Wealth Balance

Privacy Policy

This Privacy Policy explains how the operator of the Wealance service (“Wealance”, “we”, “us”, “our”) collects, uses, stores, protects and discloses personal data when you use wealance.com, the Wealance application and related services (together, the “Service”).

Wealance is currently provided free of charge. We do not charge for the Service, we do not show advertising, and we do not monetise your data in any way.

Wealance is a personal financial organisation and planning tool. You may choose to store information about your income, expenses, budgets, assets, liabilities, investments, projects and other financial matters in the Service (“Financial Content”).

Three commitments up front:

1. Who We Are

The data controller responsible for the processing described in this Policy is the operator of wealance.com (“Wealance”).

Wealance is operated privately from Ukraine. It is currently a free, independent service and is not operated by a registered company.

Privacy contact: privacy@wealance.com — this is the effective contact channel for all matters in this Policy, including requests about your data.

2. Scope

This Policy applies to personal data processed through the Wealance website, application, account system, customer support and related infrastructure. It does not apply to third-party websites or services you access independently of Wealance.

Your use of the Service is also governed by our Terms of Service.

The demonstration portfolio available on the website without registration contains fictitious sample data created by Wealance and does not relate to the Financial Content of any user.

3. Personal Data We Collect

3.1 Account information

When you create or maintain a Wealance account, we process: your name; your email address; your account identifier; your password in cryptographically hashed form (never in readable form); your encrypted two-factor authentication secret; account creation and modification timestamps; most recent sign-in information; and account status and security settings.

3.2 Demographic information

When you create an account, we ask for your age and gender. We collect age as a plain number only — we do not ask for or store your date of birth. The stored age is automatically increased by one each year from the date of registration so that it remains approximately current. For gender, you may always select “prefer not to say”; choosing this option does not limit your use of the Service in any way.

We use this information to confirm that you meet the minimum age requirement for the Service (see Section 18) and for internal, aggregated statistics about our user base that help us understand and improve the Service. Demographic information is not used for advertising, is not combined with your Financial Content for profiling, and is not shared with third parties.

3.3 Financial Content you provide

Wealance stores the financial information you voluntarily enter into the Service, which may include budgets, income sources, expense categories, financial amounts, portfolios, asset values, investments, liabilities and debts, projects, planned payments, savings goals, financial schedules, and the names and descriptions you assign to them.

We do not connect to your bank account, do not import bank statements, and never ask for online banking credentials, payment card numbers or bank account details as part of your Financial Content.

3.4 Free-form fields

Some parts of the Service allow custom names, labels and descriptions. Please do not use these fields to store information that is not necessary for your use of Wealance — in particular special categories of personal data such as medical information, credentials or passwords for other services, government identification numbers, or information revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, or a person’s sex life or sexual orientation. Wealance is not designed for storing such information.

3.5 Session, device and security information

To operate and protect your account, we automatically process: IP address; date and time of access; browser, platform and user-agent information; and session identifiers.

For administrator accounts we additionally keep a security log of account events — sign-in, sign-out, failed sign-in attempts, password and email changes, two-factor authentication events, session revocation, and security-related administrative actions — each with the IP address and user agent of the request. Ordinary accounts are not recorded in that log.

For active sessions we derive an approximate country and city from the IP address so that you can recognise unfamiliar sessions in Account Settings. We do not use this location information for advertising or profiling.

3.6 Rate limiting and abuse prevention

To prevent brute-force attacks and automated abuse, we temporarily process identifiers such as an IP address or email address together with counters of recent attempts.

3.7 Customer support

If you contact us, we process your email address, the contents of your message, any information you choose to provide, the IP address associated with the request where applicable, and technical information necessary to investigate it.

Wealance is currently free of charge, so we do not collect any payment or billing information. If paid features are introduced in the future, this Policy will be updated before launch to describe the payment provider and the billing data involved.

4. Why We Process Personal Data and on What Legal Basis

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

We do not profile you and we make no automated decisions that produce legal or similarly significant effects concerning you.

5. How We Treat Your Financial Content

Your Financial Content belongs to you. We process it only to provide and maintain the Service.

Wealance staff do not view, edit or otherwise interfere with the Financial Content in your account in the ordinary course of operating the Service. Administrative tools are not used to browse or modify users’ portfolios, budgets or other Financial Content. We access Financial Content only in narrow, exceptional cases: when you ask us to (for example, to investigate a support issue in your account); when it is strictly necessary to investigate a security incident, abuse, a suspected violation of our Terms of Service or a technical fault affecting data integrity; or when the law requires it. Any such access is limited to what is necessary for the specific purpose and is subject to our security logging of administrative actions.

We do not sell or rent Financial Content. We do not provide it to advertising networks or data brokers. We do not use it for behavioural advertising. We do not use the amounts, portfolios, budgets or debts you enter to determine your eligibility for credit, insurance, employment, housing or any other product or service.

Service providers may process limited data on our behalf only where reasonably necessary to provide infrastructure, security or communications used by Wealance, and subject to appropriate contractual and confidentiality requirements where required by law.

6. Cookies and Similar Technologies

Wealance uses only strictly necessary technologies in the browser — the Service cannot function securely without them: authentication and session cookies; a persistent “remember me” token if you choose that option; security technologies necessary to prevent automated abuse; and local browser storage required for application functionality.

Wealance does not use analytics or advertising cookies, or cross-site behavioural advertising technologies. Because we set no optional cookies, there is no consent banner on the site.

If our use of cookies changes, we will update this Policy and implement a consent mechanism before any such technology is introduced.

