Legal · GDPR
Privacy policy
Last updated: 24 August 2026 · Version 1.1
This translation is provided for convenience. In case of any discrepancy, the Dutch version prevails.
Budgetto runs on a single server in Germany, operated by GY Digital. Your data lives there and nowhere else. This document explains what data is collected, why, who gets to see it, and what your rights are under the GDPR.
Who processes your data
GY Digital is the data controller for Budgetto. That is the trading name under which Romain Goyeau works as a student entrepreneur, and the party running the server your data sits on. No data protection officer has been appointed: the processing is too limited in scale and nature to require one.
GY Digital
Romain Goyeau, student entrepreneur
Mechelen area, Belgium
Email: privacy@gy-digital.be
Phone: +32 492 49 38 04
What data we process
Strictly limited to what the app needs:
Account details
First name, last name, email address, currency preference, and your password in bcrypt-hashed form (unreadable, including to the administrator).
Financial transactions
Everything you enter yourself: name, amount, date, your own notes, category, plus the positions and trades in the Net worth module. We link this to your account ID and to nobody else.
Data through signing in with Google
Only if you use that button. Google then passes us your email address, your first and last name, and an internal Google account ID. No contacts, no calendar, no files, no profile picture that we keep. Sign in with a password and Google is not involved at all.
Session cookie
One cookie (budgetto_session) holding a JWT token, valid for 7 days. More on the cookie page.
IP address (briefly)
Only temporarily in memory for rate limiting (a few minutes at most). It is not stored in the database and not logged.
What we do not process: trackers, analytics, banking details, location, device identifiers, or anything from third parties. We buy no data and link nothing to external profiles.
Why we process it
Performance of the contract (Art. 6(1)(b) GDPR)
Without an account we cannot provide the service. Your transactions are literally what you want to do with the app.
Legitimate interest (Art. 6(1)(f) GDPR)
Rate limits on sign-in and registration to limit abuse. The IP address is neither shared nor kept outside memory.
You are not obliged to provide this data, but without an email address and a password there can be no account and therefore no service.
How long we keep it
For as long as you have an account. When you click Delete account in Settings, your account, all transactions and all categories are removed from the database immediately and permanently. Server backups may hold your data for up to 30 days, after which it is gone as well.
Where your data physically sits
On a single server in a data centre in Germany, so inside the European Union. Hosting runs through Hetzner Online GmbH, in their data centre park in Falkenstein:
Hetzner Online GmbH
Am Datacenter-Park 1, 08223 Falkenstein/Vogtland, Saxony, Germany
Registered office: Industriestr. 25, 91710 Gunzenhausen, Germany
Hetzner provides the machine and the physical security and acts as a processor within the meaning of Article 28 GDPR: they process your data solely on our instructions and may do nothing with it themselves. There is no copy of the database with any other party, in any other country.
Who we share it with
With nobody who does anything with it.
No Google Analytics, no Meta Pixel, no Cloudflare Insights, no CDN for code. Your browser only talks to this server, never to an advertising or analytics service. Your data is never sold, rented or shared for commercial purposes. Below is the full list of parties that get to see anything, and why.
Hetzner (Germany)
The hosting party above. They hold the data physically because the server sits with them, but they only process it on our instructions.
Google (only when signing in with Google)
If you use that button, you are sent to Google to sign in. Google therefore knows you have a Budgetto account and sees your IP address while doing so. For users in Europe, Google Ireland Limited is itself the controller for this, under its own privacy terms. Sign in with email and password and none of this happens.
Yahoo Finance and Frankfurter (only when you invest)
For prices, our server requests a ticker symbol from Yahoo Finance and an exchange rate from the open Frankfurter service, which publishes the daily rates of the European Central Bank. All that goes out is the symbol or the currency pair, such as TTWO or EUR/USD. No name, no email address, no amounts, no quantities, nothing that shows who is asking. Because your browser never contacts those services itself, they do not see your IP address either: they only see our server. Prices are cached in a shared way, so ten people holding the same share generate one request per day between them.
Authorities, only where the law requires it
Under a valid court order we are legally obliged to hand over data. That has never happened. If it does, we will tell you unless the law forbids it.
Transfers outside the European Economic Area
Your account, your transactions and your net worth data stay on the server in Germany and do not leave the EEA. There are two cases where traffic does go outside the EEA, and neither involves data that shows who you are:
- →When fetching share prices, our server contacts Yahoo Finance, a service of a US company. What goes out is a ticker symbol, sent by the server. No personal data.
- →If you sign in with Google, that sign-in runs through Google, which may also process data outside the EEA. Google LLC is certified for this under the EU-US Data Privacy Framework, the European Commission adequacy decision. This only happens if you use that button.
Security
Technical measures running on this instance:
- →Passwords hashed with bcrypt (12 rounds), not reversible.
- →Sessions in httpOnly cookies, unreadable to JavaScript, not stealable through XSS.
- →Rate limits on sign-in, registration and captcha to stop brute force.
- →HTTPS through Caddy (automatic TLS, HSTS headers).
- →Security headers (helmet): X-Frame-Options, X-Content-Type-Options, Referrer-Policy.
- →CAPTCHA and honeypot at registration to keep bots out.
In the event of a data breach that poses a risk to your rights and freedoms, we report it to the Data Protection Authority within 72 hours, and directly to you if the risk is high.
No profiling, no automated decisions
Budgetto makes no decision about you that produces legal effects or significantly affects you, and does no profiling. The monthly forecast is a calculation on your own figures that only you see: no scoring, no credit assessment, no advice going anywhere.
Your rights (GDPR)
You have the following rights under the GDPR. Most of them are built straight into the app. You can always email a request; we reply within 30 days.
Right of access
All the data we hold about you is visible in your account. Nothing is hidden.
Right to rectification
Through Settings you can change your profile details. Transactions and categories can be edited directly on their own page.
Right to erasure (right to be forgotten)
One click in Settings, Delete account. Confirm with your password and everything is gone.
Right to data portability
Export your data yourself as CSV or JSON with the export button in the app, or request it by email.
Right to restriction of processing
Email us if you want your data left in place without further use, for example while a complaint is being handled.
Right to object
Email the administrator if you want to object to processing based on legitimate interest.
Right to lodge a complaint
With the Data Protection Authority, Drukpersstraat 35, 1000 Brussels: gegevensbeschermingsautoriteit.be
Changes to this policy
If we change this document, we raise the version number at the top and set the date to today. For significant changes, a notice appears in the app the next time you sign in.
Contact
Questions, requests or complaints about your data: email privacy@gy-digital.be or call +32 492 49 38 04. More about who is behind it at gy-digital.be.