Privacy Policy
Version 1.0Last updated: March 8, 2026
WIMM ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our personal finance management service.
1. Information We Collect
1.1 Information You Provide
- Account Information: Email address, name, and password when you register
- Financial Data: Account names, balances, transactions, categories, and tags you manually enter
- Preferences: Display settings, currency preferences, and theme choices
1.2 Information Collected Automatically
- Log Data: IP address, browser type, pages visited, and timestamps
- Device Information: Device type, operating system, and screen resolution
2. How We Use Your Information
We use the information we collect for the following purposes:
- To provide and maintain the WIMM service
- To display your financial accounts and transactions
- To convert currencies using real-time exchange rates
- To send service-related notifications (password resets, etc.)
- To improve and optimize our service
- To detect and prevent fraud or abuse
3. Third-Party Services
We use the following third-party services:
- Exchange Rate API: We use external exchange rate providers to convert currencies. Only your selected currency codes are sent (no personal data).
- Hosting Provider: Our servers are hosted on secure infrastructure with industry-standard protections.
- Plausible Analytics: We use Plausible, a privacy-focused, cookieless analytics service. It collects aggregate data only (page views, referrer, country, device type, screen size) — no personal data, no cookies, and no cross-site tracking. Plausible is GDPR compliant by design. Learn more at plausible.io/data-policy.
We do not use advertising networks, social media trackers, or sell your data to any third parties.
4. Cookies
We use minimal cookies for essential functionality:
- Authentication Token: Stored in localStorage to keep you logged in
- Theme Preference: Stored locally to remember your dark/light mode choice
We use Plausible Analytics, a privacy-focused, cookieless analytics service that does not track you across websites or collect personal data. We do not use tracking cookies, advertising cookies, or any cookie-based analytics.
For detailed information about our cookie and local storage usage, see our Cookie Policy.
5. Data Security
We implement appropriate security measures to protect your data:
- Encryption in Transit: All data is transmitted over HTTPS with TLS 1.2+
- Password Security: Passwords are hashed using bcrypt with salt rounds
- Database Security: PostgreSQL database with restricted access and regular backups
- Backup Encryption: Database backups are encrypted at rest using age encryption
6. Data Retention
We retain your data as follows:
- Account Data: Retained while your account is active
- Financial Data: Retained until you delete it or your account
- Server Logs: Retained for 30 days for security purposes
- Backups: Retained for up to 3 months, then automatically deleted
When you delete your account, all your personal data is permanently removed within 30 days.
7. Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the following rights:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Update or correct inaccurate data
- Right to Erasure: Request deletion of your account and all data
- Right to Portability: Export your data in a machine-readable format
- Right to Restrict Processing: Limit how we use your data
- Right to Object: Object to certain types of data processing
To exercise any of these rights, contact us at [email protected].
8. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to provide our service to you
- Consent: Where you have given explicit consent (e.g., privacy policy acceptance)
- Legitimate Interests: For service improvement and security purposes
9. International Data Transfers
Your data may be processed on servers located outside your country of residence. We ensure appropriate safeguards are in place, including standard contractual clauses and adequate security measures, to protect your data during international transfers.
10. Children's Privacy
WIMM is not intended for users under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the service after changes constitutes acceptance of the updated policy.
12. Sub-Processors
We use the following sub-processors to deliver our service. Each is bound by data processing agreements and GDPR-compliant practices:
Hetzner
Purpose: Server infrastructure and hosting
Data shared: All application data (encrypted at rest and in transit)
Location: EU (Germany/Finland)
GDPR compliant
Plausible Analytics
Purpose: Privacy-focused website analytics
Data shared: Aggregate page views only — no personal data, no cookies
GDPR compliant by design
Exchange Rate API
Purpose: Currency conversion rates
Data shared: Currency codes only — no personal or financial data
GDPR compliant
Creem
Purpose: Payment processing for subscriptions
Data shared: Billing data (email, subscription tier, payment events)
GDPR compliant
13. Contact Us
For any questions about this Privacy Policy or our data practices, contact us:
WIMM - Personal Finance Management
This policy is effective as of March 2026.