Privacy policy
Westara is built so household financial data stays private — encryption in transit and at rest, tenant-isolated storage, and never sold for advertising. This notice explains personal data processing on the public website (www) and the SaaS product (app) under Articles 13 and 14 GDPR.
Last updated: 2026-08-13
1. Controller
The controller responsible for personal data processing for the SaaS offering and marketing website is:
Westara GbR
Mittelweg 26
60318 Frankfurt am Main
Deutschland
Email: legal@westara.io
Managing partners: Olga Graf, Marco Graf.
Legal form: GbR (partners are jointly and severally liable under German law).
2. Scope
This policy covers the public marketing website (e.g. westara.io / www.westara.io) and the SaaS product (e.g. app.westara.io) where we act as controller.
Self-hosted / Sovereign deployments store data on the instance operator’s server. That operator is additionally or primarily the controller there; this policy applies to such instances only where we ourselves process data (e.g. optional telemetry you explicitly enable — off by default).
3. What data we process
Depending on use, the following categories may apply:
- Account data: email, display name, hashed passwords, session/auth metadata, optional profile and onboarding fields
- In-app content (highly sensitive): household budget, actual spending and income, portfolio/transaction data, cash positions, Bitcoin balances (watch-only / zpub only — no private keys) that you enter or import
- Integration secrets: API keys for optional services (e.g. market data, Braiins, xAI, eToro Read keys) — stored encrypted
- Payment and billing data: via Stripe (we do not store full card numbers) and, if you choose Bitcoin / Lightning, invoice data from our payment server (BTCPay; no wallet keys); invoice metadata for commercial/tax purposes
- Communications: support/feedback messages you send us; with explicit consent, the record and delivery of optional notes (education, product, news)
- Technical data: IP address, timestamps, user agent, access/error logs as needed for operations and security
- Website preferences: language and theme (essential cookies / local storage)
- Optional website analytics: usage and performance measurement only with consent (see Cookies)
- AI context: when optional AI is used, only prepared, scoped context for the request — not a full export of your household or portfolio picture. Payee headlines on that screen may be included; Ask Westara does not receive IBAN, keys, or a vault dump
- Bank import / open banking (AIS): only if you actively connect; the AISP sees raw bank lines for the read; Westara then stores the account list, IBAN and holder where the bank provides them, balances, and booked lines via finAPI GmbH or BANKSapi Technology GmbH
- Broker API (eToro): only if you paste Read keys on a depot — keys encrypted, trades and cash/crypto snapshots in your workspace; Write keys are refused. Not PSD2 AIS
- Broker-rail (WealthAPI): shipped, env-gated, not PSD2 AIS — same honesty as eToro; refresh encrypted; write and orders refused
4. Heightened care for household and financial data
Household budgets, transactions, portfolios and related content are economically and personally highly sensitive. We apply heightened care:
- Encryption in transit (TLS) and at rest with our hosting/database providers
- Tenant isolation and row-level security where implemented
- No use of this content data for advertising, third-party profiling, or sale
- Staff access only for legitimate support and only as needed
- Bitcoin: non-custodial only (watch-only / zpub); we neither request nor store private keys or seed phrases
5. Purposes and legal bases
We process data only where a legal basis applies:
- Art. 6(1)(b) GDPR — performance of a contract and pre-contractual steps (account, app features, subscription, support, data export)
- Art. 6(1)(c) GDPR — legal obligations (e.g. commercial/tax retention of invoices)
- Art. 6(1)(f) GDPR — legitimate interests in secure operation, abuse prevention, error analysis, and product improvement in aggregate/anonymised form (balanced against your rights; minimal logging)
- Art. 6(1)(a) GDPR — consent, in particular for optional analytics cookies, optional email notes (education, product, news) after double opt-in, optional AI features and voluntary integrations where not already required for the contract; withdraw anytime with effect for the future
6. Hosting, recipients and processors
