Trust center · Effective August 4, 2026
Privacy Policy
This policy explains how Rubato handles information for the service. Rubato launches for adults in the United States and is designed as a private, read-only financial planning workspace.
Privacy contact and accountability
Rubato handles information as described in this policy. Privacy questions and verified rights requests can be sent to privacy@rubatoplan.com. Product support is available at support@rubatoplan.com.
Who may use Rubato
Rubato is intended for people at least 18 years old who are located in the United States. Rubato is not directed to children, does not knowingly collect information from children, and is not offered outside the launch region unless Rubato expressly expands eligibility.
Information Rubato handles
- Account and contact data: email, profile details, verification state, password hashes, sessions, plan and subscription status.
- Financial data: user-entered or imported accounts, balances, transactions, holdings, debts, budgets, goals, income expectations, recurring patterns, planning assumptions, and household answers.
- Connection data: encrypted provider access tokens and server-side identifiers for optional Plaid or SimpleFIN connections. Rubato does not receive the password entered inside a provider's connection flow.
- Site and application analytics: sanitized page path without query strings or fragments, together with ordinary browser, device, and approximate-location analytics.
- Support, consent, and operations: support messages, policy acceptance, billing events, security/audit events, device or request metadata, rate-limit records, and error diagnostics.
Rubato does not store readable account passwords. Full payment-card and PayPal credentials are handled by PayPal rather than Rubato.
Why information is used
Rubato uses information to authenticate users, sync data a user authorizes, build and update a financial plan, calculate forecasts and scenarios, preserve user choices, show prioritized next actions, provide reports, process subscriptions, prevent abuse, diagnose failures, answer support requests, and meet legal obligations. Rubato does not sell or rent personal or Plaid-derived financial data.
Connected accounts and consent
Plaid and SimpleFIN are optional. The connection screen identifies the provider and requested data. Rubato uses connected data only to provide user-requested planning functions. Rubato cannot use a read-only connection to move money. A user can avoid connected accounts, disconnect a provider in Settings, revoke access with the provider where available, or request account deletion. Disconnecting stops new retrieval but does not by itself erase financial history already saved in the workspace; deletion handles that copy.
Optional AI review
AI reviews run only after an explicit user action and use the OpenAI API. They receive bounded calculated metrics and summaries—not credentials, connection tokens, full account numbers, emails, or unrestricted raw transaction exports. Requests set store: false. OpenAI states API data is not used for model training unless the API customer opts in, and default abuse-monitoring logs may retain customer content for up to 30 days. Rubato will not opt production financial data into provider training. See the AI disclosure for details.
Service providers and disclosure
Rubato discloses data only as needed to providers that operate the service, process a user-selected connection or purchase, measure limited site and application usage, comply with law, protect users and the service, or carry out a verified user request. The current provider list identifies Cloudflare, Plaid, SimpleFIN, PayPal, OpenAI API, Google Analytics, Resend, Zoho Mail, and Yahoo Finance and explains each role. Rubato does not allow a provider to use financial data for an unrelated Rubato advertising purpose.
The Google tag does not receive balances, transactions, account identifiers, authentication tokens, entered financial values, query strings, or fragments from Rubato, and advertising signals are disabled.
See the complete service-provider list.
Retention schedule
| Record | Current lifecycle |
|---|---|
| Active account and financial workspace | Retained while the account is active, until password-verified immediate self-service deletion completes, or until a support-reviewed deletion request is verified and completed. |
| Provider connection credentials | Retained only while the connection is active; removed from Rubato when the connection or account is deleted. |
| Password recovery link | Expires after one hour and becomes unusable after use, revocation, or expiry. |
| Registration verification | Expires after 24 hours if registration is not completed. |
| Password session | Expires after 24 hours without activity and no later than seven days after creation; password changes and resets revoke prior password sessions. |
| Support-reviewed deletion request | Records a seven-day cooling-off date, remains cancelable while pending, and does not run automatically. Rubato support verifies and completes the request. |
| Immediate self-service deletion | A signed-in user who verifies the current password and confirms deletion can permanently delete supported account and financial data immediately. A minimal, non-financial completion record is retained for 30 days. |
| Deletion suppression marker | A one-way, non-financial marker may be retained indefinitely to prevent deleted private-beta or legacy access from being silently recreated. |
| Support and security records | Separately stored support and security records are not automatically deleted by in-app account deletion. They are normally retained for up to 24 months, and longer only when needed for an unresolved request, fraud or security investigation, dispute, or legal duty. |
| Billing and consent records | Retained for up to seven years where needed for tax, accounting, contract, chargeback, or legal records. |
Settings provides both the password-verified immediate deletion path and the cancelable support-reviewed request with a seven-day cooling-off date. Provider systems may retain their own legal, security, or billing records under their policies.
Security
Rubato uses HTTPS, slow salted password hashing, hashed session and recovery tokens, HttpOnly cookies, owner-scoped access, encrypted connection credentials, server-side secrets, request validation, rate limits, audit records, and private no-store responses. No security system is perfect. Suspected unauthorized access should be reported to security@rubatoplan.com.
Your choices and requests
Users can correct saved inputs, export supported data, disconnect providers, choose not to request AI review, revoke a session by changing the password, and request deletion in Settings. A person who cannot sign in may contact the public privacy mailbox. Rubato may verify identity and account ownership before disclosing or changing private data.
Policy changes
Material changes update the effective date and, when appropriate, are shown in the product or sent to the account email. Questions can be sent to privacy@rubatoplan.com.
OpenAI safety identifier
When a user requests an optional AI review, Rubato also sends OpenAI a stable, one-way pseudonymous safety identifier derived from the normalized account email. The identifier is not the email address, is not used to personalize financial guidance, and helps OpenAI detect abuse without Rubato sending the account email itself.