Short version: We collect only what we need to run VaultTrack. Your financial data is yours — we never sell it, share it with advertisers, or use it to target you. You can export or delete everything at any time.
VaultTrack ("we", "us", "our") is a personal finance web application. We are the data controller for the personal data you provide when using the Service.
For privacy enquiries: [email protected]
| Data | Why we collect it |
|---|---|
| Name & email address | Account creation, authentication, and support communication |
| Password (hashed) | Account security. We never store plain-text passwords |
| Budget data (income, expenses, categories) | Core app functionality — to show you your financial picture |
| Trading journal entries | P&L tracking and heatmap analytics |
| Mortgage and calculator inputs | To return calculation results — not stored beyond your session unless you save them |
| Financial journal entries | AI-assisted journaling feature |
| Data | Why we collect it |
|---|---|
| IP address | Security, fraud prevention, and rate limiting |
| Browser type & version | Ensuring compatibility and diagnosing technical issues |
| Pages visited & timestamps | Understanding usage patterns to improve the product |
| Session cookies | Keeping you logged in. See our Cookie Policy |
If you sign in with Google, we receive your name, email address, and profile picture from that provider. We do not receive your password. You can review what Google shares in your Google account settings.
We use your data exclusively to:
We do not use your data for advertising, profiling, or sale to third parties.
If you are located in the European Economic Area (EEA) or United Kingdom, our legal bases for processing are:
Your data is stored on servers located within the European Union. We implement the following security measures:
No security system is impenetrable. In the event of a data breach that affects your rights and freedoms, we will notify you within 72 hours of becoming aware, in compliance with GDPR Article 33.
We retain your data for as long as your account is active. When you delete your account:
You can request deletion at any time by emailing [email protected] or by deleting your account in settings.
We share data with the following trusted service providers, only to the extent necessary to operate the Service:
| Provider | Purpose | Data shared |
|---|---|---|
| Google OAuth | Optional sign-in method | Name, email (if you choose Google login) |
| Groq | AI budget analysis | Your budget summary data (anonymised where possible) |
| Payment processor | Subscription billing | Payment card details (we never see or store full card numbers) |
| Cloud hosting provider | Server infrastructure | All app data, stored encrypted |
We do not sell, rent, or trade your personal data to any third party for marketing or commercial purposes.
VaultTrack uses Groq to generate budget analysis and spending insights. When you request an AI analysis:
You may opt out of AI analysis by simply not using that feature. No data is sent to Groq unless you explicitly trigger an analysis.
Under GDPR and similar regulations, you have the following rights:
Request a copy of all personal data we hold about you.
Correct inaccurate or incomplete personal data.
Request deletion of your personal data ("right to be forgotten").
Ask us to limit how we process your data in certain circumstances.
Receive your data in a structured, machine-readable format (CSV export available in-app).
Object to processing based on legitimate interests.
To exercise any of these rights, email [email protected]. We will respond within 30 days.
VaultTrack is not directed at children under 18 years of age. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will delete it.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and update the "Last updated" date at the top of this page. We encourage you to review this page periodically.
For privacy-related questions or to exercise your rights:
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. In Ireland, this is the Data Protection Commission (DPC).