Legal

Privacy Policy

Last updated: June 17, 2026

This policy explains what personal information we collect, how we use and protect it, who we share it with, and the rights you have over it.

1. Who we are

RetiFlo (“RetiFlo”, “we”, “us”, “our”) is a retirement planning and analytics service operated by RetiFlo LLC at [registered address], available at retiflo.com. This policy covers the RetiFlo web application and marketing site. It does not cover third-party services we link to, which have their own privacy policies.

Questions about this policy or your data? Email privacy@retiflo.com or use our contact page.

2. Information we collect

We collect only what we need to provide the service.

Account & identity. Your email address, a hashed password (we never store your password in plaintext), and optionally your name, phone number, date of birth, gender, and U.S. state. If you enable multi-factor authentication (MFA), we store the data needed to verify your second factor.

Financial planning information. The financial details you choose to enter for your retirement plan — assets, income, expenses, debts, real estate, healthcare assumptions, Social Security, pensions, and scenarios. You control how much detail you provide.

Payment information (via Stripe).If you buy a paid plan, Stripe processes payment. We do not receive or store your full card number; we store only Stripe's customer/subscription identifiers and your subscription status.

AI-insight data (optional, opt-in). If you opt in to AI insights, we send a summary of aggregated plan metrics to the Anthropic (Claude) API — aggregated numbers only, with no names, account numbers, or identifying information. See section 6.

Technical & usage information. Standard data such as IP address, browser/device information, and authentication session data (a signed session cookie keeps you logged in). We send transactional emails via Resend and keep operational delivery logs.

We do not sell your personal information and do not use it for third-party advertising.

3. How we use your information

  • Provide the service — projections, Monte Carlo simulations, tax and Roth-conversion analysis, and other analytics you request.
  • Create and secure your account, including authentication and MFA.
  • Process payments and manage subscriptions (via Stripe).
  • Generate AI insights, only if you have opted in (via Anthropic).
  • Send transactional and service emails (via Resend).
  • Maintain, debug, secure, and improve the service.
  • Comply with legal obligations and enforce our terms.

5. How we share your information — sub-processors

We share personal information only with the providers necessary to operate RetiFlo, each under a data processing agreement and only for the purposes below. Data is transmitted to each over encrypted (TLS) connections.

Sub-processorPurposeData shared
StripePayment & subscription processingBilling/subscription data; card data handled by Stripe directly
Anthropic (Claude)AI-generated insights (opt-in only)Aggregated, de-identified plan metrics — no identifying information
ResendTransactional & service emailYour email address and message content
HetznerCloud hosting / infrastructure (EU)Hosts the encrypted application and database

We may also disclose information if required by law, to protect rights or safety, or in connection with a business transfer, in which case we will notify you as required.

6. AI features and your data

AI insights are optional and opt-in:

  • Disabled by default — nothing is sent to any AI provider until you grant consent.
  • When enabled, we send only aggregated plan metrics (e.g. success rate, median portfolio value, retirement age) — no names, account numbers, or identifying details.
  • Processed by Anthropic under their privacy policy.
  • You can withdraw consent at any time in Settings, which stops further data from being sent.

7. Cookies and sessions

We use a small number of strictly-necessary cookies to keep you signed in and protect your session. We do not use third-party advertising or cross-site tracking cookies. These cookies are essential, so the site will not function correctly without them.

Your financial data is not left behind in your browser after your session ends. We load it into memory only while you are using the app and do not write it to long-term browser storage; when you log out — or after 1 hour of inactivity, when we automatically log you out — we clear it from your browser. Closing the tab also clears it.

8. Data retention

  • Active account data — retained while your account is active.
  • Deleted records — immediately removed from the system.
  • Operational/email delivery logs — up to 18 months.
  • Encrypted backups — age out in approximately 14 days and are then permanently deleted; we don't selectively restore.
  • Billing records at Stripe — per Stripe's obligations (approximately 7 years for legal/tax).

9. How we protect your information

  • Encryption in transit — all traffic over HTTPS/TLS with HSTS.
  • Field-level encryption — sensitive fields encrypted at rest with AES-256.
  • Encryption at rest — the production database and secrets reside on an encrypted (LUKS) volume.
  • Access controls — least-privilege database roles and a hardened deployment.
  • Authentication — hashed passwords and optional MFA.

No method of transmission or storage is 100% secure, but we work to protect your information using industry-standard safeguards.

10. Your rights

Depending on where you live, you may have the right to:

  • Access a copy of the information we hold about you.
  • Correct inaccurate information (much of which you can edit directly in the app).
  • Delete your personal information (see section 11).
  • Port your data in a portable format.
  • Withdraw consent for optional features such as AI insights.
  • Object to or restrict certain processing.

California residents (CCPA/CPRA):you have the right to know, delete, correct, and to opt out of the “sale” or “sharing” of personal information. We do not sell or share your personal information as defined under California law, and we will not discriminate against you for exercising your rights.

To exercise any right, contact privacy@retiflo.com. We verify your identity first, and respond to verified deletion requests within 30 days (GDPR/UK GDPR) or 45 days (CCPA/CPRA), extendable to 90 days where permitted with notice.

11. Deleting your account

When you delete your account, we:

  1. Cancel any active subscription with Stripe (Stripe retains billing history for its own legal/tax obligations).
  2. Permanently and immediately erase your plan and account data — this is irreversible (we recommend exporting your data first).

Some records we are legally required to keep may persist for their mandated retention period.

12. International data transfers

RetiFlo is hosted in the European Union (Hetzner). If you access the service from outside the EU, your information will be transferred to and processed in the EU and by the sub-processors listed in section 5, which may be located in other countries. Where required, such transfers are made under appropriate safeguards (e.g. Standard Contractual Clauses).

13. Children's privacy

RetiFlo is intended for adults planning for retirement and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, contact us and we will delete it.

14. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “Last updated” date and, where appropriate, notify you. Continued use of the service after an update constitutes acceptance of the revised policy.

15. Contact us

Questions, requests, or complaints about this policy or your personal information:

  • Email: privacy@retiflo.com
  • Contact form: retiflo.com/contact
  • Operator: RetiFlo LLC, [registered address]