Privacy Policy
Last Updated: August 21, 2026
Who We Are
SuperWallet is a personal-finance application developed and operated by Rafael Miziara, trading as RM30, based in Italy. For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller for the personal data described in this policy.
You can reach us at any time at support@mysuperwallet.app.
This Privacy Policy explains what we collect when you use the SuperWallet mobile app and the mysuperwallet.app website, why we collect it, who else processes it, and what control you have over it.
Information We Collect
Information You Give Us
- Account information — your email address, display name, and (optionally) a profile photo. If you sign in with Google or Apple, we receive the identity token from that provider and the email address associated with it. We never receive or store your Google or Apple password.
- Authentication credentials — if you sign up with email and password, your password is handled and stored by Firebase Authentication in hashed form. We never see it.
- Financial records you enter — transactions (amount, date, description, currency), wallets and their balances, categories, budgets, goals, SuperBoxes and their custom fields, recurring templates, tags, and reimbursement links. SuperWallet does not connect to your bank; everything in your books is there because you or the assistant put it there.
- People and groups you create — names and optional avatars of people you record in order to attribute spending (for example a flatmate you split bills with). These are private labels inside your own account. They are not user accounts, they are never contacted, and they are never shown to anyone but you. Only add details you are comfortable storing on someone else's behalf.
- Assistant messages — the sentences you type into the AI assistant, and the transaction proposals it returns. See The AI Assistant below.
- Support correspondence — anything you send us by email.
Information Collected Automatically
- Device and app information — device model, operating system version, and app version, collected as context on crash and error reports.
- Diagnostics and crash reports — stack traces, error messages, and a sample of performance traces, sent to Sentry when the app misbehaves. We strip the email address from these reports before they are sent.
- Device attestation — Firebase App Check uses Apple App Attest (iOS) and Google Play Integrity (Android) to confirm that requests come from a genuine, unmodified copy of SuperWallet. This produces a short-lived attestation token; it does not identify you or your device to us.
What We Do Not Collect
- We do not use an advertising or analytics SDK. There is no Firebase Analytics, no ad identifier, no tracking pixel, and no cross-app or cross-site tracking in SuperWallet.
- We do not collect your contacts, precise location, photos (beyond a profile picture you deliberately choose), or health data.
- We do not sell or rent personal data to anyone, and we do not share it with advertisers or data brokers.
The AI Assistant
SuperWallet's assistant turns a sentence like "spent 12,50 € on lunch yesterday from my main wallet" into a transaction proposal. This is the one feature that sends your data to a third-party AI provider, so we want to be explicit about it.
- What is sent. When you send a message to the assistant, we transmit: the text of your message, the last few messages in that conversation (a rolling window of five), today's date, and the names of your wallets and categories so the assistant can match what you meant to your real setup. Your balances, your full transaction history, your email address, and your name are not sent.
- Who processes it. The request goes to our agents service hosted on Mastra Cloud, which passes it to Anthropic for processing by the Claude model. Anthropic acts as our processor under an API agreement.
- It is not used to train models. Data submitted through the Anthropic API is not used to train Anthropic's models.
- What is stored. Assistant conversations are stored in our agents service's database so a conversation can continue across messages, scoped strictly to your account. Operational traces are sent to Mastra's platform dashboard with sensitive values filtered out.
- Where it is processed. Mastra Cloud and Anthropic may process this data outside the European Economic Area, including in the United States. These transfers are covered by the Standard Contractual Clauses adopted by the European Commission.
- Nothing is saved without you. The assistant only ever proposes a transaction. It cannot write to your books until you tap Confirm.
- You can avoid it entirely. The assistant is optional. If you never open it, none of your data is ever sent to an AI provider — every other SuperWallet feature works without it.
