Last updated: 9 October 2026Privacy policy
How Wealvo handles data, in plain words. The short version: your ledger stays on your phone.
DeutschSlovenščina
1Who is responsible
Wealvo is published by Gabix (info@gabix.si). Gabix is the controller within the meaning of the GDPR. Wealvo is a personal finance overview on your device. We are not a bank or a payment institution, and we do not hold accounts for you.
2What stays on your phone
Your entries, accounts, goals, documents, settings and lock PIN are stored on the phone. The data is stored locally and encrypted at rest. There is no Wealvo cloud account for your ledger and we do not run a central database of your finances.
3Receipt scanning and AI suggestions
When you scan a receipt or a bill, a downsized photo is sent to our server (Supabase) and on to Google’s Gemini model, which reads the amount, merchant, date and fuel. For category suggestions, only a short entry text (for example the merchant name) is sent.
- Both are optional. You can turn AI suggestions off in Settings, and you can always type entries by hand.
- We do not store images or texts. The server only keeps a usage counter to cap costs.
- You always confirm the result before anything is saved.
4Google Drive backup
If you sign in with Google, an encrypted copy of your wallet is stored in the app’s hidden folder in your own Google Drive. The copy is encrypted on your phone with your passphrase, so we cannot read it, and we cannot recover it if you lose the passphrase.
5Shared wallet
If you create or join a shared wallet, changes travel through our server (Supabase), encrypted with the key from the invite. The server only sees encrypted packets and an anonymous device ID, never the content.
6Purchases and subscriptions
Subscriptions and the lifetime purchase are handled by Google Play and RevenueCat. We only receive the subscription status and an anonymous ID, never your card or payment details.
7App lock and biometrics
A PIN and, if you like, biometrics (fingerprint or Face ID) protect opening the app on this device. Biometric templates stay in the phone’s operating system; Gabix never receives them.
8Legal bases
Where we process data, we rely on the following bases under the GDPR:
- Providing the app (for example subscription status and shared-wallet sync): performance of a contract, Art. 6(1)(b).
- AI processing of receipt photos and texts (Gemini): your consent, Art. 6(1)(a). You give it by using the feature and can withdraw it at any time, with effect for the future, by turning AI suggestions off in Settings.
- The usage counter that caps costs: our legitimate interest, Art. 6(1)(f).
9Transfers outside the EEA
Google (Gemini, Google Drive, Google Play) and RevenueCat may transfer data to the United States. Where there is no adequacy decision, the transfer relies on the European Commission’s standard contractual clauses (Art. 46 GDPR).
10How long data is kept
Your financial data lives only on your device (and, if you use it, encrypted in your Google Drive) until you delete it or reset the app. We do not store receipt photos or AI texts. Shared-wallet data and the usage counter are kept only as long as needed for their purpose.
11Your rights
Under the GDPR you have the right to:
- access your data and receive a copy,
- have it corrected or erased,
- restrict or object to processing,
- data portability (Art. 15–21 GDPR).
Because you hold the data yourself, you can edit, export or delete it at any time, or erase it by resetting the app. For any request, write to info@gabix.si.
12Right to complain
You have the right to lodge a complaint with a data-protection supervisory authority, in particular in the EU member state of your habitual residence or workplace, or where the alleged infringement took place. In Slovenia this is the Information Commissioner (Informacijski pooblaščenec).
13Changes to this policy
If this policy changes in a meaningful way, we update the date at the top of this page. The current version is always the one published here.