Privacy Policy
Last updated: 4 October 2026
This policy explains what personal data we process when you use Waleteer, why, who we share it with, how long we keep it and what rights you have, under the General Data Protection Regulation (GDPR).
1. Data controller
The controller of your data is Nuno Miguel Pontes Leite Helfrich, a sole trader, with Portuguese tax identification number 213516993 and address at Rua Arco do Carvalhão, 19B, 2.º, 1070-008 Lisboa, Portugal. You can contact us about privacy at [email protected].
We have not appointed a data protection officer, as the law does not require one for our activity; the contact above covers every privacy question.
2. What data we process
Account data: name, email, password (stored only as an irreversible hash), profile photo if you upload one, language, currency, time zone, the tax country and settings you choose, preferences, the time of your last sign-in and, if you turn it on, your two-factor authentication setup. We also keep the date and version of the Terms you accepted.
Sign in with Apple or Google: if you use it, the identifier that provider gives you and the email address it gives us and, for Apple, a code that lets us disconnect Waleteer from your Apple account when you delete your account.
Financial data you enter: wallets, balances, transactions with their descriptions and notes, categories, tags, payees, budgets, goals, rules, automatic payments, the statements you import and the people you share expenses with or owe money to (the names you type and the amounts).
Notifications: the alerts the service raises for you (budgets, upcoming payments, goals, price rises) are kept in your account.
Files: receipts and other attachments you upload, and the files of imported statements. In the app, we only access the camera and photos when you choose to take or pick a photo for a receipt or for your profile.
Suggestions and complaints: the messages you send us from the portal or the app, our replies and, so we understand the context, where it came from (portal or app), the app version and the language.
Households: the members of your households, their access and the email addresses of the people you invite.
Subscription: plan status, store or purchase channel, trial, start, renewal and end dates, subscription identifiers, when you asked for Pro to start straight away and any withdrawals you make. We do not receive your card details, which are handled by Stripe or the store.
Waiting list: if you leave your email on the home page while registration is not open, we keep that email and the language of the page, and nothing else.
Technical data: IP address, device and browser type, sessions and signed-in devices, request and error logs needed to keep the service secure and running, and a log of security actions on your account (sign-ins, failed attempts with the IP address they came from, email, password and two-factor changes, recovery codes used, devices, data downloads), visible in Settings.
Phone notifications: if you allow them, the notification address (token) of each signed-in device and its operating system.
Error reports: when the app or the server fails, a technical report is sent with the error, the app version, the device model and operating system, and the steps that led to the error. We do not include your IP address, your email or your financial data in these reports.
Back-office log: when we take an administrative action on your account (for example, resending a confirmation email, suspending or deleting the account), we record the action, the date and who took it.
3. Where the data comes from
Almost all data is provided by you. Technical data is generated when you use the service, and the subscription status reaches us from RevenueCat, Stripe and the stores.
If you sign in with Apple or Google, that provider gives us your account identifier, your email address (which may be an Apple relay address if you choose to hide yours) and whether that address is verified.
If someone invites you to a household, we receive your email address from that person and use it only to send the invitation and link it to your account if you accept.
The data you record about other people (the names of people who share expenses with you, payees, attachments and statements) is chosen by you; we process it only to provide the service to you and never use it to contact those people.
Registration data (name, email and password) and acceptance of the Terms are needed to create the account; without them we cannot provide the service. All other data is optional and depends on the features you use.
4. What we use the data for and on what basis
To provide the service, create and manage your account, run the calculations and sync your data between devices (performance of the contract).
To manage the Pro subscription, the trial and refunds (performance of the contract) and to meet legal obligations (legal obligation).
To protect the service, prevent abuse and fraud, detect and fix errors, measure performance and keep a log of administrative actions taken on accounts (legitimate interest).
To answer the suggestions and complaints you send us, including by email or phone notification when we reply (performance of the contract and legitimate interest in improving the service).
To send you news and notices about Waleteer, by email, phone notification and notice in the service (legitimate interest in keeping the people who use the service informed about it). You can opt out at any time: emails are turned off in Settings or with one click in each one, and notifications in your phone’s settings. We do not send third-party advertising.
To send you service emails, such as account confirmation, password recovery, invitations, notices about changes to the Terms and, if you turn them on, alerts and the monthly summary (performance of the contract and, for alerts and the summary, your choice in preferences, which each summary lets you undo in one click).
To send you a single email saying registration has opened, if you left your email on the waiting list (your consent, which you can withdraw at any time by writing to [email protected]).
To send household invitations to the people the account holder names (the account holder’s legitimate interest in sharing their wallets).
The service automatically analyses your history to suggest recurring payments, spot price rises and make forecasts, and applies the categorisation rules you set up. These analyses only show you suggestions and alerts: we do not make solely automated decisions that produce legal effects on you or similarly significantly affect you.
We do not use your financial data, not even anonymised or aggregated, for any other purpose, to build commercial profiles or to train artificial intelligence models.
