1. What Claroo does
Claroo is a personal financial-intelligence app. When you connect your bank, brokerage, or crypto accounts (all read-only), Claroo analyzes your transactions and holdings to build a behavioral financial profile: a structured understanding of how you earn, spend, save, and plan. Claroo uses that profile to give you a daily briefing, insights, and an AI money chat, and, only when you explicitly choose, to share context with AI assistants you connect.
2. Information we collect
- Account information: email address, name, and sign-in provider (email, Google, or Apple), managed through our authentication provider; your profile settings (display name, country, language, timezone).
- Bank data: when you connect a bank via Plaid or Salt Edge: accounts (including, for European banks, IBAN and account numbers), balances, and transactions (amount, date, merchant, category, location data provided by your bank, and payment details such as payer/payee references). We never see or store your bank login credentials. Note: when we connect you through Salt Edge, your email address is used as your customer identifier with Salt Edge.
- Brokerage data: when you connect a brokerage via SnapTrade: accounts, balances, holdings/positions, and account activity (trades, dividends, fees). Read-only.
- Crypto data: when you add a wallet: your public wallet address and its on-chain transaction history, read via Zerion. Never private keys.
- Derived and inferred data: the behavioral profile our analytics engine builds from your transactions: spending patterns, categories, recurring payments, inferred income streams, cashflow forecasts, money-skills scores, insights, and personality-style indicators inferred from financial behavior (see Section 6).
- Locations you save: if you add places like "home" or "work," the address and coordinates you select (via Google Places address search). Claroo does not collect device GPS location, contacts, or camera data.
- Device and notifications: device identifier, platform and app version, push notification token, and your notification preferences. Biometric unlock happens entirely on your device; biometric data never leaves it.
- Usage analytics and diagnostics: product analytics events (screens viewed, features used) and error/crash diagnostics, as described in Section 9.
- Waitlist information: email address and country, if you join the waitlist.
3. How we use your information
We use your data to: provide the Service (build and maintain your behavioral financial profile, generate your briefings and insights (including, when AI features are enabled, AI-written briefing narratives) and power the AI chat); share structured context with AI assistants only when you explicitly connect one; improve the accuracy of our categorization and insights (including when you correct a category or confirm a recurring payment); secure the Service and prevent fraud and abuse; send you service communications and, with your consent, product updates; and comply with our legal obligations.
We will never sell, rent, or share your personal or financial data with third parties for their marketing purposes.
4. Legal bases (GDPR)
- Performance of our contract with you: operating the Service, processing your connected account data to deliver insights and briefings, and handling your account.
- Your explicit consent: connecting each financial account, adding a crypto wallet (Article 6(1)(a)), sharing data with an AI assistant, marketing emails, and non-essential analytics and cookies. You can withdraw consent at any time.
- Legitimate interests: securing the Service, preventing abuse, and measuring basic service performance.
- Legal obligation: where we must retain or disclose data under applicable law.
5. How your data is processed: Neumetria
Claroo's behavioral analysis is performed by Neumetria, our affiliated behavioral-intelligence engine, acting as our processor. Your transactions and holdings are sent to Neumetria pseudonymously (keyed to an internal identifier, without your name or email) and processed on EU infrastructure (Frankfurt, Germany). Neumetria generates the derived data described in Section 2 and uses vetted sub-processors (including cloud infrastructure, and AI and mapping services for merchant recognition) under contractual data protection obligations consistent with this policy.
6. Profiling: what we do with it
Building your behavioral profile is, in GDPR terms, profiling: we infer characteristics about your financial behavior from your transaction data, including spending patterns, income streams, and personality-style indicators. This profile exists to power your own insights and briefings. It is not used to make automated decisions about you that produce legal or similarly significant effects, it is not sold or shared for advertising, and personality indicators are never included in what AI chat or connected assistants see. You can object to profiling or delete your data at any time (Sections 11 and 12).
7. What AI services receive
Daily Brief composition. When AI features are enabled, your daily briefing's narrative is written by our AI model provider (Anthropic) from a limited, auditable “fact pack”: aggregated figures (such as yesterday's totals and category labels), a small number of transaction-level facts (your largest purchase and upcoming recurring payments, as merchant and amount), and behavioral signals. Your full transaction history, account identifiers, name, and email are never included. The inputs of every AI-written edition are stored so you can audit exactly what the model saw.
