Privacy Policy
How Usavvy handles your data on this website and in the app.
Last updated: June 5, 2026
This Privacy Policy explains what data Usavvy (“we”, “us”) collects, why, and your rights over it. Usavvy is operated by Evgenii Kovalev, who acts as the data controller. For any privacy question or request, contact support@usavvy.app.
1. The short version
- Usavvy never connects to your bank or accesses any financial account. You enter spending manually.
- We collect the minimum needed to run the app and this site.
- Product analytics are opt-in — nothing is sent until you agree.
- To generate AI insights, the expense text you write may be processed by OpenAI (see §4).
- We never sell your personal data.
2. Data we collect
On this website (usavvy.app)
- Anonymous analytics — page views and basic device/browser info, used to understand traffic. Respects your browser's “Do Not Track” signal.
- We do not run a waitlist and do not collect your email through this site unless you choose to email us.
In the Usavvy app
- Financial entries you create — amounts, categories, notes, and dates you type, dictate, or capture from a receipt. This is data you enter; we do not import it from any bank.
- Account & sync data — a user identifier and authentication token so your entries can sync securely across your devices.
- Subscription status — whether you have an active Pro subscription (handled via Apple / RevenueCat). We do not receive your full payment card details.
- Optional product analytics — only if you grant consent during onboarding. You can withdraw consent at any time.
We do not collect bank login credentials, account numbers, or balances — the app has no access to them by design.
3. Why we use your data (legal bases)
| Purpose | Legal basis (GDPR) |
|---|---|
| Provide the app and sync your entries | Performance of a contract |
| Generate AI insights from your entries | Performance of a contract |
| Manage subscriptions | Performance of a contract |
| Product analytics | Your consent |
| Security, fraud and abuse prevention | Legitimate interests |
| Comply with legal obligations | Legal obligation |
4. AI processing
To produce weekly insights, the text of the expenses you log may be sent to our AI provider, OpenAI, which processes it on our behalf to return a summary. We send only what is needed to generate the insight; we do not send bank credentials or account data, because the app holds none. OpenAI acts as a processor under our instructions. We are working to ensure a Data Processing Addendum and limited data-retention terms are in place with OpenAI.
5. Who we share data with (sub-processors)
We use a small number of trusted service providers to run Usavvy. They process data only on our instructions:
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Database & secure backend (stores your entries) | EU / US |
| OpenAI | Generating AI insights from entry text | US |
| Amplitude | Opt-in product analytics | US |
| Cloudflare | Website hosting & security | Global edge |
| Apple | App distribution & in-app purchases | US / Global |
| RevenueCat | Subscription management | US |
We do not sell personal data and do not share it with advertisers.
6. International transfers
Some providers are located in the United States. Where data is transferred outside the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses offered by those providers.
7. How long we keep data
- Your app entries are kept while your account is active. Deleting your account removes them.
- Analytics data is retained in aggregate for a limited period.
- Emails you send us are kept only as long as needed to handle your request.
8. Your rights
Depending on where you live (e.g. under GDPR or CCPA), you have the right to:
- Access the personal data we hold about you;
- Correct or delete it;
- Object to or restrict certain processing;
- Withdraw consent (e.g. turn off analytics) at any time;
- Receive a portable copy of your data;
- Lodge a complaint with your local data protection authority.
To exercise any of these, email support@usavvy.app.
9. Children
Usavvy is not directed to children under 16, and we do not knowingly collect their data.
10. Security
We use industry-standard measures including encryption in transit, secure token storage, and access controls. No system is perfectly secure, but we work to protect your data.
11. Changes to this policy
We may update this policy as the product evolves. We will update the “Last updated” date above and, for material changes, provide a clearer notice.
12. Contact
Evgenii Kovalev — support@usavvy.app