Skip to content
vokse.

Last updated: 5 September 2026 · v3.3

Privacy Policy

2 min read
On this page
  1. What we collect
  2. Where we store it
  3. Who we share with
  4. What we never do
  5. Your rights (GDPR)
  6. Retention

What we collect

Account information you give us (email, name, password hash, optional avatar). Financial data you choose to import (accounts, transactions, balances, categories, notes). Device metadata required to run the service (IP address, user agent, time zone). AI conversation transcripts when you use the assistant. From the IP address we estimate a city, with a geolocation database that runs on our own servers, so the email about a new sign-in can tell you where it came from; the address is sent to nobody for this. That database includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.

Where we store it

In the European Union. Railway for production data (Postgres, Redis, object storage); encrypted off-site backups in Cloudflare R2, also in the EU. Encrypted at rest with AES-256 and in transit with TLS 1.3. Backups are encrypted with a separate key and retained for 35 days.

Who we share with

A short list of sub-processors with the same standards we hold ourselves to: Railway (hosting), Cloudflare (edge and backups), Stripe (billing), Plaid and Enable Banking (bank connections), Anthropic and OpenAI (AI models), Resend (transactional email), Sentry (error monitoring, scrubbed). All are EU-based or covered by Standard Contractual Clauses. The full, current list is at /sub-processors. We notify you in-app and by email at least 14 days before adding a new sub-processor.

What we never do

We never sell your data. We never use your transactions, balances or conversations to train public AI models. We never move money on your behalf. We never store your bank login credentials. Our open-banking provider handles authentication and we only receive read-only data.

Your rights (GDPR)

You have the right to access, rectify, export (DSAR), restrict, object and erase your data. A full machine-readable export is available any time from Settings → Privacy & data; you don't need to ask. Account deletion is permanent after a 30-day grace period. If you're unhappy, you can complain to your national supervisory authority.

Retention

Transactions and account history: for as long as your household exists. Audit log: 2 years, append-only. Soft-deleted households: 30-day grace, then irrecoverable purge. Support emails: 2 years. Anonymous analytics: 26 months.