How We Use Your Information, and Our Legal Basis
| What we do | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and maintain your account, sync your data across devices | To provide the service you signed up for | Performance of a contract |
| Store and display the financial records you enter | Core function of the app | Performance of a contract |
| Process your assistant messages to produce transaction proposals | You chose to use an optional feature | Performance of a contract |
| Refresh daily exchange rates | To show your totals in your home currency | Performance of a contract |
| Verify that requests come from a genuine app install | To protect your account and our systems from abuse | Legitimate interest |
| Collect crash reports and diagnostics | To find and fix bugs and keep the app stable | Legitimate interest |
| Answer your support emails | To help you | Legitimate interest |
| Notify you of material changes to the service or these terms | To keep you informed | Legal obligation / legitimate interest |
We do not use your financial data for profiling, credit scoring, or automated decision-making that produces legal effects.
Where Your Data Is Stored
Your account and all the records you enter live in Firebase (Google Cloud), in the europe-west1 region (Belgium, European Union). Cloud Functions and Cloud Storage for your profile photo run in the same region.
Two categories of data are processed outside the EEA: assistant conversations (see above) and crash reports (Sentry). Both are covered by Standard Contractual Clauses.
We protect data in transit with HTTPS/TLS and at rest with the encryption Google Cloud applies to Firestore and Cloud Storage. Access to your records is enforced by Firestore Security Rules, which scope every document to its authenticated owner.
Third-Party Services
| Service | What it does | Their privacy policy |
|---|---|---|
| Firebase / Google Cloud | Authentication, database, cloud functions, file storage, App Check | firebase.google.com/support/privacy |
| Google Sign-In | Optional sign-in method | policies.google.com/privacy |
| Apple Sign-In | Optional sign-in method | apple.com/legal/privacy |
| Anthropic | AI model behind the assistant | anthropic.com/legal/privacy |
| Mastra Cloud | Hosts our agents service | mastra.ai/privacy-policy |
| Sentry | Crash and error reporting | sentry.io/privacy |
| ExchangeRate-API | Daily currency exchange rates (no personal data is sent) | exchangerate-api.com/terms |
| Vercel | Hosts the mysuperwallet.app website | vercel.com/legal/privacy-policy |
How Long We Keep It
- Account data is kept for as long as your account exists.
- Deleted accounts — when you delete your account, your authentication record, your Firestore documents, and your stored files are erased automatically. Residual copies in encrypted backups are removed within 30 days.
- Assistant conversations are kept only as long as needed to run the feature, and are deleted with your account.
- Crash reports are retained by Sentry for up to 90 days.
Your Rights
Under the GDPR you have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate data. Most of it you can edit directly in the app.
- Erasure — delete your account and your data.
- Restriction — ask us to pause certain processing.
- Portability — receive your data in a structured, machine-readable format.
- Object — object to processing we base on legitimate interest.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
To exercise any of these, email support@mysuperwallet.app. We will respond within one month.
You also have the right to lodge a complaint with a supervisory authority — in Italy, the Garante per la protezione dei dati personali — or with the authority in your country of residence.
Deleting Your Account
You can delete your account and everything in it from Profile → Account inside the app, or by emailing us. Deletion is irreversible: your transactions, wallets, budgets, goals, boxes, people, and profile photo are removed along with your login.
Children's Privacy
SuperWallet is not intended for anyone under 16. We do not knowingly collect personal data from children under 16, and we do not offer a parental-consent mechanism. If you believe a child under 16 has created an account, contact us at support@mysuperwallet.app and we will delete it.
California Residents (CCPA/CPRA)
If you live in California, you have the right to know what personal information we collect and why, to request its deletion, to correct it, and not to be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding twelve months. To exercise these rights, email support@mysuperwallet.app.
Changes to This Policy
We may update this policy to reflect changes in the app, our processors, or the law. When a change is material we will notify you in the app or by email before it takes effect, and we will always update the "Last Updated" date above. Continuing to use SuperWallet after a change takes effect means you accept the updated policy.
Contact
- Email: support@mysuperwallet.app
- Website: https://mysuperwallet.app
- Controller: Rafael Miziara (RM30), Italy