Wertly
EN/DE
Log inTry for 14 days
DEEN
How it worksPrivacyPricingLog inTry for 14 days

Privacy Policy

Last updated: 18 September 2026

1. What this Policy is about

This Privacy Policy explains which personal data we process in connection with Wertly (website wertly.ch and web app/PWA at app.wertly.ch), why we do so — and what we deliberately cannot see. It applies to visitors of our website and to users of the Wertly app and meets the requirements of the Swiss Federal Act on Data Protection (FADP/DSG). For persons in the European Economic Area (EEA), the information in this Policy relating to the EU General Data Protection Regulation (GDPR) additionally applies. Who is responsible for the data processing and how to reach us is set out in Section 15.

2. The essentials at a glance

Wertly is built so that we cannot read the content of your financial data. Your assets, liabilities, amounts, labels and histories are encrypted on your device before they ever reach our server (end-to-end encryption). Only ciphertext (= the unreadable, encrypted form of your data) is stored on the server. Only you hold the key.

For the app to function, we additionally process a limited amount of unencrypted data (e.g. your e-mail address for login). The following overview shows honestly what we can and cannot see:

What we can seeWhat we CANNOT see
E-mail address and password hash (never the password itself)Your assets and liabilities (type, name, amount)
Times of registration and logins, IP address, browser typeAmounts, currencies of individual items, interest rates
Language setting, country, reference currency, dark modeYour snapshots and histories in detail
Subscription status and Stripe references (no card data)Your projections — they are calculated exclusively on your device and stored nowhere
Timestamps and the number of your encrypted entries (when something changed and how many entries you have)The content of those entries and changes
Product-related usage events of your account, without financial content (see Section 7)A profile of your financial situation

3. What data we process

a) Account data. E-mail address, password (as a cryptographic hash), time of registration and of e-mail confirmation, login times. Without this data we cannot operate your account.

b) Encrypted content data. Your financial data (assets, liabilities, snapshots) is stored exclusively as ciphertext encrypted on your device. We cannot decrypt this content and do not pass it on to anyone in readable form — we simply do not have it. The encrypted vault includes two technical, unencrypted identifiers (a vault ID and a verification value used to verify your key); decryption of your data is not possible with them.

c) Unencrypted settings. Country, language, reference currency and display mode. We also store the time at which you confirmed your Recovery Key. This information is technically necessary; it contains no financial content.

d) Technical log data. When you access our systems, the IP address, browser/device type (user agent) and timestamps are recorded by default — in security logs (e.g. login audit) and in short-lived infrastructure logs of our hosting providers.

e) Subscription and payment data. Selected plan, status (trial/active/cancelled), periods, date of first payment, and technical references of our payment provider Stripe (customer and subscription ID). Credit card and payment data are collected and processed exclusively by Stripe — they never reach our systems. At purchase we transmit to Stripe your e-mail address, an internal user ID and the selected plan (including the indication of whether it is a Founder plan).

f) E-mail delivery data. For system e-mails (registration, password reset, payment confirmations) we log the recipient address, template, time and delivery status. During delivery, the e-mail (address and content) temporarily resides in our delivery system.

g) Founder record. If you purchase one of the limited Founder offers, we store a small proof record (internal user ID, Stripe customer reference, plan, timestamp — no e-mail, no name). It exists in your interest: it allows us to prove your Founder price guarantee to you at any time — even years later, or if you have deleted your account in the meantime — and ensures that the limit of 100 Founder places is enforced fairly. For these reasons, this record also remains after an account deletion (details in Section 10).

h) Local data on your device. The app stores on your device (browser storage/IndexedDB): your key material, your session, settings, a local copy of your (encrypted) data and, where applicable, unfinished onboarding inputs. This local data does not leave your device in readable form. Note: if you delete browser data or reinstall the app, your local key is removed as well — without your Recovery Key, neither you nor we can restore the data (see Section 12).

