Privacy Policy
Last updated October 9, 2026
This policy explains what WalletSteer Europa collects, why, who else sees it, and what you can do about it. It describes what the app does today — not what it might do later.
Who we are
WalletSteer is a personal budgeting app operated by WalletSteer Europa. We decide what data is collected and why, which under the GDPR makes us the data controller for it.
Write to hello@walletsteer.com about anything in this policy — a question, a correction, or a request to exercise one of your rights. A person reads that inbox.
The short version
If you read nothing else:
- WalletSteer never connects to your bank. There is no login to give us, and no read access to any account.
- Your data gets in because you put it there — by typing it, or by importing a statement you downloaded yourself.
- We do not sell, rent, or trade your data, and we never will.
- There are no ads, no advertising networks, and no third-party analytics or tracking of any kind.
- You can wipe your financial data from Settings at any time.
What we collect
Everything below is either something you typed, something you imported, or something the app needs to keep working. Nothing is bought from a data broker or inferred about you elsewhere.
Your account
Your email address, and optionally a first and last name, a birth year, a profession, and a profile picture. Only the email is required — the rest exists so the app can address you properly, and you can leave every one of those fields empty.
Your password, if you set one
A password is optional; email links and Google sign-in work without one. If you set a password we store only a scrypt hash of it, never the password itself. Nobody at WalletSteer can read it, and we cannot tell you what it was.
Google sign-in, if you choose it
Signing in with Google means Google sends us your name, email address and profile picture, and we store the tokens that keep that connection working. We ask for nothing beyond the basic profile — no Gmail, no Drive, no contacts.
Your money data
Transactions (date, description, amount, currency, category), any cash withdrawal you split into parts, labels you create, savings funds and their deposits, monthly budgets, and obligations with their due dates. This is the app — without it there is nothing to show you.
Statement imports
When you import a bank statement we keep the file name, how many rows it had, and which column meant what, so a bad import can be undone in one move. The file itself is not stored: it is read in memory, turned into transactions, and dropped.
Your preferences
Your base currency, your interface language and your light or dark theme are saved to your account, so all three follow you to any device you sign in on. Before you have an account, the language and theme you pick stay in your own browser and are never sent to us.
Technical data
A session record for every device you are signed in on, so you can sign the others out. We also record the IP address behind a sign-in link request or a failed password attempt, purely to rate-limit them. We keep no general access logs, no history of what you looked at inside the app, and no device fingerprints.
What we never collect
Some of this is a choice. Most of it is simply not built:
- Bank credentials, PSD2 access, or any read connection to a financial institution — the app cannot reach your bank, because no such connection exists.
- Card numbers or anything a payment processor would need. We take no payments.
- Analytics, heatmaps, session recordings, or behavioural tracking. None of those libraries are in the code.
- Advertising cookies, marketing pixels, and third-party trackers.
- Special category data. Please do not put health, religious, political, or biometric details into a transaction description.
Why we use it, and on what legal basis
The GDPR requires a lawful basis for each purpose. Ours are:
To provide the service — performance of a contract
Creating and running your account, signing you in, storing your transactions and funds, working out what you can spend, and sending the mail the app needs to function: a sign-in link, a confirmation of an email change. Without this data there is no service to give you.
To keep it safe and working — legitimate interests
Rate-limiting sign-in attempts and the emails the app sends, spotting abuse, and fixing what breaks. We use the least data that does the job: a counted attempt and an IP address, kept only as long as the rate-limit window.
To meet legal obligations — legal obligation
If the law requires us to keep or hand over specific data we comply, but only as far as it actually requires — and we will tell you unless we are forbidden from doing so.
Data leaving the EU
Some of the providers above are based in the United States. Where data reaches them, the transfer rests on the European Commission's Standard Contractual Clauses or on an adequacy decision covering that provider, whichever applies.
Ask at hello@walletsteer.com if you want to know which mechanism covers a specific provider.
How long we keep it
- Your account and everything in it: for as long as the account exists. Delete something in the app and it is gone from the database, not archived out of sight.
- IP addresses recorded for rate-limiting: only as long as the window they serve. They expire on their own and are used for nothing else.
- After you ask us to delete your account: removed within 30 days, including from backups as those cycle out.
How it is kept safe
- Everything travels over HTTPS.
- Passwords are stored as scrypt hashes with their own parameters, never in a readable form.
- Sessions are rows in the database, so signing a device out genuinely ends its session instead of waiting for a token to expire.
- The strongest protection is structural: there are no bank credentials in the system, so there are none to steal.
No system is perfectly safe. If a breach ever affects your data we will tell you and the supervisory authority within the time the GDPR allows.
Your rights
Under the GDPR you can ask us to:
- Give you a copy of the personal data we hold about you.
- Correct anything that is wrong — most of it you can edit yourself in Settings.
- Delete your account and everything in it.
- Hand your data over in a machine-readable format, or send it on to another service.
- Pause processing while a correction or a complaint is being sorted out.
- Object to the processing we base on legitimate interests.
Email hello@walletsteer.com and say which one you want. We answer within 30 days and it costs you nothing. We may ask you to confirm the request from the address on the account, so that nobody can make it in your name.
What you can do yourself, today
These are in the app right now, under Settings:
- Wipe every transaction and import you have, in one move.
- Undo a single statement import without touching anything else.
- Change your email address, confirmed by a link sent to the new one.
- Set or change a password, which signs every other device out.
- Sign out every other device while staying signed in here.
- Change your language, base currency, theme, and profile details.
- Delete your account outright — every row and every session, with nothing archived.
One thing is not a button yet, and we would rather say so than imply otherwise: exporting your data. Ask at hello@walletsteer.com and we do it by hand, within 30 days.
Children
WalletSteer is not for people under 16. We do not knowingly collect anything from them, and if we find that we have, we delete it.
If our answer does not satisfy you
Tell us first — most of it is a misunderstanding we can fix. If that does not settle it, you can complain to your national data protection authority. In Romania that is ANSPDCP, the National Supervisory Authority for Personal Data Processing, at dataprotection.ro.
Changes to this policy
If something here changes in a way that matters to you, we email you before it takes effect rather than quietly editing the page. The date at the top always says when this version was written.
Contact
Questions, requests, or a correction to this page — email hello@walletsteer.com.