Encrypted on your device. Carlo can't decrypt it.
The content you create is encrypted on your device with AES-256-GCM before it's sent to Carlo's servers. The servers store only ciphertext, and Carlo cannot decrypt it.
- Amounts and payee names
- Notes
- Category, account and goal names
- Your income, budgets and bills
- Your journal entries and weekly reflections
- Charitable giving records
- Photos. Location and camera data is stripped before they're encrypted and uploaded.
- If you connect a bank: each transaction's amount, description and merchant
- In a shared space: the space's name and everything shared in it, encrypted with a key only its members hold. Carlo never has it.
Encrypted values are also padded to coarse size buckets, so even their exact length can't be read. If Carlo is ever compelled by legal process to hand over this data, it can hand over only ciphertext.
Processed briefly to do a job, not stored
A few features send information off your phone because you chose to use them.
- Voice entry. Your recording, with your list of payee names, goes to Groq to be transcribed. The transcript, with your category and account names, goes to Anthropic's Claude API to be turned into an entry. Those names are processed briefly by Carlo's server and these providers during a voice entry, and are not stored. Carlo doesn't store the transcript, and the entry is encrypted on your device before it's stored. Groq doesn't retain your audio after transcription, except where required by law. Anthropic processes the transcript in real time and doesn't store it after responding, except where required to comply with law or prevent misuse, and doesn't train on it.
- Ask Carlo, the help chat. The questions you type go to Anthropic to be answered, under the same zero data retention. Ask Carlo has no access to your financial data, only the text you type into the chat.
- Plaid. If you connect a bank through Plaid, bank data passes through Carlo's servers on its way to your phone and isn't kept there.
Information Carlo can read to run the service
- Your account. Your name, email address and the sign-in identifier from Apple or Google. If a recovery email is stored on your account, Carlo can read it. This is separate from your 12-word recovery phrase.
- The structure of your records. The dates on your transactions, when you created and edited entries, the ID numbers that link your records together, and flags such as whether something is archived or is income rather than an expense.
- Photos, as attachments. That a photo is attached and its rough size tier, never its exact size or the image itself.
- Tags. Tag names are encrypted. A tag's colour slot and emoji icon are readable.
- What that adds up to. Someone with access to Carlo's servers could tell that you recorded something on a given day and roughly how much data your account holds, but not what any of it was or what it was worth.
- Shared spaces. Who belongs to a space, and the display names and display colours members show each other.
- Your subscription. Whether it's active or expired, through RevenueCat, but not your payment details, which Apple or Google handle. RevenueCat receives your Carlo account ID to manage your subscription state.
- Your device and crash reports. Device type, OS version and app version. Crash and diagnostic reports go to Sentry automatically when Carlo crashes or freezes, and when some features start up or fail. They contain technical information about the app and your device, plus your Carlo account ID, so support can connect a problem you report with what happened. Carlo is designed not to include your financial entries, notes or journal content in them.
- Account email. Carlo uses Postmark to send account-related emails.
If you connect a bank
Bank Reminders are optional, and Carlo works fully without a bank connection. If you turn them on, the connection is read-only and limited to transactions. Carlo never gets your banking password, can't move money, and doesn't request your account or routing numbers, identity, liabilities, investments or income.
- Encrypted with your key: each transaction's amount, description and merchant.
- Readable by Carlo: which institution a connection belongs to, each transaction's date, and whether it's pending.
- With Plaid, Carlo's servers hold the credential that keeps the connection open, so it can refresh. That credential isn't encrypted with your key. A subpoena or a breach reaching Carlo's infrastructure could reach it and the readable fields above, but not your entries or transaction details.
- With SimpleFIN, the credential stays on your phone. Carlo's servers never hold it, and Carlo only requests the accounts you pick.
- Disconnecting revokes the connection at the provider and deletes the stored credential. Transactions already brought in stay until you delete them or your account.
What you choose to send Carlo
- Feedback. Feedback is one of the few things Carlo doesn't encrypt, because you're choosing to send it so it can be read. Your message and up to three screenshots go to Carlo's developer, with your account email attached so Carlo can follow up. Screenshots, and the selfie a testimonial asks for, are stored unencrypted and kept for up to 90 days, then deleted. Your financial data is never part of it. A testimonial is shown publicly only with a name you type in yourself.
Your keys and your cloud account
Your master key is derived from your 12-word recovery phrase. The phrase, not the key, is kept in a private app area of your own iCloud or Google account, so it can sync to your devices, and you can keep your own copy too. Carlo's servers never receive or store the recovery phrase.
That means anyone who can sign into that iCloud or Google account could recover the phrase and unlock your Carlo data, the same way they could reach your photos or email. Protect that account with a strong, unique password and two-factor authentication. On iPhone, Advanced Data Protection for iCloud makes your recovery phrase end-to-end encrypted to Apple as well. "End-to-end encrypted" means Carlo can't read your data, not that someone with your Apple or Google password couldn't.
Your exports are yours
Exports are decrypted on your device, so they're readable. This covers the Transactions and Journal spreadsheets, the Photos zip and a System Backup. Treat them like a financial statement and store them somewhere secure.