How Carlo handles your data.
We collect only what we need to run your simulations, we never sell your data, and we give you full control over deleting it. If anything here is unclear, write to privacy@carlo.finance.
Carlo Finance, Inc. (“Carlo,” “we,” “us,” or “our”) operates the website carlo.finance and the Carlo financial decision simulator. This Privacy Policy explains what information we collect, how we use it, who we share it with, and what rights you have over your data.
Information we collect.
Information you provide directly
- Account information — name, email address, and password when you create an account.
- Financial goals and profile — income, savings targets, planned purchases, retirement timeline, and other details you enter to power your simulations.
- Support communications — messages you send us through email or in-app support.
- Demo-booking information — your name, email address, and selected appointment time when you choose to schedule a demo through Google Calendar.
- Billing information — billing name and address, subscription status, transaction identifiers, invoices, payment history, and your acceptance of subscription terms. Stripe collects and stores your full payment-card details; Carlo does not.
Information from optional address lookup
When you manually add a real-estate asset and choose the optional address lookup, the address text in that field is sent from your browser to Mapbox so Mapbox can return address suggestions. We do not send bank credentials, account identifiers, balances, or transaction data to Mapbox.
Information from Plaid
When you connect a financial account through Plaid, we receive the following categories of data from your financial institution via Plaid’s API:
- Account information — account name, type (checking, savings, credit, investment), and institution name.
- Balance data — current and available balances for each connected account.
- Transaction data — transaction history including date, amount, merchant name, and category.
We do not receive or store your bank login credentials. Plaid uses OAuth-based connections to securely access your data from your financial institution. For details on how Plaid handles your data, see Plaid’s End User Privacy Policy.
Information from SnapTrade
When you connect a brokerage account through SnapTrade, we receive the following categories of data from your brokerage via SnapTrade’s API:
- Account information — account name, type, and institution name.
- Balance and holdings data — account balances, positions, and security identifiers for each connected account.
- Transaction data — trade and transfer history including date, amount, and security.
Connections made through SnapTrade are read-only, and we do not receive or store your brokerage login credentials. For details on how SnapTrade handles your data, see SnapTrade’s privacy policy.
Information collected automatically
- Usage data — pages visited, features used, simulations run, and interaction patterns.
- Device and browser information — browser type, operating system, screen resolution, and language preferences.
- Log data — IP address, access times, referring URLs, and server logs.
Information processed by AI providers
When you use Carlo’s natural-language or document-upload features, the content of your requests, uploaded documents, and the parts of your stored data necessary to answer them — which may include account balances, transaction summaries, and the goals and figures in your profile — is sent from Carlo’s servers to third-party AI model providers — such as OpenAI and Anthropic, accessed directly or through a cloud platform that hosts their models — for processing. Uploaded originals are encrypted and stored in Carlo-controlled Amazon S3 storage until you delete the file or your account. Carlo may send a document or locally extracted document text to the AI provider path above to extract financial facts. We log request metadata (model used, latency, token counts, error state) for product reliability, abuse prevention, and unit economics.
See Section 04 for details on our AI provider path, data minimization, and what is stored outside Carlo-controlled systems.
How we use your information.
- Financial simulation and scenario modeling — your connected account data, goals, and profile power Carlo’s projections and “what if” scenarios. This is the core product.
- Personalized projections — we use your real financial data to make projections specific to your situation rather than generic estimates.
- Product and model improvement — aggregate, de-identified data — stripped of personal identifiers so it cannot reasonably be linked back to you — helps us understand which features matter and may be used to research, develop, and improve Carlo’s own models, features, and services.
- Communications — account-related emails (password resets, security alerts, receipts, renewal reminders, failed-payment notices, and cancellation confirmations) and, with your consent, product updates.
- Security and fraud prevention — protecting your account and detecting anomalous activity.
Third-party services
We use a small number of third-party services to operate Carlo:
- Plaid — connects your bank accounts and provides financial data. Plaid acts as a data processor on our behalf and is contractually required to protect your data. Plaid processes your data in accordance with its own End User Privacy Policy.
- Stripe — processes subscription payments, stores payment methods, calculates applicable tax, provides invoices and a billing portal, and helps prevent payment fraud. Stripe processes billing and device information under its Privacy Policy. Carlo receives subscription and transaction records, but not your complete card number or security code.
- Mapbox — provides optional real-estate address suggestions when you choose address lookup while manually adding a property. The address text you ask us to look up is sent to Mapbox from your browser and is processed under Mapbox’s Privacy Policy.
- Vercel — hosts our application infrastructure. Vercel processes data in accordance with its Privacy Policy.
