Section 1: Introduction
Welcome to Wealtie. We believe you have a right to know exactly what data we collect, why we collect it, and who we share it with. This Privacy Policy is written to be honest and complete — we are not hiding anything.
Wealtie is a personal finance management mobile application that lets you manually track your income, expenses, accounts, budgets, and financial goals. We do not connect to your real bank accounts, we do not initiate real financial transactions, and we do not provide financial advice.
By using our Service, you consent to the data practices described in this Privacy Policy. If you do not agree, please do not use the Service. If you have questions, email us at [email protected].
Section 2: Information We Collect
We collect the following categories of information. We have tried to be specific — this is not a vague list.
Section 2.1: Account & Profile Information
When you create an account, we collect and store the following personal information:
- First and last name
- Email address — verified via a code sent to your inbox
- Password — stored as a cryptographic hash; we never store your plaintext password
- 4-digit PIN code — stored on our servers; used for in-app security confirmation
- Date of birth — stored as a date; used to verify you meet the minimum age requirement
- Country — 2-letter country code
- Gender — optional, user-provided
- Language preference — defaulted from device settings; changeable in-app
- Display currency — your preferred currency for displaying balances
- Timezone — used for notification scheduling and analytics reporting
- Profile photo URL — optional; sourced from your OAuth provider or not set
- Authentication method — whether you registered via email/password, Google, or Apple
Section 2.2: Onboarding Survey Data
During onboarding, we ask several questions to personalize your experience. Your answers are stored and associated with your account:
- Financial goals you selected — e.g., "save for a house", "build an emergency fund", "pay off debt"
- How you found Wealtie — e.g., "social media", "app store search", "friend recommendation"
- Recently installed apps on your device — a list of apps detected on your phone at the time of onboarding, used for personalization
The list of recently installed apps is collected once during onboarding only and is not updated after that.
Section 2.3: Financial Data You Enter
All financial data in Wealtie is entered manually by you. We store everything you input:
- Transactions — amount, currency, category, account, date, and optional description for every income and expense you log
- Accounts — account name, currency, balance, and icon (e.g., "Savings Wallet", "Cash")
- Categories — custom category names and icons you create
- Budgets — budget name, period (monthly, quarterly, etc.), total amount, per-category allocations, and the spending health status we calculate from your data
- Goals — goal name, target amount, period, current progress, and per-category progress
- Recurring transactions — amount, currency, frequency, start/end dates, and description for each scheduled transaction
- Transfers between accounts — amounts, currencies, and the exchange rate applied at transfer time
Section 2.4: OAuth Login Data (Google, Apple)
If you sign in using Google or Apple, we receive and store the following from that provider:
- Your unique user ID at that provider
- Your email address
- Your first and last name
- Your profile picture URL (if provided by the provider)
- The OAuth access token and refresh token issued by the provider
The OAuth tokens are stored in our database associated with your account. They are used to support your authentication session.
Section 2.5: Technical & Device Data
We automatically collect certain technical information:
- Push notification token — your Expo device token, stored on our servers for delivering notifications to you
- Timezone — sent with requests to our servers for notification scheduling and analytics reporting
- Last login timestamp — recorded each time you log in
- App version and device info — sent to our crash reporting service (Sentry) for debugging
- Advertising identifier (IDFA on iOS, Ad ID on Android) — we request access to the advertising identifier on your device. On iOS, you are prompted by the system before this is shared. This is used for personalized advertising and analytics purposes.
Section 2.6: Behavioral Analytics (PostHog)
We use PostHog to understand how users interact with the app. The following categories of events are tracked and sent to PostHog along with your user ID, email, and name:
- Onboarding funnel progression (steps completed, abandoned, or finished)
- Authentication method chosen and success or failure
- Feature usage (creating transactions, budgets, goals, recurring transactions)
- In-app navigation and filter interactions
- Attempts to access features that require a premium plan
- Language selection and changes
- App performance metrics (screen load times, response times)
- Errors encountered during sign-up, onboarding, or navigation
PostHog also collects your app version, plan type (free or premium), subscription status, country, and language preference as user properties.
Session replay is enabled. PostHog records video-like replays of your screen interactions for a sample of sessions, and for sessions in which an error occurs.
Section 2.7: Crash & Error Reporting (Sentry)
We use Sentry for crash reporting and error monitoring. When a crash or error occurs, the following is sent to Sentry:
- Your user ID and email address
- The full error stack trace
- Device model, OS version, and app version
- A log of actions you took before the error
- Network request information
- Session replay (screen recording) context around the error
Sentry processes error data in the EU. Session replays are collected for a sample of sessions and for all sessions in which an error occurs.
