Skip to main content
Privacy

Privacy Policy | Assetli

Privacy Policy for Assetli - How we process your data in compliance with GDPR

Assetli Privacy Policy

Last updated: October 1, 2026
Version: 1.2


1. Data Controller

Ondřej Smutný
Business ID (IČO): 75343533
Registered office: Družstevní 511, 294 41 Dobrovice, Czech Republic
Email: info@assetli.app
Web: https://assetli.app

Given the scope of processing, no Data Protection Officer (DPO) has been appointed. For any questions regarding the protection of personal data, contact info@assetli.app.


2. What Data We Process

2.1 Registration and Profile Data

  • First and last name
  • Email address
  • Hashed password (bcrypt, SALT_ROUNDS=12 — we never store the password in readable form)
  • Registration date, language preference
  • Optionally: phone number, date of birth
  • 2FA configuration (TOTP seed, hashed backup codes)

2.2 Financial Data

This is the most sensitive data we process:

Bank accounts: name, type (checking, savings, investment, credit card, loan, cash), currency, balance, status (active/archived), and optionally the account number, IBAN, and notes. We store the account number, IBAN, and notes in encrypted form (AES-256-GCM).

Transactions: date, amount, description/payee, counterparty and their account, payment symbols, category, tags, type (income/expense/transfer), notes, source, and import batch number. We process statements uploaded for import (CSV, Excel, PDF, XML, and other bank formats) and store only the transactions extracted from them; we do not store the statement file itself. Excel and CSV files are read directly in your browser; PDF and other formats are processed on the server.

Budgets: name, category, limits, period, spending status.

Savings envelopes: name, target amount, current status, contribution history.

Subscriptions: service name, amount, frequency, category, renewal date.

2.3 Investment Data

Stocks and ETFs: brokerage accounts, trades (date, symbol, quantity, price, fees), dividends (amount, withholding tax, ex-date, pay date), live prices (from external market data providers, in particular Yahoo Finance).

Cryptocurrencies: exchange accounts, trades (12+ types including buy, sell, swap, staking), holding positions, live prices (from CoinMarketCap/CoinGecko).

Alternative investments: P2P loans, crowdfunding, commodities, pension products — original value, current value, returns, events.

2.4 Asset Data

Real estate: type, purpose, address, area, purchase price, current value, rental income, expenses, utility readings (electricity, gas, water), appliances with power consumption, photovoltaic panels with production.

Vehicles: type, make, model, year, license plate, VIN, mileage, costs (fuel, insurance, maintenance), service events, valuation.

Valuables: category (16 types), purchase price, current value, depreciation, warranty, condition.

Mortgages and loans: principal, interest rate, installments, link to real estate.

2.5 Shared Expenses Data (Bill Splitting)

Group name, members (name, optionally email), shared expenses, settlements, comments, activity log. When a group is shared via a public link, the data may be visible to persons without an Assetli account.

2.6 Family Legacy Data

Contacts of trusted persons (name, email, relationship), access conditions, encrypted notes (AES-256-GCM), access log. Notes for heirs are encrypted at the database level — not even the Operator has access to them in readable form.

2.7 Payment Data

Payments are processed exclusively by Stripe, Inc. On Assetli's servers we store only: Stripe Customer ID, the last 4 digits of the card, card type, expiration date. We never store card numbers, CVV, or complete payment details.

2.8 Technical and Analytical Data

  • IP addresses and approximate geolocation
  • Browser and device type (User-Agent)
  • Login timestamp
  • Application error and performance logs
  • Account identifier for errors that occur while signed in (no name or e-mail)

2.9 Features Using Artificial Intelligence

Conversations with the AI assistant are stored in the database under the User's account, and the User can delete them at any time. We send the AI provider (Anthropic; OpenAI or Google only if the User has entered their own API key for that provider) only what the given feature needs:

  • AI assistant and weekly review: the User's messages, a financial summary of the active profile, and the results of the tools the model calls.
  • AI transaction categorization: the description and merchant of uncategorized transactions.
  • AI-assisted statement column mapping: only the header and a few sample rows, never the entire statement.
  • Transcription of a scanned statement: the entire scanned statement (PDF), and only if the User explicitly confirms it for the specific file. Before confirmation, we show the User that the statement will be sent to the AI provider, along with the approximate price.
  • Property check and vacation planner: the listing text or the User's input and the data needed to answer.

All AI features are paid from the User's AI credit based on actual usage. Automatic AI categorization after import, which draws on the credit without further prompting, can be enabled only with explicit consent; we record the date and wording of the consent in the consent log (Section 2.12).

