Legal

Privacy Policy

This policy explains how Sarro Solutions LLC handles information when invited users access Sarfolio.

Effective October 4, 2026

1. Who operates Sarfolio

Sarfolio is operated by Sarro Solutions LLC ("Sarro Solutions," "we," "us," or "our"). Sarfolio is currently an invitation-only personal finance and portfolio analytics service. Questions or privacy requests may be sent to support@sarrosolutions.com.

2. Information we collect

Account and authentication information

We collect your email address as your sign-in identity and store a cryptographic hash of your password. We also use authentication and security cookies to keep you signed in and protect access to your account.

Financial information you enter

Sarfolio stores information you choose to enter about bank accounts, credit cards, bills, debts, balances, pay schedules, and related preferences. For a manually entered bank account, Sarfolio stores its routing number and the last four digits of its account number. For a card, Sarfolio stores only the last four card digits. It does not ask for or store a full bank account or payment-card number.

Alpaca connection and portfolio information

If you connect Alpaca, we receive authorization and information needed to provide the connection, such as your Alpaca account identifier, account-number ending, connection environment and status, granted permissions, and access token. OAuth access tokens are encrypted before storage. Depending on the features available to your account, Sarfolio may retrieve and store or display balances, positions, orders, activity, portfolio history, and market-related information associated with your Alpaca account.

Aria and AI feature information

When Aria or another AI-assisted feature is available to you, we process the prompts you submit, generated responses, relevant recent conversation context, and financial or market context needed to produce the response. Aria conversations may be stored in Sarfolio so the feature can maintain history for your session.

Usage and technical information

Our hosting and service providers may process standard request and operational information, such as IP address, browser or device details, timestamps, requested pages, error details, and security events. Sarfolio does not currently use advertising cookies or third-party advertising trackers.

3. How we use information

  • Provide, personalize, maintain, and troubleshoot Sarfolio.
  • Authenticate users and keep each user's records separated.
  • Display financial, brokerage, portfolio, and market information requested by the user.
  • Provide AI-assisted explanations, analysis, and automation when those features are enabled.
  • Protect the service, investigate errors or misuse, and enforce our Terms of Use.
  • Comply with law and respond to valid legal requests.

4. When information is shared

We share information only as needed for the service, including with these providers:

  • Alpaca, when you authorize a connection, to authenticate that connection and retrieve brokerage and market information permitted by your authorization.
  • Neon, which provides the hosted PostgreSQL database used to store Sarfolio account and application data.
  • Vercel, which hosts and delivers the application and may process operational request and deployment logs.
  • OpenAI, which processes prompts and the relevant context supplied by Sarfolio to provide AI-assisted features. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer opts in.

Sarfolio also obtains public or licensed market and reference data from sources such as Alpaca, Finnhub, the Federal Reserve Economic Data service, SEC EDGAR, and OpenFIGI. Those sources ordinarily provide market or reference information rather than receiving your Sarfolio account records.

We may also disclose information when required by law, to protect users or the service, or as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate safeguards and notice where required.

5. No sale or targeted advertising

Sarfolio does not sell personal information. Sarfolio does not share personal information for cross-context behavioral advertising or use personal information to serve targeted advertisements. If these practices change, we will update this policy and provide any choices required by law.

6. Artificial intelligence

Sarfolio uses OpenAI's API to provide Aria and other AI-assisted features. When you use one of these features, Sarfolio may send OpenAI your prompt, recent conversation context, relevant account or portfolio information, configured investment rules, and market data needed to generate the requested response. Sarfolio does not send your password or Alpaca access token to OpenAI.

OpenAI processes this information on Sarfolio's behalf. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer affirmatively opts in. OpenAI may retain API content and related logs according to its API data controls and legal obligations. AI output may be inaccurate, so Sarfolio may store the input and output to provide conversation history, operate safeguards, investigate errors, and improve the application experience.

Use of available AI features is optional. Avoid including information in a prompt that is not needed for your request. You can clear available Aria conversation history through the product and may contact us regarding stored information as described below.

7. Cookies

Sarfolio uses essential cookies for authentication, security, redirect handling, and available Aria conversation sessions. These cookies are used to operate the service and are not advertising cookies. Your browser can remove or block cookies, but doing so may prevent sign-in or other features from working.

8. Security

We use administrative and technical measures designed to protect information. These include hashed passwords, encrypted Alpaca OAuth tokens, server-side secret handling, authenticated routes, and separation of records by user. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

9. Retention, disconnection, and deletion

We retain information while your account is active and as reasonably needed to operate Sarfolio, protect the service, resolve disputes, meet legal obligations, and preserve appropriate financial or security records. Retention periods vary by the type of data and by provider backup and log schedules.

Disconnecting Alpaca disables Sarfolio's use of that connection. You may also revoke authorization through Alpaca. Connection records may be retained for security, audit, reconnection, and compliance purposes. Clearing Aria history removes the conversation history available through that feature, subject to temporary backups and provider retention. To request account or data deletion, email support@sarrosolutions.com. We may retain limited information when required by law or reasonably necessary for security, fraud prevention, or dispute resolution.

10. Your choices and privacy rights

You can choose what financial information to enter, whether to connect Alpaca, and whether to use available AI features. You may ask to access, correct, export, or delete your personal information by contacting us. Depending on where you live, privacy law may provide additional rights and an appeal process. We may need to verify your identity before completing a request.

11. Children's privacy

Sarfolio is intended for adults and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided information to Sarfolio, contact us so we can review and delete it as appropriate.

12. Changes to this policy

We may update this policy as Sarfolio changes. We will post the revised policy here, change the effective date, and provide additional notice when required by law. Your continued use after an update is subject to the revised policy.

13. Contact

Sarro Solutions LLC
support@sarrosolutions.com