WalletSteerSign in

Privacy Policy

Last updated October 9, 2026

This policy explains what WalletSteer Europa collects, why, who else sees it, and what you can do about it. It describes what the app does today — not what it might do later.

Who we are

WalletSteer is a personal budgeting app operated by WalletSteer Europa. We decide what data is collected and why, which under the GDPR makes us the data controller for it.

Write to hello@walletsteer.com about anything in this policy — a question, a correction, or a request to exercise one of your rights. A person reads that inbox.

The short version

If you read nothing else:

What we collect

Everything below is either something you typed, something you imported, or something the app needs to keep working. Nothing is bought from a data broker or inferred about you elsewhere.

Your account

Your email address, and optionally a first and last name, a birth year, a profession, and a profile picture. Only the email is required — the rest exists so the app can address you properly, and you can leave every one of those fields empty.

Your password, if you set one

A password is optional; email links and Google sign-in work without one. If you set a password we store only a scrypt hash of it, never the password itself. Nobody at WalletSteer can read it, and we cannot tell you what it was.

Google sign-in, if you choose it

Signing in with Google means Google sends us your name, email address and profile picture, and we store the tokens that keep that connection working. We ask for nothing beyond the basic profile — no Gmail, no Drive, no contacts.

Your money data

Transactions (date, description, amount, currency, category), any cash withdrawal you split into parts, labels you create, savings funds and their deposits, monthly budgets, and obligations with their due dates. This is the app — without it there is nothing to show you.

Statement imports

When you import a bank statement we keep the file name, how many rows it had, and which column meant what, so a bad import can be undone in one move. The file itself is not stored: it is read in memory, turned into transactions, and dropped.

Your preferences

Your base currency, your interface language and your light or dark theme are saved to your account, so all three follow you to any device you sign in on. Before you have an account, the language and theme you pick stay in your own browser and are never sent to us.

Technical data

A session record for every device you are signed in on, so you can sign the others out. We also record the IP address behind a sign-in link request or a failed password attempt, purely to rate-limit them. We keep no general access logs, no history of what you looked at inside the app, and no device fingerprints.

What we never collect

Some of this is a choice. Most of it is simply not built:

Why we use it, and on what legal basis

The GDPR requires a lawful basis for each purpose. Ours are:

To provide the service — performance of a contract

Creating and running your account, signing you in, storing your transactions and funds, working out what you can spend, and sending the mail the app needs to function: a sign-in link, a confirmation of an email change. Without this data there is no service to give you.

To keep it safe and working — legitimate interests

Rate-limiting sign-in attempts and the emails the app sends, spotting abuse, and fixing what breaks. We use the least data that does the job: a counted attempt and an IP address, kept only as long as the rate-limit window.

To meet legal obligations — legal obligation

If the law requires us to keep or hand over specific data we comply, but only as far as it actually requires — and we will tell you unless we are forbidden from doing so.

Cookies and local storage

WalletSteer sets a small number of its own cookies, and every one of them is there because signing in would not work without it. There are no third-party cookies, because there are no third parties in the page.

Every one below is strictly necessary — remove it and you are signed out, or a page can no longer tell what just happened. Nothing you chose on purpose is kept in a cookie: your language and your theme are saved to your account when you have one, and in your own browser when you do not.

authjs.session-token

What it does
Keeps you signed in. Sessions live in our database rather than in the cookie, so it carries only an opaque token pointing at one row. Named __Secure-authjs.session-token on the live site. Flags: httpOnly, Secure in production, SameSite=Lax.
How long
30 days
Kind
Strictly necessary

ws_link_sent

What it does
Confirms that a sign-in link really was sent, so the check-your-email page does not tell someone who arrived from a bookmark that mail is waiting for them. Flags: httpOnly, Secure in production, SameSite=Lax.
How long
15 minutes
Kind
Strictly necessary

Auth.js sign-in cookies

What it does
The CSRF token and callback URL the sign-in flow needs, plus a PKCE code verifier and a state value when you sign in with Google. Set by the library with its own defaults, and short-lived — they exist only while you are signing in.
How long
The sign-in flow
Kind
Strictly necessary

Local storage in your browser

Three things are kept in your browser's local storage rather than in a cookie. The law treats anything stored on your device the same way whatever the technology, so they belong here rather than tucked out of sight:

All three stay until you clear your browser data, and none of them is sent to us from there. When you are signed in, your language and theme are saved to your account as well — that copy is the one described under what we collect.

Why there is no cookie banner

Under the ePrivacy rules — Law 506/2004 in Romania — storage that is strictly necessary for a service you explicitly asked for does not require consent, and neither does a preference you set yourself. Everything listed above falls into one of those two, so there is nothing here for you to accept or refuse. What does remain obligatory is telling you plainly what is stored and why, which is what this section is for.

You can clear cookies and local storage in your browser whenever you like. Nothing breaks permanently: you will be signed out, and this browser goes back to English and the dark theme. If you have an account, the language and theme saved there come back the moment you sign in.

What is not here

No analytics of any kind. There is no Google Analytics, gtag, Plausible, PostHog, Vercel Analytics or equivalent anywhere in the code.

Who else sees it

Running the app means a handful of companies process data on our behalf. Each is bound by a contract to use it only for what we ask. This is the complete list:

Vercel

What it does for us
Hosts and serves the app.
What it sees
Requests to the site, including IP address and browser, as any web host does.

Neon

What it does for us
Runs the database.
What it sees
Everything stored in your account.

Resend

What it does for us
Sends our email.
What it sees
Your email address and the contents of the message.

Google

What it does for us
Signs you in, if you choose that route.
What it sees
Only what a sign-in involves. They send us your name, email and picture.

Anthropic

What it does for us
Powers the optional AI category suggestions and written summaries.
What it sees
Only the transaction text and amounts a given request needs, and only when you use the feature.

The AI features are the only place your transaction text leaves our own systems, and only for the request you asked for. Under Anthropic's API terms that content is not used to train their models.

That is the whole list. We do not sell, rent, or trade your data, we share nothing with advertisers or data brokers, and we hand nothing to anyone else unless the law requires it.

Data leaving the EU

Some of the providers above are based in the United States. Where data reaches them, the transfer rests on the European Commission's Standard Contractual Clauses or on an adequacy decision covering that provider, whichever applies.

Ask at hello@walletsteer.com if you want to know which mechanism covers a specific provider.

How long we keep it

How it is kept safe

No system is perfectly safe. If a breach ever affects your data we will tell you and the supervisory authority within the time the GDPR allows.

Your rights

Under the GDPR you can ask us to:

Email hello@walletsteer.com and say which one you want. We answer within 30 days and it costs you nothing. We may ask you to confirm the request from the address on the account, so that nobody can make it in your name.

What you can do yourself, today

These are in the app right now, under Settings:

One thing is not a button yet, and we would rather say so than imply otherwise: exporting your data. Ask at hello@walletsteer.com and we do it by hand, within 30 days.

Children

WalletSteer is not for people under 16. We do not knowingly collect anything from them, and if we find that we have, we delete it.

If our answer does not satisfy you

Tell us first — most of it is a misunderstanding we can fix. If that does not settle it, you can complain to your national data protection authority. In Romania that is ANSPDCP, the National Supervisory Authority for Personal Data Processing, at dataprotection.ro.

Changes to this policy

If something here changes in a way that matters to you, we email you before it takes effect rather than quietly editing the page. The date at the top always says when this version was written.

Contact

Questions, requests, or a correction to this page — email hello@walletsteer.com.