Privacy Policy
Last updated: September 11, 2026
This Privacy Policy describes what personal data we process when you use Whallet (wallet.whilehaus.net), how we use it, who we share it with, and what rights you have. The data controller is Martin Bonafede, Argentine tax ID (CUIT) 20-33215496-7, registered under the simplified tax regime (monotributo), at Av. Rivadavia 5785, floor 15, apartment 1, City of Buenos Aires (postcode 1406), Argentina, trading as Whilehaus. Contact: hola@whilehaus.net.
The short version: your financial data is yours. We store it to show it to you, we do not sell it, we do not use it for advertising, and we do not train AI models with it.
1. What data we process
- Account data: email, name (if you provide it), password (stored as a hash, never in plain text) and, if you sign in with Google or GitHub, the identifier and email that provider shares with us.
- Financial content entered by you or your authorized agents: accounts, transactions, balances, budgets, investments, notes and receipts. This is the most sensitive category and we handle it with the greatest care.
- Subscription and payment data: which plan you have, subscription status and charge metadata. Your card details are processed by Mercado Pago or Dodo Payments; they never reach our servers.
- Technical and usage data: IP address, device and browser type, access and error logs. We use them for security and to keep the Service working.
- Support: the messages you send us when you write to us.
If you sign in with Google, the sign-in goes through the Google application registered under the name Whilehaus (which is why Google’s consent screen says Whilehaus), and the only permissions it requests for Whallet are openid and email: identifying your account and learning your email address in order to create the session. Whallet does not request access to your Google Drive, your calendar or any other data in your Google account. What we receive from Google is used for that alone, is not shared or sold, is not used for advertising or to develop, improve or train artificial intelligence models, and is not read by anyone, in line with the Google API Services User Data Policy and its Limited Use requirements. You can revoke access at any time at https://myaccount.google.com/permissions.
2. What we use it for (and on what basis)
- Providing you the Service: storing and displaying your data, calculating totals and summaries, syncing exchange rates and prices. Basis: performance of the contract.
- Charging your subscription and issuing receipts. Basis: performance of the contract and legal obligations.
- Security and abuse prevention: logs, usage limits, detection of unauthorized access. Basis: legitimate interest.
- Transactional emails (account verification, password recovery, notices of material changes). Basis: performance of the contract.
- Improving the product with aggregated usage metrics. Basis: legitimate interest.
We do not use your financial content for advertising and we do not sell it to anyone. We do not train AI models with your data.
3. AI features
Some Whallet features use AI models (for example, smart categorization or statement import). When you use them, the data strictly necessary for that operation is sent to the corresponding AI provider:
- If you configured your own keys (BYOK), the data goes directly to the provider you chose, under that provider’s terms and privacy policy.
- If you connect an AI agent via MCP (for example Claude), that agent accesses your data with the token you created, under your authorization and control: you can limit its permissions and revoke the token at any time. The agent provider handles that data under its own policy.
4. Who we share data with (subprocessors)
We do not share your data with anyone, except the providers we need to operate the Service:
- Supabase (database and authentication), hosted on AWS, region sa-east-1 (São Paulo, Brazil).
- Vercel (hosting and delivery of the application), United States.
- Mercado Pago (payments in Argentina) and Dodo Payments (payments as Merchant of Record in the rest of the world).
- Resend (transactional email delivery).
- Google AdSense (only if you use the Free plan; see the advertising section).
The public price sources (for example Yahoo Finance or CoinGecko) work in the opposite direction: we ask them for market prices; none of your data travels to them.
We may also disclose data if a law or a competent authority requires us to.
5. Advertising on the Free plan (Google AdSense)
The Free plan displays a single Google AdSense ad at the end of the content. Paid plans do not show advertising and do not load any ad scripts.
About that ad, you should know that:
- Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this or other websites.
- The use of advertising cookies by Google and its partners enables them to show you ads based on your browsing across the internet.
- You can opt out of personalized advertising in Google’s ad settings (adssettings.google.com) or at www.aboutads.info.