Section 2.8: Subscription & Payment Data
If you subscribe to Wealtie Premium, we store:
- Your subscription plan (free or premium)
- Subscription status (active, cancelled, expired, grace period)
- Your RevenueCat subscriber ID
- The product identifier (App Store or Play Store SKU)
- Subscription start date, expiry date, and cancellation date
- Whether the subscription auto-renews
- Subscription lifecycle events (purchase, renewal, cancellation, expiration, billing issues) with the full event payload from RevenueCat
- If you used a promotional code, we store which code you used and when
We never collect, see, or store your payment card details. All payment processing is handled entirely by Apple App Store or Google Play Store through RevenueCat.
Section 2.9: Engagement & Achievement Data
We track in-app engagement to power gamification features:
- Streaks — the number of consecutive days you have logged activity in the app
- Milestones — achievement thresholds you have reached (e.g., first transaction logged, 100 transactions logged)
Section 3: How We Use Your Information
We use the information we collect for the following purposes:
- Providing the Service: To create and manage your account, store and display your financial data, process your preferences, and deliver all features you request
- Authentication & Security: To verify your identity, manage sessions, enforce account lockouts after failed login attempts, and prevent unauthorized access
- Notifications: To send push notifications to your device (daily reminders and milestone/streak alerts) using your stored Expo push token and timezone
- Transactional Emails: To send you email verification codes, welcome emails, and password reset codes
- Analytics & Improvement: To understand how users use the app, identify where users drop off, and make product decisions using PostHog analytics and session replay
- Crash Debugging: To identify and fix bugs and crashes using Sentry error reports
- Currency Conversion: To calculate exchange rates for multi-currency account transfers and display currency conversions using cached exchange rate data
- Subscription Management: To determine your plan entitlements (free vs. premium limits) and process subscription lifecycle events via RevenueCat
- Personalization: To use your onboarding answers (financial goals, marketing channels) to customize your initial app experience
- Legal Compliance: To comply with legal obligations, enforce these policies, and protect our rights and those of our users
We do not use your financial data to train AI models, sell insights to advertisers, or share individual financial information with third parties beyond what is described in this policy.
Section 4: Third-Party Services
We integrate with the following third-party services. Each of them receives certain data about you as described below. We encourage you to review their privacy policies.
Section 4.1: Sentry — Error Monitoring
What we send: Crash reports, error stack traces, your user ID, your email address, device info, app version, pre-crash action breadcrumbs, and session replay recordings.
Sentry processes data in the EU. Your email address and user ID are included in error reports to help us identify and reproduce issues.
Section 4.2: PostHog — Product Analytics
What we send: Behavioral event data (feature usage, onboarding funnel, errors), user properties (user ID, email, name, plan type, subscription status, country, language), and session replay recordings.
Session replay is active — PostHog captures video-like recordings of your screen interactions.
Section 4.3: RevenueCat — Subscription Management
What we send: Subscription purchase queries and your RevenueCat subscriber ID. RevenueCat receives payment events from Apple App Store and Google Play Store on our behalf.
RevenueCat manages all in-app purchase verification and subscription status. We store the RevenueCat subscriber ID and subscription lifecycle events in our database.
Section 4.4: Expo — Push Notifications
What we send: Your Expo push token and notification payload (title, body). Expo routes notifications to Apple Push Notification Service (APNs) or Firebase Cloud Messaging (FCM) on our behalf.
Section 4.5: Google and Apple — Authentication
When you authenticate via Google or Apple, you interact with their login flow. We receive an identity token and basic profile data (name, email, profile picture URL) from the provider. The OAuth tokens are stored in our database.
Your use of these login flows is also governed by the respective privacy policies of Google and Apple.
Section 4.6: Exchange Rate API — Currency Conversion
We use an external exchange rate API to fetch current currency exchange rates. No personal user data is sent to this service — only currency code lookups.
Section 4.7: SMTP Email Provider — Transactional Emails
We send transactional emails (verification codes, password reset codes, welcome emails) via SMTP. Your email address and the content of the email (including the verification/reset code) are sent through this channel.
Section 5: Information Sharing and Disclosure
We do not sell your personal information. We do not sell your financial data. We do not share your data for third-party advertising profiling beyond the advertising identifier described above.
We share your information only in these circumstances:
- Service Providers: As described in the Third-Party Services section above (Sentry, PostHog, RevenueCat, Expo, exchange rate API, SMTP provider). These providers process data on our behalf under contractual data processing agreements.