i) Technical operations log. The app keeps a technical service log (ops_events) recording certain operational events — e.g. a failed payment, an account deletion or a failed login attempt. An entry consists only of the event type, the time, a short technical code and a few fixed parameters (e.g. selected plan); error messages, inputs, e-mail addresses or IP addresses are never stored and are filtered out technically. Your account appears in it only as an irreversible fingerprint (HMAC with a secret key); attribution to your account is possible only for us, using that key. Only the owner has access, via the database. Entries are deleted automatically after 90 days. Purpose: operational security, troubleshooting and abuse prevention.

j) Feedback. If you send us a message via the feedback function in the app, we store: the type of message (problem/idea), your text, the time, for problem reports optionally the identifier of the affected screen, and a technical context consisting of four fixed items (operating system family, browser family, installed app yes/no, app language). By default, your message is linked neither to your e-mail address nor to your account. Only if you choose "With contact" do we additionally store your e-mail address so that we can reply to you about this message; you can withdraw this consent at any time by asking us to delete it. Feedback messages — unlike your financial data — are not end-to-end encrypted so that we can read them; therefore, do not write any amounts or any personal or sensitive information in them. To prevent spam, we keep a short-lived counter (maximum 3 messages per 24 hours) that contains only an irreversible fingerprint of your account ID, is not linked to your message, and is deleted after 2 days.

4. Purposes and legal bases

We process personal data for the following purposes. The legal bases stated refer to the GDPR where applicable; under the Swiss FADP we rely on the corresponding statutory processing principles.

PurposeDataLegal basis (GDPR)
Providing account and app, synchronisationa, b, c, hContract (Art. 6(1)(b))
Payment processing, subscription managementeContract ((b))
System e-mails (registration, reset, confirmations)fContract ((b))
Security, abuse and fraud preventiondLegitimate interest ((f))
Technical operations log (Section 3 i)iLegitimate interest ((f))
Feedback (message, technical context)jLegitimate interest ((f))
Reply to your feedback (e-mail address)jConsent ((a)), withdrawable at any time
Founder limit and price guaranteegLegitimate interest ((f))
Product analytics (Section 7)c, account-related eventsLegitimate interest ((f))
Website visit measurement (Section 6)technical characteristicsLegitimate interest ((f))
Statutory retention (accounting)e (at Stripe and with us)Legal obligation ((c))

Our legitimate interests in this respect are: security and abuse prevention, the fair enforcement of limited offers, and the improvement and reach measurement of the product.

We currently do not send marketing e-mails. Should we offer this in the future, it will only happen with your prior consent (opt-in), which you can withdraw at any time.

We do not make automated individual decisions within the meaning of Art. 21 FADP or Art. 22 GDPR. The projections in the app are pure computational displays based on your own inputs and have no legal effect.

5. Cookies and local storage

We use no advertising cookies and no tracking services of advertising networks or data brokers. The following are used exclusively:

NameOriginPurposeDuration
__cf_bmCloudflare (security/CDN service)bot protection, technically requiredapprox. 30 minutes
__dplLovable hostingtechnical delivery of the website (deployment), technically required24 hours
session-idVisit measurement (Section 6), first-partycounting of visits30 minutes
Browser storage (localStorage/sessionStorage/IndexedDB)Wertlylogin session, keys, settings, local data copyuntil deleted by you

During payment on checkout.stripe.com, Stripe sets its own technically necessary cookies; Stripe's privacy notices apply to these.

You can block or delete cookies and website data at any time in your browser settings. The technically required storage (session, keys) is necessary for using the app — without it, login and decryption do not work.

6. Website visit measurement

Our hosting platform (Lovable) measures visits to the website with its own first-party script: it counts pages viewed, approximate origin (country, derived from time zone or IP), device type, language and referrer source (which page you came from). A short-lived session cookie (30 minutes) may be set for this. The analysis is aggregated — we see statistics, not identified individuals, and there is no profiling and no sharing with advertising networks. If you do not want this, you can block cookies for wertly.ch and app.wertly.ch in your browser; the website remains usable.

7. Product analytics (in the app)

To improve Wertly, we record sparing, product-related events — deliberately without financial content. Each event consists only of the event name, the time and your account ID, and is stored at most once per account. The table holding these events has technically no field for content — it is not possible to store an amount, a type, a label or a category with an event. In short: we see that you completed the setup — not what you entered into it.

