Encrypted on your device. Carlo can't decrypt it.

The content you create is encrypted on your device with AES-256-GCM before it's sent to Carlo's servers. The servers store only ciphertext, and Carlo cannot decrypt it.

Encrypted values are also padded to coarse size buckets, so even their exact length can't be read. If Carlo is ever compelled by legal process to hand over this data, it can hand over only ciphertext.

Processed briefly to do a job, not stored

A few features send information off your phone because you chose to use them.

Information Carlo can read to run the service

If you connect a bank

Bank Reminders are optional, and Carlo works fully without a bank connection. If you turn them on, the connection is read-only and limited to transactions. Carlo never gets your banking password, can't move money, and doesn't request your account or routing numbers, identity, liabilities, investments or income.

What you choose to send Carlo

Your keys and your cloud account

Your master key is derived from your 12-word recovery phrase. The phrase, not the key, is kept in a private app area of your own iCloud or Google account, so it can sync to your devices, and you can keep your own copy too. Carlo's servers never receive or store the recovery phrase.

That means anyone who can sign into that iCloud or Google account could recover the phrase and unlock your Carlo data, the same way they could reach your photos or email. Protect that account with a strong, unique password and two-factor authentication. On iPhone, Advanced Data Protection for iCloud makes your recovery phrase end-to-end encrypted to Apple as well. "End-to-end encrypted" means Carlo can't read your data, not that someone with your Apple or Google password couldn't.

Your exports are yours

Exports are decrypted on your device, so they're readable. This covers the Transactions and Journal spreadsheets, the Photos zip and a System Backup. Treat them like a financial statement and store them somewhere secure.

More detail