Privacy Policy

Effective date: [DATE] · Version 1.0

The short version

  • You give us your name, your email address and a password. That is all we ask for to open an account.
  • Everything else in Valunto is what you type in yourself. Valunto never connects to a bank, a card, a broker or any other account of yours, and never asks for their credentials.
  • We do not run analytics, advertising, tracking pixels or third-party SDKs. We do not sell data, and we do not use your data to train anything.
  • Your data lives on our own servers in [the European Union]. Two companies help us run the service: our hosting provider and our email provider. Nobody else receives your data unless the law forces us or you share it with your own household.
  • You can export or delete everything, at any time, from Settings. Deleting your account removes your data from our live systems immediately.

The rest of this page is the long version, written to be read.

1. Who we are

[LEGAL NAME OF THE CONTROLLER][Tax ID / NIF / CNPJ][Postal address][Registry details, if a company]Email: [CONTACT EMAIL]

We are the "controller" of your personal data under the EU General Data Protection Regulation (GDPR) and the Brazilian Lei Geral de Proteção de Dados (LGPD). This means we decide why and how the data described here is used, and we are responsible for it. For questions about this policy or your data, write to [CONTACT EMAIL].

2. What data we hold, and where it comes from

2.1 What you give us

Your account. Your name, your email address and your password. We store the password only as a one-way hash, which means we cannot read it and cannot recover it. We also record when your email address was verified and when your password was last changed, so the security page can show you facts rather than guesses.

Your financial records. Everything you enter to use Valunto: assets and debts, transactions and categories, budgets, goals, big-purchase plans, the currencies you track, and your preferences (language, date format, primary currency, notification settings). This is financial information, and it is the reason the service exists. It is entered by you, by hand, and only you and the household members you choose can see it. Valunto has no bank connections, so nothing arrives that you did not type.

Your household. If you invite someone to your household, we store the email address you enter and send them an invitation. Once they join, we store their role (owner, member or viewer) and share the household's data with them according to that role. By inviting someone you confirm that you may share their email address with us.

Support requests. If you contact support from inside the app, we store what you write, the category you choose, and the diagnostics you agree to send. Diagnostics may include: the page you were on, the size of your window, your browser or device model, your language and time zone, the app version, the last few pages you visited, the last few requests the app made to our server (with their identifiers, never their contents), and any error messages. You can also attach a screenshot; every money amount on it is masked before capture, and you see exactly what will be sent before you send it. Each request also creates an email notification to us so that we notice it.

2.2 What our systems record on their own

Access logs. Each request to our server writes one log line with the request time, the path requested, the response status, the duration, an anonymous request identifier, and the IP address it came from. We use this to keep the service running and to investigate abuse. Logs are kept for [LOG RETENTION, e.g. 30 days] and then deleted.

Rate limiting. To slow down password guessing and other abuse, our server counts requests per IP address in memory. Nothing is written to disk and the count disappears within minutes.

Sessions. When you sign in, we store the browser or app identifier ("user agent") of that sign-in, so you can see and revoke your active sessions. Sessions expire after 7 days at the latest.

2.3 What we do not collect

No analytics, no advertising identifiers, no location, no contacts, no device fingerprinting, no third-party scripts, no session recording. We do not read your data to build a profile of you, and we make no automated decisions about you.

3. Why we use your data, and on what legal basis

What we doData involvedLegal basis (GDPR / LGPD)
Provide the service you signed up for: your account, your records, your household, exportsAccount, financial records, householdPerformance of a contract — GDPR art. 6(1)(b); LGPD art. 7, V
Send the emails the service needs: email verification, password reset, email change, household invitations, [notifications you turn on]Email address, namePerformance of a contract — GDPR art. 6(1)(b); LGPD art. 7, V
Keep the service secure: access logs, rate limiting, session list, abuse investigationIP address, user agent, timestampsOur legitimate interest in running a secure service — GDPR art. 6(1)(f); LGPD art. 7, IX
Answer your support requestsWhat you send usPerformance of a contract — GDPR art. 6(1)(b); LGPD art. 7, V
Keep billing records once you pay for a subscriptionBilling details [to be defined with the payment provider]Legal obligation — GDPR art. 6(1)(c); LGPD art. 7, II
Comply with a legal orderWhatever the order namesLegal obligation — GDPR art. 6(1)(c); LGPD art. 7, II

We do not send marketing emails. If that ever changes, we will ask for your consent first and you will be able to withdraw it at any time.

4. Cookies and device storage

Valunto uses only the cookies it needs to work. There is no cookie banner because there is nothing to choose: none of these cookies track you, and none is set by a third party.

