Privacy Policy
Last updated: 11 July 2026
1. Controller
The controller responsible for processing your personal data on GroWealth is [OPERATOR LEGAL NAME], [REGISTERED ADDRESS]. For anything related to your data, contact [email protected].
2. The short version
- Your financial data exists in GroWealth because you put it there — we never connect to your bank.
- We show you no ads, run no analytics or tracking, and never sell data.
- Your data is hosted in the EU (Germany); files and sensitive fields are encrypted at rest.
- AI features send only what they need to our AI providers, who are contractually barred from training on it.
- You can export everything and delete your account — immediately, yourself, in Settings.
3. What data we process
a. Account and sign-in
Email address, first and last name, country, date of birth, password hash, optional passkeys and 2FA secrets (encrypted), language and theme preferences, session tokens, and — during early access — your answers in the registration questionnaire. Purpose: creating and securing your account. Legal basis: contract performance (Art. 6(1)(b) GDPR); security measures also rest on our legitimate interest (Art. 6(1)(f)).
b. Financial data you import
Bank and broker statements you upload (stored encrypted), the transactions extracted from them, manually recorded accounts and transactions, balances, holdings, budgets, goals, and receipt photos (stored encrypted, location metadata stripped on upload). Transaction descriptions can contain names of third parties — your landlord, employer or friends. This data stays inside your private ledger; we process it on the basis of contract performance (Art. 6(1)(b)) and, for third-party names inside your records, our and your legitimate interest in a complete ledger (Art. 6(1)(f)) — the same balance your bank relies on. Full counterparty IBANs are stored only in encrypted form and redacted elsewhere.
c. AI assistant and AI features
When you use Grovi, receipt scanning or other AI features, the relevant context — your question, the transactions or holdings it concerns, the receipt image, statement excerpts during import — is sent to our AI provider (section 6) to generate the answer. Merchant-recognition requests contain merchant names, never amounts. When you use read-aloud, the answer text is sent to our speech provider. Legal basis: contract performance — these are product features you actively invoke (Art. 6(1)(b)).
d. Community
Your handle, display name, bio, avatar and cover image, and the content you publish (posts, polls, questions, comments, reactions, follows). Financial figures appear in the community only through explicit sharing actions that preview exactly what becomes visible. Moderation (including automated triage of reported content) rests on our legitimate interest in a safe community (Art. 6(1)(f)).
e. Notifications and push
In-app notifications, your notification preferences and — if you enable push notifications in the installed app — a push subscription (endpoint URL and delivery keys issued by your browser). Push can be disabled at any time in your browser or system settings. Legal basis: contract performance and your consent expressed through the browser permission (Art. 6(1)(a), (b)).
f. Feedback and support
Feedback reports, comments and attachments you submit, and email correspondence with us. Legal basis: contract performance and our legitimate interest in improving the Service (Art. 6(1)(b), (f)).
g. Technical and security data
Server and container logs (size-capped, minimized), IP-based rate-limit counters, an AI usage ledger (token counts and costs per account — no content), and error reports (stack traces without user identifiers or request bodies). Legal basis: our legitimate interest in operating the Service securely (Art. 6(1)(f)) and our security obligations under Art. 32 GDPR.
4. Cookies and local storage
GroWealth sets only strictly necessary cookies. There are no analytics cookies, no tracking pixels, no advertising identifiers and no third-party embeds anywhere on the site or in the app.
| Name / kind | Purpose | Lifetime | Category |
|---|---|---|---|
| Session cookies (better-auth) | Keeping you signed in securely | 60 days, refreshed while you use the app | Strictly necessary |
| cookie-consent (local storage) | Remembering your choice in the cookie banner | Until cleared | Strictly necessary |
| Preferences (local storage) | Theme, language, selected account scope, prompt snoozes | Until cleared | Functional (first-party, no tracking) |
Because strictly necessary cookies are exempt from consent (Art. 5(3) ePrivacy Directive), the cookie banner is informational today. Should we ever introduce optional cookies, they will remain off unless you allow them there.
