Privacy Policy

Last updated: July 31, 2026

RK Sterling, LLC ("Sterling," "we," "us") provides a software platform for registered investment advisors and financial-services professionals. Sterling holds some of the most sensitive information a client will ever share with an advisor: account balances, tax returns, estate documents, and family circumstances. This Privacy Policy describes what we collect, how we use it, who else touches it, and the choices you have. We have written it to be read, not skimmed.

By registering for or using the Services, you acknowledge that you have read and understood this Privacy Policy. You represent that you are 18 years of age or older and a resident of the United States. If you do not agree with this Privacy Policy, do not access the Site or the Services. Please also review our Terms of Service at https://www.rksterling.com/legal/terms-of-service.


Roles: Who Controls What

Customer means the organization (your advisory firm, broker-dealer, or another entity) that entered into an agreement with Sterling. The Customer controls its instance of the Services and the client information within it. For information about a Customer's clients ("Client Data"), Sterling acts as a service provider processing that data on the Customer's behalf and on its instructions. For account, billing, and usage information about you as a user, Sterling acts as the controller. We execute Data Processing Agreements with Customers who require one.


Information We Collect

Information You Provide to Us

  • Account information – name, email address, phone number, professional credentials, and authentication identifiers. Sterling does not store passwords; authentication is handled by our identity provider.
  • Business information – firm name, address, website, regulatory registrations, and team membership within your firm.
  • Client Data – information about your clients that you enter into the Services or upload as documents, including household composition, income, expenses, investments, real estate, liabilities, insurance, tax, and estate-planning information.
  • Documents – files you upload to the platform's document vault, such as account statements, tax returns, and estate documents.
  • Payment information – billing details processed by our payment provider. Sterling does not store full card numbers.
  • Communications – information you provide when you contact support or otherwise communicate with us.

Information from Services You Connect

The Services can connect to third-party systems, always at the Customer's or user's initiative and through authorized, revocable connections. Sterling does not ask for, collect, or store your clients' banking or brokerage login credentials.

  • Email and calendar – if you connect a mailbox or calendar (for example, Microsoft Outlook or Google Workspace), we sync messages, calendar events, and related metadata for the accounts you authorize, so client communications appear alongside the household record. Access is granted via OAuth and can be revoked at any time.
  • Meeting recordings and transcripts – if you enable meeting capture, transcripts of client meetings from services such as Zoom, Microsoft Teams, or Google Meet are processed into notes and structured data.
  • Custodial and financial-account data – where a Customer authorizes a data feed from a custodian or financial institution holding its clients' accounts, we receive positions, balances, transactions, and account attributes through the institution's own integration channels, under authorizations executed with that institution. Such data is used solely to serve the specific client it belongs to and is subject to the institution's agreements in addition to this policy.

Information We Collect Automatically

  • Usage information – features accessed, actions taken, frequency of use, and metered AI usage for billing.
  • Log data – IP address, browser type, operating system, referring URLs, and pages viewed.
  • Audit records – a compliance-grade log of user actions affecting client records, retained to support Customers' regulatory obligations.
  • Device information and cookies – device identifiers and cookies or similar technologies that keep you signed in and capture interactions with the Services.

How We Use Information

  • Provide the Services – operate the platform, including financial planning and tax analysis, advice generation, CRM and workflows, document management, communications history, and reporting.
  • Account creation and authentication – register your account and securely authenticate your sessions.
  • Platform operation and improvement – maintain, troubleshoot, develop, and improve the Services; perform accounting, auditing, billing, and other internal functions.
  • Billing – meter platform usage and bill the Customer through our payment provider.
  • Communications – send administrative, billing, support, and service notices; send marketing communications only where you have opted in, with the ability to opt out at any time.
  • Security and fraud prevention – detect, prevent, and respond to errors, fraud, abuse, security incidents, and technical issues.
  • Legal compliance – comply with applicable law, regulation, legal process, or enforceable governmental requests, and enforce our Terms of Service.

We do not use Client Data for advertising, and we do not sell personal information, whether yours or your clients'.


How AI Processing Works

Certain features of the Services use large language models: generating planning recommendations for advisor review, the advisor chat assistant, extracting structured data from uploaded documents, summarizing meeting transcripts, drafting emails and reports, and similar assistive functions. Because these features process Client Data, they operate under specific commitments:

  • AI is off until the advisor turns it on. Every client household starts with no AI access. No Client Data is sent to any AI model until an advisor deliberately enables AI processing for that household. The control is enforced on the server and fails closed.
  • Your data is not used to train models. AI requests run on enterprise cloud infrastructure (currently AWS Bedrock and Google Cloud Vertex AI) in U.S. regions, under agreements that exclude the use of our customers' data for model training, exclude retention beyond transient processing, and exclude human review by the provider.
  • Sterling does not train its own models on Client Data. We do not use Client Data to develop, train, or fine-tune any AI model.
  • Output is advisor-facing. AI-generated recommendations and drafts are presented to the advisor for review; the platform does not deliver AI output directly to a Customer's clients.
  • Deterministic calculations stay deterministic. Tax and cash-flow projections are computed by Sterling's calculation engine, not by an AI model; AI features may invoke the engine and present its results.

The Services also offer an optional connector that lets a user query their Sterling data from an external AI assistant of their choosing. The connector is user-initiated, requires authentication with your Sterling identity, and is limited to read-only access. Data you retrieve through an external assistant is thereafter handled under that provider's terms, so connect only assistants whose terms you and your firm accept.

Customer responsibilities: You are responsible for using the Services in accordance with laws applicable to your business, including GLBA, SEC Regulation S-P, and state privacy statutes, and for providing your clients any notices and obtaining any consents those laws require for your use of service providers such as Sterling.


Data Storage and Security

  • Encryption – information is encrypted in transit and at rest.
  • Firm isolation – the platform is multi-tenant, and firm identity is part of every data query. Every request for household data is authorized on the server; automated checks in our build pipeline fail any change that ships a household data endpoint without its authorization check.
  • Authentication – sign-in is handled by an enterprise identity platform; Sterling never stores passwords. Sessions expire after 12 hours, and after 1 hour of inactivity.
  • Access control – access to a household requires an authenticated session, membership in the owning firm, and a granted permission to that household.
  • Audit trail – actions affecting client records are logged for compliance review.
  • Independent assessment – Sterling maintains a continuously monitored control environment; a SOC 2 Type II attestation is in progress, and the report will be available to customers under NDA upon issuance.

No system is impenetrable, and we cannot guarantee absolute security. We will notify affected Customers of a security incident involving their data without undue delay, consistent with applicable law and our contractual commitments.


Service Providers and Subprocessors

We share information with vendors that process it on our behalf, under contracts that restrict their use of it to providing their service to us. Categories currently in use:

  • Cloud hosting and storage – application hosting, database, and encrypted document storage
  • AI infrastructure – enterprise model inference for the AI features described above (no training, no retention)
  • Identity – authentication and session management
  • Payments – usage-based billing (Sterling does not store full card numbers)
  • Email and calendar sync – connecting mailboxes and calendars a user authorizes
  • Transactional email – delivery of service notifications
  • Real-time infrastructure – live updates within the application
  • Document processing – extraction of structured data from uploaded documents
  • Meeting transcription – capture and transcription of meetings a user enables
  • Error monitoring – diagnosing application failures

A current, named list of subprocessors is published in the Sterling Trust Center and is generated from our source code so it cannot silently fall out of date.


Information Sharing and Disclosure

Beyond the service providers above, we may share information:

  • Within your firm – with other authorized users of your Customer's instance, according to the permissions your firm's administrators configure.
  • At your direction – with integrations and third parties you choose to connect, which handle data under their own terms and privacy policies.
  • For legal reasons – when disclosure is required by law or necessary to protect rights, safety, or property.
  • Business transfers – in connection with a merger, acquisition, financing, or sale of all or a portion of our business, subject to this policy's commitments.
  • With your consent – when you explicitly agree to the sharing.

Data Retention and Deletion

We retain information as long as necessary to provide the Services and fulfill the purposes in this policy, taking into account the amount, nature, and sensitivity of the data and applicable legal requirements. Client Data is retained under the Customer's control: Customers can delete client records through the Services, and upon termination of a Customer agreement we delete the Customer's Client Data in accordance with that agreement, subject to legal retention obligations and routine backup cycles. Audit records are retained for the period the Customer's regulatory obligations require.


Your Rights and Choices

Depending on your jurisdiction, you may have the right to access, correct, delete, restrict, or port personal information about you, or to withdraw consent. Contact us as described below to exercise these rights. Where your request concerns Client Data controlled by a Customer, we will refer the request to that Customer and support their response, consistent with our role as service provider. Marketing emails include an unsubscribe link; administrative and service notices are sent as needed to operate the Services.


International Data Transfers

We are based in the United States and process and store information in the United States. By using the Services you consent to the transfer, processing, and storage of your information in the U.S.


Children's Privacy

The Site and Services are not directed to children under 18, and no child should provide personal information through them. We do not knowingly collect information from children and do not allow them to register. If we discover we have inadvertently collected such information, we will promptly delete it and close the associated account.


Changes to This Privacy Policy

We may update this policy periodically. Material changes will be announced by email (if provided) or within the Services before they take effect. Continued use after changes take effect constitutes acceptance.


Contact Us

RK Sterling, LLC 2431 Quitman Street, Denver, CO 80212 info@rksterling.com