Privacy Policy
Last updated: 18 September 2026
1. What this Policy is about
This Privacy Policy explains which personal data we process in connection with Wertly (website wertly.ch and web app/PWA at app.wertly.ch), why we do so — and what we deliberately cannot see. It applies to visitors of our website and to users of the Wertly app and meets the requirements of the Swiss Federal Act on Data Protection (FADP/DSG). For persons in the European Economic Area (EEA), the information in this Policy relating to the EU General Data Protection Regulation (GDPR) additionally applies. Who is responsible for the data processing and how to reach us is set out in Section 15.
2. The essentials at a glance
Wertly is built so that we cannot read the content of your financial data. Your assets, liabilities, amounts, labels and histories are encrypted on your device before they ever reach our server (end-to-end encryption). Only ciphertext (= the unreadable, encrypted form of your data) is stored on the server. Only you hold the key.
For the app to function, we additionally process a limited amount of unencrypted data (e.g. your e-mail address for login). The following overview shows honestly what we can and cannot see:
| What we can see | What we CANNOT see |
|---|---|
| E-mail address and password hash (never the password itself) | Your assets and liabilities (type, name, amount) |
| Times of registration and logins, IP address, browser type | Amounts, currencies of individual items, interest rates |
| Language setting, country, reference currency, dark mode | Your snapshots and histories in detail |
| Subscription status and Stripe references (no card data) | Your projections — they are calculated exclusively on your device and stored nowhere |
| Timestamps and the number of your encrypted entries (when something changed and how many entries you have) | The content of those entries and changes |
| Product-related usage events of your account, without financial content (see Section 7) | A profile of your financial situation |
3. What data we process
a) Account data. E-mail address, password (as a cryptographic hash), time of registration and of e-mail confirmation, login times. Without this data we cannot operate your account.
b) Encrypted content data. Your financial data (assets, liabilities, snapshots) is stored exclusively as ciphertext encrypted on your device. We cannot decrypt this content and do not pass it on to anyone in readable form — we simply do not have it. The encrypted vault includes two technical, unencrypted identifiers (a vault ID and a verification value used to verify your key); decryption of your data is not possible with them.
c) Unencrypted settings. Country, language, reference currency and display mode. We also store the time at which you confirmed your Recovery Key. This information is technically necessary; it contains no financial content.
d) Technical log data. When you access our systems, the IP address, browser/device type (user agent) and timestamps are recorded by default — in security logs (e.g. login audit) and in short-lived infrastructure logs of our hosting providers.
e) Subscription and payment data. Selected plan, status (trial/active/cancelled), periods, date of first payment, and technical references of our payment provider Stripe (customer and subscription ID). Credit card and payment data are collected and processed exclusively by Stripe — they never reach our systems. At purchase we transmit to Stripe your e-mail address, an internal user ID and the selected plan (including the indication of whether it is a Founder plan).
f) E-mail delivery data. For system e-mails (registration, password reset, payment confirmations) we log the recipient address, template, time and delivery status. During delivery, the e-mail (address and content) temporarily resides in our delivery system.
g) Founder record. If you purchase one of the limited Founder offers, we store a small proof record (internal user ID, Stripe customer reference, plan, timestamp — no e-mail, no name). It exists in your interest: it allows us to prove your Founder price guarantee to you at any time — even years later, or if you have deleted your account in the meantime — and ensures that the limit of 100 Founder places is enforced fairly. For these reasons, this record also remains after an account deletion (details in Section 10).
h) Local data on your device. The app stores on your device (browser storage/IndexedDB): your key material, your session, settings, a local copy of your (encrypted) data and, where applicable, unfinished onboarding inputs. This local data does not leave your device in readable form. Note: if you delete browser data or reinstall the app, your local key is removed as well — without your Recovery Key, neither you nor we can restore the data (see Section 12).
i) Technical operations log. The app keeps a technical service log (ops_events) recording certain operational events — e.g. a failed payment, an account deletion or a failed login attempt. An entry consists only of the event type, the time, a short technical code and a few fixed parameters (e.g. selected plan); error messages, inputs, e-mail addresses or IP addresses are never stored and are filtered out technically. Your account appears in it only as an irreversible fingerprint (HMAC with a secret key); attribution to your account is possible only for us, using that key. Only the owner has access, via the database. Entries are deleted automatically after 90 days. Purpose: operational security, troubleshooting and abuse prevention.
