Privacy Policy

Effective date: July 30, 2026

What we collect

  • Account data: your email address and password (stored hashed by our auth provider, Supabase).
  • Plan data: the financial planning inputs you enter (ages, balances, income, spending, assumptions) and the simulation results the app saves for you.
  • Billing data: subscription status and Stripe identifiers. Card details are collected and stored by Stripe, our payment processor — they never touch our servers.
  • Technical and product-use data: logs and error reports needed to keep the service running and secure, plus a small set of categorical setup events described below.

How we use it

Only to operate Retirivo: authenticate you, store and compute your plans, process your subscription, send account emails such as verification and password reset, show billing status in the app, and fix problems. We do not sell your data, and we do not use your plan data for advertising.

Where it lives

Account and plan data are stored in our Supabase-hosted Postgres database, protected by row-level security so each account can only read its own rows. Payments are processed by Stripe. The app is hosted on Vercel. Each provider processes data under its own security and privacy commitments.

Retirivo Assistant and AI Plan Review

If you use Retirivo Assistant, the message you type, up to six recent turns from that help conversation, the current Retirivo view and section, Base or Refine mode, and an application-owned help topic are sent to OpenAI's API. For ordinary product-help questions, the request does not contain plan values, calculated results, plan identifiers, field catalogs, or saved-plan revisions. When you ask the Assistant to explain your saved plan or a displayed calculation, Retirivo first verifies the plan owner and saved revision on the server, replays the relevant calculation, and sends OpenAI only a bounded read-only evidence summary relevant to that question. It does not send the editable plan object or raw simulation paths. The Assistant can explain that evidence and offer validated navigation, but it cannot change your plan.

Product experience analytics

Retirivo records a small, allowlisted set of setup milestones so we can find confusing steps and improve the product. These events identify actions such as starting or completing the Base Plan, finishing a named setup step, running a market test, adding a refinement, saving a scenario, or opening the report. Event details are categorical ranges rather than exact values. They never include retirement balances, income, spending, result amounts, email addresses, plan identifiers, AI content, or free text. Your account identifier is converted on the server to a one-way keyed pseudonym before storage. Product events are retained for no more than 13 months.

Retirivo does not save Assistant conversations in your account, database, analytics, error reports, or administration tools. The conversation stays in the current browser page while you navigate or switch plans and is cleared by New Conversation, logout, or page reload.

AI Plan Review is separate. When you generate a review, Retirivo verifies ownership, the current saved-plan revision, and current Risk & Stress evidence on the server. It then sends OpenAI a bounded evidence summary containing household and retirement timing, aggregate resources, core spending and reliable income, visible assumptions, and verified current risk results. It does not send the full saved plan or annual projection ledger. The generated review can be saved with your planner state and added to your report. A review follow-up sends the question, up to six recent review turns, the saved review, and the same current verified evidence; follow-up turns are not saved as a customer transcript.

OpenAI processes these API requests under its published API data controls and retention terms. Retirivo retains only content-free aggregate operational totals such as request counts, feature and model, token usage, response time, outcome, and estimated cost. These totals contain no user identifier, message, response, plan identifier, or financial plan value. Do not enter Social Security numbers, tax IDs, account numbers, passwords, payment information, or exact street addresses into either AI experience.

Account balance CSV refresh

If you use the optional account-balance refresh on the Account page, Retirivo reads the CSV in your browser. The file, account names, and row-level contents are not uploaded or stored. After you review the category totals, only the balance fields you explicitly approve are sent to update your selected saved plan. The normal plan validation, ownership, and version-conflict protections still apply.

Read-only plan sharing

If you create a plan-sharing invitation, Retirivo stores the selected plan, access level, relationship category, expiry, acceptance, and revocation state. The invitation secret is stored only as a one-way hash and the link is shown to the owner once. The first signed-in person who accepts the link receives read-only access until expiry or revocation. Retirivo does not ask for or reveal the reviewer's email to the plan owner. Shared views omit owner identity, account controls, billing, journals, scenarios, expense profiles, and the annual projection ledger.

Plan-review freshness

Retirivo can store the date you reviewed account balances, the saved-plan revision you confirmed, the date an annual review was completed, and the calculation and reference-data versions used at that time. This checkpoint contains no copied balances, income, spending, plan inputs, or risk outputs. It is used to tell you when facts, results, or Retirivo's model should be reviewed again.

Retention and deletion

We keep your data while your account exists, including through trial expiry or cancellation, so you can return without losing your plans. You can permanently delete your account from the Account page. After you re-enter your password, Retirivo cancels an attached membership, revokes active sessions, deletes your Supabase Auth user, and cascades deletion through your account-owned plans and planner state. Non-sensitive security audit records and records Stripe or applicable law requires us to retain may remain for their required retention period; they do not contain your raw financial plan.

Your choices

  • You can view, edit, or delete your plan data in the app at any time.
  • You can export a copy or delete your account from the authenticated Account page.
  • If self-service is unavailable, you can request support-assisted access or deletion using the contact below. We will verify account ownership before acting.
  • Account emails used for verification, password reset, or required service notices are operational; we do not send marketing email without consent.

Changes

If this policy changes materially, we will notify you by email or in the app before the change takes effect.

Contact

Privacy questions or requests: Get support