Conto

Privacy Policy

This policy explains what information Conto collects, how we use and share it, and the choices you have. It covers the conto.finance website, the Conto dashboard and API, our developer tools, and our sandbox and demo environments.

Effective date: August 10, 2026. Last updated: August 10, 2026.

1. Who we are and what this covers

Conto is operated by Conto Finance, Inc., a Delaware corporation ("Conto," "we," "us"). Conto is a business-to-business platform: organizations register, define spend policies, and connect AI agents that transact under those policies. This policy applies to personal data we handle when you visit our site, create an account, use the dashboard or API, or contact us. It does not cover the practices of our customers or of third parties we link to.

2. Information we collect

Account and organization data. When you register we collect your name, email address, organization name, and a password (stored only as a salted hash). If you enable multi-factor authentication we store your TOTP secret in encrypted form and hashed backup codes.

Billing data. Paid subscriptions are processed by Stripe. Stripe collects your payment card details directly; we receive and store subscription status, plan, invoicing metadata, and a Stripe customer reference. We do not store your full card number for billing.

Transaction and policy metadata. Using the product generates records of agents, wallets, connected payment methods, policies, approvals, and transactions. For payment cards you connect, we store masked details only (a friendly name, the last four digits, brand, and expiry); full card numbers stay with the card provider. This data is mostly organizational, but it can include personal data such as cardholder names or counterparty details.

Usage and log data. We collect API request logs, audit logs of actions taken in your organization, IP addresses, browser and device information, and diagnostic events (including error reports sent to our monitoring service).

Communications. If you email us, contact sales, or submit a form, we keep the correspondence.

Sandbox and demo data. Our public try mode and demos may process the inputs you provide there. Treat these environments as evaluation tools and do not enter sensitive personal data into them.

3. How we use information

  • Provide, operate, and maintain the service, including policy enforcement, approvals, audit logging, and webhooks.
  • Authenticate users, secure accounts, and prevent fraud and abuse.
  • Process subscriptions and payments and send billing communications.
  • Send transactional email such as verification, password reset, alerts, and approval notifications.
  • Respond to support requests and sales inquiries.
  • Send occasional product updates and marketing email. You can opt out at any time using the unsubscribe link in any such message, and transactional email is not affected.
  • Monitor performance and errors, debug issues, and improve the product, including through aggregated usage statistics.
  • Comply with legal obligations and enforce our Terms of Service.

Some product features use AI models (for example the in-dashboard assistant and demo narration). Inputs to those features are sent to our AI model provider to generate the response.

4. Cookies and analytics

We use cookies that are necessary to operate the service: session cookies that keep you signed in and security cookies such as CSRF protection tokens. These are essential and cannot be switched off while using the dashboard.

For site analytics we use Vercel Analytics, which measures page views using anonymized, aggregated data and does not use cookies or track visitors across sites. We do not use advertising cookies or sell data to ad networks. If we add other analytics tools in the future, we will update this policy.

5. How we share information

We do not sell personal data. We share it with service providers who process it on our behalf under contract, and only as needed to run the service:

  • Stripe: subscription billing and payment processing.
  • Privy: managed wallet key infrastructure for agent transactions.
  • Vercel: application hosting, content delivery, and privacy-focused site analytics.
  • Neon: managed Postgres database hosting.
  • Upstash: managed Redis for sessions, rate limiting, and caching.
  • Sentry: error and performance monitoring.
  • Resend: transactional email delivery.
  • Anthropic: AI model inference for assistant and demo features.
  • Inngest: background job processing.
  • Mintlify: documentation site tooling.

We may also disclose information to comply with law or valid legal process, to protect the rights, safety, or property of Conto, our customers, or others, or as part of a merger, acquisition, or sale of assets (in which case this policy will continue to apply until updated).

6. Controller and processor roles

For account, billing, website, and marketing data, we act as the data controller. For personal data contained in customer content that organizations and their agents submit to the platform (for example counterparty names inside transaction records), we act primarily as a processor on behalf of the customer organization, which is responsible for its own legal basis and notices. A data processing addendum is available to business customers on request at support@conto.finance.

7. Data retention

We keep account data for the life of your account. After you delete your account, we delete or de-identify your account data, and residual copies may persist in backups for up to 90 days. Audit logs are retained according to your plan: 30 days on the free plan, one year on the Builder plan, and seven years on the Enterprise plan. Transaction and billing records are retained for up to 7 years as required for tax and accounting purposes. Diagnostic logs and telemetry, including error reports sent to our monitoring service, are retained for up to 13 months. Records we must keep to comply with legal obligations or to resolve disputes may be retained longer. When retention periods end, we delete or de-identify the data.

8. Security

We encrypt data in transit, encrypt sensitive secrets (such as MFA seeds) at rest, hash passwords, support multi-factor authentication, and restrict internal access to production data. No system is perfectly secure, so we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities within the timeframes required by applicable law. If you find a vulnerability, please report it through our security disclosure policy, which includes safe-harbor terms for good-faith research.

9. Your rights and choices

You can access and update most account information in your dashboard settings. You can also email support@conto.finance to request access to, correction of, or deletion of your personal data, a portable copy of it, or to object to or restrict how we process it. We honor these requests for everyone, wherever you live, subject to records we must keep by law, and we respond within the timeframes required by applicable law. If your data was submitted to Conto by a customer organization, we may refer your request to that organization.

European Economic Area, United Kingdom, and Switzerland (GDPR). If GDPR applies to you, you have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office). Our legal bases are performance of a contract, our legitimate interests in operating and securing the service, compliance with legal obligations, and consent where we ask for it.

California (CCPA/CPRA). If you are a California resident, you have the right to know, correct, and delete personal information we hold about you, and the right not to be discriminated against for exercising those rights. The categories of personal information we collect are described in Section 2, we collect them from you and from your use of the service, and we use and share them as described in Sections 3 and 5. We do not sell personal information and do not share it for cross-context behavioral advertising as those terms are defined in the CPRA. To exercise your rights, email support@conto.finance. An authorized agent may submit a request on your behalf with proof of your authorization.

10. International data transfers

Our service providers are primarily located in the United States, and data we collect is processed there. If you access the service from outside the United States, your data will be transferred to and processed in the United States and other countries where our providers operate. For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as standard contractual clauses where required.

11. Children

The service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. We will post the updated version on this page and update the effective date. For material changes we will provide more prominent notice, such as email to your account address or a notice in the dashboard.

13. Contact

Privacy questions and requests: email support@conto.finance. The controller for the data described in this policy is Conto Finance, Inc., a Delaware corporation. Legal notices can be sent to the same email address.