Privacy policy

Effective August 14, 2026

What we collect

  • Account data: email address, sign-in identifiers, and authentication events.
  • Plan data you provide: ages, savings amounts, income, spending, and related answers.
  • Holdings data you confirm: institutions, account types, fund names, tickers, balances. Account numbers are redacted before storage and never persisted.
  • Screenshots you upload: retained only until you confirm the parse or 30 days, whichever is first, then permanently deleted.
  • Voice interview transcripts: if you use the voice interview, your audio is transcribed in real time and the written transcript is saved to your account until you delete it. The audio itself is never stored.
  • Product analytics: feature usage and funnel events. Analytics never include financial values.

How we use it

To compute your forecasts, run the features you ask for, secure the service, and improve the product. We do not sell personal information and we do not share it for cross-context behavioral advertising.

AI processing

Production AI processing will use third-party APIs under agreements that prohibit training on your data. Identifiers are stripped before processing wherever feasible. xAI's default API retention can be up to 30 days, so production launch is blocked until the enterprise zero-data-retention agreement is signed and live requests confirm that control. During a voice interview, audio streams through our relay for live transcription and a compliance check — it is processed in the moment and never recorded by RetireGlide.

Retention schedule

  • Screenshots: deleted on confirmation or within 30 days.
  • Voice interview transcripts: kept until you delete them from the privacy center (or delete your account). Raw audio is never stored at all.
  • Plan and holdings data: kept while your account is active.
  • Deleted accounts: all personal data permanently removed within 30 days of the request, including backups on their rotation schedule.
  • Audit and security logs: up to 12 months.

Your rights

Regardless of where you live, you can access, export (JSON), correct, and delete your data from the in-app privacy center, or by emailing [email protected]. We honor these requests for all users at CCPA/CPRA standard, without discrimination.

Security

TLS 1.2+ in transit, AES-256 at rest, row-level data isolation, MFA for internal access, audited administrative actions, and a written incident-response plan with breach notification per applicable law (including the FTC Safeguards Rule).

Contact

[email protected] · RetireGlide, Inc.