j) Feedback. If you send us a message via the feedback function in the app, we store: the type of message (problem/idea), your text, the time, for problem reports optionally the identifier of the affected screen, and a technical context consisting of four fixed items (operating system family, browser family, installed app yes/no, app language). By default, your message is linked neither to your e-mail address nor to your account. Only if you choose "With contact" do we additionally store your e-mail address so that we can reply to you about this message; you can withdraw this consent at any time by asking us to delete it. Feedback messages — unlike your financial data — are not end-to-end encrypted so that we can read them; therefore, do not write any amounts or any personal or sensitive information in them. To prevent spam, we keep a short-lived counter (maximum 3 messages per 24 hours) that contains only an irreversible fingerprint of your account ID, is not linked to your message, and is deleted after 2 days.
4. Purposes and legal bases
We process personal data for the following purposes. The legal bases stated refer to the GDPR where applicable; under the Swiss FADP we rely on the corresponding statutory processing principles.
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Providing account and app, synchronisation | a, b, c, h | Contract (Art. 6(1)(b)) |
| Payment processing, subscription management | e | Contract ((b)) |
| System e-mails (registration, reset, confirmations) | f | Contract ((b)) |
| Security, abuse and fraud prevention | d | Legitimate interest ((f)) |
| Technical operations log (Section 3 i) | i | Legitimate interest ((f)) |
| Feedback (message, technical context) | j | Legitimate interest ((f)) |
| Reply to your feedback (e-mail address) | j | Consent ((a)), withdrawable at any time |
| Founder limit and price guarantee | g | Legitimate interest ((f)) |
| Product analytics (Section 7) | c, account-related events | Legitimate interest ((f)) |
| Website visit measurement (Section 6) | technical characteristics | Legitimate interest ((f)) |
| Statutory retention (accounting) | e (at Stripe and with us) | Legal obligation ((c)) |
Our legitimate interests in this respect are: security and abuse prevention, the fair enforcement of limited offers, and the improvement and reach measurement of the product.
We currently do not send marketing e-mails. Should we offer this in the future, it will only happen with your prior consent (opt-in), which you can withdraw at any time.
We do not make automated individual decisions within the meaning of Art. 21 FADP or Art. 22 GDPR. The projections in the app are pure computational displays based on your own inputs and have no legal effect.
5. Cookies and local storage
We use no advertising cookies and no tracking services of advertising networks or data brokers. The following are used exclusively:
| Name | Origin | Purpose | Duration |
|---|---|---|---|
__cf_bm | Cloudflare (security/CDN service) | bot protection, technically required | approx. 30 minutes |
__dpl | Lovable hosting | technical delivery of the website (deployment), technically required | 24 hours |
session-id | Visit measurement (Section 6), first-party | counting of visits | 30 minutes |
| Browser storage (localStorage/sessionStorage/IndexedDB) | Wertly | login session, keys, settings, local data copy | until deleted by you |
During payment on checkout.stripe.com, Stripe sets its own technically necessary cookies; Stripe's privacy notices apply to these.
You can block or delete cookies and website data at any time in your browser settings. The technically required storage (session, keys) is necessary for using the app — without it, login and decryption do not work.
6. Website visit measurement
Our hosting platform (Lovable) measures visits to the website with its own first-party script: it counts pages viewed, approximate origin (country, derived from time zone or IP), device type, language and referrer source (which page you came from). A short-lived session cookie (30 minutes) may be set for this. The analysis is aggregated — we see statistics, not identified individuals, and there is no profiling and no sharing with advertising networks. If you do not want this, you can block cookies for wertly.ch and app.wertly.ch in your browser; the website remains usable.
7. Product analytics (in the app)
To improve Wertly, we record sparing, product-related events — deliberately without financial content. Each event consists only of the event name, the time and your account ID, and is stored at most once per account. The table holding these events has technically no field for content — it is not possible to store an amount, a type, a label or a category with an event. In short: we see that you completed the setup — not what you entered into it.