7. Service Providers and Other Recipients

We use a limited number of service providers, each of which may process personal data only to the extent reasonably necessary for its service:

Everything else the Service needs — fonts, stylesheets, scripts, icons — is served from our own infrastructure.

8. We Do Not Sell Personal Data

We do not sell personal data for money or other consideration, and we do not share personal data for cross-context behavioural advertising.

If the privacy law of your place of residence gives you a right to opt out of the “sale” or “sharing” of personal information as those terms are defined by that law, you may exercise it by contacting privacy@wealance.com. Where applicable law requires us to honour a recognised universal opt-out signal (such as Global Privacy Control), we will do so.

9. Legal Requests and Disclosure to Authorities

We disclose personal data to authorities only where we reasonably believe disclosure is required by applicable law, a valid court order or another legally binding governmental request. Where legally permitted and practicable, we review requests for validity and seek to disclose only the information the request requires.

We may also process or disclose information where necessary to protect the rights, property or safety of Wealance, our users or others, to investigate fraud or security incidents, or to establish, exercise or defend legal claims.

10. International Processing

Wealance is operated from Ukraine and our primary infrastructure is located in Ukraine. If you access the Service from another country, including a country in the European Economic Area or the United Kingdom, your personal data may therefore be processed in Ukraine. Some service providers may process information in other countries.

Where applicable data protection law requires safeguards for an international transfer of personal data, we rely on legally recognised safeguards or on providers offering appropriate contractual protections. You may contact us for more information about the safeguards applicable to a particular transfer.

11. Data Retention

We keep personal data only as long as reasonably necessary for the purposes described in this Policy or as required by law:

Backups

Personal data may remain temporarily in backup copies after deletion from active systems. Backups are created daily and stored on a separate, access-restricted backup server. Backup copies are rotated and deleted automatically upon expiration of the retention period:

No backup copies are retained beyond these periods. Backup copies are not used for ordinary business purposes. If a backup must be restored after a technical incident, previously completed deletion requests will be reapplied where technically required.

12. Security

We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access. These include: HTTPS/TLS encryption in transit; cryptographic password hashing; encrypted storage of two-factor authentication secrets; mandatory two-factor authentication for all user accounts; a visible session list with remote session revocation; rate limiting and abuse prevention; access controls and restricted administrative access; and logging of security-relevant events. The application’s technical logs do not contain the amounts, names or descriptions entered by users.

Access to personal data is limited to persons and providers who reasonably need it for operational, security, support or legal purposes. We review our security measures regularly in light of the risks associated with the data we process.

No internet-based service can be guaranteed to be completely secure, and we do not claim otherwise. Nothing in this Policy excludes or limits any responsibility, right or remedy that cannot lawfully be excluded or limited under applicable law.

13. Personal Data Breaches

If we become aware of a personal data breach, we will investigate and take reasonable steps to contain and remediate it. Where required by applicable law, we will notify the competent supervisory authority within the legally required timeframe, and notify affected users with the information required by law, including recommended protective steps. We maintain records of personal data breaches where required.

14. Your Privacy Rights

Regardless of where you live, we intend to make the following core controls available where reasonably practicable:

Depending on applicable law, you may also have the right to restrict or object to certain processing, withdraw consent where processing is based on consent, and complain to a competent data protection authority. Where the GDPR applies, you may have the rights set out in Articles 15–22 GDPR, subject to the conditions provided by law.

Send requests to privacy@wealance.com, preferably from the email address your account uses. We may take reasonable steps to verify your identity before acting on a request, and we respond within the period required by applicable law (under the GDPR, normally within one month).

We will not discriminate against you for exercising a privacy right protected by applicable law.

15. European Economic Area Users

If the GDPR applies to our processing of your personal data, you may lodge a complaint with the supervisory authority of the EEA country where you live, work or where you believe an infringement occurred. You may contact us first at privacy@wealance.com, but doing so does not limit your right to contact a supervisory authority.

16. United Kingdom Users

If UK data protection law applies, you may have rights under the UK GDPR and the Data Protection Act 2018, and you may raise a complaint with the UK Information Commissioner’s Office.

17. Ukrainian Users

We process personal data in accordance with the Law of Ukraine “On Personal Data Protection” No. 2297-VI and other applicable Ukrainian law. You may contact us to exercise your rights under Ukrainian law or submit a complaint to the Ukrainian Parliament Commissioner for Human Rights, the authority responsible for personal data protection.

18. Children

Wealance is intended for adults. The Service is not intended for persons under 18 years of age, and we do not knowingly permit children to create accounts. The age you provide at registration is used to enforce this requirement: registration is not available to persons who indicate an age under 18. If you believe a person under 18 has provided personal data to Wealance, contact privacy@wealance.com and we will investigate and, where appropriate, delete the information.

19. Business Transfers

If Wealance or substantially all of the business or assets associated with the Service are involved in a merger, acquisition, financing, restructuring or sale, personal data may be transferred as part of that transaction where permitted by applicable law. Any successor will be required to handle personal data consistently with applicable data protection requirements. Where required by law, we will notify users of a material change in the identity of the controller or in the purposes of processing.

20. Changes to This Policy

We may update this Policy when the Service, our processing practices, our service providers or legal requirements change. The “Last updated” date at the top shows the most recent revision. For material changes affecting how we process Financial Content or other personal data, we will provide additional notice inside the application, by email or by another appropriate method where required. We will not materially reduce protections applicable to previously collected Financial Content without notice and any additional steps required by law.

21. Contact

Operator of wealance.com (“Wealance”)
Ukraine
Email: privacy@wealance.com
Website: wealance.com