2.10 Uploaded Files

Documents, receipts, and photos uploaded to the File Manager are stored in object storage (Vercel Blob or Cloudflare R2, depending on the operating configuration). The files are assigned to the User's account and accessible only through an authenticated API. The files are permanently deleted upon account deletion.

2.11 Google Sheets Add-on (Assetli Finance)

The Assetli Finance add-on for Google Sheets is a separate product covered by its own policy: Privacy Policy for the Google Sheets add-on.

In short: the add-on requires no sign-in, has no connection to an Assetli account, works only in the spreadsheet it is open in, and sends nothing to assetli.app — it has no network permission at all. None of the processors listed in Section 5 are involved, because the add-on transmits no data.

2.12 Statement Import by Email

On the Premium and Max plans, the User can send statements to their own secret email address. We process the sender, subject, and attachments of these messages, the list of allowed senders, and messages from unknown senders held in quarantine. We do not store the statement attachment; we read it in memory and store only the transactions awaiting approval (for no more than 14 days). Mail is received by Resend, which retains a copy of the message, including attachments, for 30 days and does not allow earlier deletion. In the consent log, we record when and with what wording the User consented to automatic import or to the use of AI credit, as well as any withdrawal of that consent; the log serves as evidence in the event of a dispute.

2.13 Anonymous Statistics and Voluntary Statement Samples

When the import cannot recognize a statement with certainty, we store an anonymous record of the table's structure: the column names from the header, the delimiter, the number of columns, the selected bank, and the import result. We do not store any data from the rows or any link to the account; if the header contains anything that looks like data (a date, amount, account number, or email), we store nothing from it. The record is deleted two years after its last occurrence.

The User may voluntarily send us an anonymized sample of a statement so that we can improve the import for their bank. The anonymization takes place in the User's browser (names, descriptions, account numbers, and amounts are replaced); before sending, the User sees the entire text to be sent and must confirm the submission. We store the sample without any link to the account (so it cannot be traced or deleted upon request), and it is deleted automatically after one year.

2.14 Property Check

During a property check, we process the listing text that the User pastes or that the extension reads in their browser, and the data the User enters. Public registers and map services receive only the minimum needed to answer (the address, coordinates, and parcel identification). If the User enters the seller's name and date of birth or company ID, we verify them in the insolvency register; we do not process personal identification numbers. The User is responsible for having a legitimate reason to enter data about a third party. The browser extension has its own policy: Privacy Policy for the browser extension.


3. Cookies and Tracking Technologies

3.1 Cookie Overview

Cookie Provider Purpose Type Validity Period
authjs.session-token Assetli Authentication of the logged-in user Necessary 7 days
authjs.csrf-token Assetli Protection against CSRF attacks Necessary Session
authjs.callback-url Assetli Redirect after login Necessary Session
lang Assetli Language preference Functional 1 year
cookiehub CookieHub Storing the cookie consent choice Necessary 1 year
_ga, _ga_* Google Analytics Anonymized traffic analysis Analytics 2 years
_clck, _clsk Microsoft Clarity Analysis of user behavior (heatmaps) Analytics 1 year / Session

3.2 Cookie Categories

Necessary cookies — required for the application to function (login, security). They cannot be refused.

Analytics cookies — help us understand how users use the application. They are activated only with your consent. You can refuse them at any time in the cookie banner settings.

3.3 Cookie Management

We manage consent for analytics cookies through the CookieHub platform. Analytics scripts (Google Analytics, Microsoft Clarity) are loaded only after consent is granted. You can manage cookies:

  • Through the cookie banner (CookieHub) on your first visit and at any time thereafter
  • In your browser settings
  • By deleting cookies in your browser

4. Purposes of Processing and Legal Basis

Purpose of Processing Legal Basis (GDPR) Data Processed
Provision of the Service (accounts, transactions, budgets) Performance of a contract (Art. 6(1)(b)) Registration, financial, investment, asset data
AI categorization of transactions Performance of a contract (Art. 6(1)(b)) Description and merchant of uncategorized transactions
AI chat assistant Performance of a contract (Art. 6(1)(b)) Conversations, financial snapshot
AI transcription of a scanned statement Consent (Art. 6(1)(a)), given for the specific file The entire scanned statement
Statement import by email Performance of a contract (Art. 6(1)(b)) Sender, subject, and attachments of messages sent to the secret address
Automatic import and automatic AI categorization Consent (Art. 6(1)(a)) Transactions from the statement; entry in the consent log
Consent log Legitimate interest (Art. 6(1)(f)) — evidence in the event of a dispute Type, time, and wording of the consent
Property check Performance of a contract (Art. 6(1)(b)) Listing text, entered data, queries to public registers
Anonymous statistics of unrecognized statements and voluntary samples Legitimate interest (Art. 6(1)(f)) — improving the import; samples only with consent Column names; anonymized sample
Payment processing Performance of a contract (Art. 6(1)(b)) Payment data (via Stripe)
Account security (2FA, rate limiting, brute-force protection) Legitimate interest (Art. 6(1)(f)) IP addresses, login logs
Email notifications (budgets, subscriptions, security) Consent (Art. 6(1)(a)) Email address
Analytics and service improvement Legitimate interest (Art. 6(1)(f)) Anonymized analytics data
Legal obligations (tax records) Legal obligation (Art. 6(1)(c)) Payment records

