Financial Data Policy - Rufi
Last updated: May 22, 2026
1. Financial Data We Collect
Rufi's finance module collects and processes the following data:
- Financial transactions (amount, date, category, description)
- Registered bank accounts (name, account type — no full number)
- Financial goals and budgets
- Registered investments (type, amount, yield)
2. How We Protect Your Financial Data
- Encryption at rest: Sensitive data is encrypted in the database using AES-256.
- Encryption in transit: All communication uses TLS 1.3.
- Security PIN: Access to the finance module is protected by a PIN encrypted with PBKDF2 (10,000 iterations).
- Minimum necessary access: Each system component accesses only the data required for its function.
3. Financial Data and Artificial Intelligence
When you use AI-powered financial analyses, your data is anonymized before being sent:
- Merchant names are replaced by generic categories
- Amounts are rounded to ranges (e.g., R$45 → "R$40-50")
- Dates are converted to periods (e.g., "week 3 of the month")
- Personally identifiable data is removed completely
4. We Do NOT Collect
- Bank passwords or access tokens to real accounts
- Credit card data (processed through PCI-DSS certified gateways)
- Direct connections to financial institutions
5. Financial Data Retention
- Transaction data: kept while the account is active + 5 years (tax obligation)
- After account deletion: data anonymized within 30 days, deleted within 90 days
- Payment audit logs: 7 years (tax compliance)
6. Your Rights
- Export all of your financial data in CSV/JSON format
- Request deletion of specific financial data
- Turn off AI analyses without losing access to the finance module
7. Contact
For questions about financial data: financeiro@rufi.app