Privacy Policy

Version 1.0

Last updated: March 8, 2026

WIMM ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our personal finance management service.

1. Information We Collect

1.1 Information You Provide

  • Account Information: Email address, name, and password when you register
  • Financial Data: Account names, balances, transactions, categories, and tags you manually enter
  • Preferences: Display settings, currency preferences, and theme choices

1.2 Information Collected Automatically

  • Log Data: IP address, browser type, pages visited, and timestamps
  • Device Information: Device type, operating system, and screen resolution

2. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide and maintain the WIMM service
  • To display your financial accounts and transactions
  • To convert currencies using real-time exchange rates
  • To send service-related notifications (password resets, etc.)
  • To improve and optimize our service
  • To detect and prevent fraud or abuse

3. Third-Party Services

We use the following third-party services:

  • Exchange Rate API: We use external exchange rate providers to convert currencies. Only your selected currency codes are sent (no personal data).
  • Hosting Provider: Our servers are hosted on secure infrastructure with industry-standard protections.
  • Plausible Analytics: We use Plausible, a privacy-focused, cookieless analytics service. It collects aggregate data only (page views, referrer, country, device type, screen size) — no personal data, no cookies, and no cross-site tracking. Plausible is GDPR compliant by design. Learn more at plausible.io/data-policy.

We do not use advertising networks, social media trackers, or sell your data to any third parties.

4. Cookies

We use minimal cookies for essential functionality:

  • Authentication Token: Stored in localStorage to keep you logged in
  • Theme Preference: Stored locally to remember your dark/light mode choice

We use Plausible Analytics, a privacy-focused, cookieless analytics service that does not track you across websites or collect personal data. We do not use tracking cookies, advertising cookies, or any cookie-based analytics.

For detailed information about our cookie and local storage usage, see our Cookie Policy.

5. Data Security

We implement appropriate security measures to protect your data:

  • Encryption in Transit: All data is transmitted over HTTPS with TLS 1.2+
  • Password Security: Passwords are hashed using bcrypt with salt rounds
  • Database Security: PostgreSQL database with restricted access and regular backups
  • Backup Encryption: Database backups are encrypted at rest using age encryption

6. Data Retention

We retain your data as follows:

  • Account Data: Retained while your account is active
  • Financial Data: Retained until you delete it or your account
  • Server Logs: Retained for 30 days for security purposes
  • Backups: Retained for up to 3 months, then automatically deleted

When you delete your account, all your personal data is permanently removed within 30 days.

7. Your Rights (GDPR)

Under the General Data Protection Regulation (GDPR), you have the following rights:

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Update or correct inaccurate data
  • Right to Erasure: Request deletion of your account and all data
  • Right to Portability: Export your data in a machine-readable format
  • Right to Restrict Processing: Limit how we use your data
  • Right to Object: Object to certain types of data processing

To exercise any of these rights, contact us at [email protected].

8. Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Contract Performance: Processing necessary to provide our service to you
  • Consent: Where you have given explicit consent (e.g., privacy policy acceptance)
  • Legitimate Interests: For service improvement and security purposes

9. International Data Transfers

Your data may be processed on servers located outside your country of residence. We ensure appropriate safeguards are in place, including standard contractual clauses and adequate security measures, to protect your data during international transfers.

10. Children's Privacy

WIMM is not intended for users under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the service after changes constitutes acceptance of the updated policy.

12. Sub-Processors

We use the following sub-processors to deliver our service. Each is bound by data processing agreements and GDPR-compliant practices:

Hetzner

Purpose: Server infrastructure and hosting

Data shared: All application data (encrypted at rest and in transit)

Location: EU (Germany/Finland)

GDPR compliant

Plausible Analytics

Purpose: Privacy-focused website analytics

Data shared: Aggregate page views only — no personal data, no cookies

GDPR compliant by design

Exchange Rate API

Purpose: Currency conversion rates

Data shared: Currency codes only — no personal or financial data

GDPR compliant

Creem

Purpose: Payment processing for subscriptions

Data shared: Billing data (email, subscription tier, payment events)

GDPR compliant

13. Contact Us

For any questions about this Privacy Policy or our data practices, contact us:

WIMM - Personal Finance Management

This policy is effective as of March 2026.