5. Where your data lives and who processes it
GroWealth runs on servers in Germany. We use a small number of service providers as processors under Art. 28 GDPR data-processing agreements:
| Provider | Role | Location | What they see | Transfer mechanism |
|---|---|---|---|---|
| Hetzner Online GmbH | Hosting | Germany (EU) | Everything at rest (encrypted volumes; sensitive fields additionally encrypted) | None needed (EEA) |
| Cloudflare, Inc. | Network transit, DDoS protection | USA (global edge) | Traffic in transit (TLS), client IPs | EU-US Data Privacy Framework + SCCs |
| Anthropic, PBC | AI features (assistant, receipt scanning, categorization, translations) | USA | The context of each AI request (section 3c) | SCCs; no training on API data |
| OpenAI, L.L.C. | Read-aloud speech synthesis | USA | The answer text being read aloud | SCCs; no training on API data |
| Resend, Inc. | Transactional email | USA | Your email address, name and message content | SCCs |
| Functional Software, Inc. (Sentry) | Error monitoring | EU ingest region (DE) | Stack traces — configured without user identifiers or request bodies | EU data residency; DPF + SCCs |
Market data (stock quotes, indices) is fetched from public sources using ticker symbols only — none of your personal data is sent there. We disclose personal data beyond this table only where the law obliges us to (for example a court order), or with your consent.
6. International transfers
Where a provider processes data outside the EEA (see the table above), we rely on the EU Commission’s adequacy decision for the EU-US Data Privacy Framework where the provider is certified, and otherwise on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), supplemented by technical measures — encryption in transit everywhere and data minimization at every AI boundary. You can request a copy of the safeguards via [email protected].
7. How long we keep data
| Data | While your account exists | After you delete your account |
|---|---|---|
| Account, financial data, receipts, statements, assistant threads | Kept for you | Deleted immediately |
| Community content | Kept until you delete it | Deleted with the account |
| AI usage ledger (counts and costs, no content) | Up to 24 months | Retained de-identified |
| Error reports (no user identifiers) | 90 days at the provider | |
| Server logs | Days (size-capped rotation) | |
Backups: encrypted infrastructure snapshots are kept on a short rolling schedule, so deleted data can persist in backups for up to about seven days before it ages out. Backups are used only for disaster recovery; if we ever restore one, re-deleted accounts are removed again.
8. How we protect your data
- Files and sensitive database fields are encrypted at rest (AES-256-GCM envelope encryption with key rotation).
- All traffic is encrypted in transit; the application servers accept no direct inbound connections.
- Uploaded images are stripped of location metadata; IBANs are redacted outside encrypted fields.
- Access is protected by verified email sign-in, optional passkeys and two-factor authentication; sessions are revoked on password reset.
- Containers run read-only with minimal privileges; every route is covered by an access-control test suite.
9. Your rights
Under the GDPR you have the right to:
- Access and portability (Arts. 15, 20) — Settings offers a one-click full export of your data in a machine-readable format.
- Rectification (Art. 16) — everything you enter can be edited in the app.
- Erasure (Art. 17) — deleting your account in Settings removes your data immediately (section 7 covers the backup tail).
- Restriction and objection (Arts. 18, 21) — in particular against processing based on legitimate interests, on grounds relating to your particular situation.
- Withdrawal of consent (Art. 7(3)) — where processing rests on consent (for example push notifications), you can withdraw it at any time without affecting past processing.
- Complaint (Art. 77) — with a supervisory authority, in particular in the member state of your residence. The authority responsible for us is [SUPERVISORY AUTHORITY].
10. AI transparency and automated decisions
Grovi and the other AI features are clearly labelled as AI. AI output is informational; any change to your data proposed by the assistant requires your explicit confirmation. GroWealth makes no decisions based solely on automated processing that produce legal effects concerning you (Art. 22 GDPR). Our AI providers process your requests to answer them and are contractually barred from using them to train their models.
11. Children
The Service is intended for adults. You must be 18 or older to create an account.
12. Changes to this policy
We update this policy when the Service or our providers change. The current version is always available at this address; material changes are announced in the app. The date at the top tells you when it last changed.
13. Contact
Questions, requests, or anything that worries you: [email protected].