Privacy Policy

Walletify — a private, non-commercial application. Last updated 15 August 2026.

1. Who runs this application

Alwin Paul operates this application as a private person. It is not a business, and it is not offered to the public. Contact: alwin.paulpv@gmail.com.

2. What the application does

The application reads the operator's own bank accounts and shows the operator a summary of income and expenses. It has exactly one user, who is also the operator.

3. What data it processes

The bank data feed also provides the account balance. The application stores each balance it receives, together with the moment it was reported, and shows the most recent one beside the account. Every record comes from the operator's own bank statements and the operator's own mailbox. No other person uses the application.

The operator can unlock the application with the fingerprint or face already on the phone. Matching stays on the phone. No fingerprint or face image is sent to the server.

4. Why it processes this data

The single purpose is a personal overview of the operator's own income and expenses. The data is not used for profiling, for advertising, for training a model, or for any other purpose.

5. Legal basis

Article 6(1)(a) GDPR: consent. The operator gives explicit consent to each bank during the authorisation step. The operator can withdraw that consent at any time, in the bank's own interface or by deleting the connection in the application.

6. Who receives the data

Nobody else receives the data. The phone application talks only to the operator's own server. The application uses no analytics service, no advertising network, and no error reporting service. No artificial intelligence service is called at all only when TWO things are unset on the server: the API key and the Claude tool. The Claude path needs no API key — it uses the operator's own subscription — so removing keys alone does not disable it.

7. Where the data is stored

On a private server operated by the operator, located in Germany. The database is not reachable from the public internet. Transport uses HTTPS only.

8. How long the data is kept

Until the operator deletes it. There is no automatic deletion, because the purpose is a long-term personal record. Deleting the database removes all of it.

9. Rights

The only data subject is the operator, who holds full and direct control over the database. The rights under Articles 15 to 21 GDPR — access, correction, deletion, restriction, portability, and objection — are exercised directly on that database.

10. Changes

This page changes when the application changes. The date at the top always shows the current version.