Privacy Policy
Rumbo ("Rumbo", "we", "us") is a personal finance app operated by CodeCans. This policy explains what information the app handles, why, and the choices you have. By using Rumbo you agree to this policy.
1. Information we collect
- Account information. When you create an account we collect your email address and a password (passwords are stored in hashed form by our authentication provider — we never see them).
- Financial information you enter. The data you add to the app: account names and balances, asset and debt figures, savings goals, cash-flow amounts, investment holdings (ticker symbols and share counts), and your projection settings.
- Assistant conversations. If you use the in-app AI assistant, the questions you send and a snapshot of your current financial figures are processed to generate a response (see "Third-party services").
- Technical data. Basic request information (such as timestamps and error logs) generated by our hosting provider to operate and secure the service. Rumbo does not embed third-party advertising or analytics SDKs and does not track you across other apps or websites.
2. How we use your information
- To provide the app's core features — computing net worth, allocation, goal progress, cash flow, and independence projections from your data.
- To sign you in and sync your data across your devices.
- To fetch current market prices for the stock holdings you add.
- To generate answers from the AI assistant when you use it.
- To operate, secure, debug, and improve the service.
3. Where your data is stored
Your account and financial data are stored using Supabase, our backend and authentication provider, on cloud infrastructure located in the United States. Access is restricted by per-user security rules so that your data is only accessible to your authenticated account. The app also keeps a copy on your device so it works offline.
4. Third-party services
Rumbo relies on a small number of processors to deliver specific features. We share only the minimum needed for each:
- Supabase — authentication and secure storage of your account and financial data.
- Finnhub — market data. When you add stock holdings, the relevant ticker symbols (e.g. "AAPL") are sent to fetch current prices. No personal or account information is sent.
- Anthropic (Claude) — powers the AI assistant. When you send a message, that message and a snapshot of your financial figures are transmitted to generate a reply. Do not include information in assistant messages that you do not wish to be processed for this purpose.
These providers process data under their own privacy terms. We do not sell your personal information, and we do not share it for advertising.
5. Data retention and deletion
We keep your data for as long as your account exists. You can request deletion of your account and associated data at any time by emailing paulo.guerra.figueiredo@gmail.com. We will delete your stored financial data and account record, subject to any limited records we must retain for legal or security reasons.
6. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these, contact us at the email above.
7. Security
Data is encrypted in transit (HTTPS) and at rest by our storage provider, and access is protected by authentication and per-user access rules. No system is perfectly secure, but we take reasonable measures to protect your information.
8. Children
Rumbo is not directed to children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect their data.
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, through the app.
10. Contact
Questions or requests? Email paulo.guerra.figueiredo@gmail.com.