1. What Data We Collect
Account data (name, email, country, hashed password); financial data you enter manually, import from a file, or forward by email from your bank; direct bank-connection data when you use it; optional identity data if you enable credit score monitoring; usage data (pages visited, errors) and device data (IP, browser) for security and fraud prevention.
2. What We Do With Your Data — and What We Don't
We use it to provide the service: recording and categorizing your transactions with AI assistance, building budgets and projections, sending you service emails, and, once billing is active, processing your subscription. We never sell your data, never use it for targeted advertising on other platforms, never share it with employers or insurers, and it is never used to train third-party AI models: we use AI providers under terms that exclude training on your information.
3. Who We Share Data With
We share the minimum necessary with providers that help us operate: Supabase (database and authentication), Vercel (hosting), Resend (transactional email), Google Gemini and Anthropic Claude (categorization and receipt reading, no training), and our current payment provider once billing is active. None of them may use your data for their own purposes beyond providing us the contracted service.
4. Security
We encrypt the connection with TLS 1.2 or higher and data at rest with AES-256. We isolate your information by household at the database level (PostgreSQL Row Level Security): every query can only return rows belonging to your own user or household; shared catalog tables (default categories, supported banks) hold no personal data and don't need that policy. We offer two-factor authentication (TOTP) with single-use backup codes, and store bank-connection tokens encrypted separately. After a confirmed security incident, we notify affected people within 72 hours.
5. Your Rights
You have the right to access, correct, export, and delete your data, and to object to a specific use without it affecting the rest of the service. You can exercise these from Settings or by writing to [email protected]. If your country has a data-protection law with its own rules (such as response deadlines or a supervisory authority), the jurisdiction-specific notice is at walomoney.com/legal/privacy/global.
6. Data Retention
We keep your data while your account is active. If you don't log in for 24 months we email you a warning, and after 36 months of inactivity we delete the account. When an account is deleted — whether you request it or it's deleted for inactivity — personal data is removed immediately and encrypted backups are purged within 90 days, except for accounting records the law requires us to keep longer.
7. Cookies
We use only essential cookies to make the session work (authentication, language, CSRF protection). Any analytics we run, when active, anonymizes traffic and does not identify people or track you across unrelated sites.
8. Children's Privacy
Wälo is not directed at children under 18 and we do not knowingly collect data from minors. If you believe a minor created an account, write to [email protected] and we will delete it.
9. International Transfers
Your information is processed on Supabase and Vercel infrastructure, which may run servers outside your country. Where applicable, we use standard contractual clauses or other valid mechanisms to protect that data in transit.
10. AI connectors (Claude, ChatGPT and others)
If you connect Wälo to a third-party AI assistant — for example Anthropic’s Claude or OpenAI’s ChatGPT — through our MCP server, that assistant can read the household data you authorize on the permissions screen: financial summary, transactions, budget, debts, investments or goals. Access is read-only, you grant it explicitly, and you can revoke it at any time from Settings → Connect your AI. Changing your password also revokes it. For each connection, Wälo stores the app name, its return address, the permissions, when it was authorized and a log of every request (tool used, date, IP address and country). We do not store the content of your conversations with the AI or the request parameters in clear text, and credentials are stored only as a cryptographic hash. The data the assistant receives is subject to its provider’s terms and privacy policy. Wälo does not sell that data or get paid for sharing it.
11. Changes to This Policy and Contact
If we make a material change to this policy (new third parties, new data uses), we will email you at least 15 days ahead; minor changes take effect immediately and are reflected by updating this page's date. For any privacy question, write to [email protected]; we respond within 5 business days.