- We never target advertising with your financial data: the ad knows nothing about your transactions, balances or accounts.
6. Cookies
We use essential cookies to make the Service work: your session (authentication) and your language and theme preferences. Without them the app does not work, so they are always active.
The only non-essential cookies are those of the ad provider, and they only load if you use the Free plan (see the previous section).
7. How long we keep your data
- While your account exists, we keep your data to provide you the Service.
- If you delete your account, your data is deleted from production systems within 30 days. Encrypted backups may persist for up to 90 more days before they are rotated out.
- Billing data is retained for the period required by Argentine tax and commercial regulations (up to 10 years).
- Free accounts inactive for more than 12 months may be deactivated and deleted, always with prior notice by email.
8. International transfers
Your data is hosted primarily in Brazil (AWS sa-east-1 via Supabase), a country whose data protection law (LGPD) offers an adequate level of protection. Some subprocessors (Vercel, Resend, Google) process data in the United States or other jurisdictions, with standard contractual safeguards.
9. Your rights
You can exercise your rights of access, rectification, updating, deletion and portability at any time (export your data from the app, or ask us). To exercise them, write to hola@whilehaus.net; we respond within the legal timeframes.
If you are in Argentina: access to your data is free of charge at intervals of no less than six months, unless a legitimate interest justifies more frequent access (Ley 25.326, Argentina’s Personal Data Protection Act, sections 14 and 16). The Agencia de Acceso a la Información Pública (AAIP), the government agency that enforces Ley 25.326, handles complaints and claims from anyone whose personal data protection rights have been affected.
If you are in the European Union or the United Kingdom, you also have the rights granted by the GDPR (including restriction of processing, objection, and lodging a complaint with your supervisory authority). If you are in a US state with a privacy law, you have the equivalent rights under that law.
10. Minors
Whallet is for people 18 and older. We do not knowingly collect data from minors; if we detect an account belonging to a minor, we delete it.
11. Security
We protect your data with technical and organisational measures proportionate to the risk. They apply to everything we process, and with particular care to your financial content, which is the most sensitive category:
- Encryption in transit: all communication between your device and Whallet travels over HTTPS with TLS 1.2 or above, with HSTS enforced on wallet.whilehaus.net.
- Encryption at rest: the database and its backups are stored encrypted with AES-256 on the provider’s infrastructure (AWS, region sa-east-1).
- Per-user isolation: your data is protected by row-level security policies in the database, on top of the application’s own access control.
- Credentials and tokens: your password is stored only as a hash; agent (MCP) tokens and OAuth tokens are likewise stored as hashes, never in the clear, and each carries limited permissions that you define and can revoke at any time. Your card details are processed by Mercado Pago or Dodo Payments and never reach our servers.
- Access control: every access requires authentication, and administrative access, both to Whallet and to the providers’ consoles, is restricted to the studio accounts that need it in order to operate the service.
- Logging: accesses and errors are logged for security purposes.
- No human access: nobody at the studio reads your financial content, unless you expressly consent to a specific support operation, it is necessary for security (including the investigation of abuse or vulnerabilities) or the law requires it.
- Deletion: if you delete your account, your data is removed from production systems within 30 days and encrypted backups are rotated out within a further 90 days at most, as detailed in section 7.
No system is infallible: if we detect an incident affecting your data, we contain it and notify you, and the relevant authority, in accordance with applicable law.
12. Changes to this policy
We may update this Policy. If a change is material, we will notify you by email or within the app before it takes effect. The date of the last update appears at the top.
13. Contact
For any privacy questions or to exercise your rights: hola@whilehaus.net.
Martin Bonafede (Whilehaus), CUIT 20-33215496-7, Av. Rivadavia 5785, floor 15, apartment 1, City of Buenos Aires (postcode 1406), Argentina.
This Policy was written in English, which is the version that governs. Translations are provided as a courtesy: if there is any inconsistency, the English version prevails.