Privacy Notice
1. Who runs this app
THRIVE is a small personal-budgeting app operated by Inge Vinković (Croatia). For any privacy or data-protection question, write to vinkovic.inge@gmail.com.
1a. Testing phase
THRIVE is currently in a private testing phase with a small group of invited users. It is not yet offered as a commercial service. If you are a test user:
- Your data (email address, and the budget entries you create) is stored in your own account and is not visible to other users. It is never sold or shared with third parties.
- You can stop at any time — write to vinkovic.inge@gmail.com and your account and all its data will be permanently deleted.
- Because this is a test, features may change and occasional bugs are possible. Do not rely on THRIVE as your only record of financial information.
2. What data we process
| Data | Source | Why |
|---|---|---|
| Email address | You, when signing in | To identify your account and sync your budget across devices. |
| Bank account info (IBAN, account name, balance, currency) | Your bank, via Enable Banking, after you authorise it | To display your accounts and balances inside THRIVE. |
| Bank transactions (date, amount, counterparty, description) | