Trust center · Effective August 4, 2026

Service providers

Rubato uses a small set of providers for hosting, account connectivity, payments, optional AI, email, and public market data. A provider receives only the categories needed for its role.

Current provider list

ProviderPurposeData involved
CloudflareHosting, edge security, server runtime, database and deployed assetsAccount, application, financial and operational data
PlaidOptional read-only financial account connection and synchronizationUser-authorized account, balance, transaction and investment data
SimpleFINOptional read-only financial account aggregationUser-authorized account, balance and transaction data
PayPalSubscription checkout, billing status and cancellationContact, plan, transaction and provider billing identifiers
OpenAI APIOptional AI-supported explanations and plan reviewsBounded calculated metrics, category and normalized merchant summaries, and a stable one-way pseudonymous safety identifier
Google AnalyticsLimited site and application usage measurement with advertising signals disabledSanitized page path without query strings or fragments, browser and device information, and approximate location; no financial values or authentication tokens
ResendTransactional verification, recovery and service emailRecipient email, message content and delivery metadata
Zoho MailHuman-operated support, privacy and security mailboxesMessages and attachments a person chooses to send
Yahoo FinancePublic market-price history used for educational chartsPublic ticker requests; no bank credentials

Provider choice and consent

Plaid, SimpleFIN, PayPal, and AI-supported review are used only when the user chooses the corresponding connection, purchase, or review. A user can keep a manual Free workspace without connecting a bank. Disconnecting a provider stops new retrieval; account deletion covers the Rubato-side records described in the Privacy Policy.

Changes

Rubato may replace a provider when needed for security, reliability, price, or product coverage. Material changes that alter how private financial data is processed will be reflected here and in the Privacy Policy before or when the change takes effect.

OpenAI safety identifier

Alongside bounded review context, Rubato sends OpenAI a stable, one-way pseudonymous safety identifier derived from the normalized account email. OpenAI receives the identifier rather than the email address; Rubato uses it for provider abuse detection and not to personalize recommendations.