In-app AI chat. When you use Ask AI, your question and relevant parts of your financial context (such as recent spending, recurring payments, forecasts, and behavioral signals) are sent to the same provider to generate the response. If your question requires it, the assistant can retrieve individual transactions (merchant, amount, date, category) matching your question, in small batches, for the duration of the conversation. Chat conversations are not stored in Claroo's database. Our provider processes this data as our service provider under commercial API terms and does not use it to train its models.
Merchant recognition. To identify merchants, short fragments of transaction descriptions (with personal identifiers removed) may be shared with AI and mapping services by our processing engine. Amounts, balances, and your identity are never included. You can switch this off (“Merchant recognition” in Privacy settings).
Your controls. Every AI use above is governed by the switches in Settings → Privacy and applies the moment you flip it: turning off AI features stops AI composition of your briefing, stops AI answers, and hides previously AI-written content; turning off the AI assistant disables chat entirely; turning off Merchant recognition stops description fragments being shared. These switches are enforced server-side, not just in the app.
Connected AI assistants. When you connect an external AI assistant, it accesses your data only within the permission scopes you explicitly approve on the consent screen: typically your behavioral patterns, insights, and metrics, and, only if you grant it, transaction details. No scope can move money. The assistant's own handling of the data it receives is governed by its provider's privacy policy. You can review and revoke access at any time in settings.
8. Third-party services
We work with the following categories of service providers: financial connections: Plaid and Salt Edge (banking), SnapTrade (brokerage), Zerion (crypto); infrastructure: Supabase (authentication and database), Google Cloud (hosting, EU), Neumetria (behavioral analysis, EU); AI: Anthropic (AI chat and daily-brief composition); communications: Expo/Apple/Google push services (notifications), Resend (service email), MailerLite (waitlist and product emails); analytics and diagnostics: PostHog (product analytics), Sentry (error monitoring), and, on our marketing website only, web analytics as described in Section 9; and content: Sanity (editorial content for Lyra) and Vercel Blob (video storage for Lyra) — neither receives user financial data. Each provider receives only the data needed for its role, under data protection obligations. A current list is available from privacy@claroo.com.
9. Cookies, analytics, and tracking
The Claroo app uses product analytics (PostHog) and error monitoring (Sentry) to understand feature usage and fix problems. The claroo.com website may additionally use web analytics and conversion measurement tools. Where required by law (including in the EU/EEA), non-essential cookies, analytics, and measurement tools run only with your consent, which you can give or withdraw through the cookie settings on the site and the privacy settings in the app. We do not use advertising cookies to build advertising profiles of you, and we do not sell your data to advertisers.
10. International data transfers
Your core financial data is processed in the European Union (our behavioral engine runs in Frankfurt, Germany; our primary database is EU-hosted). Some service providers process data in the United States (including our AI provider, product analytics, and, for US/Canadian/UK banks, Plaid). Where personal data leaves the EEA or the UK, we use safeguards recognized by GDPR, such as the European Commission's Standard Contractual Clauses.
11. Your rights (GDPR)
You have the right to: access your personal and financial data; export a copy (data portability), available in-app, delivered by email within 30 days; correct inaccurate data (including fixing transaction categories directly in the app); delete your account and all associated data, available in-app; disconnect any bank, brokerage, or wallet at any time; revoke any AI assistant's access at any time; object to processing, including profiling; restrict processing; and withdraw consent at any time where processing is based on consent.
To exercise any right, use the in-app controls or email privacy@claroo.com. You also have the right to lodge a complaint with a supervisory authority: our lead authority is the Latvian Data State Inspectorate (Datu valsts inspekcija), and you may also complain to the authority in your country of residence.
12. Data retention and deletion
Your financial data and behavioral profile are retained while your account is active. When you delete your account (or disconnect an account provider), the associated financial data (including everything held by our processing engine and connection partners on our behalf) is permanently deleted within 30 days. Deletion is irreversible. Waitlist data is deleted within 30 days of unsubscribing. We may retain limited records where required by law (for example, records of consent and of deletion requests).
13. Security
All financial data is encrypted in transit, and sensitive credentials (such as connection tokens) are additionally encrypted at rest. Bank connections are established through our partners' secure infrastructure; we never see or store your banking credentials. Access to production data is strictly limited. No system is completely secure; if a breach affects your data, we will notify you and the relevant authorities as required by law.
14. Children
Claroo is for adults. We do not knowingly collect data from anyone under 18.
15. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date above shows the latest revision. If a change is material, we will notify you by email or in the app before it takes effect.
16. Contact
privacy@claroo.com
Claroo SIA, Dzirnavu iela 67, Centra rajons, Rīga, LV-1011, Latvia · Reg. no. 50203511861