatory requirements.
- Whether disposal methods remain adequate given current data storage technologies.
- Whether new data categories have been introduced that need retention schedules.
- Whether any regulatory changes require adjustments to retention or disposal practices.
The next scheduled review is April 2027.
Responsible parties
- Policy owner — the CTO is responsible for maintaining this policy and ensuring that retention and disposal practices are implemented as described.
- Implementation — automated purge jobs for analytics data and server logs are managed by the engineering team. Manual deletion processes (support communications) are tracked and executed by the responsible team member.
- Compliance verification — retention compliance is verified during the annual policy review. As the team grows, this will be incorporated into our planned SOC 2 audit cycle.
Contact
Questions about this policy or requests related to data retention and deletion: