Privacy Policy
Last updated: 2026-09-04
1. Data Controller
The controller of your personal data is the operator of GWYM (Grow With Your Money), a sole proprietorship (OSVC) registered in the Czech Republic.
Contact email: privacy@gwym.app
2. Personal Data We Collect
Account Data
- Email address (required for registration)
- Username (required for registration)
- Password (stored as a secure hash, never in plain text)
- First and last name (optional)
- Preferred language and currency settings
Financial Data
- Income sources and entries
- Expense categories and entries
- Assets, liabilities, and net worth data
- Invoices and receipts (uploaded files)
- Recurring transaction rules
- Bank account identifiers (IBAN, account numbers)
Usage Data
- Session data (authentication tokens)
- Product usage events: feature name and timestamp only, never amounts or text (opt-out in Settings)
- Anonymous analytics via Plausible (no cookies, no personal data)
- Error reports via Sentry (with financial data scrubbed)
3. Purpose and Legal Basis
| Purpose | Legal Basis (GDPR) |
|---|---|
| Providing the financial tracking service | Contract performance (Art. 6(1)(b)) |
| Account authentication and security | Contract performance (Art. 6(1)(b)) |
| AI-powered financial insights and reports (Growth/Advisor tier, requires your explicit consent) | Consent (Art. 6(1)(a) GDPR) |
| Error monitoring and service stability | Legitimate interest (Art. 6(1)(f)) |
| Anonymous usage analytics | Legitimate interest (Art. 6(1)(f)) |
| Product usage event tracking (feature name and timestamp, no financial data) | Legitimate interest (Art. 6(1)(f)), opt-out via Settings |
| Email notifications (service updates) | Contract performance (Art. 6(1)(b)) |
4. Data Recipients
We share your data with the following categories of recipients:
Processors (acting on our instructions)
| Recipient | Purpose | Data categories | Location | Safeguard |
|---|---|---|---|---|
| Hetzner Online GmbH | Server hosting and database infrastructure | All personal and financial data stored in the application database | Germany (EU) | Processing within the EU/EEA; no third-country transfer |
| S3-compatible object storage |
Storage of uploaded invoice and receipt files
(Only if S3 media storage is enabled. It is currently disabled: uploaded files are stored on the server disk of our hosting provider in Germany.) |
Uploaded documents (invoices, receipts) and their file names | EU | Processing within the EU/EEA; no third-country transfer |
| Sentry (Functional Software, Inc.) | Error tracking and application performance monitoring | Technical error reports and stack traces, with financial data scrubbed before sending | USA | EU Standard Contractual Clauses (Module 2, controller to processor) |
| Plausible Analytics | Anonymous, cookie-free website analytics | Aggregated page-view statistics; no personal identifiers | EU | Processing within the EU/EEA; no third-country transfer |
| Resend | Transactional email delivery for account, security and billing notifications | Recipient email address and email content | USA | EU Standard Contractual Clauses (Module 2, controller to processor) |
| Google LLC (Gemini API) |
AI-powered financial insights and question answering
(Only when you explicitly consent to AI data processing (Growth/Advisor tier). Your data is not used to train AI models. Google stores it for a limited period to detect abuse.) |
Financial data included in the AI query context (income, expenses, assets, net worth) | USA | EU Standard Contractual Clauses (Module 2, controller to processor) |
| Anthropic PBC |
AI-powered financial insights and question answering
(Only when you explicitly consent to AI data processing (Growth/Advisor tier). Your data is not used to train AI models. Anthropic deletes it within 30 days.) |
Financial data included in the AI query context (income, expenses, assets, net worth) | USA | EU Standard Contractual Clauses (Module 2, controller to processor) |
| GitHub, Inc. |
Storage of in-app bug reports, submitted as GitHub Issues
(Only when you submit in-app feedback) |
Report title, description, browser info, username and optional screenshot | USA | EU Standard Contractual Clauses (Module 2, controller to processor) |
| finAPI GmbH |
Bank account connection and transaction data aggregation
(Only when you connect a bank account) |
Bank account identifiers and transaction history | Germany (EU) | Processing within the EU/EEA; no third-country transfer |
Independent controllers
The following recipients process your data under their own legal basis, not as our processor:
| Recipient | Purpose | Data categories | Location | Safeguard |
|---|---|---|---|---|
| Paddle.com Market Ltd |
Merchant of record: payment processing, invoicing, subscription billing and sales tax compliance
(Only when you take out a paid subscription) |
Email address, internal user ID, selected plan, payment and billing details, IP address | United Kingdom; USA via Paddle.com Inc. for buyers based in the USA | UK adequacy decision of 19 December 2025; additionally EU Standard Contractual Clauses (Module 1, controller to controller) as an additional safeguard |
Currency conversion (frankfurter.app) and market price data (Twelve Data, Yahoo Finance) are provided by third-party APIs that receive only currency codes or ticker symbols, with no data that identifies you. They are not processors of personal data.
5. Data Retention
We retain personal data only as long as necessary for the purposes outlined above. Specific retention periods:
- Account and financial data: retained while your account is active
- AI query logs: automatically deleted after 90 days (service improvement and debugging)
- Generated financial reports: automatically deleted after 365 days (you may export reports for longer retention)
- Bank transaction data: raw payloads deleted after classification; classified entries retained per your account lifecycle
- Error logs (Sentry): automatically deleted after 90 days
- Product usage events: automatically deleted after 12 months
- Analytics data (Plausible): aggregated, no personal data retained
- Database backups: retained for 30 days, then permanently deleted
- After account deletion: all personal data is permanently deleted promptly upon request
6. Your Rights
Under GDPR, you have the following rights:
- Right of access -- request a copy of your personal data
- Right to rectification -- correct inaccurate data via account settings
- Right to erasure -- delete your account and all data via account settings
- Right to data portability -- export your data in CSV format via the export feature
- Right to restriction -- request restriction of processing
- Right to object: object to processing based on legitimate interest (e.g. disable usage event tracking in Settings)
To exercise any of these rights, contact us at privacy@gwym.app. We will respond within 30 days as required by GDPR.
7. Supervisory Authority
You have the right to lodge a complaint with the Czech Data Protection Authority (UOOU -- Urad pro ochranu osobnich udaju) if you believe your data protection rights have been violated.
8. Cookies and Local Storage
GWYM uses the following browser storage:
| Name | Type | Purpose | Required |
|---|---|---|---|
| sessionid | Cookie | User authentication | Essential |
| csrftoken | Cookie | Cross-site request forgery protection | Essential |
| django_language | Cookie | Language preference | Essential |
| theme | Local storage | Light/dark theme preference | Functional |
| cookie_consent | Local storage | Cookie consent preference | Essential |
Plausible Analytics does not use cookies and does not collect personal data. No third-party tracking cookies are used.
9. Automated Decision-Making
GWYM provides AI-powered financial insights and health scores. These are informational only and do not produce legal effects or similarly significant effects on you. All automated analyses can be reviewed and overridden by you. No decisions are made solely on the basis of automated processing.
10. International Transfers
Your data is primarily hosted within the EU (Hetzner, Germany). The following processors are located in the USA: Google (Gemini API), Anthropic, Sentry, Resend, and GitHub. Transfers to these processors are protected by EU Standard Contractual Clauses (SCCs, Module 2, controller to processor) as required by GDPR. Google and Anthropic receive your financial data only when you have granted AI data-processing consent; under our agreements with both providers, your data is not used to train their AI models.
Paddle, our merchant of record for subscription payments, acts as an independent controller rather than our processor. Paddle.com Market Ltd is based in the United Kingdom; transfers to it are covered by the UK adequacy decision, with EU Standard Contractual Clauses (Module 1, controller to controller) as a contractual overlay. Buyers based in the USA contract with Paddle.com Inc. under the same Clauses.
11. Changes to This Policy
We may update this privacy policy to reflect changes in our practices or legal requirements. Material changes will be communicated via email or in-app notification. The "Last updated" date at the top of this page indicates the most recent revision.