Who processes your data
Every third party that receives any of your data, what exactly it receives, and when. Maintained from the code, not from a privacy template.
Last updated: September 16, 2026
This list was compiled by reading every outbound call in the application code on the date above. It names the service, what it receives, and under which condition. If you find an outbound call that is not here, write to info@assetli.app.
Always, for every user
| Service | What it receives | Why |
|---|---|---|
| Vercel (Frankfurt) | Every request to the app: method, path, status, timing, your IP; output of server functions (error messages) | Hosting of the application and API |
| MongoDB Atlas | All application data | Database |
| Vercel Blob or Cloudflare R2 | Files you upload: statements, photos, documents | Object storage; which one is used depends on the deployment configuration |
| Cloudflare R2 | Nothing from you; the app downloads public reference data (price lists, statistics) from it | Reference data packs |
| GitHub | A daily database dump, encrypted with AES-256 before upload, kept 30 days; scheduled jobs (notifications, price-list ingestion) run on GitHub Actions with database access | Backups and scheduled jobs |
| jsDelivr | Your IP and browser headers when it serves script files, like any CDN | Script delivery |
When you pay
| Service | What it receives |
|---|---|
| Stripe | Your email, name and payment details. Card numbers never pass through Assetli. Payment records stay with Stripe under its own retention rules. |
When Assetli emails you
| Service | What it receives |
|---|---|
| Resend | Your email address, the subject and body of the message, and its language. A notification email carries the same text as the in-app notification, so a budget alert includes the amounts it mentions. |
When you sign in or send a form
| Service | What it receives |
|---|---|
| Your Google account identity if you sign in with Google. On the sign-in, sign-up, contact and roadmap forms, reCAPTCHA sends Google browser signals to tell humans from bots. | |
| Your Facebook account identity, only if you sign in with Facebook. | |
| ip-api.com | The IP address of a Family Legacy contact when they request access, to detect their country and flag VPN or hosting addresses. Only the IP is sent. The free tier of this service does not offer TLS, so the request travels over plain HTTP. |
On the website, after cookie consent
| Service | What it receives |
|---|---|
| Google Analytics | Page views and interactions on the website |
| Microsoft Clarity | Page views and session recordings on the website |
| CookieHub | Your consent choice |
| Better Stack | Loads the status page embedded at /status. The status line in the footer asks our server, not Better Stack — your browser never contacts it |
| Google Fonts | Your IP and browser headers when the browser downloads web fonts |
None of these see API traffic or the MCP connection.
When you use AI features
| Service | What it receives | Which feature |
|---|---|---|
| Anthropic | Your messages, the financial snapshot of the active profile and the results of the tools the model calls | In-app assistant, weekly review |
| Anthropic | Description and merchant of uncategorised transactions | AI categorisation (opt-in) |
| Anthropic | The header row and a few sample rows of a CSV, never the whole statement | Assisted column mapping on import |
| Anthropic | The listing text, the facts extracted from it and the protocol; optionally a scanned zoning plan you chose to have read | Property check |
| Anthropic | Your inputs to the planner | Vacation planner suggestions |
| OpenAI or Google | The same data as the in-app assistant sends to Anthropic, only if you entered your own API key for that provider and the Assetli budget is exhausted | In-app assistant with your own key |
The MCP connection sends nothing to any AI provider from our side. Your AI client (Claude, ChatGPT, Gemini) receives the tool results directly; see Security and data flow.
Market data
| Service | What it receives |
|---|---|
| Alpha Vantage, Tiingo, Twelve Data, Yahoo Finance, Finnhub, EOD Historical Data, Marketstack | Ticker symbols of the stocks and ETFs you hold. Never quantities or values. |
| CoinMarketCap, CoinGecko | Symbols of the cryptocurrencies you hold |
| frankfurter.app | Currency codes, for ECB exchange rates |
Fuel and electricity prices for the vehicle calculator are static tables in the application; no query is made.
Only if you switch it on
| Service | What it receives |
|---|---|
| Wallet by BudgetBakers | The Wallet API token you pasted, on every sync. Assetli reads your Wallet records and never writes to Wallet. |
| Claude, ChatGPT, Gemini (MCP) | Results of the tools your AI client calls, under the scope you granted |
When you run a property check
These sources are queried only during a check, with the minimum needed to answer one question. The listing portal itself is never contacted by the server.
| Source | What it receives |
|---|---|
| OpenStreetMap Nominatim and Overpass | The address, to obtain coordinates; the coordinates, to list amenities around the point |
| Wikidata | The municipality name, for demographics |
| ČÚZK (RÚIAN, ArcGIS) | The address and parcel identification |
| SPÚ (BPEJ), ČGS (radon, landslides), HEIS VÚV (floods), IPR Praha (noise), NGÚP (zoning) | The coordinates of the point |
| ARES | The name of the owners’ association or company and the street |
| ISIR insolvency register | The seller’s name and date of birth, or company ID, as you typed them. The birth number is never sent and cannot be entered. |
A check run without an account is cached for 7 days by a fingerprint of the listing text, so the same listing pasted by ten people is analysed once.
What is not on this list
No error-tracking service, no advertising network, no data broker, no bank API. There is no server-side fetching of listing pages.