- Amazon Web Services — hosts Carlo-controlled storage, including encrypted S3 storage for uploaded documents.
- AI model providers and platforms — provide the AI model infrastructure used for natural-language and document-import features. Carlo accesses models from providers such as OpenAI and Anthropic, either directly or through hosting platforms such as Amazon Bedrock, Microsoft Foundry, or OpenRouter. Inference requests are handled under the terms and data-control settings in effect for our accounts with each provider or platform. See Section 04 for the current list and details.
- PostHog — provides product analytics and session replay, which we use to understand how Carlo is used, operate and secure the service, diagnose problems, and improve the product. These tools record your interactions with Carlo, which may include the pages and content you view and information you enter. Recordings are configured to exclude passwords and account credentials. PostHog processes this data on our behalf under contract and does not use it for its own purposes. Carlo does not use analytics tools that track you across other websites.
- Google Calendar — hosts appointment scheduling when you choose “Book a demo.” Google receives the name, email address, and appointment time you submit and processes them under its Privacy Policy. Carlo receives the booking details needed to hold and follow up on the meeting; the Carlo app does not send Google your financial data.
AI providers and your prompts.
Carlo uses third-party AI models to power its natural-language and document features. Today these include models from providers such as OpenAI and Anthropic, which Carlo accesses either directly through a provider’s API or through a cloud platform that hosts these models (for example, Amazon Bedrock, Microsoft Foundry, or OpenRouter). We may add, remove, or change the AI providers and platforms we use; the current set is listed under “Our AI subprocessors” below and is updated from time to time. We send the minimum context needed for the feature you invoke and keep provider credentials on Carlo servers.
What we send
The content needed to answer your request. This may include the natural-language text you type, relevant financial figures from your profile, and selected balance or transaction context from your connected accounts. For document-upload features, it may include up to 120,000 characters of locally extracted document text, or the uploaded file itself when local text extraction is not available. We do not send your password, Plaid access tokens, provider API keys, or other secrets to AI model prompts.
What happens outside Carlo
- Provider path — Carlo sends model requests from Carlo servers to the AI provider or hosting platform selected for that request. The browser never calls AI providers directly.
- Region — our AI providers and platforms generally process requests in the United States, and some do not offer a data-residency or region commitment for our accounts, so Carlo does not claim a specific processing region.
- Data minimization — prompts include the user request and only the account, transaction, goal, document, or model context needed for that request.
- No secrets in prompts — Carlo does not put passwords, Plaid access tokens, provider API keys, or internal service credentials in AI prompts.
- Provider-side retention — we prefer providers and configurations that limit retention. Under the providers’ published policies, content sent for inference is retained transiently to process your request, plus any limited service-operation and abuse-monitoring period the provider applies — retention windows vary by provider and configuration — and is then deleted, unless a provider is required to retain it longer to comply with a law, court order, or legal process (for example, a litigation preservation order). Carlo does not control these providers’ systems and cannot guarantee provider-side retention or deletion beyond each provider’s own terms.
- Not used to train the providers’ models— we select and configure our AI providers so that your content is not used to train or improve their models, using the data controls and account settings each provider offers. Your prompts, uploaded documents, and the responses generated for you are not used to train these providers’ models.
- Improving Carlo — Carlo may use de-identified or aggregated data — information stripped of personal identifiers that cannot reasonably be linked back to you — to research, develop, and improve Carlo’s own models, features, and services. Carlo-controlled product records remain governed by this policy.
Our AI subprocessors
| Subprocessor | Purpose | Region | Reference |
|---|---|---|---|
| AI model providers (currently OpenAI, Anthropic) | LLM inference for natural-language requests and document extraction | Primarily United States; region commitments vary and may not be offered | OpenAI, Anthropic |
| AI hosting & routing platforms (currently Amazon Bedrock, Microsoft Foundry, OpenRouter) | Access to hosted models when Carlo routes a request through a platform rather than a provider’s own API | Varies by platform and configuration | Each platform’s data-processing terms |
| Amazon Web Services (S3) | Encrypted Carlo-controlled storage for uploaded originals until file or account deletion | US East (N. Virginia), unless configured otherwise | Amazon S3 overview |
If we add or replace AI subprocessors or materially change AI provider routing, we will update this list and notify you in accordance with Section 11 of this policy.
Data sharing.
We do not sell, rent, or trade your personal or financial data. Not in identifiable form, and not as de-identified or “anonymized” data either. We do not license your data to third parties, and we never share it with anyone for their marketing or advertising purposes. Carlo is funded by subscriptions, not by your data.
