Legal
Privacy Policy
Last updated:
Arvo is built so your financial data stays private. This policy explains what Arvo processes, where it is stored, when it is shared with AI providers or MCP clients you enable, and the rights you have.
Contents
- Who this policy applies to
- Data the software processes
- How the data is used
- Where and how data is stored
- No selling, no ads, no tracking
- AI providers
- MCP clients
- Security measures
- Retention and deletion
- Data export
- Cookies and local storage
- Children
- International users and your rights
- Changes to this policy
- Contact
1. Who this policy applies to
Arvo is proprietary software operated by Arvo (“we” or “us”). This policy explains how Arvo handles personal data. For the accounts and data in Arvo, we act as the data controller (or “data fiduciary” under India’s Digital Personal Data Protection Act, 2023). Questions can be sent to vineet.likhitkar@gmail.com.
This website
This marketing website describes the software. It does not ask you to create an account, makes no calls to the Arvo app, and uses no tracking or advertising cookies.
2. Data the software processes
Depending on the features you use, Arvo processes the following categories of data:
- Account and profile data: your name, email address, a hashed password, preferences such as default currency and locale, and session tokens.
- Financial data: accounts you create (bank, card, loan, investment and cash accounts), transactions, transfers, balances, categories, merchants, rules, budgets and goals.
- Uploaded files: bank and card statements you import in CSV, XLSX or PDF format, and the rows parsed from them during review.
- AI conversations: if you use AI features, the questions you ask and the answers returned.
- Technical logs: application and server logs such as request timestamps, error messages and IP addresses, used to operate, secure and troubleshoot the service.
Statements can contain sensitive information, including account numbers, counterparties and spending patterns. Arvo does not need, and you should not upload, government identifiers, card CVVs, PINs or online banking passwords.
3. How the data is used
Data is used only to provide the features of the software to the account that owns it, namely to:
- authenticate you and keep your session secure;
- import, review, de-duplicate and store your statements and transactions;
- categorize transactions using your rules, known merchants, history and, if enabled, an AI provider;
- compute analytics such as cash flow, net worth, spending by category and recurring charges;
- answer questions you ask through AI features or connected MCP clients; and
- diagnose errors and protect the service against abuse.
Our legal basis for this processing is your consent and the performance of the service you asked for.
4. Where and how data is stored
Your data is stored on secured infrastructure operated by us and our hosting providers, isolated to your account and accessed only over encrypted connections. It does not leave that infrastructure unless you enable a feature that sends it elsewhere, as described in the sections on AI providers and MCP clients.
5. No selling, no ads, no tracking
- Arvo does not sell, rent or trade personal data.
- The application contains no advertising and no third-party advertising or analytics trackers.
- Your financial data is not used to profile you for marketing or shared with data brokers.
6. AI providers
AI features are optional. Arvo computes its numbers deterministically, and the core features work without any AI provider. When AI is enabled, Arvo can use one of these providers:
- Private models run within Arvo’s infrastructure. Prompts and data do not leave it.
- Cloud providers such as Anthropic, OpenAI or Google Gemini. Cloud AI is opt-in and is disclosed in the app when in use.
When a cloud provider is enabled and you use an AI feature, your question and the relevant financial data needed to answer it (for example computed totals, category summaries or selected transactions) are sent to that provider. The provider processes the data under its own terms and privacy policy, which may include retention for abuse monitoring. Review those terms before enabling a cloud provider.
AI outputs can be inaccurate. Any budgets, goals or rules drafted by AI features are presented as suggestions and are saved only when you approve them.
7. MCP clients
Arvo includes a Model Context Protocol (MCP) server that lets AI clients you choose, such as desktop assistants, call tools like spending summaries and cash-flow reports. An MCP client can only access data after you authorize it with your own credentials, and its tools are scoped to your account.
Data returned to a connected client is then handled by that client and any AI provider behind it, under their terms. You can stop sharing at any time by disconnecting the client or signing out its session.
8. Security measures
The software is designed with the following safeguards:
- Passwords are hashed with Argon2; plain-text passwords are never stored.
- Short-lived access tokens are used for API requests, and refresh tokens are kept in an httpOnly cookie that page scripts cannot read.
- Per-user data isolation: every query for financial data is scoped to the authenticated user.
- File validation on uploads, including type and size checks, before a statement is parsed.
- Imports go through a review step, and nothing is written to the ledger until you commit it.
No system is perfectly secure, but we protect the service with encrypted connections, restricted access controls, secrets management and regular updates. If you believe you have found a vulnerability, contact vineet.likhitkar@gmail.com.
9. Retention and deletion
Data is kept until you delete it or ask us to. You can:
- delete imports and the uploaded statement files associated with them;
- delete individual transactions, accounts, categories and rules; and
- ask for your account to be deleted, which removes your profile, financial data and files from our live systems. Where the app does not yet offer self-service account deletion, we do it on request.
Deleted data may persist in backups, snapshots or logs until those are rotated on our backup schedule. Data already sent to a cloud AI provider is retained under that provider’s policy.
10. Data export
You have the right to a copy of your data in a portable format. Where the app offers in-app export, you can download it yourself; otherwise email us and we will provide an export. Your original statement files remain in storage until you delete them.
12. Children
Arvo is intended for adults managing their own finances. Arvo does not knowingly create accounts for children under 18, or the age of digital consent in your jurisdiction, without verifiable consent from a parent or guardian. If you believe a child’s data has been provided without that consent, contact us so it can be deleted.
13. International users and your rights
Depending on where you live, laws such as the EU and UK General Data Protection Regulation (GDPR), India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and US state privacy laws such as the California Consumer Privacy Act (CCPA) give you rights over your personal data. Subject to applicable law, you can ask the data controller to:
- Access the personal data held about you and learn how it is processed;
- Correct inaccurate or incomplete data;
- Delete your data (erasure);
- Port your data in a structured, machine-readable format;
- Withdraw consent at any time, for example by disabling AI features or disconnecting an MCP client, without affecting processing that already took place;
- object to or restrict certain processing, and not be discriminated against for exercising your rights; and
- nominate another person to exercise your rights in the event of death or incapacity, where the DPDP Act allows.
Grievances
To raise a request or grievance, email vineet.likhitkar@gmail.com. We will respond within the time required by law. If you are not satisfied, you may complain to your data protection authority, such as the Data Protection Board of India or your local supervisory authority in the EU or UK.
14. Changes to this policy
This policy may be updated as Arvo or the law changes. The “Last updated” date at the top shows when it last changed. For material changes, we will notify users in the app or by email before the change takes effect.
15. Contact
Questions or requests about this policy or your data can be sent to:
Arvo
Email: vineet.likhitkar@gmail.com
See also the Terms of Use and the Financial Disclaimer.