Privacy policy
Draft v0.1 (closed beta). Final wording pending attorney review before public launch.
1. Data Controller
The controller of your personal data within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council ("GDPR") is:
- Marcin Rejdych
- TBD before public launch
- Tax ID: TBD before public launch
- Email: rodo@skarbify.pl
You may contact us regarding personal data matters at the email above.
2. Service status — closed beta
Skarbify (https://skarbify.pl) currently operates as a closed beta: access is limited to invited testers. The service is not publicly available or commercially offered. Features may change without prior notice.
3. Personal data we process
| Category | Scope | Source |
|---|---|---|
| Account identification | Email address; optionally display name and avatar | You (at sign-up) |
| Authentication | Magic-link tokens, optionally TOTP secret, recovery codes | System-generated |
| Financial portfolio data | Transactions, balances, instruments, broker accounts, mortgages, financial goals, watchlist, notes | You (manual entry or import) |
| Operational data | Language preference (PL/EN), theme preference, account creation timestamp | Your in-app choices |
| Audit data | Sign-in events, authentication attempts, GDPR requests | System (automatic logging) |
| Technical data | IP address used for rate limiting; hashed, not stored in plaintext | Your HTTP requests |
We do not collect payment data, location data, marketing cookie data, biometric data, or special-category data (Art. 9 GDPR).
4. Purposes and legal bases
| Purpose | Legal basis | Duration |
|---|---|---|
| Provision of the service (sign-up, sign-in, app operation) | Art. 6(1)(b) GDPR (contract performance) | Until account deletion |
| Security (multi-factor authentication, audit log, rate limiting) | Art. 6(1)(f) GDPR (legitimate interest — security) | Until account deletion |
| Implementation of GDPR rights (export, deletion) | Art. 6(1)(c) GDPR (legal obligation) | As requested |
| Account-related communication (login links, confirmations) | Art. 6(1)(b) GDPR | During service provision |
5. Technical and organisational measures (Art. 32 GDPR)
We apply the following protections to your data:
- Column-level PII encryption (AES-256-GCM) in the database — email addresses, display names, avatars, transaction notes, and the full contents of the audit log are stored exclusively in encrypted form.
- Pseudonymisation — email lookups are performed via a deterministic HMAC hash with a separate pepper; plaintext email never appears in search indexes.
- Two-factor authentication (TOTP) — optional; TOTP secrets are encrypted at the row level with master-key version tracking.
- Passwordless authentication — single-use magic links (10 min validity); no passwords are stored.
- Multi-tenant isolation — every operation on financial data runs under PostgreSQL Row-Level Security; a programming mistake cannot expose another user's data.
- Secure HTTP headers — Content-Security-Policy, HSTS, X-Frame-Options, Permissions-Policy.
- EU data residency — all data stored in data centres located within the European Union (Germany).
6. Recipients — sub-processors
We rely on the following sub-processors to provide the service:
| Sub-processor | Function | Location | Transfer basis |
|---|---|---|---|
| Neon Inc. | Hosted PostgreSQL database | Frankfurt (DE) — EU | — |
| Vercel Inc. | Web application and serverless function hosting | Frankfurt (DE) — EU | SCC (Standard Contractual Clauses) for US-headquartered processor |
| Resend Inc. | Email delivery (login links) | EU | SCC for US-headquartered processor |
In the future (before production launch) we plan to add:
- Amazon Web Services (AWS KMS) — master encryption key management,
eu-central-1(Frankfurt) region. Status: planned.
The current sub-processor list is published on this page. We notify users of changes 30 days in advance via the account email.
7. Transfers outside the European Economic Area
Data is stored in the EU (Frankfurt). Some sub-processors are US-registered companies (Vercel, Resend, future AWS) — transfers are based on Standard Contractual Clauses approved by the European Commission (Implementing Decision 2021/914), supplemented by a Transfer Impact Assessment in accordance with the Schrems II judgment (C-311/18).
8. Your rights (Art. 15–22 GDPR)
You have:
- Right of access — the built-in "Export my data" function in account settings generates a JSON/CSV bundle with all your data;
- Right to erasure ("right to be forgotten") — the built-in "Delete account" function in settings; deletion takes effect after a 30-day grace period (cancellable);
- Right to rectification — all fields are editable in-app;
- Right to restriction of processing;
- Right to data portability — JSON/CSV export satisfies this;
- Right to object;
- Right not to be subject to a decision based solely on automated processing — Skarbify makes no such decisions.
To exercise any of the above rights, contact us at rodo@skarbify.pl or use the relevant function in account settings.
You also have the right to lodge a complaint with a supervisory authority — in Poland: the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, https://uodo.gov.pl.
9. Cookies and similar technologies
Skarbify uses only essential cookies required for the service to function:
- authentication session cookie (HttpOnly, Secure, SameSite=Lax),
- language preference cookie (PL/EN),
- theme preference cookie (light/dark/system).
We do not use marketing or tracking cookies, nor third-party analytics beyond those listed below. If we enable Plausible analytics, it operates without cookies and without identifying individual users.
10. Data retention
We retain your data until account deletion. Following a deletion request:
- a 30-day grace period applies (data marked "to delete", account unavailable, decision reversible);
- after 30 days, data is permanently deleted along with all related records (transactions, balances, mortgages, audit log entries concerning your account).
Exception: the system event log may be retained in anonymised form (without account identification) for up to 12 months for security purposes.
11. Changes to this Privacy Policy
We notify users of any material change to this Policy via the account email at least 30 days in advance. Continued use of the service after the changes take effect constitutes acceptance.
12. Contact
For matters relating to personal data protection:
- Email: rodo@skarbify.pl
- Controller: Marcin Rejdych, TBD before public launch