We use carefully selected service providers. Where they process personal data on our behalf, we rely on Art. 28 GDPR processing agreements or the providers’ standard Data Processing Agreements (DPAs) and maintain an internal register of processors in use. Typical recipients:
- Vercel Inc. — hosting and delivery of website/app (edge/CDN); optional Web Analytics and Speed Insights only with consent
- Neon, Inc. — PostgreSQL database for the SaaS product; production data is hosted in the EU (typically AWS eu-central-1 / Frankfurt or another configured EU region)
- Stripe, Inc. / Stripe Payments Europe Limited — card payments and subscriptions (partly independent controller for payment data)
- BTCPay Server (operated by us, e.g. on Start9) — Bitcoin and Lightning invoices only if you choose that rail; we do not hold wallet keys for plan payments
- Resend, Inc. — transactional email (e.g. magic link, notices) where used
- xAI — optional AI features (AI chat help, insights); transfer only when you actively use the feature and only with prepared, scoped context
- Sentry (Functional Software, Inc.) — application error monitoring; events are scrubbed; no session replay
- Google LLC — optional Google sign-in on Cloud (SaaS) only; the provider sees that you use Westara
- Apple Inc. — optional Sign in with Apple on Cloud (SaaS) only; Hide My Email may share a relay address instead of your mailbox
- finAPI GmbH or BANKSapi Technology GmbH (BaFin-supervised AISPs, EEA) — optional PSD2 bank read only if you connect it and the plan enables it; the AISP sees raw bank lines for the read; file import (CSV/CAMT) does not use an AISP
- eToro — optional depot connect (Read keys only) if you set it up; eToro remains responsible for the broker account; we store the portfolio data returned
- WealthAPI — shipped, env-gated broker-rail (not PSD2 AIS) if you connect it; refresh stored encrypted; write and orders refused; we store the returned portfolio data
7. International transfers (especially US / xAI)
Some providers are established or use sub-processors in the United States or other third countries outside the EEA. Where an adequacy decision does not apply, we rely on appropriate safeguards under Art. 46 GDPR — in particular EU Standard Contractual Clauses (SCCs) — plus supplementary technical and organisational measures (encryption, access restriction, data minimisation).
Optional AI (xAI) involves a transfer to the US only when you actively use the feature. Only prepared context for the specific request is sent — never a full export of your household, budget, or portfolio picture. Payee headlines already on that screen may be included. If you do not use AI features, no xAI transfer occurs for that purpose. Sub-processor details appear in the providers’ DPAs.
Error monitoring (Sentry) may involve a US processor; events are scrubbed and session replay is not used.
Optional Google or Apple sign-in on Cloud (SaaS) is a transfer to a US identity provider, only when you choose that button. Self-hosted / Sovereign does not offer social login.
Optional broker APIs (eToro, WealthAPI) call the vendor’s public API when you connect. The broker or rail remains independently responsible for that account and may use infrastructure outside the EEA, under its own terms.
8. Bank import, open banking (AIS), and broker APIs
The primary bank import is a file you upload (CSV/CAMT). File import does not use an AISP — it is a private path with no licensed reader. Optional live read (PSD2 AIS) uses finAPI GmbH or BANKSapi Technology GmbH, licensed account information service providers (AISPs) in the EEA supervised by BaFin, only on your initiative and bank authorisation, and only when the plan enables it.
Westara is not an AISP. We do not hold PSD2 certificates, do not perform strong customer authentication with your bank, and do not store online-banking passwords, PINs, or TANs. The AISP that performs the read (finAPI GmbH or BANKSapi Technology GmbH) sees the raw bank lines needed for that read. After you approve access at the bank, we receive and store in your tenant workspace: the account list and metadata (including IBAN and account-holder name where the bank provides them), balances, and booked lines (counterpart and remittance). Lists in the product show last four digits; you can export or delete your data. Payment accounts land in Actuals. When the bank also exposes a securities account on the same login, positions and trades land in Activity, not Actuals. The first live fetch covers about 90 days; later fetches add new days only.
