Saventa← Back to home

Privacy Policy

Last updated: 1 September 2026

This Privacy Policy explains how LUCA S. MIHAI-SORIN PERSOANĂ FIZICĂ AUTORIZATĂ (“Saventa”, “we”, “us”) collects, uses, and protects your personal data when you use the Saventa application (the “Service”). We are the data controller for the personal data described here, within the meaning of the EU General Data Protection Regulation (GDPR).

1. Who we are

Controller: LUCA S. MIHAI-SORIN PERSOANĂ FIZICĂ AUTORIZATĂ, Piața Nouă, Bl. V, Sc. E, Et. 1, Ap. 44, Cisnădie, Sibiu County, Romania.
Sole trader registered with the Trade Register Office of the Sibiu Tribunal, Romania: registration number F2025039187007 (EUID ROONRC.F2025039187007), tax identification number (CUI) 52669122.
Contact for privacy matters: support@saventa.app.

2. Data we collect

Account data

  • Your name and email address, provided at registration.
  • A hashed version of your password (we never store the password itself), or — if you sign in with Google — your Google account identifier and verified email. We do not receive your Google password.

Financial data you enter

  • Portfolios, transactions, holdings, savings deposits, property values, income entries, goals, and related notes that you create or import into the Service.
  • This data is provided voluntarily by you and is used solely to operate the Service for you. We do not connect to your bank accounts.

Broker and exchange connections (optional)

  • You can optionally connect a portfolio to a broker or crypto exchange (currently Binance, Trading 212, Kraken, and Interactive Brokers) by giving us a read-only API credential that you create at that provider. We use it only to fetch your own transaction history from that provider and record it in the connected portfolio — never to trade, move money, or change anything at the provider.
  • The credential is stored encrypted (AES‑GCM) and is never shown again, logged, or included in exports; the app displays only its last four characters so you can tell two credentials apart. Disconnecting deletes the stored credential immediately, and deleting your account deletes all of them.
  • When a sync runs, the request goes to the provider you connected, on your behalf. What that provider logs about the request is governed by its own privacy policy.

Security and session metadata

  • IP address, browser user-agent, and sign-in timestamps for your active sessions and a short account-activity log, shown to you in your profile's Security tab so you can spot unauthorized access.

Feedback

  • If you submit feedback or a bug report, we store its content along with basic context (the page you were on, app version, browser, and plan) to help us act on it. If you leave the “email me when you respond” box ticked, we use your account email address to write back about that report — and only about that report.
  • If you attach screenshots to a report, we store the images. They are resized and re-encoded before they are stored, which removes any embedded metadata such as GPS coordinates or camera details. Whatever is visible in the picture is kept as you sent it — if it shows figures or names, so does our copy. Only you and we can see them; see AI features for the automatic check they pass through on upload, and Data retention for how long they are kept.

Billing data

  • If you purchase a paid plan, payment is handled by Stripe. We never see or store your card details; we store only your plan, its renewal date, and Stripe customer/subscription references.

3. Why we process your data (legal bases)

  • To provide the Service (contract performance, Art. 6(1)(b) GDPR): account management, storing and displaying your financial data, notifications you enable, reports, and billing.
  • To keep the Service secure (legitimate interest, Art. 6(1)(f)): session management, the account-activity log, and abuse prevention such as rate limiting.
  • To communicate with you (contract performance / legitimate interest): transactional emails such as email verification and password reset. We do not send marketing emails without your consent.
  • To provide the optional features you switch on (consent, Art. 6(1)(a)): the AI features, emailed statements, webhooks, broker and exchange connections, and donating an import sample. Each is off until you choose it, and you can stop it at any time.
  • To comply with legal obligations (Art. 6(1)(c)): e.g. accounting records related to paid subscriptions.

4. Processors and sub-processors

We share personal data only with the service providers needed to run the Service:

ProviderPurposeData involved
Microsoft AzureHosting (application and database)All data described above
ResendTransactional email deliveryEmail address, email content
StripePayment processing for paid plansEmail, payment details (held by Stripe)
GoogleOptional “Sign in with Google”Google account identifier, name, email
PostHog (EU)Anonymous product analytics, hosted in the EUAnonymous usage events only (see “Analytics” below); no account or financial data
Anthropic (US)The AI features — portfolio summaries, the in-app assistant, import column matching, screenshot screening, and support-mailbox theme summariesOnly what that feature needs (see “AI features” below); requests do not carry your name, email, or account identifier
Zoho (EU)Our support mailbox, hosted in the EUWhatever you write to us, and the address you write from
Sentry (EU)Crash and error reporting, hosted in the EUTechnical error details only (see “Error reporting” below); not linked to your account, and no financial data

Market data (asset prices, dividends) is fetched from third-party market-data providers; those requests contain no personal data. We never sell your data or share it with advertisers.

5. Cookies and local storage

The Service does not use advertising or tracking cookies. We use your browser's local storage only to keep you signed in (authentication tokens) and to remember preferences such as your theme and cached data for faster loading. Our analytics (see below) is cookieless: it stores nothing on your device.

6. Analytics

To understand how the Service is used and improve it, we collect a minimal amount of anonymous usage data using PostHog, hosted in the European Union. This processing is based on our legitimate interest in understanding aggregate product usage (Art. 6(1)(f) GDPR). It is designed to be privacy-preserving:

  • Anonymous — analytics events are never linked to your account, name, or email, and we do not build individual user profiles.
  • Cookieless — no cookies or local storage are used for analytics, so activity is not tracked across visits.
  • Minimal — we collect only which pages are visited and which features are used. Identifiers in page addresses (such as portfolio ids) are removed before sending, and your financial data is never included. When you import a file we record whether it could be read — which broker it came from, how many rows were understood, and the broker's own name for any transaction type we do not recognise — so that we can fix imports when a broker changes its export format. No amounts, dates, holdings or file contents are included.
  • IP discarded — your IP address is not stored with analytics events.
  • No cross-site tracking — analytics is limited to this Service and is never shared with advertisers or used for advertising.

