Security & privacy, in plain English

You're trusting us with a picture of your retirement. Here is exactly what happens to it — no legalese.

The life of a screenshot

  1. 1. You upload it

    The image travels over an encrypted connection (TLS 1.2+) into a private, encrypted bucket (AES-256 at rest) that only your account can access.

  2. 2. AI reads it

    A vision model extracts your holdings into structured numbers. Account numbers are stripped out at this step and are never stored anywhere.

  3. 3. You confirm what it found

    You review every extracted field next to the image. Nothing enters your plan until you approve it — especially the account type, which we always ask you to confirm.

  4. 4. The image is deleted

    As soon as you confirm (or after 30 days, whichever comes first), the original image is permanently deleted. Your privacy center shows a deletion confirmation, and there's a delete-now button if you don't want to wait.

UploadAI reads & redactsYou confirmImage deleted

What we store — and what we never store

We store

  • Your answers (ages, savings, spending)
  • Confirmed holdings: fund names, tickers, balances
  • Your scenarios and forecast history
  • Voice interview transcripts — yours to read and delete anytime in the privacy center
  • Email and sign-in details

We never store

  • Account usernames or passwords (we never ask)
  • Account numbers — stripped before saving
  • Your screenshots after you confirm the results (or after 30 days, whichever comes first)
  • Recordings of your voice — audio streams through live and is never saved
  • Financial values in our analytics

The life of a voice conversation

If you talk to the interviewer instead of typing, the same rules apply — plus one more: your voice itself is never kept.

  1. 1. You talk

    Your audio travels over an encrypted connection and streams straight through for live transcription. It is processed in the moment — no recording is ever saved.

  2. 2. Every response is checked

    A compliance filter reviews what the interviewer says as it speaks, so the conversation stays educational — it can never tell you to buy or sell anything.

  3. 3. You confirm every fact

    Anything the interviewer heard — a balance, an age, a goal — becomes part of your plan only after you approve it on a confirmation card.

  4. 4. The transcript is yours

    The written transcript is saved to your account so you can re-read the conversation. Delete it anytime from your privacy center — no waiting period.

AI verification

Our AI never does the math — and we can prove it

AI helps gather your inputs and explain the results. A separate, deterministic planning engine computes every projection, tax estimate, and simulation.

  1. Engine boundary

    A CI test fails the build if the planning engine imports an AI model, network client, or other runtime dependency.

  2. Reproducible runs

    Each simulation is seeded and stamped with an engine version, so the same saved inputs can reproduce the same result.

  3. One typed provenance registry

    The server owns one allowlist that maps every eligible tool path and generated-artifact claim path to exactly one numeric kind: money cents, percentage rate, percentage points, count, age, or year. Figure grounding and claim rendering use that same registry; user inputs, overridden assumptions, labels, write proposals, errors, and unknown paths never become evidence.

    Look for “Numbers checked against your plan” on verified explanations.

  4. Atomic numeric checks

    Every numeric-looking sequence must be consumed as one supported token and match a same-kind registered value with its sign and displayed precision intact. Unicode and accounting negatives, cents, ranges, ages, and directional point changes are handled explicitly; scientific notation, malformed fragments, ambiguous numbers, and incompatible claim formats fail closed before display.

  5. Compliance gates

    A deterministic output filter keeps explanations educational, and red-team evaluations run in CI to test the boundary continuously.

RetireGlide is an educational planning tool. Verified means the entire marked artifact passed the compliance gate and every numeric-looking sequence matched an eligible same-kind path in the server-owned provenance registry; it does not promise a particular future result.

We assume any AI can be wrong. That's why every figure the assistant states is cross-checked against your plan's deterministic results — and only marked verified when it matches.

AI-provider privacy is a launch gate

We crop and strip identifying details wherever feasible and require agreements that prohibit training on your data. xAI's default API retention can be up to 30 days. RetireGlide will not launch production AI processing until its enterprise zero-data-retention agreement is signed and live requests confirm that control. Until that gate passes, production launch remains blocked; automated testing uses synthetic mock data.

Your rights, self-serve

From your privacy center you can see everything we hold, export it all as JSON, watch screenshot deletion status, or delete your entire account. Deletion is immediate in the product and completed permanently within 30 days, backups included. These rights apply to every user in every state.

Security practices

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Row-level isolation: every record is scoped to your account at the database layer
  • Multi-factor authentication available to everyone; required for our staff
  • Designated security lead, written incident-response plan, vendor due-diligence reviews
  • Audit logging of administrative access and deletions