Complete list of the 18 events (as of: 18 September 2026):

EventMeaning
signup_completedregistration completed (e-mail confirmed)
trial_started14-day trial started
first_asset_enteredfirst asset or liability created (without type and amount)
projection_viewednet worth projection viewed for the first time
pwa_installed_androidapp installed on the device (Android / desktop Chrome)
pwa_first_standalone_iosapp first launched from the iPhone home screen
onb_startonboarding started
onb_profile_doneprofile step completed
onb_savings_donesavings step completed
onb_assets_pickedselection of asset categories confirmed (not which ones)
onb_liabs_pickedselection of liability categories confirmed (not which ones)
onb_seq_startform sequence for the selected categories started
onb_seq_skip_allform sequence skipped entirely
onb_finish_openfinal step "create starting point" opened
onb_doneonboarding completed (first monthly snapshot saved)
onb_exitonboarding deliberately left
onb_resume_never"don't ask again" chosen for the onboarding resume card
monthly_update_2_savedmonthly update saved in a second, different month

In addition, we record: one activity marker per day (only the date, no time, no actions; automatic deletion after 12 months) · the origin of your first visit (UTM parameters source, medium, campaign), only for accounts younger than 24 hours · your subscription status (from Stripe) · timestamps of when encrypted records last changed (not their content).

If we add new events, we update this list before their introduction (Section 14). These events are linked to your account and contain no financial content: no amounts, no asset or liability types, no labels, no age, no projections. They do not leave our systems, are not shared with third parties, and are deleted together with your account.

8. Recipients and service providers (processors)

First, the essential point: none of these service providers can read the content of your financial data — it exists everywhere only in encrypted form, and the key stays on your device.

We use the following service providers for operation. Data processing agreements (DPAs) are in place with all of them:

Service providerRegistered office / data locationFunctionData
Lovable (Lovable Labs Inc.) with sub-processor SupabaseData location: EU (Frankfurt); company registered office: USAhosting, database, authenticationaccount data, ciphertext, logs
Lovable e-mail serviceUSA (infrastructure incl. Cloudflare/AWS)sending of system e-mailse-mail address, e-mail content
StripeContracting party: Stripe Payments Europe Ltd., Ireland; parent company: Stripe Inc., USApayment processing, subscription management, receiptse-mail, user ID, plan; payment data directly at Stripe
Cloudflare Inc.USA (global network)CDN, security filter in front of the website and execution of the app's server-side functionsIP, technical access data
Frankfurter (frankfurter.dev)EUdaily exchange ratesonly IP and requested currency pairs — no account or financial data

Beyond this, we only disclose personal data if we are legally obliged to do so (e.g. to authorities on the basis of a legally binding order).

9. Disclosure abroad

Regardless of the country: your encrypted financial content is unreadable everywhere — the key stays on your device.

Your financial data (as ciphertext) and your account data are stored in the EU (Frankfurt region) — under Annex 1 of the Swiss Data Protection Ordinance, the EU provides an adequate level of data protection.

Individual supporting services process data partly in the USA: payment processing (Stripe), the sending of system e-mails, and the security/CDN filter in front of the website. These transfers are based on the Swiss-U.S. Data Privacy Framework (Stripe is certified under it) or on the EU Standard Contractual Clauses with the Swiss addendum as appropriate safeguards within the meaning of Art. 16 para. 2 FADP. A copy of the respective safeguards is available on request.

10. Retention and deletion

During use, we retain your data for as long as your account exists.

When you delete your account (function in the settings), the following happens:

