This policy explains what information Conto collects, how we use and share it, and the choices you have. It covers the conto.finance website, the Conto dashboard and API, our developer tools, and our sandbox and demo environments.
Effective date: August 10, 2026. Last updated: August 10, 2026.
Conto is operated by Conto Finance, Inc., a Delaware corporation ("Conto," "we," "us"). Conto is a business-to-business platform: organizations register, define spend policies, and connect AI agents that transact under those policies. This policy applies to personal data we handle when you visit our site, create an account, use the dashboard or API, or contact us. It does not cover the practices of our customers or of third parties we link to.
Account and organization data. When you register we collect your name, email address, organization name, and a password (stored only as a salted hash). If you enable multi-factor authentication we store your TOTP secret in encrypted form and hashed backup codes.
Billing data. Paid subscriptions are processed by Stripe. Stripe collects your payment card details directly; we receive and store subscription status, plan, invoicing metadata, and a Stripe customer reference. We do not store your full card number for billing.
Transaction and policy metadata. Using the product generates records of agents, wallets, connected payment methods, policies, approvals, and transactions. For payment cards you connect, we store masked details only (a friendly name, the last four digits, brand, and expiry); full card numbers stay with the card provider. This data is mostly organizational, but it can include personal data such as cardholder names or counterparty details.
Usage and log data. We collect API request logs, audit logs of actions taken in your organization, IP addresses, browser and device information, and diagnostic events (including error reports sent to our monitoring service).
Communications. If you email us, contact sales, or submit a form, we keep the correspondence.
Sandbox and demo data. Our public try mode and demos may process the inputs you provide there. Treat these environments as evaluation tools and do not enter sensitive personal data into them.
Some product features use AI models (for example the in-dashboard assistant and demo narration). Inputs to those features are sent to our AI model provider to generate the response.
For account, billing, website, and marketing data, we act as the data controller. For personal data contained in customer content that organizations and their agents submit to the platform (for example counterparty names inside transaction records), we act primarily as a processor on behalf of the customer organization, which is responsible for its own legal basis and notices. A data processing addendum is available to business customers on request at support@conto.finance.
We keep account data for the life of your account. After you delete your account, we delete or de-identify your account data, and residual copies may persist in backups for up to 90 days. Audit logs are retained according to your plan: 30 days on the free plan, one year on the Builder plan, and seven years on the Enterprise plan. Transaction and billing records are retained for up to 7 years as required for tax and accounting purposes. Diagnostic logs and telemetry, including error reports sent to our monitoring service, are retained for up to 13 months. Records we must keep to comply with legal obligations or to resolve disputes may be retained longer. When retention periods end, we delete or de-identify the data.
We encrypt data in transit, encrypt sensitive secrets (such as MFA seeds) at rest, hash passwords, support multi-factor authentication, and restrict internal access to production data. No system is perfectly secure, so we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities within the timeframes required by applicable law. If you find a vulnerability, please report it through our security disclosure policy, which includes safe-harbor terms for good-faith research.
You can access and update most account information in your dashboard settings. You can also email support@conto.finance to request access to, correction of, or deletion of your personal data, a portable copy of it, or to object to or restrict how we process it. We honor these requests for everyone, wherever you live, subject to records we must keep by law, and we respond within the timeframes required by applicable law. If your data was submitted to Conto by a customer organization, we may refer your request to that organization.
European Economic Area, United Kingdom, and Switzerland (GDPR). If GDPR applies to you, you have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office). Our legal bases are performance of a contract, our legitimate interests in operating and securing the service, compliance with legal obligations, and consent where we ask for it.
California (CCPA/CPRA). If you are a California resident, you have the right to know, correct, and delete personal information we hold about you, and the right not to be discriminated against for exercising those rights. The categories of personal information we collect are described in Section 2, we collect them from you and from your use of the service, and we use and share them as described in Sections 3 and 5. We do not sell personal information and do not share it for cross-context behavioral advertising as those terms are defined in the CPRA. To exercise your rights, email support@conto.finance. An authorized agent may submit a request on your behalf with proof of your authorization.
Our service providers are primarily located in the United States, and data we collect is processed there. If you access the service from outside the United States, your data will be transferred to and processed in the United States and other countries where our providers operate. For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as standard contractual clauses where required.
The service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.
We may update this policy from time to time. We will post the updated version on this page and update the effective date. For material changes we will provide more prominent notice, such as email to your account address or a notice in the dashboard.
Privacy questions and requests: email support@conto.finance. The controller for the data described in this policy is Conto Finance, Inc., a Delaware corporation. Legal notices can be sent to the same email address.