Last updated: June 2026 · Version 1.0 (Beta)
Pocket Money Advisor ("we", "us", "our") is committed to protecting your personal data in compliance with the EU General Data Protection Regulation (GDPR) and applicable German data protection law (BDSG).
The data controller for this service is:
Pocket Money Advisor
[Legal entity name to be confirmed — pending UG/GmbH formation]
[Address — pending registration]
Email: info@pocketmoneyadvisor.de
| Data | Source | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| Email address, full name, profile picture | Clerk authentication provider (sign-up / OAuth) | Account identification and communication | Art. 6(1)(b) — contract performance |
| Financial goals questionnaire responses | User input on first login | Personalising the dashboard experience | Art. 6(1)(a) — consent |
| Imported bank transaction data (CSV) | User-uploaded CSV export from their bank | Spending analysis, categorisation, insights | Art. 6(1)(a) — explicit consent; Art. 6(1)(b) — service provision |
| App preferences (language, currency, notifications) | Settings page | Personalising your experience | Art. 6(1)(b) — contract performance |
| In-app feedback (page rating, optional comment) | Feedback widget | Product improvement | Art. 6(1)(a) — consent |
| Waitlist sign-up (email, interest areas) | Waitlist form | Notifying you when premium features launch | Art. 6(1)(a) — consent |
| Error and performance data (Sentry) | Automatic — browser and server | Bug detection and reliability | Art. 6(1)(f) — legitimate interest |
| Product usage events (pages visited, features used, import errors), linked to your account email | Automatic — in-app, first-party only (no third-party analytics) | Diagnosing problems and improving the product during the alpha phase | Art. 6(1)(f) — legitimate interest |
| Structural file-layout sample when a bank format is not yet recognised (your name, your address, IBANs and account numbers automatically redacted before storage; the transaction lines are kept, so a shop or payee name printed in a description can remain) | Import of an unrecognised bank file | Adding support for your bank's format | Art. 6(1)(f) — legitimate interest |
All personal data is stored in a PostgreSQL database running on our own server hosted by Hostinger in Frankfurt, Germany — within the European Economic Area. The database accepts connections only from the application on the same machine (it is not reachable from the internet), the server firewall exposes only the web ports, and administrative access is restricted to SSH key authentication. All traffic between your browser and our server is encrypted with TLS (HTTPS, enforced via HSTS).
Authentication is handled by Clerk (clerk.com), which processes your email and identity data. Clerk is GDPR-compliant and can be configured for EU data residency. See Clerk's Privacy Policy.
When you upload a bank statement (CSV, QIF, Excel, PDF, or MT940), the file is processed in memory on our server and never stored as a raw file. Only the parsed and normalised transaction rows (date, description, amount, category) are stored in our database. The original file is discarded immediately after parsing.
One exception: if your bank's file format is not yet recognised, we keep a small structural sample of the file layout so we can add support for it. Your name, your address, IBANs and account numbers are automatically redacted from that sample before it is stored. The transaction lines themselves are kept, because their layout is the whole point of the sample — so a shop or payee name printed in a description can remain in it. The sample is deleted 30 days after we add support for that format, and after 180 days in any case — whether we have added support or not.
Your bank credentials are never requested or stored. Statement import is entirely offline — no connection is made to your bank.
We use Sentry to capture application errors. Error reports may include IP addresses, browser type, and anonymised stack traces. Sentry processes data under a Data Processing Agreement. No financial transaction data is included in error reports.
Diagnostic server logs are automatically redacted of personal data (your name, your address, IBANs, account numbers) before being written, and are automatically deleted after 30 days. Statement text written to a log keeps its transaction lines, so a shop or payee name printed in a description can remain.
We do not sell your personal data. We share data only with the following processors under GDPR-compliant agreements:
No data is transferred outside the EU/EEA.
| Data type | Retention period |
|---|---|
| Account data | Until account deletion |
| Transaction data (CSV imports) | Until account deletion or manual deletion of the import |
| Questionnaire responses | Until account deletion |
| Feedback submissions | Until account deletion, or 2 years after submission |
| Waitlist entries | Until you request removal or premium launches |
| Error logs (Sentry) | 30 days |
| Product usage events | Until account deletion (deleted together with the account) |
| Server logs (PII-redacted) | 30 days |
| Structural file-layout samples (PII-redacted) | 30 days after bank support is added |
You have the following rights:
To exercise any right, email info@pocketmoneyadvisor.de. We will respond within 30 days.
We use localStorage in your browser to store your preferences (language, currency, onboarding status). We use session cookies issued by Clerk for authentication. No marketing or advertising cookies are set.
If you use the optional “Transfers between your own accounts” setting, the name you enter is also kept in localStorage. This is the one item stored there that identifies you, so we state it separately: it is entered by you, it stays in that browser, it is never transmitted to our servers and we never see it, and clearing the field deletes it. It is used only to recognise payments between your own accounts so they are not counted as income.
We will ask for your consent before setting any non-essential cookies (analytics, error tracking).
This service is not directed at users under 18. We do not knowingly collect data from minors.
We may update this policy. We will notify you of material changes via email (if provided) or a prominent notice in the app. Continued use after notification constitutes acceptance.
You have the right to lodge a complaint with the relevant data protection supervisory authority. In Germany, this is the Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) or the relevant state authority (Landesbeauftragter).
Data protection enquiries: info@pocketmoneyadvisor.de