  1. Any existing subscription is first cancelled at Stripe. If this fails, the deletion is aborted — so that no subscription continues to run without an account.
  2. Your financial data (ciphertext), your vault and your account including profile, subscription entries, sessions and all product analytics events (Section 7, incl. activity markers) are deleted from our database immediately and irretrievably. There is no recovery period.
  3. In rolling backups of our database, deleted entries may for technical reasons still exist for a short time; they are overwritten automatically — as a rule within 7 days, at the latest within 30 days. Backups are not used for any other purposes.
  4. The following remain:
    • Payment and receipt data (incl. billing e-mail): retention due to statutory bookkeeping and retention obligations (Art. 958f of the Swiss Code of Obligations: 10 years) — at Stripe and, insofar as we ourselves retain accounting-relevant receipts, also with us.
    • E-mail delivery logs (recipient address, template, delivery status): retained for as long as required for proof of delivery and abuse prevention.
    • Security/audit logs (IP addresses of login events): retained for as long as required for protection against abuse; short-lived infrastructure logs of our providers are overwritten automatically after a few days to weeks.
    • Technical operations log (Section 3 i): entries remain until automatic deletion after 90 days at the latest; after an account deletion, we can practically no longer attribute them to any person.
    • Feedback messages (Section 3 j): are deleted automatically after 6 months at the latest. As they are not linked to your account, they are not deleted automatically upon account deletion; we delete messages containing your e-mail address earlier at any time on request to support@wertly.ch.
    • Founder record (Section 3 g): remains — so that your Founder price guarantee remains provable even after an account deletion and the 100-place limit cannot be circumvented. It contains neither e-mail nor name; an attribution to your person is only possible in connection with the payment records legally retained at Stripe.
    • Local data on your device is not deleted by us automatically — remove it via your browser data or by uninstalling. Without the server and the key, it is unusable for third parties.

11. Your rights

You have the rights under the FADP and — where applicable — the GDPR:

  • Access to the data processed about you (Art. 25 FADP / Art. 15 GDPR) — including the analytics events stored for your account (event names and dates)
  • Rectification of inaccurate data (Art. 32 FADP / Art. 16 GDPR)
  • Erasure (Art. 32 FADP / Art. 17 GDPR) — fastest directly via the account deletion function in the app
  • Data release / portability (Art. 28 FADP / Art. 20 GDPR): via "Export data" in the app you can obtain your data at any time as a machine-readable JSON file — including during the trial and after its expiry
  • Restriction of processing (Art. 18 GDPR, where applicable)
  • Objection to processing based on legitimate interest (Art. 21 GDPR), and withdrawal of any consent given, with effect for the future

Please direct requests to support@wertly.ch. For security, we may require confirmation via your registered e-mail address. Note: we cannot "release" or view the content of your encrypted financial data — it is unreadable to us; use the export function in the app for that.

You can also lodge a complaint with a supervisory authority: in Switzerland with the Federal Data Protection and Information Commissioner (FDPIC), in the EEA with the data protection authority of your place of residence.

12. Data security

  • End-to-end encryption: your financial data is encrypted and decrypted on your device (modern, proven web cryptography). The master key never leaves your device.
  • Recovery Key: when setting up, you receive a recovery key. Keep it safe: without the Recovery Key, your encrypted data cannot be restored by anyone in the event of device loss, browser reset or password loss — not even by us. That is the price of true end-to-end encryption.
  • Transport encryption (TLS) for all connections; server-side access controls (Row Level Security). At the application level, only the owner has access to the database; our hosting providers (Section 8) operate the infrastructure — they, too, see your financial data exclusively as ciphertext.
  • In the event of a data security breach with an expected high risk, we will inform the FDPIC and — where required — the affected persons in accordance with Art. 24 FADP or Art. 33/34 GDPR.

13. Minors

Wertly is intended for persons aged 18 and over. By registering, you confirm that you are of legal age. We do not knowingly process data of minors; we delete such accounts.

14. Changes to this Policy

We will adapt this Privacy Policy if our data processing or the legal situation changes. The version published on wertly.ch at the relevant time applies. In the event of significant changes, we will inform you in the app or by e-mail. This Policy is provided in German and English; in case of discrepancies, the German version prevails.

15. Controller and contact

The controller responsible for data processing in connection with Wertly is:

SPANIK.ECOMMERCE
Owner: Pavel Spanik

c/o Pavel Spanik, Goetzstrasse 5, 8006 Zurich, Switzerland

UID: CHE-320.389.197

E-mail: support@wertly.ch

For any data protection requests — including exercising your rights under Section 11 — you can reach us at support@wertly.ch.

Wertly

Private Swiss wealth projections. From now to retirement.

Product
How it worksPrivacyPricing
Company
AboutContact
Legal
Legal noticePrivacy policyTerms
© 2026 Wertly
EN/DE
Built in Switzerland