This policy explains what data Vaulty (“we”, “us”, “our”) collects when you use the app, why, and how you can control it. Vaulty is a personal budgeting tool, so most of what we store is the financial data you choose to enter — we don’t sell it, and we don’t use it for advertising.
1. Information we collect
Account information: your email address, and — if you sign in with Apple or Google — the basic profile details those providers share (name, email). Passwords are never stored in plain text; authentication is handled by Supabase Auth.
Financial data you enter: transactions, budgets, subscriptions, direct debits, debts, linked accounts and balances, savings goals, categories, and any receipt images you attach. This is the core of what Vaulty does — track it for you.
Preferences: your display currency, language, and plan tier.
Diagnostic data: if error reporting is enabled, we receive crash and error reports (via Sentry) to help us fix bugs — these capture technical details about what went wrong, not your financial records.
2. How we use it
To operate the app: show you your own data, compute derived figures like budget spend and payoff estimates, enforce plan entitlements, and keep your account secure. We don’t use your financial data for advertising, and we don’t sell it to third parties.
3. Where and how it’s stored
Your data lives in a Postgres database (via Supabase), hosted in the EU (Ireland). Every table is scoped with row-level security to your account, so your data is only ever readable by you, server-side code acting on your behalf, or us if we’re helping you with a support request. Connections are encrypted in transit (TLS). You can add an authenticator-app second factor from Settings > Security for extra protection.
4. Who we share it with
We use a small number of infrastructure providers to run Vaulty: Supabase (database and authentication, EU-hosted), Stripe (payment processing for the Pro plan — Stripe handles your card details directly and we never see or store them), Sentry (error monitoring, which captures technical crash details but is not sent your financial records), and Apple/Google (only if you choose to sign in with them). We don’t share your data with anyone else, and never for marketing purposes.
5. Cookies
Vaulty uses a session cookie to keep you signed in. That’s it — no advertising or third-party tracking cookies. Our visit statistics are first-party and anonymous: an event name and a page path, with no cookies, no user identifiers, no IP addresses and no fingerprinting — they cannot be tied to you or your account.
6. Data retention and deletion
We keep your data for as long as your account is active. You can permanently delete your account and every piece of data associated with it at any time from Settings > Danger zone — this is immediate and irreversible on our end.
7. Your rights
Under UK GDPR you have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can exercise most of these yourself in the app — CSV export on Transactions, Subscriptions, Direct debits and Debts, and account deletion in Settings. For anything not covered by those exports yet, or any other request, email us at privacy@romsics.com and we’ll help. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk).
8. Children
Vaulty isn’t directed at children, and we don’t knowingly collect data from anyone under 18.
9. Changes to this policy
We may update this policy as Vaulty evolves. We’ll update the “last updated” date above when we do, and material changes will be communicated by email or in-app notice.
10. Contact
Questions about your data? Email us at privacy@romsics.com.