Trust center · Effective August 4, 2026
AI disclosure
Rubato uses the OpenAI API for optional explanations and plan reviews. Core financial arithmetic, permissions, account ownership, saved user choices, and money movement are not delegated to an AI model.
When AI is used
An application AI review runs only after a user deliberately requests a supported review. Rubato may use AI assistance while drafting public education, but published articles identify the editorial process and cite visible primary sources.
What is sent
Rubato sends only bounded context needed for the selected task: calculated plan metrics, category summaries, normalized merchant summaries, and relevant user-entered planning context. It does not send financial-institution credentials, Plaid or SimpleFIN connection tokens, full account numbers, Rubato passwords, or an unrestricted raw transaction export.
Provider handling
Requests use OpenAI's API with application storage disabled through store: false. OpenAI states that API data is not used to train or improve its models unless the API customer explicitly opts in; Rubato will not enable that opt-in for production financial data. Under OpenAI's default API controls, abuse-monitoring logs may contain prompts and responses for up to 30 days unless a longer period is legally or safety-required. See OpenAI's current API data-controls documentation.
What AI cannot do
AI cannot move money, place an order, connect an account, change access, silently override a user-locked category, or save a plan outside the application's validated persistence path. Deterministic code performs calculations and entitlement checks.
Limitations and control
AI output can be incomplete or wrong. Rubato labels AI-supported review, shows relevant numbers and confidence limits, and lets the user ignore the output. A failed review does not alter saved financial data. Users can avoid AI reviews while continuing to use deterministic planning features.
Pseudonymous safety identifier
Each requested AI review includes a stable, one-way pseudonymous safety identifier derived from the normalized Rubato account email. OpenAI receives the identifier rather than the account email. Rubato supplies it for abuse detection, not to personalize the financial review, and keeps it stable across repeated requests within the corresponding review flow.