We may publish or share aggregate statistics that cannot identify you (for example, overall usage or adoption metrics), and we use aggregate, de-identified data internally to improve Carlo as described in Sections 02 and 04 — but that data is never sold or licensed.
We share data that identifies you only in these limited circumstances:
- Service providers — with the third-party services listed above, only to the extent necessary for them to perform their function.
- Legal requirements — if required by law, subpoena, or court order.
- Safety — if we believe disclosure is necessary to protect the rights, property, or safety of Carlo, our users, or the public.
- Business transfers — in connection with a merger, acquisition, or sale of assets, your data would transfer to the successor entity under the same privacy commitments.
Data retention
We retain your data for the duration of your active account, and otherwise for as long as reasonably necessary to provide the Services and for the legitimate business purposes described in this policy (such as security, fraud prevention, and compliance). When you delete your account:
- Information associated with your account, including personal data, financial data, uploaded documents, and extracted account records, is deleted from Carlo production systems, typically within 30 days of your verified request, subject to legal, security, and fraud-prevention retention constraints.
- Uploaded originals remain in encrypted Carlo-controlled Amazon S3 storage until you delete the file or your account. Deleting a file removes the original and raw extraction; normalized facts already added to your financial model remain until corrected or deleted on their owning surface.
- Backups containing your data are purged as backup rotation completes, typically within 30 days of the deletion request.
- Uploaded documents, prompts, and AI-generated responses may be sent to our AI providers for inference. carlo.finance retains product copies and extracted account data in your account for as long as the conversation, projection, scenario, or account record it belongs to is retained. On the provider side, under the providers’ published policies, inference content is retained transiently plus any limited service-operation and abuse-monitoring period (windows vary by provider and configuration) before deletion, unless required to be retained longer by law or legal process. This content is not used to train the providers’ models (see Section 04).
- Usage data, analytics, and session recordings are retained under the schedules in our Data Retention & Disposal Policy. Aggregate, de-identified data that cannot identify you may be retained beyond those schedules.
For detailed retention periods by data category, see our Data Retention & Disposal Policy.
Your rights.
You have the right to:
- Access your data — request a copy of all personal data we hold about you.
- Correct your data — update inaccurate or incomplete information.
- Delete your data — request deletion of your account and associated data. We typically complete deletion within 30 days of your verified request, subject to the exceptions in Section 06 (for example, aggregate, de-identified data that can no longer identify you, or records we must keep for legal or security reasons).
- Port your data — receive your data in a structured, commonly used, machine-readable format.
- Disconnect financial accounts — revoke Plaid’s access to your financial institution at any time, either through Carlo or directly through your bank.
To exercise any of these rights, contact us at privacy@carlo.finance. We will respond within 30 days.
Security measures
We take the security of your financial data seriously. Our protections include:
- Encryption in transit — all data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher.
- Encryption at rest — stored data is encrypted using AES-256 or equivalent.
- Access controls — internal access to user data is restricted to authorized personnel on a need-to-know basis using role-based access controls.
- No credential storage — we never see or store your bank or brokerage login credentials. Provider-backed account connections go through the secure connection flows of our data providers (Plaid and SnapTrade).
For a full description of our security practices, see our Security Policy.
Children’s privacy
Carlo is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at privacy@carlo.finance and we will promptly delete it.
California residents
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:
The categories of personal information we collect are described in Sections 01 and 02 and include Internet or other electronic network activity information, such as pages viewed, features used, and interaction patterns.
- Right to know — you can request the categories and specific pieces of personal information we have collected.
- Right to delete — you can request deletion of your personal information, subject to certain exceptions.
- Right to opt out of sale or sharing — we do not sell or share your personal information (as the CCPA defines those terms), so there is nothing to opt out of. Aggregate, de-identified data that cannot identify you is not “personal information” under the CCPA; we use it internally as described in Sections 02 and 04.
- Non-discrimination — we will not discriminate against you for exercising your CCPA rights.
To exercise your CCPA rights, contact us at privacy@carlo.finance. We will verify your identity and respond within 45 days.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the “Last updated” date at the top of this page.
- For material changes, notify you by email or through the application — for example, a new category of data collection, a materially new use of your data, or a new type of third-party service with access to financial data.
- For material changes to how we use, share, sell, or retain data that identifies you, we will notify you at least 30 days before the change takes effect, and the change will apply only to data collected after it takes effect unless you consent otherwise.
- Other changes take effect when the updated policy is posted, unless we state a later effective date or applicable law requires advance notice.
Contact us
If you have questions about this Privacy Policy or how we handle your data: