← Back to oro-ia.comVersión en español

Privacy Policy

Last updated: July 20, 2026

1. Information We Collect

Oro collects only the information necessary to provide you with the personal finance management service:

Account data

  • Email address
  • Name (optional)
  • Password (stored in encrypted form)
  • Currency and country preferences

Financial data entered by the user

  • Transactions (income and expenses) with description, amount, and category
  • Monthly budgets and expense categories
  • Savings goals and contributions
  • Patrimony data: assets, liabilities, investments, and their valuation
  • Shared expenses in rooms and invited member data
  • Conversations with AI assistants (Luna and Sol)

Automatically processed data

  • Receipt images sent for OCR scanning (processed and not stored as images)
  • Date and time of access
  • Features used
  • Preferred communication channel (web, WhatsApp, Telegram)

2. Information We Do NOT Collect

It is important that you know Oro never collects or requests:

  • Banking credentials (username, password, or PIN for your bank)
  • Credit or debit card numbers (payments are processed by third parties)
  • Access to your bank accounts
  • Information from other financial applications
  • Biometric data
  • Precise geographic location

Oro does not connect to banks or financial institutions. All financial information is entered voluntarily by you.

3. How We Use Your Information

We use your data exclusively for:

  • Providing the service: recording transactions, calculating budgets, monitoring savings goals, tracking patrimony
  • AI analysis: generating personalized insights, suggestions, and reports about your finances
  • Receipt OCR: extracting information from receipt images to facilitate transaction recording
  • Shared rooms: managing group expenses and calculating balances between members
  • Notifications: budget alerts, goal reminders, monthly summaries
  • Service improvement: understanding usage patterns to improve the experience
  • Support: answering inquiries and resolving technical issues

We never sell, rent, or share your personal or financial data with third parties for advertising or marketing purposes.

4. Storage and Security

Your data is stored securely with the following measures:

  • Database: PostgreSQL hosted on Railway with restricted access
  • Encryption in transit: all communications use HTTPS/TLS
  • Passwords: stored with bcrypt hash (never in plain text)
  • Session tokens: JWT with expiration and revocation via blacklist
  • Restricted access: only authorized personnel can access the infrastructure
  • Rate limiting: protection against brute force attacks
  • OCR images: processed in memory and not permanently stored on our servers

We do not store financial data on local devices. All information resides on secure servers with automatic backup.

5. Third-Party Services

Oro uses the following third-party services for its operation. Each has limited access only to the data necessary for its function:

  • OpenAI: natural language processing for Luna and Sol assistants, and OCR processing of receipts. Conversations and images are sent to generate responses. OpenAI does not retain this data for training.
  • Resend: sending transactional emails (verification, notifications, summaries). Only receives your email address.
  • Cloudflare: attack protection, CDN, and CAPTCHA verification during registration.
  • MercadoPago (Chile): subscription payment processing. We do not store card data.
  • Hotmart (International): international payment processing. Manages the subscription independently.
  • NOWPayments (Crypto): cryptocurrency payment processing. Only receives the amount and payment address.
  • Railway: hosting infrastructure for the application and database.

6. Data in Shared Rooms

When using the Rooms feature (shared expenses):

  • Invited members can see expenses recorded in the room, but not your personal data or other transactions
  • The room owner can see all expenses recorded by members within the room
  • Member names are visible to other participants in the same room
  • When leaving a room, your historical expenses remain in the room's record

7. Your Rights

As an Oro user, you have the following rights over your data:

  • Access: you can view all the information we have about you at any time from the application
  • Rectification: you can correct or update your personal and financial data
  • Deletion: you can request complete deletion of your account and all associated data
  • Export: you can request a copy of all your data in a readable format
  • Portability: you can request your data in a standard format to migrate to another service

To exercise any of these rights, contact soporte@oro-ia.com. We will respond within a maximum of 15 business days.

8. Data Retention

Your data is maintained while your account is active. Specifically:

  • Active account: all data is maintained indefinitely
  • Canceled account: data is kept for an additional 90 days in case you wish to reactivate
  • Deletion request: data is permanently deleted within 30 days
  • Extended inactivity: accounts inactive for more than 12 months may be deleted after notification

Audit logs and security records are kept for a maximum of 6 months for security purposes.

9. Cookies

Oro uses cookies minimally and exclusively for functional purposes:

  • Session cookie: keeps your session active while using the application (deleted upon logout)
  • Preferences: stores your theme preference (light/dark)

We do not use tracking cookies, advertising cookies, or third-party cookies for behavioral analysis.

10. Children's Privacy

Oro is not intended for minors under 18 years of age. We do not knowingly collect information from underage individuals. If we discover that a minor has created an account, we will proceed to delete it along with all associated data.

If you are a parent or guardian and believe your minor child has provided information to Oro, contact soporte@oro-ia.com to request deletion.

11. Changes to This Policy

We may update this Privacy Policy periodically. When we do:

  • We will update the effective date at the beginning of the document
  • We will notify you by email about significant changes
  • We will display a notice within the application

We recommend reviewing this policy periodically. Continued use of the service after changes constitutes your acceptance of the updated policy.

12. Contact

If you have questions, concerns, or requests related to your privacy and the handling of your data, you can contact us at:

We are committed to responding to all privacy-related inquiries within a maximum of 15 business days.