Privacy Policy
Last updated: September 24, 2026
WealthMgr SAS ("we," "our," or "us"), a Sociedad por Acciones Simplificadas registered in Uruguay, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our personal finance application. Please read this policy carefully. By accessing or using WealthMgr, you agree to the collection and use of information in accordance with this policy.
1. Overview
WealthMgr is a personal finance application built with a local-first architecture. Your financial data — accounts, transactions, budgets, goals, and other records — is stored primarily in a database that lives inside your browser. Cloud synchronization to our servers is optional and available only to paid subscribers. This design means the vast majority of your financial information never leaves your device unless you explicitly enable cloud sync.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Your email address
- A hashed version of your password (we never store your plaintext password)
- Passkey credentials (stored as public-key pairs on our server; the private key remains on your device)
- Two-factor authentication secrets (if enabled)
- Session tokens and authentication metadata
- Your subscription tier (Free, Starter, Growth, or Enterprise)
2.2 Financial Data
Financial data — including accounts, transactions, categories, budgets, goals, bills, automation rules, and projections — is stored in a SQLite database that runs inside your browser using Turso WASM. This data is local to your device by default.
- Free plan users: Financial data is stored entirely in your browser. We have no access to it, and it is never uploaded to our servers.
- Paid plan users: If you enable cloud sync, your financial data is replicated to a per-user Turso Cloud database. Data is encrypted in transit via TLS and encrypted at rest on Turso's infrastructure. WealthMgr is not an end-to-end-encrypted or zero-knowledge system: the encryption keys that protect your cloud-synced data are derived and held on our servers, so WealthMgr — and, in practice, the infrastructure providers listed in §4 — have the technical ability to read the data stored in your cloud database. Free-tier financial data is never uploaded to our servers under any circumstances. For a full technical description, see Security.
2.3 Usage Information
We collect limited usage information to operate and improve the service:
- Server access logs (IP address, request timestamps, requested URLs) maintained by our hosting provider
- API call counts used to enforce tier-based rate limits
- Error reports and crash logs for debugging
- If you use our live-chat support: the messages you exchange with our team, along with basic device and browser metadata and the page you were on.
In addition to the above, WealthMgr collects a small amount of anonymized product measurement to understand onboarding and activation: page views, three one-time lifecycle events (signup complete, first transaction, first insights, recorded at most once per browser), and page-load performance timings. These records carry no user id, email address, account identifier, or any financial content, and they are processed by our hosting provider, Vercel, exactly as described in §4.
We honor privacy signals ourselves: when your browser requests Do Not Track or sends Global Privacy Control, or when you set the va-disable flag in this site's local storage, all page views, lifecycle events, and performance measurements are dropped in your browser before anything is sent. We do not use advertising trackers, and we do not sell your data to third parties.
3. How Your Data is Stored
3.1 Local-First Storage
WealthMgr uses a local-first architecture. Your financial data is stored in a SQLite database running in your browser, powered by the Turso WASM adapter. This database resides in your browser's IndexedDB or OPFS (Origin Private File System) storage. It is not accessible to other websites or applications.
3.2 Optional Cloud Sync
Paid subscribers may enable cloud synchronization. When enabled, your local database is bidirectionally synced with a dedicated per-user Turso Cloud database. This provides:
- Backup and disaster recovery
- Access from multiple devices
- Data portability
Cloud sync can be disabled at any time from your billing settings. When disabled, the cloud copy is eventually cleaned up, and your local data remains untouched.
3.3 Meta Database
Account information (email, password hashes, sessions, passkeys, subscription data) is stored in a separate "meta" database hosted on Turso Cloud. This database contains no financial data — only authentication and account management information.
3.4 Data Migration Integrity
The schema migrations that create your local database are integrity-checked with SHA-256 checksums in transit. Each migration's content is hashed and the hash is verified against an expected value before the migration is applied, so the database structure is consistent across all clients and any alteration between the server and your browser is detected before it takes effect.
4. Third-Party Services and Subprocessors
WealthMgr SAS relies on a small number of third-party services to operate. The entities below act as subprocessors (or, in Paddle's case, merchant of record) for the personal data described. For each, we list the legal entity, the country where it is established, and the data it processes.
Turso — ChiselStrike, Inc. (United States)
Provides the database infrastructure for both the meta database (authentication, sessions) and per-user cloud sync databases (financial data for paid users). Turso processes and stores data encrypted in transit and at rest. Their privacy practices are governed by Turso's Privacy Policy.
Vercel Inc. (United States)
Hosts the WealthMgr web application and handles server-side rendering. Vercel processes HTTP requests and may log IP addresses and request metadata for operational purposes. Vercel also operates the anonymized measurement described in §2.3 on our behalf: Web Analytics (page views and three one-time lifecycle events) and Speed Insights (page-load performance timings). In both products, Vercel identifies a visitor only through a hash derived from the request — discarded within 24 hours — uses no third-party cookies, does not associate events with IP addresses, and stores only coarse attributes (approximate location, device, browser) derived server-side. Their privacy practices are governed by Vercel's Privacy Policy.
Paddle.com Market Limited (United Kingdom)
Handles all payment processing for subscriptions as our merchant of record. We never receive or store your credit card numbers, bank details, or other payment credentials. Paddle processes your email address and payment information. Their privacy practices are governed by Paddle's Privacy Policy.
Better Auth (library, not a subprocessor)
WealthMgr uses Better Auth, an open-source authentication library, to manage user sessions, credentials, passkeys, and two-factor authentication. Better Auth is not a subprocessor: it runs entirely within our infrastructure as bundled application code and does not transmit your data to external servers operated by the Better Auth project.