Complete list of the 18 events (as of: 18 September 2026):
| Event | Meaning |
|---|---|
signup_completed | registration completed (e-mail confirmed) |
trial_started | 14-day trial started |
first_asset_entered | first asset or liability created (without type and amount) |
projection_viewed | net worth projection viewed for the first time |
pwa_installed_android | app installed on the device (Android / desktop Chrome) |
pwa_first_standalone_ios | app first launched from the iPhone home screen |
onb_start | onboarding started |
onb_profile_done | profile step completed |
onb_savings_done | savings step completed |
onb_assets_picked | selection of asset categories confirmed (not which ones) |
onb_liabs_picked | selection of liability categories confirmed (not which ones) |
onb_seq_start | form sequence for the selected categories started |
onb_seq_skip_all | form sequence skipped entirely |
onb_finish_open | final step "create starting point" opened |
onb_done | onboarding completed (first monthly snapshot saved) |
onb_exit | onboarding deliberately left |
onb_resume_never | "don't ask again" chosen for the onboarding resume card |
monthly_update_2_saved | monthly update saved in a second, different month |
In addition, we record: one activity marker per day (only the date, no time, no actions; automatic deletion after 12 months) · the origin of your first visit (UTM parameters source, medium, campaign), only for accounts younger than 24 hours · your subscription status (from Stripe) · timestamps of when encrypted records last changed (not their content).
If we add new events, we update this list before their introduction (Section 14). These events are linked to your account and contain no financial content: no amounts, no asset or liability types, no labels, no age, no projections. They do not leave our systems, are not shared with third parties, and are deleted together with your account.
8. Recipients and service providers (processors)
First, the essential point: none of these service providers can read the content of your financial data — it exists everywhere only in encrypted form, and the key stays on your device.
We use the following service providers for operation. Data processing agreements (DPAs) are in place with all of them:
| Service provider | Registered office / data location | Function | Data |
|---|---|---|---|
| Lovable (Lovable Labs Inc.) with sub-processor Supabase | Data location: EU (Frankfurt); company registered office: USA | hosting, database, authentication | account data, ciphertext, logs |
| Lovable e-mail service | USA (infrastructure incl. Cloudflare/AWS) | sending of system e-mails | e-mail address, e-mail content |
| Stripe | Contracting party: Stripe Payments Europe Ltd., Ireland; parent company: Stripe Inc., USA | payment processing, subscription management, receipts | e-mail, user ID, plan; payment data directly at Stripe |
| Cloudflare Inc. | USA (global network) | CDN, security filter in front of the website and execution of the app's server-side functions | IP, technical access data |
| Frankfurter (frankfurter.dev) | EU | daily exchange rates | only IP and requested currency pairs — no account or financial data |
Beyond this, we only disclose personal data if we are legally obliged to do so (e.g. to authorities on the basis of a legally binding order).
9. Disclosure abroad
Regardless of the country: your encrypted financial content is unreadable everywhere — the key stays on your device.
Your financial data (as ciphertext) and your account data are stored in the EU (Frankfurt region) — under Annex 1 of the Swiss Data Protection Ordinance, the EU provides an adequate level of data protection.
Individual supporting services process data partly in the USA: payment processing (Stripe), the sending of system e-mails, and the security/CDN filter in front of the website. These transfers are based on the Swiss-U.S. Data Privacy Framework (Stripe is certified under it) or on the EU Standard Contractual Clauses with the Swiss addendum as appropriate safeguards within the meaning of Art. 16 para. 2 FADP. A copy of the respective safeguards is available on request.
10. Retention and deletion
During use, we retain your data for as long as your account exists.
When you delete your account (function in the settings), the following happens:
- Any existing subscription is first cancelled at Stripe. If this fails, the deletion is aborted — so that no subscription continues to run without an account.
- Your financial data (ciphertext), your vault and your account including profile, subscription entries, sessions and all product analytics events (Section 7, incl. activity markers) are deleted from our database immediately and irretrievably. There is no recovery period.
- In rolling backups of our database, deleted entries may for technical reasons still exist for a short time; they are overwritten automatically — as a rule within 7 days, at the latest within 30 days. Backups are not used for any other purposes.
