1. Controller
The controller responsible for processing personal data is:
Yarego Brozek
Wiener Straße 11
10999 Berlin
Germany
Email: brozek.yarego@gmail.com
2. Scope
This policy applies to the Violetly website and application (the “Service”), including marketing pages, free tools, accounts, the AI assistant, paid subscriptions (Plus), and the Violetly ChatGPT app/plugin (MCP integration).
3. Data we process
Depending on how you use Violetly, we may process:
- Account data: email address, name (if provided), authentication session identifiers, OAuth access/refresh tokens for ChatGPT connections
- Finance data you enter: accounts, transactions, budgets, goals, holdings, plans, preferences (e.g. currency, locale, risk profile)—including data created or updated via ChatGPT tools
- Billing data: plan (Free/Plus), subscription status, Stripe customer and subscription identifiers, invoice metadata, and limited payment-method metadata Stripe stores. We do not store full payment card numbers on our servers; Stripe processes card data as an independent payment processor
- AI interaction data: prompts, tool results, and conversation history needed to run the assistant; ChatGPT conversations remain with OpenAI under their terms when you use Violetly inside ChatGPT
- Technical data: IP address, device/browser information, timestamps, security logs, MCP tool audit metadata (tool name, outcome; not full financial payloads in logs)
- Acquisition data: self-reported “how did you find us”, ChatGPT attribution when you connect via the ChatGPT app, and first-touch campaign parameters (UTM), landing path, and referrer when available
- Analytics data (only with consent): product usage events, funnels, feature adoption, and error/diagnostic events via PostHog; anonymous usage via Vercel Analytics when consented
- Advertising conversion data (when campaigns run): limited conversion events (e.g. registration) via OpenAI Conversions / ads measurement, subject to your analytics consent where required
4. Purposes and legal bases (GDPR)
- Create and secure your account, send magic links / ChatGPT OAuth email codes, keep you signed in — Art. 6(1)(b) contract
- Provide finance tracking, investments quotes, AI features, and ChatGPT app tools you request (read and write) — Art. 6(1)(b) contract
- Process paid subscriptions (Plus), invoices, and cancellations via Stripe — Art. 6(1)(b) contract
- Hosting, backups, abuse prevention, security — Art. 6(1)(f) legitimate interests
- Product analytics and error diagnostics with cookies/similar storage — Art. 6(1)(a) consent (and ePrivacy / TDDDG where applicable)
- Understand acquisition (self-report + UTMs + ChatGPT connect) — Art. 6(1)(f) legitimate interests; analytics cookies still require consent
- Optional product update emails (features, tips, important product changes) — Art. 6(1)(a) consent; you can change this anytime in Settings
- Measure ad conversions when you consent to optional analytics — Art. 6(1)(a) consent
- Comply with law, respond to requests — Art. 6(1)(c) legal obligation
You may withdraw analytics consent at any time (cookie banner before sign-in, or Settings after). Withdrawal does not affect prior lawful processing. You may also turn off product update emails in Settings. You can disconnect Violetly from ChatGPT and revoke OAuth tokens anytime (ChatGPT app settings and/or by deleting your Violetly account).
5. Essential vs optional cookies
Essential (no consent required): session/auth cookies required to sign in and operate the Service (Better Auth); OAuth authorize-session cookies/state for ChatGPT Connect; cookies Stripe may set on Checkout / Customer Portal hosts.
Optional (consent required): PostHog product analytics cookies/local storage; Vercel Analytics when enabled under consent; advertising / conversion measurement tags when campaigns are active.
6. Processors and partners
We use service providers that process data on our instructions:
- Neon — PostgreSQL database hosting (account and finance data)
- Vercel — application hosting and (with consent) Vercel Analytics
- Resend — transactional email (magic links, ChatGPT OAuth codes, account deletion confirmation) and, when you opt in, product update emails
- Stripe — payment processing for Violetly Plus (subscriptions, invoices, payment methods). Card numbers are handled by Stripe, not stored in Violetly’s database
- OpenAI (ChatGPT) — when you install/connect the Violetly ChatGPT app, OpenAI acts as the chat host; Violetly receives OAuth tokens and performs tools you approve. OpenAI processes chat content under their terms. OpenAI may also receive conversion signals when ads are used
- Google (Gemini / Google AI) — processes prompts and related context to power the Violetly assistant and transcription features you use
- Alpha Vantage — primary market data / symbol search / quotes for investment features you use (typically symbols and request metadata, not your full ledger)
- EODHD — preferred end-of-day history and ISIN / EU ETF search when configured (typically symbols and request metadata)
- Yahoo Finance — secondary market data fallback when Alpha Vantage has no match (e.g. some European ETFs or crypto symbols); typically symbols and request metadata only
- PostHog — product analytics and error diagnostics only when you consent
Providers may process data in the EU and/or third countries (including the United States). Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.
7. Retention
- Account and finance data: until you delete your account, or sooner if you request erasure where applicable
- Auth sessions: until expiry or sign-out
- OAuth refresh tokens for ChatGPT: until expiry, revoke/disconnect, or account deletion
- AI conversations: retained while your account exists (or until you delete them / the account)
- Billing / Stripe records: retained as needed for the subscription, tax, and accounting obligations; Stripe retains payment records under its policies
- Analytics events: per PostHog/Vercel retention settings while consent is active
- Acquisition fields: retained with the account for product measurement
After account deletion we remove or anonymize personal data within a reasonable period, cancel active Stripe subscriptions, and request deletion of the Stripe customer where practicable, except where law requires longer retention.
8. Your rights
If you are in the EEA/UK (and similar regimes), you may have rights to access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent.
In-app: Settings → delete account (GDPR right to be forgotten for account data we control). Billing: Settings → Billing (Stripe Customer Portal for payment method and invoices).
You may lodge a complaint with a supervisory authority (in Germany, typically your Landesdatenschutzbehörde / BfDI).
9. Children
Violetly is not directed at children under 16. Do not use the Service if you are under the age required in your country.
10. Changes
We may update this policy. The Last updated date above will change. Material changes may also be communicated in-product or by email when appropriate.
11. Contact
Privacy questions: brozek.yarego@gmail.com