Live chat — self-hosted Chatwoot (our own infrastructure, not a subprocessor)
WealthMgr offers optional live-chat support through Chatwoot, an open-source support platform that we run on our own infrastructure at support.wealthmgr.app — the same site as the application. It is not a third-party service: no chat data is sent to the Chatwoot project or any other vendor, and the widget sets no third-party or cross-site cookies. If you start a chat, the messages you send are stored in our own support database together with basic device metadata (browser and device type, and the page you were on), used only to answer you and maintain the conversation.
Cross-border data transfers
Several of the subprocessors listed above are established in jurisdictions outside Uruguay — including the United States (ChiselStrike, Inc. and Vercel Inc.) and the United Kingdom (Paddle.com Market Limited). Where we transfer personal data outside Uruguay, or outside the European Economic Area for EU-resident users, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) executed with the subprocessor or — where no other safeguard applies — on your explicit consent. You may request a copy of the safeguards in place, or exercise any related right, by writing to support.wealthmgr@gmail.com.
5. Your Rights
You have the following rights regarding your personal data:
Right to Access
You can view all data associated with your account from the Settings page, including your account information, subscription status, and all financial records stored in your local database.
Right to Export
You can export a complete copy of your financial data as a SQLite file at any time from the "Data Export & Import" section of your Settings. This export contains your entire local database in a portable, open format.
Right to Deletion
You may permanently delete your account and all associated server-side data from the "Danger Zone" section of your Settings. Deletion removes:
- Your account credentials and sessions
- Your cloud sync database (if applicable)
- Any active subscription (canceled immediately)
- All passkeys and authentication secrets
Note: Local browser data on your device is not removed by account deletion. You can clear this data manually through your browser's storage settings, or it will be removed automatically when you clear your browser data.
Right to Rectification
You can update your email address, password, and passkeys at any time from the Settings page. Financial records can be edited directly within the application.
6. Data Retention
Account Data
Account information is retained for as long as your account is active. When you delete your account, all server-side data is removed within 30 days.
Financial Data (Cloud Sync)
If you disable cloud sync or cancel your subscription, your cloud database is retained for up to 90 days to allow for accidental cancellation recovery. After this period, it is permanently deleted. Your local data is never affected by subscription changes.
Financial Data (Local)
Local browser data persists indefinitely until you clear your browser storage, uninstall the browser, or delete the data manually. We have no ability to remotely delete data stored in your browser.
Billing Records
Paddle retains transaction records as required by applicable tax and financial regulations. We retain references to subscription transactions (without payment details) for the life of your account.
7. Cookies
WealthMgr SAS uses essential session cookies to maintain your authenticated session. These cookies:
- Are strictly necessary for the application to function
- Are scoped to the WealthMgr domain and are not shared with third parties
- Expire when your session ends or after a fixed period of inactivity
- Do not contain personal data beyond a session identifier
If you use our live-chat support, the widget sets one small first-party cookie on our own domain that merely remembers your support conversation so it is not lost between pages, and keeps the widget's state in local storage on our support subdomain; it carries no advertising or cross-site identifier. The measurement scripts described in §2.3 and §4 use no third-party cookies and no tracking pixels. Like most applications, WealthMgr also keeps a few small flags in your browser's local storage — for example, one flag per lifecycle event so each is recorded at most once per browser, a flag recording that you loaded sample data on this device, and the va-disable flag if you set it yourself to opt out of measurement. These flags are non-identifying, contain no financial data, and stay on your device until you clear your browser storage. No consent banner is required because we set no cookies for advertising or cross-site tracking, and the session cookie, the live-chat conversation cookie, and the local-storage flags are strictly operational.
8. Security Measures
We take the security of your data seriously. Important context: WealthMgr is not an end-to-end-encrypted or zero-knowledge system. The encryption keys that protect cloud-synced data are derived and held on our servers, and free-tier financial data is never uploaded to our servers under any circumstances. The following measures are in place:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS/HTTPS.
- Encryption at rest: Cloud databases are encrypted at rest by our infrastructure providers.
- Password hashing: Passwords are hashed using strong, industry-standard algorithms. We never store plaintext passwords.
- Passkey authentication: Passkeys use public-key cryptography. The private key never leaves your device.
- Two-factor authentication: Optional TOTP-based 2FA provides an additional layer of protection for password-based accounts.
- Integrity-checked migrations: Database schema migrations are integrity-checked with SHA-256 checksums in transit, so any alteration between the server and your browser is detected before the migration is applied.
- Server-only code isolation: Server-side code (database access, API keys, secrets) is physically separated from client code and cannot be accessed from the browser.
- Per-user databases: Each paid user's cloud sync data is stored in a dedicated database, providing logical isolation.
While we implement robust security measures, no system is completely secure. We encourage you to use strong passwords, enable two-factor authentication, and keep your browser and device up to date.
9. Children's Privacy
WealthMgr SAS is not directed at children under the age of 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete that information.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:
- Updating the "Last updated" date at the top of this page
- Posting a prominent notice within the application
- Sending an email to the address associated with your account (for material changes)
We encourage you to review this Privacy Policy periodically. Your continued use of WealthMgr after changes are posted constitutes acceptance of the updated policy.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
We will respond to legitimate requests within 30 days. If you have an unresolved concern about our data practices, you may have the right to lodge a complaint with your local data protection authority.
© 2026 WealthMgr SAS. All rights reserved.