Gå til indholdet

Legal document

Privatlivspolitik

What Vukassa knows about you, why, for how long, and who we share it with.

Last updated 14. september 2026Skift til FrançaisSkift til English
Contents

Data controller

The controller of your personal data is Rivel BABINDAMANA KOUKEBA, a sole trader (French entrepreneur individuel, EI) trading as Vukassa, whose registered address is 173 rue de Courcelles, 75017 Paris, France. Its full identification appears in the legal notice.

For any question or request about your data, one address: privacy@vukassa.com.

This policy covers the iOS and Android apps, the vukassa.com website and the associated services. It does not cover third-party sites we may link to.

Three principles

  • No bank connection. Vukassa connects to no bank and aggregates no statement: everything the app knows about your finances is what you entered.
  • No card number. Subscriptions go through the App Store or Google Play, which collect payment. No banking details pass through our servers.
  • No resale, no advertising. Your data is neither sold, nor rented, nor passed to an ad network. There is no advertising in the apps.

The data we process

We process the following, and nothing more:

  • Account — email address, display name, profile picture if your identity provider sends one, sign-in providers used, language, time zone, theme, display and notification preferences, last sign-in date.
  • Referral — if someone told you about Vukassa and you enter their name in the app, that name, and the link between your account and that person when they are part of our programme. That link exists to credit them.
  • Budget space — standard or freelance profile, start day of the budget month, tax provision rate if you enable it.
  • Budget — your templates, your envelopes and their allocated amounts, and your transactions: amount, date, label, category, note. If you import a statement, your import profiles come with it: the name you give them, how the file's columns are read, and the labels you matched to an envelope. The file itself is never sent to us.
  • Goals and net worth — names, target amounts, deadlines, asset and liability items, successive value readings.
  • Shared budget — if you share a space: each person's membership (owner or member, join date, leave date), the current invitation code and its expiry, the join request that claimed it, and the author of every envelope, transaction, goal and net worth item — that is what lets the screen say who entered what.
  • Subscription — plan, status, dates, payment channel and transaction identifier sent by the store. Never a card number.
  • Messages — a log of the emails we send you (recipient, template, subject, delivery status) and your device's notification token.
  • Technical logs — audit events, with timestamp, IP address and device or browser identifier: sign-ins, sensitive operations, payment events.
  • Suggestions — if you send us an idea from the app, its title and text, linked to your account.
  • Diagnostics — crash reports collected by Firebase Crashlytics, on iOS and on Android: state of the app at the time of the crash, device model, system version. No budget content appears in them.
  • Website — see the cookie policy: without your consent, no audience measurement.

We process no sensitive data within the meaning of the GDPR, and we take no automated decision producing legal effects concerning you.

Why, and on what basis

  • Providing the service — account, budgets, goals, net worth, syncing between your devices. Basis: performance of the contract between us.
  • Managing subscriptions — activation, renewal, end of entitlement, answering a billing complaint. Basis: performance of the contract, then our accounting obligations.
  • Keeping you informed — messages about your account, your budget or your subscription. Basis: performance of the contract for service messages; your consent, revocable in the settings, for the rest.
  • Securing the service — audit logs, detection of abnormal use, alert on sign-in from a new device. Basis: our legitimate interest in protecting accounts.
  • Fixing defects — crash reports and error logs. Basis: our legitimate interest in keeping a working app.
  • Measuring website audience — only if you accept. Basis: your consent, withdrawable at any time.
  • Complying with the law — retention of accounting records, response to a legal request. Basis: our legal obligations.

For how long

  • Account and budget data — for as long as your account exists. After deletion it becomes immediately inaccessible, then is erased from our databases within thirty days.
  • Audit logs — seven years. Only critical events are recorded — account creation and closure, erasure, consents, referral attribution, payment events — those the law requires us to be able to account for.
  • In-app notifications — twelve months.
  • Log of sent emails — twenty-four months.
  • Subscription records — ten years, the retention period for accounting documents under the French commercial code.
  • Crash reports — the retention period applied by Firebase Crashlytics, as published by Google.
  • Website audience measurement — see the cookie policy.

Beyond those periods, data is deleted or anonymised.

Processors and recipients

We neither sell nor rent your data. It is accessible to the people who operate the service, and to the providers below, each for the stated purpose only and under a processing agreement.

If you share a budget, the other member of the space is a recipient too. They read the envelopes, transactions, goals, net worth items and subscriptions of the shared space, and they see your display name, your profile picture and the author of every entry. Never your email address. This sharing is something you do: it starts when you accept a join request, or when yours is accepted, and it ends the moment either of you leaves the space — but what you entered in someone else's space stays there: it is their budget, not yours.

Someone whose name you entered receives nothing from you: our programme shows them totals, never an account, never a person.

ProviderRoleEntity and country
Google Cloud PlatformHosting of the application and the databaseGoogle Cloud EMEA Limited (Ireland)
Firebase AuthenticationAuthentication and account managementGoogle Cloud EMEA Limited (Ireland)
Firebase Cloud MessagingSending push notificationsGoogle Cloud EMEA Limited (Ireland)
Firebase CrashlyticsCrash reportsGoogle Cloud EMEA Limited (Ireland)
ResendSending service emailsResend Inc. (United States)
AppleCollecting payment for subscriptions bought in the appApple Distribution International Ltd. (Ireland)
Google PlayCollecting payment for subscriptions bought in the appGoogle Commerce Limited (Ireland)
Google Analytics 4 — not active yetWebsite audience measurement, after consentGoogle Ireland Limited (Ireland)

Transfers outside the European Union

Our servers and our database are hosted in the European Union. Some providers nevertheless belong to groups established outside the Union, or run part of their support there: a transfer cannot be ruled out.

Such transfers are framed by the European Commission's standard contractual clauses, supplemented where applicable by the relevant adequacy mechanisms. The contracting entity of each provider and its country are shown in the table above.

Security

Exchanges between the app and our servers are encrypted in transit (TLS), and data is encrypted at rest at our hosting provider. On your phone, the local database lives in the app's private storage, protected by the system's encryption; an optional biometric lock sits on top.

The detail — what we never collect, where data lives, what we do in case of an incident — is on the security page.

Your rights

You have the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw your consent where a processing relies on it, and the right to give directives on what happens to your data after your death.

Most are exercised directly in the app: viewing and correcting your data, changing your preferences, deleting your account. The steps are described in how your data is used.

For everything else — obtaining a copy, asking a question, challenging a processing — write to privacy@vukassa.com. We reply within one month. If our answer does not satisfy you, you may refer the matter to the CNIL.

Minors

The service is not intended for children under 15 and we do not seek to collect their data. If you find that an account has been created by a child under 15 without their legal guardian's consent, write to privacy@vukassa.com: the account will be deleted.

Cookies and trackers

The mobile apps set no advertising tracker. The website writes no cookie until you have accepted, and works fully without one. The complete inventory is in the cookie policy, where you can also change your mind.

Changes

This policy may change along with the service or with regulation. The date at the top of the page indicates the latest version, and a substantial change is announced in the app or by email.

Write to us

Questions and requests about your data: privacy@vukassa.com. Other topics are on the contact page.