Privacy policy
Westara is built so household financial data stays in your vault — encrypted, tenant-isolated, and not sold for advertising.
Westara (early access)
early-access@westara.io
Controller
The controller for personal data processing in connection with the SaaS offering is identified in the imprint.
What we store
Account credentials (including hashed passwords), household budget and portfolio data you enter or import, and encrypted integration secrets when you connect optional services.
Purposes and legal bases
Processing is necessary to provide the service and perform the contract (Art. 6(1)(b) GDPR), and where needed for legitimate interests in secure operation and abuse prevention (Art. 6(1)(f) GDPR).
Hosting and location
SaaS production uses EU-minded defaults (including Germany-hosted vault messaging in product). Sovereign / self-hosted deployments keep data on your server.
AI features
Chat help is optional. When used, only scoped context for the question is sent to our AI partner — not a dump of your whole vault. See Help for the current disclosure.
Retention
We retain data while your account exists and the product features require it. After account deletion we delete or anonymize data within operational retention windows.
Your rights
Access, rectification, erasure, restriction, portability, and objection under the GDPR. Export and delete controls live in product account settings; contact support via Help / the imprint.
Complaints
You may lodge a complaint with a supervisory authority, in particular in your habitual residence or place of the alleged infringement.
This policy describes Westara product privacy. Formal operator identity and contact appear in the imprint; in case of conflict, the imprint and applicable law prevail.