Security & your data

We're early stage but we take security very seriously. Trusting us with your financial data is a huge honour we do not take for granted at all. This is everything that happens with your data.

Where your data lives

All data is stored in Frankfurt, Germany. Our database and servers run in the EU region of our providers Supabase and Render respectively. This means your data is stored securely in a physical data center in Frankfurt. Your data is encrypted at rest and in transit.

What we do with your data

We make our money ONLY when you pay us by subscribing to use our app, and never sell your data. We also never sell even anonymized or aggregated data to data brokers.

We do not use your data to recommend or sell products to you like insurances or electricity providers.

Deleting your data

You can delete your account with us at any time in the Settings page. Once your account is deleted, all your associated data with us is deleted.

Data in our backup databases is still retained for 7 days before being totally deleted as well.

Connecting your bank account

Bank sync runs through our partner, Qwist GmbH, a BaFin-regulated open banking provider (Germany's Federal Financial Supervisory Authority). This means they're licensed and supervised by Germany's financial regulator to securely access bank data, meeting strict standards for security, capital, and compliance.

Your bank login credentials never reach heyFinance. We never see nor store them. They are also never stored with Qwist.

Connecting your bank account securely gives heyFinance read-only access to your data. We cannot initiate payments or move money from your account.

You can also use heyFinance without connecting your bank account directly. You can import your bank statement monthly, or add your transactions manually.

Disconnecting your bank account

You can disconnect your bank account at any time. Once disconnected, we stop pulling new transactions immediately.

Transactions already imported stay in your account. However, you can easily delete them at any time.

Who can see your data

Your data is yours. You can access it by logging in with your password, through Google or Apple authentication, or with biometric login.

If you need help from our support team, there's a toggle on the app to hide all balances to keep your data private.

Right now, only one person, our technical founder, has access to the production database. Data can be accessed if needed for support requests, for fixing issues, or if required by law.

You and your partner

Each partner gets their own login. Personal accounts can be marked as private, but aside from that, everything belongs to the household by default. So, if one of you deletes their personal account, the shared data stays with the household.

Personal accounts you mark as private are not visible to your partner at all — not the account, not its transactions.

Payments

Subscriptions are handled by Stripe, Apple, or Google, depending on where you subscribe. We never see or store your card details.

Artificial Intelligence (AI) usage

We make use of AI to improve the service that we provide. However, you have to opt-in manually. This means these features are turned off by default. We use OpenAI as our AI provider.

  • AI categorization — we send transaction description, purpose and the amount so it can suggest a category from your list of categories.
  • AI insights — we send aggregated data and your country, to provide personalized insights and recommendations.

These features make the experience on our app better, but we also have a robust rule-based transaction matching system and you can create custom rules to auto-categorize your transactions without using AI.

Who we work with

We have third-party companies that process some data on our behalf or partner with us. They are either licensed and heavily regulated providers, we have signed Data Processing Agreements (DPA), or both.

  • Supabase — our database (Frankfurt, EU)
  • Render — our servers (Frankfurt, EU)
  • Vercel — our website
  • Qwist — bank sync
  • Stripe, Apple, Google — payments
  • Resend — emails
  • OpenAI — AI features (opt-in, off by default)

What's next

We said at the top that we're early stage, so we're still working hard to make our security practices even better. Two-factor authentication is the next thing we're adding. After that, logging every time production data is accessed, having an independent security review, and then, having yearly penetration tests.

As we grow, we plan to have a formal certification to prove our commitment to data privacy and security, such as ISO 27001.

Want to know more?

If you have further questions or concerns, you can reach us at security@heyfinance.co.

For the formal detail — legal bases, retention periods, your rights under GDPR — see our privacy policy.