NamePurposeLifetime
fi_sessionKeeps you signed in on the websiteUntil you sign out or the session expires (7 days at most)
fi_refreshRenews your session without asking for your password againSame as above
fi_userLets the website show your name and settings without a round trip to the serverSame as above
NEXT_LOCALERemembers your language[1 year]

The mobile app stores your session in the device's secure storage and your language and display preferences in the app's private storage. Nothing is stored anywhere else on your device.

5. Who we share your data with

We share your data with nobody, except:

Your household. Members and viewers of your household see the household's shared data according to their role. You control who is in your household.

Companies that work for us (processors). They act only on our instructions, under a contract, and only to provide the service:

ProviderWhat they doWhere
Hetzner Online GmbHHosts our servers and database[Germany / Finland — confirm the server location]
Resend, Inc.Delivers the emails the service sends[EU region or United States — confirm]

Public data sources we call. Exchange rates come from Frankfurter (European Central Bank reference rates) and, for digital assets, CoinGecko. Our server fetches these rates on its own schedule; the requests carry nothing about you.

When the law requires it. We will disclose data if a court or authority with jurisdiction over us orders it. We will tell you when we are allowed to.

We never sell personal data and never share it for advertising.

6. Where your data is stored and transfers outside the EU

Your data is stored on servers in [the European Union]. If a provider processes data outside the EU or Brazil, we rely on the safeguards the law provides: for the United States, the EU–US Data Privacy Framework where the provider is certified, and otherwise the European Commission's standard contractual clauses (GDPR art. 46). For users in Brazil, transfers follow LGPD art. 33. [Confirm the Resend region and edit this paragraph to match.]

7. How long we keep your data

DataKept for
Your account and everything in itAs long as your account exists
Accounts that never verified their email and have no active sessionDeleted automatically after 7 days
Sign-in sessionsDeleted when you sign out, when you revoke them, or after 7 days
Verification, password-reset and invitation linksUntil used or expired (a few days), then deleted
Access logs[LOG RETENTION]
Support requests and screenshotsUntil you delete your account [or N months after the request is closed, whichever comes first]
Billing records[As long as tax law requires — typically 4 years in Spain, 5 years in Brazil; confirm]
BackupsDeleted data may survive in encrypted backups for up to [BACKUP RETENTION] before those backups are rotated

When you delete your account, everything you own is removed from our live systems immediately, including support screenshots. Data you shared with a household is reassigned or removed according to the household rules explained in the app at deletion time.

8. How we protect your data

  • All traffic between you and Valunto is encrypted (TLS).
  • Passwords, session tokens and email links are stored only as one-way hashes.
  • The database is not reachable from the internet, only from our application.
  • Money amounts are masked in support screenshots and never included in diagnostics.
  • Sessions expire, and you can see and revoke them from the security page.

No system is perfectly secure. If we ever learn of a breach that affects you, we will tell you and the relevant authority as the law requires.

9. Your rights

You have the right to access, correct, export, delete and object to the use of your data, and to ask us to restrict its use. Most of these you can do yourself, right now, from the app:

RightHow
See the data we hold about youSettings → Privacy & data, or ask us
Correct your name or emailProfile → edit; other data you edit directly
Export your dataSettings → Privacy & data → Export (CSV for transactions, JSON for everything)
Delete your account and all its dataSettings → Danger zone → Delete account. On the mobile app: Settings → Delete account
Object to processing based on our legitimate interestsSettings → Privacy & data, or ask us; we record the objection
Restrict processing, or anything elseWrite to [CONTACT EMAIL]

If you uninstalled the mobile app, you can still delete your account by signing in at [https://valunto.com] and using Settings → Danger zone, or by emailing [CONTACT EMAIL] from the address on the account. We answer within one month (GDPR art. 12(3)) and within fifteen days for LGPD access requests (LGPD art. 19).

You also have the right to complain to a data protection authority. In Spain that is the Agencia Española de Protección de Datos (aepd.es); in Brazil, the Autoridade Nacional de Proteção de Dados (gov.br/anpd); elsewhere in the EU, the authority of the country you live in. We would prefer you write to us first so we can fix the problem.

10. Children

Valunto is not intended for anyone under [18]. We do not knowingly collect data from children. If you believe a child has opened an account, write to [CONTACT EMAIL] and we will delete it.

11. Changes to this policy

When we change this policy we will update the date at the top. If a change affects how we use your data, we will tell you by email or inside the app before it takes effect. Past versions are available on request.

12. Contact

[LEGAL NAME][Postal address][CONTACT EMAIL]