5. Recipients of Personal Data (Processors)

5.1 Processor Overview

Processor Purpose Data Location Transfer Outside the EU
MongoDB Atlas (MongoDB, Inc.) Database EU (Frankfurt, AWS eu-central-1) No
Cloudflare, Inc. Files (R2), CDN, protection Global Yes — Standard Contractual Clauses
Vercel, Inc. Application hosting (Frankfurt region), object storage for files (Vercel Blob) EU (Frankfurt) / Global Yes — Standard Contractual Clauses
Stripe, Inc. Payment processing EU No (primarily)
Resend, Inc. Sending emails; receiving messages for statement import by email (copy kept for 30 days) USA Yes — Standard Contractual Clauses
Anthropic, PBC AI features (Section 2.9) USA Yes — Standard Contractual Clauses
OpenAI, L.L.C. / Google LLC (Gemini) AI assistant, only with the User's own API key USA Yes — Standard Contractual Clauses
GitHub, Inc. Encrypted daily database backups (30 days), scheduled jobs USA Yes — Standard Contractual Clauses
Google LLC Google Analytics, Google sign-in, reCAPTCHA, web fonts USA Yes — Standard Contractual Clauses
Meta Platforms, Inc. Sign-in with Facebook (only if the User uses it) USA Yes — Standard Contractual Clauses
Microsoft Corp. Clarity (analytics) USA Yes — Standard Contractual Clauses
CookieHub ehf. Cookie consent management (cookie banner) EU/EEA (Iceland) No

5.2 What We Share with AI Providers

The scope for each feature is set out in Section 2.9. We never share login credentials, passwords, or payment information. A complete and continuously updated list of all services that receive any data, including market data and public registers used for the property check, is available on the page Who processes your data.

In the settings, the User may enter their own API key for Anthropic, OpenAI, or Google Gemini — in which case the data is sent directly to the provider without any markup on Assetli's part.

5.3 Market Data

Live prices: external market data providers, in particular Yahoo Finance (stocks and ETFs), CoinMarketCap/CoinGecko (crypto), frankfurter.app — based on the reference exchange rates of the European Central Bank (exchange rates). We do not send any personal data to these providers — only general queries for market data (stock symbol, currency code).

5.4 Wallet by BudgetBakers

During synchronization via WBB, transactions are transferred from WBB to Assetli. WBB is an independent data controller with its own license for accessing banking data via Open Banking. The terms of data processing are governed by the terms of BudgetBakers s.r.o.

5.5 No-Sale-of-Data Statement

We never sell, share, or provide your personal and financial data to third parties for marketing, advertising, or commercial purposes.


6. Data Transfers Outside the EU

Some processing involves the transfer of data to the USA (Anthropic, Resend, Cloudflare, Vercel, GitHub, Google, Microsoft, and where applicable OpenAI and Meta). For these transfers, we use Standard Contractual Clauses (SCC) approved by the European Commission pursuant to Art. 46(2)(c) GDPR. Copies of the SCC are available upon request.


7. Data Retention

Type of Data Retention Period
Registration data For the duration of the account
Financial data (transactions, accounts, investments) For the duration of the account
AI conversations For the duration of the account (the user can delete at any time)
Uploaded files For the duration of the account
Payment records 5 years after the payment is made (Czech tax regulations)
After account deletion — personal data Deleted immediately from the production database; kept in encrypted backups for no more than 30 days
After account deletion — anonymized financial data May be retained for up to 5 years (legal obligations)
Inactive account (typically 12+ months without login) The Operator reserves the right to delete the account after prior email notice (with a deadline for logging in)
Imported statement files and email attachments Not stored; processed in memory
Copies of messages for import by email (at Resend) 30 days from receipt
Transactions awaiting approval (import by email) Deleted immediately after import; unapproved ones after 14 days
Consent log For the duration of the account
Notifications 30 days
Encrypted database backups 30 days
Anonymous statistics of unrecognized statements 2 years from the last occurrence
Voluntarily submitted anonymized statement samples 1 year
Login and error logs 12 months

8. Automated Decision-Making and Profiling

8.1 AI Categorization of Transactions

Transactions are first categorized by rules without artificial intelligence (system rules and the User's own rules). For the remaining transactions, Assetli may use Claude AI models (Anthropic), but only when the User runs or enables it. This processing has no direct legal consequences for the User, can be manually corrected at any time, and is transparent — the User sees the assigned category.