- The following remain:
- Payment and receipt data (incl. billing e-mail): retention due to statutory bookkeeping and retention obligations (Art. 958f of the Swiss Code of Obligations: 10 years) — at Stripe and, insofar as we ourselves retain accounting-relevant receipts, also with us.
- E-mail delivery logs (recipient address, template, delivery status): retained for as long as required for proof of delivery and abuse prevention.
- Security/audit logs (IP addresses of login events): retained for as long as required for protection against abuse; short-lived infrastructure logs of our providers are overwritten automatically after a few days to weeks.
- Technical operations log (Section 3 i): entries remain until automatic deletion after 90 days at the latest; after an account deletion, we can practically no longer attribute them to any person.
- Feedback messages (Section 3 j): are deleted automatically after 6 months at the latest. As they are not linked to your account, they are not deleted automatically upon account deletion; we delete messages containing your e-mail address earlier at any time on request to support@wertly.ch.
- Founder record (Section 3 g): remains — so that your Founder price guarantee remains provable even after an account deletion and the 100-place limit cannot be circumvented. It contains neither e-mail nor name; an attribution to your person is only possible in connection with the payment records legally retained at Stripe.
- Local data on your device is not deleted by us automatically — remove it via your browser data or by uninstalling. Without the server and the key, it is unusable for third parties.
11. Your rights
You have the rights under the FADP and — where applicable — the GDPR:
- Access to the data processed about you (Art. 25 FADP / Art. 15 GDPR) — including the analytics events stored for your account (event names and dates)
- Rectification of inaccurate data (Art. 32 FADP / Art. 16 GDPR)
- Erasure (Art. 32 FADP / Art. 17 GDPR) — fastest directly via the account deletion function in the app
- Data release / portability (Art. 28 FADP / Art. 20 GDPR): via "Export data" in the app you can obtain your data at any time as a machine-readable JSON file — including during the trial and after its expiry
- Restriction of processing (Art. 18 GDPR, where applicable)
- Objection to processing based on legitimate interest (Art. 21 GDPR), and withdrawal of any consent given, with effect for the future
Please direct requests to support@wertly.ch. For security, we may require confirmation via your registered e-mail address. Note: we cannot "release" or view the content of your encrypted financial data — it is unreadable to us; use the export function in the app for that.
You can also lodge a complaint with a supervisory authority: in Switzerland with the Federal Data Protection and Information Commissioner (FDPIC), in the EEA with the data protection authority of your place of residence.
12. Data security
- End-to-end encryption: your financial data is encrypted and decrypted on your device (modern, proven web cryptography). The master key never leaves your device.
- Recovery Key: when setting up, you receive a recovery key. Keep it safe: without the Recovery Key, your encrypted data cannot be restored by anyone in the event of device loss, browser reset or password loss — not even by us. That is the price of true end-to-end encryption.
- Transport encryption (TLS) for all connections; server-side access controls (Row Level Security). At the application level, only the owner has access to the database; our hosting providers (Section 8) operate the infrastructure — they, too, see your financial data exclusively as ciphertext.
- In the event of a data security breach with an expected high risk, we will inform the FDPIC and — where required — the affected persons in accordance with Art. 24 FADP or Art. 33/34 GDPR.
13. Minors
Wertly is intended for persons aged 18 and over. By registering, you confirm that you are of legal age. We do not knowingly process data of minors; we delete such accounts.
14. Changes to this Policy
We will adapt this Privacy Policy if our data processing or the legal situation changes. The version published on wertly.ch at the relevant time applies. In the event of significant changes, we will inform you in the app or by e-mail. This Policy is provided in German and English; in case of discrepancies, the German version prevails.
15. Controller and contact
The controller responsible for data processing in connection with Wertly is:
SPANIK.ECOMMERCE
Owner: Pavel Spanik
c/o Pavel Spanik, Goetzstrasse 5, 8006 Zurich, Switzerland
UID: CHE-320.389.197
E-mail: support@wertly.ch
For any data protection requests — including exercising your rights under Section 11 — you can reach us at support@wertly.ch.