5. Who we share the data with
Processors, which handle data only on our behalf and on our instructions, under contracts requiring them to protect it: Laravel Cloud (hosting of the application, the database and real-time updates, in the London region, United Kingdom), Cloudflare R2, through Laravel Cloud (file storage), Resend (sending email; the alerts and monthly summary you turn on include amounts, categories and payees), RevenueCat (subscription management, in the app and on the website checkout page), Sentry (error reports from the app and the server) and Expo (sending notifications to your phone, delivered through Apple’s and Google’s notification services, and distributing app updates).
Independent controllers, which process data for their own purposes and under their own privacy policies: Stripe, which sells the subscription on the website as merchant of record and handles payment, invoicing and VAT; and Apple and Google, for purchases made in their stores and when you use them to sign in.
The people in your households see the data of the wallets you share with them.
We only access your financial data when you ask us for help and allow it, when it is needed to investigate a security problem, or when the law requires it.
We may also disclose data to authorities where the law requires. We do not sell your data or use it for advertising.
6. Transfers outside the European Union
Some providers process data outside the European Union. Hosting is in the United Kingdom, which benefits from a European Commission adequacy decision.
Cloudflare, Resend, RevenueCat, Sentry and Expo may process data in the United States. In those cases, the transfer relies on the EU-US Data Privacy Framework, where the provider is certified, or on the standard contractual clauses approved by the European Commission that are part of each provider’s data processing agreement. You can ask us for a copy of the safeguards that apply.
7. How long we keep the data
Account data, financial data, attachments and imported statements: for as long as the account exists, or until you delete them. Transactions, wallets and transfers you delete are kept as deleted so you can restore them, until you delete the account. When you delete the account, the data and files are erased immediately.
Suggestions and complaints: for as long as the account exists; they are deleted with it.
Sign in with Apple or Google: for as long as the link exists; when you delete your account, we disconnect Waleteer from your Apple account and delete the link.
Notification addresses: for as long as the device is signed in; they are deleted when you sign out on that device or it is signed out for inactivity.
Household invitations: expire after 14 days and are deleted when the household or the owner’s account no longer exists.
Waiting list: until we send the notice that registration has opened, or until you ask to leave it; after that, the email is deleted.
Security action log: 12 months. Back-office log: 24 months. Sessions: on the website, the session ends after 2 hours without use, or up to 90 days if you choose to stay signed in; in the apps, a device is signed out after 90 days without use and is then deleted.
Technical logs and error reports kept by the hosting and monitoring providers, and database backups: up to 30 days, after which they are overwritten or deleted. A deleted account’s data disappears from the backups within that period.
Billing and payment data: kept by Stripe or the store, as independent controllers, for as long as the law requires them to.
Subscription records (identifiers, store, product, dates, notices received from RevenueCat and withdrawals): when you delete the account they are no longer linked to it, but we keep them for up to 10 years to handle complaints and refunds and to meet legal obligations.
8. Your rights
You have the right to access your data, correct it, erase it, restrict or object to its processing, receive it in a commonly used format and withdraw any consent you have given, without affecting processing carried out before.
You can download all your data and delete your account at any time in Settings, under Your data. While the Pro subscription renews automatically, the account can only be deleted once you have cancelled the renewal; until then, you can ask us by email to restrict processing.
To exercise your other rights, write to [email protected] from your account’s email address. We reply within one month, extendable by two further months for complex requests, in which case we will let you know.
If you believe your data is not being processed lawfully, you can lodge a complaint with the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (www.cnpd.pt), or with the supervisory authority of the European Union country where you live or work.
9. Security
Connections to Waleteer are encrypted, passwords are stored as irreversible hashes, two-factor secrets are encrypted, files are kept in private storage, idle device sessions expire and access to data is restricted. No system is completely secure, but we review these measures regularly.
If a data breach is likely to put you at high risk, we will tell you without undue delay, as well as notifying the CNPD as the law requires.
10. Cookies and storage on your device
We only use cookies needed for the service to work: the session cookie, the one protecting against forged requests and, if you choose it, the one that keeps you signed in, which lasts up to 90 days. Your chosen language is kept in your account or the session, with no cookie of its own.
The light or dark theme and whether the sidebar groups are open or closed are kept in your browser’s local storage. We use no advertising cookies and no third-party analytics in the browser. Stripe’s checkout page uses its own cookies, described in Stripe’s policy.
The app keeps a copy of your data on your phone, so it works offline and opens faster, and keeps your session in the system’s secure storage. This copy is deleted when you sign out or uninstall the app.
If you turn on the app lock with Face ID, fingerprint or your phone’s passcode, the check is done by your device’s operating system: we neither receive nor store biometric data.
The home screen widget shows balances and the next payment from that local copy. With the app lock on, it shows no amounts.
11. Minors
Waleteer is not intended for anyone under 18 and we do not knowingly collect data from people under that age. If we learn that an account belongs to a minor, we delete it.
12. Changes to this policy
We may update this policy. The date of the version in force is at the top of this page. If the changes are material, we will tell you by email or in the service before they take effect.
13. Contact
For any question about privacy or to exercise your rights, write to [email protected].
See also: Terms and Conditions