Live Open Banking on Cloud or on a self-hosted / Sovereign install is not a “Westara-blind” path: the AISP still sees raw lines, and Westara still stores the approved list, balances, and booked lines. Self-hosted / Sovereign stays file-based unless you attach live AIS yourself.
Disconnecting the bank in the app stops new fetches and revokes the live login. Stored Actuals, Activity rows, and Westara accounts remain unless you choose the optional wipe of imported Open Banking rows on those accounts, or until you delete them in the app, or until you delete your Westara account. File import stays available.
The AISP that performs the read (finAPI GmbH or BANKSapi Technology GmbH) is independently responsible for the bank interface and consent under its AISP licence. Processing of data delivered into Westara follows the contractual and privacy terms agreed with the provider (including Art. 28 GDPR where the provider acts as processor). Household members you invite may see the same books according to household sharing.
Optional broker connect (eToro) is not PSD2 AIS. You paste Read keys (Public / Private) from eToro on a depot. Write keys are refused and never stored. We encrypt the Read keys and call eToro’s public API on your initiative. We store the returned trades, cash snapshots, and crypto-wallet snapshots in your workspace for Activity and Holdings. eToro remains independently responsible for the broker account. Disconnect always deletes the stored keys and stops further fetches. Imported eToro rows stay unless you choose the optional wipe on that depot. Keys and raw eToro history are not sent to xAI. CSV import stays available and uses the same row identity.
Optional broker-rail (WealthAPI) is shipped, env-gated, and not PSD2 AIS — the same honesty shape as eToro. Refresh tokens are stored encrypted. Write access and orders are refused. Disconnect always deletes the stored refresh and stops further fetches. Imported rows stay unless you choose the optional wipe on that depot. WealthAPI remains independently responsible for the broker connection.
BANKSapi Technology GmbH is a second licensed EEA AISP behind the same adapter; it is offered only when operators enable it.
Typical data flow: the app runs on Vercel; books are stored in Neon in the EU (typically Frankfurt). You either upload a file (no AISP) or connect AIS (finAPI GmbH or BANKSapi Technology GmbH sees the raw lines). Optional Ask Westara sends a scoped slice to xAI. Price vendors supply marks.
Typical data flow
Cloud books live in the EU. That is residency plus a household envelope for leftover IBANs, holder names, account notes, and booking payee when the envelope is on. It is not a promise that nobody can read the books, and it is not immunity from foreign lawful access. Self-hosted / Sovereign is the only non-access promise: we do not operate that database.
- App (Vercel) — website and captain app
- Books (Neon, EU, typically Frankfurt) — tenant workspace; leftover IBANs / Inhaber / notes / payee sealed with a per-household key when the envelope is on
- File import (CSV / CAMT) — private path; no AISP
- Optional live AIS — finAPI GmbH or BANKSapi Technology GmbH see the raw bank lines
- Optional Ask Westara — a scoped slice to xAI; payee headlines already on that screen may be included
- Price vendors — marks only
9. Cookies and similar technologies (TDDDG)
On the marketing website we store:
- Essential: language preference (captain-locale-preference) and display mode (captain-theme-preference / local storage) — required for the experience you request; § 25(2) TDDDG / Art. 6(1)(f) or (b) GDPR
- Optional (consent only): Vercel Web Analytics and Speed Insights — reach and performance measurement; § 25(1) TDDDG / Art. 6(1)(a) GDPR. Optional analytics cookies are not loaded without consent
- We store your choice locally (captain.marketing.cookie-consent) as essential or all; you can change it anytime via Cookie settings in the banner or footer
10. AI features
AI chat help and AI insights are optional and plan-dependent. When used, only prepared, scoped context for the question is sent to our AI partner (xAI) — not a full export of your household or portfolio picture. Bridge insights may use a unified but still limited context; fleet/chat help is narrower (e.g. equities-only weight %). See Help (Grok / privacy) for the current disclosure. You may clear chat history in the app where the feature allows. AI outputs are non-binding assistance only — not financial, investment, tax, or legal advice.
