Legal

Privacy Policy

Last updated: 6 May 2026  ·  Effective: 6 May 2026

Contents
  1. Who We Are
  2. What Data We Collect
  3. How We Use Your Data
  4. Legal Basis for Processing
  5. Data Storage & Security
  6. Data Retention
  7. Third Parties
  8. AI Processing
  9. Your Rights
  10. Children's Privacy
  11. Changes to This Policy
  12. Contact & Complaints

Short version: We collect only what we need to run VaultTrack. Your financial data is yours — we never sell it, share it with advertisers, or use it to target you. You can export or delete everything at any time.

1. Who We Are

VaultTrack ("we", "us", "our") is a personal finance web application. We are the data controller for the personal data you provide when using the Service.

For privacy enquiries: [email protected]

2. What Data We Collect

2.1 Data you provide directly

DataWhy we collect it
Name & email addressAccount creation, authentication, and support communication
Password (hashed)Account security. We never store plain-text passwords
Budget data (income, expenses, categories)Core app functionality — to show you your financial picture
Trading journal entriesP&L tracking and heatmap analytics
Mortgage and calculator inputsTo return calculation results — not stored beyond your session unless you save them
Financial journal entriesAI-assisted journaling feature

2.2 Data collected automatically

DataWhy we collect it
IP addressSecurity, fraud prevention, and rate limiting
Browser type & versionEnsuring compatibility and diagnosing technical issues
Pages visited & timestampsUnderstanding usage patterns to improve the product
Session cookiesKeeping you logged in. See our Cookie Policy

2.3 OAuth login data

If you sign in with Google, we receive your name, email address, and profile picture from that provider. We do not receive your password. You can review what Google shares in your Google account settings.

3. How We Use Your Data

We use your data exclusively to:

We do not use your data for advertising, profiling, or sale to third parties.

If you are located in the European Economic Area (EEA) or United Kingdom, our legal bases for processing are:

5. Data Storage & Security

Your data is stored on servers located within the European Union. We implement the following security measures:

No security system is impenetrable. In the event of a data breach that affects your rights and freedoms, we will notify you within 72 hours of becoming aware, in compliance with GDPR Article 33.

6. Data Retention

We retain your data for as long as your account is active. When you delete your account:

You can request deletion at any time by emailing [email protected] or by deleting your account in settings.

7. Third Parties

We share data with the following trusted service providers, only to the extent necessary to operate the Service:

ProviderPurposeData shared
Google OAuthOptional sign-in methodName, email (if you choose Google login)
GroqAI budget analysisYour budget summary data (anonymised where possible)
Payment processorSubscription billingPayment card details (we never see or store full card numbers)
Cloud hosting providerServer infrastructureAll app data, stored encrypted

We do not sell, rent, or trade your personal data to any third party for marketing or commercial purposes.

8. AI Processing

VaultTrack uses Groq to generate budget analysis and spending insights. When you request an AI analysis:

You may opt out of AI analysis by simply not using that feature. No data is sent to Groq unless you explicitly trigger an analysis.

9. Your Rights

Under GDPR and similar regulations, you have the following rights:

Right of Access

Request a copy of all personal data we hold about you.

Right to Rectification

Correct inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your personal data ("right to be forgotten").

Right to Restriction

Ask us to limit how we process your data in certain circumstances.

Right to Portability

Receive your data in a structured, machine-readable format (CSV export available in-app).

Right to Object

Object to processing based on legitimate interests.

To exercise any of these rights, email [email protected]. We will respond within 30 days.

10. Children's Privacy

VaultTrack is not directed at children under 18 years of age. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and update the "Last updated" date at the top of this page. We encourage you to review this page periodically.

12. Contact & Complaints

For privacy-related questions or to exercise your rights:

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. In Ireland, this is the Data Protection Commission (DPC).