- OAuth Providers: When you choose to authenticate via Google or Apple, your interaction with those services is governed by their own privacy policies.
- App Stores: Apple App Store and Google Play Store process subscription payments and share subscription status with RevenueCat.
- Legal Requirements: We may disclose information if required by applicable law, court order, or government request, or if we believe disclosure is necessary to prevent harm or protect rights.
- Business Transfers: If Wealtie is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such event.
Section 6: Data Security
We implement the following security measures to protect your data:
- Password hashing: Your password is cryptographically hashed before storage. We never store or transmit your plaintext password.
- Token-based authentication: Access tokens are short-lived and signed. Refresh tokens are stored as hashed values and can be revoked at any time.
- Encrypted database connections: All connections to our database are encrypted in transit.
- Account lockout: Repeated failed login attempts trigger a temporary account lockout to prevent brute-force attacks.
- Rate limiting: Sensitive operations such as email verification resends, password reset requests, and API queries are rate-limited to prevent abuse.
- Webhook verification: Incoming subscription webhooks from RevenueCat are cryptographically verified before processing.
- Duplicate prevention: Financial transactions include safeguards to prevent duplicate entries caused by network errors.
Despite these measures, no system is 100% secure. If you believe your account has been compromised, contact us immediately at [email protected].
Section 7: Data Retention
We retain your data for as long as your account is active. Here is what happens to different types of data:
- Account deletion: When you delete your account, all of your data is permanently and irreversibly deleted from our database. This includes your profile, all transactions, accounts, categories, budgets, goals, recurring transactions, OAuth provider records, refresh tokens, and subscription records. This is a hard, cascading delete — not a soft delete.
- Items you delete within the app (transactions, categories, budgets, etc.): These are "soft deleted" — marked as deleted and hidden from your view, but the record remains in our database. We do not currently have an automatic hard-delete schedule for individually deleted items.
- Email verification and password reset codes: Automatically deleted shortly after issuance.
- Access tokens: Short-lived; expire automatically.
- Analytics & crash report data stored with PostHog and Sentry: subject to those services' own retention policies.
Section 8: Push Notifications
We send push notifications to your device using your Expo push token. Notification types include:
- Daily reminders to log your transactions (if notifications are enabled)
- Milestone achievement notifications (premium feature)
- Streak achievement notifications (premium feature)
You can disable push notifications at any time in the app settings under Notification Settings, or through your device's system notification settings. Disabling notifications removes your push token from active use for sending.
Section 9: Your Rights and Choices
You have the following rights regarding your data:
- Access: You can view all of your financial data directly in the app at any time.
- Correction: You can update your profile information and edit or delete any financial data you have entered at any time within the app.
- Deletion: You can permanently delete your account and all associated data from within the app (Settings → Account → Delete Account). This action is immediate and irreversible.
- Notification preferences: You can enable or disable push notifications in app settings.
- Data portability: We do not currently offer a data export feature. If you need a copy of your data, please contact us at [email protected] and we will work to provide it manually.
- Advertising identifier (iOS): On iOS, you can revoke advertising identifier access through iOS Settings → Privacy & Security → Tracking.
If you are located in the EU, EEA, or UK, you also have rights under GDPR including the right to object to processing and the right to lodge a complaint with your local data protection authority. To exercise any of these rights, contact us at [email protected].
Section 10: Children's Privacy
Wealtie is intended for users who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. We collect date of birth during registration; if we determine that a user is under 18, we will delete their account and data.
If you believe a minor has created an account, please contact us immediately at [email protected].
Section 11: International Data Transfers
Wealtie is a global service supporting 18 languages. Your data may be processed in countries other than where you reside. Our backend infrastructure and third-party services (Sentry, PostHog, RevenueCat, Expo) may store and process data outside your country.
Sentry processes error data in the EU. For other services, data may be processed in the United States or other jurisdictions. By using the Service, you consent to this transfer. We rely on standard contractual clauses or equivalent mechanisms where required for cross-border transfers.
Section 12: Changes to This Privacy Policy
We may update this Privacy Policy when our data practices change. When we do:
- We will update the "Effective Date" at the top of this page
- For material changes, we will notify you by email or with a prominent notice in the app
Your continued use of the Service after a policy update constitutes acceptance of the updated policy. If you do not agree with the changes, you may delete your account.
Section 13: Contact Us
If you have any questions, requests, or concerns about this Privacy Policy or how we handle your data, please reach out:
Data & Privacy Inquiries
Email: [email protected]
We aim to respond within 30 days. For urgent security or privacy matters, please indicate this in your subject line.