11. Retention
We retain personal data only as long as needed for the purposes:
- Account and app content: while the account exists and features require it
- After account deletion: delete or anonymise within operational windows (typically within 30 days), unless legal retention applies
- Invoices and payment records: typically 6–10 years under commercial and tax law
- Security and access logs: short-term (usually days to a few weeks) unless an incident requires longer retention
- Open Banking (AIS) bookings: remain with app content after you disconnect the bank, unless you choose the optional wipe of imported Open Banking rows on those accounts, or until you delete the lines in the app or delete the account
- eToro Read keys: deleted on Disconnect. Imported eToro rows stay unless you choose the optional wipe on that depot
- WealthAPI refresh: deleted on Disconnect. Imported WealthAPI rows stay unless you choose the optional wipe on that depot
- Cookie consent: until withdrawn or local storage is cleared
- Optional notes consent: the proof record (time, wording version, source, status) while the account exists and afterwards within operational windows where we must demonstrate lawfulness
12. Your rights
Under the GDPR you have the right to:
- Access (Art. 15)
- Rectification (Art. 16)
- Erasure (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20) — structured, commonly used, machine-readable format
- Object to processing based on legitimate interests (Art. 21)
- Withdraw consent with effect for the future (Art. 7(3))
13. Exercising your rights
Export and delete controls are available in product account settings where possible. You may also contact us at legal@westara.io. We respond within statutory timeframes (typically within one month). We may request suitable proof of identity.
14. Complaints to a supervisory authority
You may lodge a complaint with a supervisory authority, in particular in your Member State of habitual residence, place of work, or place of the alleged infringement. For the controller’s seat in Hesse (Germany), the competent authority includes:
The Hessian Commissioner for Data Protection and Freedom of Information (HBDI)
Gustav-Stresemann-Ring 1
65189 Wiesbaden
Germany
https://datenschutz.hessen.de
15. No sale for advertising
We do not sell your personal data to third parties for advertising. Household and portfolio content is processed to provide the service to you — not to build advertising profiles and not to sell to data brokers.
16. Obligation to provide data and consequences of not providing
Without certain data (e.g. email and authentication) we cannot provide an account or contract. Optional data (AI, bank import, analytics cookies) is not required for basic free use of the marketing website. Not providing optional data only limits the respective optional features.
17. Automated decision-making
We do not make solely automated decisions under Art. 22 GDPR that produce legal effects or similarly significant effects. AI outputs are assistance only and are not binding financial or legal advice.
18. Personal data breach
In the event of a personal data breach we notify the competent supervisory authority under Art. 33 GDPR and — where required — affected individuals under Art. 34 GDPR if the breach is likely to result in a high risk to your rights and freedoms.
19. Data protection impact assessment (DPIA)
For processing of highly sensitive household and financial data in the SaaS context we maintain a data protection impact assessment (Art. 35 GDPR) and update it when processing changes materially, where the risk to natural persons’ rights and freedoms is likely to be high. Outcomes feed technical and organisational measures. A summary may be provided on request to the imprint address where trade secrets do not preclude disclosure.
20. Self-hosted / Sovereign
Self-hosted / Sovereign is an alternative deployment of the same app on Start9 or Docker. Books Westara does not host stay on your server — that mode is the non-access promise for those books. Optional outbound connections (live prices, AIS, AI) are your choice; live AIS on a home server still shares raw bank lines with the AISP. The instance operator is usually the primary controller for content data stored there. Our responsibility is limited to the software we provide and — if any — optional services we operate that you deliberately connect.
21. Optional notes by email
If you expressly opt in, we may send occasional notes on family wealth, the product, and education to your account email. The account works without this consent. The checkbox is not pre-ticked. We send these notes only after you confirm a separate confirmation email (double opt-in). Transactional mail (verify, sign-in, invoices, security, invites) and Radar alerts are separate. Withdraw anytime in Profile or via the unsubscribe link in such a mail; effect for the future. Household and portfolio amounts do not belong in these notes.
Formal provider identity appears in the imprint. In case of conflict, the imprint, this policy, and applicable law prevail. Last updated: 2026-08-13.