7. Error reporting

When something goes wrong in the Service, we collect a technical report of the failure so that we can find and fix it, using Sentry, hosted in the European Union. This is based on our legitimate interest in keeping the Service working correctly and securely (Art. 6(1)(f) GDPR). Like our analytics, it is kept deliberately narrow:

  • Not linked to you — error reports do not carry your name, email, or account identifier, and we do not build profiles from them.
  • Technical detail only — a report contains the error message, the place in our code where it happened, the page you were on, and your browser and version. Your portfolios, transactions, balances and other financial data are never included.
  • No IP address — your IP address is not collected with error reports.
  • Sensitive values removed — where a page address contains a one-time code (such as a password-reset link), that value is removed before the report is sent.

8. AI features

Some features are powered by a large language model run by Anthropic, in the United States. They only run when you ask for them — nothing is sent to the model while you simply use the app. The one exception is one you switch on yourself: if you enable Generate summaries automatically in your profile, an AI summary is produced when you open a portfolio without waiting to be asked. It is off unless you turn it on. The transfer outside the EU is covered by the European Commission's Standard Contractual Clauses. What each feature sends:

  • AI summary — produced when you press Generate or Refresh (or automatically, if you switched that on). At most one is generated per portfolio per day; looking at one that already exists sends nothing. It contains a snapshot of your own figures: totals and net worth, your goals, your target allocation and how far the real one has drifted from it, your largest positions, your currency mix, and your risk band. No name, email, or account identifier is attached. The summary written back is stored so the same one can be shown again rather than regenerated; you can see it on the card that produced it.
  • In-app assistant — the questions you type and the answers so far in that conversation. We do not store the conversation on our servers; it lives in your browser until you close it.
  • Import column matching — the column headings of a file you are importing, and nothing else. No amounts, dates, holdings, or any other cell value is sent.
  • Support mailbox themes — messages sent to our support address may be summarised by the model so we can see recurring themes across them. The text of the message is processed for this; the sender's address is withheld from the model, and the summary describes themes, not individual senders.
  • Screenshot screening — an image you attach to a feedback report is sent to the model once, at upload, to check that it is not explicit or abusive content, and the one-word answer is stored with it. This happens once per image and never again: opening a report later does not send the image anywhere. If the check fails the image is refused and never stored at all.

Anthropic processes this data on our instructions only, under their commercial terms: it is not used to train their models, and they delete it within 30 days. We do not use it to make any decision about you. Nothing about the AI features is automated decision-making within the meaning of Art. 22 GDPR — an AI summary describes what your figures already say, and neither it nor the assistant gives investment advice.

9. Data you choose to send elsewhere

  • Webhooks — if you configure a webhook, we send the notifications you subscribed to, to the address you gave us. Where they go and who can read them is then up to you; we are no longer in a position to control it.
  • API access — a personal API token lets a program you choose read your data through our API. Treat it like a password; you can revoke it at any time from your profile.
  • Donated import samples — if you offer a sample of a broker export so we can support that broker, your browser removes identifying details and rescales the amounts before anything is sent, and you can see what will go. We keep the donated sample and the mapping you built, and use them only to build and test that importer. Donating is entirely optional and imports work without it.

10. Data retention

Your data is retained for as long as your account exists. If you delete your account, all of your personal data and financial data is permanently deleted immediately (see “Your rights” below). Billing records required by law may be retained by our payment provider and in our accounting records for the legally mandated period.

When you delete something inside the app — a portfolio, a transaction, a custom asset — we keep a copy for 30 days so you can undo it, then delete it permanently. You can see and restore these from History. Deleting your whole account removes this recovery data along with everything else, immediately.

We also keep a record of the changes made to your account (what was created, changed or deleted, and when) so that History can show it. We keep the most recent 5,000 of these per account and remove older ones. This record is included in your data export and is deleted with your account.

Of the AI summaries we keep only the current one for each portfolio, and one for your net worth: the moment a new one is generated, the one it replaces is deleted. They are included in your data export and deleted with your account.

To avoid sending the same email twice, we keep a small ledger of the transactional emails sent to you (which email, and when — not its content). It is deleted with your account.

11. Your rights (GDPR)

  • Access & rectification — your data is visible and editable directly in the app, and you can download a complete copy of your account data at any time from Profile → Security → Your data.
  • Erasure — delete your account at any time from Profile → Security → Delete account. This permanently removes your account and all data you have entered.
  • Portability — download everything at once from Profile → Security → Your data (account data plus all portfolios as re-importable CSV files), or export portfolios individually as CSV or Excel from the portfolio dashboard.
  • Objection & restriction — contact us at support@saventa.app.
  • Complaint — you have the right to lodge a complaint with your local data-protection supervisory authority.

12. Security

All traffic is encrypted in transit (HTTPS). Passwords are stored using the bcrypt hashing algorithm. Broker and exchange API credentials are stored encrypted with AES‑GCM. Sessions are short-lived and individually revocable from the Security tab. Access to production systems is restricted and audited.

13. Children

The Service is not directed at children under 16, and we do not knowingly collect personal data from them.

14. Changes to this policy

We may update this policy as the Service evolves. Material changes will be announced in the app. The “Last updated” date above always reflects the current version.

15. Contact

Questions about this policy or your data: support@saventa.app.

Terms of Service · Home