8.2 Financial Score (0–850)

Assetli automatically calculates a financial health score based on 7 components. This score is for informational purposes only, does not affect access to loans or other financial products, and is not shared with third parties.

8.3 Predictions and Analytics

Cash flow predictions, latte factor analysis, lifestyle inflation check, and other analytical functions are automated calculations that are purely informational in nature.

8.4 Right to Human Review

In accordance with Art. 22 GDPR, the User has the right to human review of any automated output. Contact info@assetli.app.


9. Your Rights (GDPR Art. 15–22)

Right How to Exercise It
Right of access (Art. 15) Settings → Data Export (GDPR export in JSON)
Right to rectification (Art. 16) By editing the data in account settings
Right to erasure (Art. 17) Settings → Danger Zone → Delete Account
Right to data portability (Art. 20) Settings → Data Export (complete GDPR export in JSON format)
Right to restriction of processing (Art. 18) Contact info@assetli.app
Right to object (Art. 21) Settings → Privacy, or info@assetli.app
Right to withdraw consent Settings → Notifications, cookie banner

Response deadline: 30 days. For complex requests, this may be extended by a further 60 days with notice.

Supervisory authority: Czech Data Protection Authority (ÚOOÚ), Pplk. Sochora 27, 170 00 Praha 7, posta@uoou.cz, www.uoou.cz


10. Protection of Children

The Service is not intended for children under 15 years of age (in accordance with Section 7 of Act No. 110/2019 Coll.). We do not knowingly collect personal data of children under 15 years of age. If we find that we have collected data from a person under 15 years of age without the consent of a legal guardian, we will delete such data without delay.


11. Security

11.1 Technical Measures

  • Encrypted connections (HTTPS/TLS)
  • Password hashing (bcrypt, SALT_ROUNDS=12)
  • Two-factor authentication (TOTP)
  • Protection against brute-force attacks with automatic account lockout
  • Form protection with reCAPTCHA v3
  • Encryption of sensitive fields (AES-256-GCM): account number, IBAN, and notes for bank accounts, the Wallet by BudgetBakers token, two-factor authentication secrets, custom AI API keys, Family Legacy notes
  • OAuth tokens and API keys stored only as a hash (SHA-256)
  • Encrypted daily database backups (AES-256)
  • Database hosted in the EU (MongoDB Atlas, Frankfurt, AWS eu-central-1)

11.2 Data Breach Notification

In accordance with Art. 33 and 34 GDPR, we will report a security breach to the supervisory authority (ÚOOÚ) within 72 hours of detection. We will inform affected users without undue delay if the breach poses a high risk.

11.3 Disclaimer

Although we implement reasonable measures, no method of data transmission or storage is 100% secure. If you detect unauthorized access to your account, contact us immediately at info@assetli.app.

11.4 Vulnerability Reporting

If you discover a security vulnerability, contact info@assetli.app. We appreciate responsible disclosure of vulnerabilities and will not take legal action against persons who report vulnerabilities in good faith.


12. Rights of Users Outside the EU

12.1 United Kingdom (UK GDPR)

The processing of data of users in the United Kingdom is governed by the UK GDPR and the Data Protection Act 2018. Your rights are similar to those under the EU GDPR. Supervisory authority: Information Commissioner's Office (ICO), www.ico.org.uk.

12.2 California (CCPA/CPRA)

If you are a California resident, you have rights under the CCPA/CPRA:

  • Right to know about the data collected
  • Right to delete personal data
  • Right to correct inaccurate data
  • Right to opt out of the sale/sharing of data — we do not sell or share your data for advertising
  • Right to non-discrimination

Contact info@assetli.app. We will respond within 45 days.

12.3 Other US States

Residents of Colorado, Connecticut, Virginia, and other states with privacy laws may have similar rights. Contact info@assetli.app.


13. Aggregation and Anonymization

We reserve the right to create aggregated and anonymized data for the purpose of improving the Service and training AI models. Aggregated data must not allow the identification of an individual User and is not subject to the GDPR.


14. Changes to This Policy

  • Minor changes: announced on the website
  • Material changes: announced by email at least 30 days in advance
  • For changes requiring consent, we will request new active consent
  • Older versions are archived and available upon request

15. Contact

Ondřej Smutný
Email: info@assetli.app
Web: https://assetli.app
Address: Družstevní 511, 294 41 Dobrovice, Czech Republic


Effective date: October 1, 2026
© 2026 Assetli. All rights reserved.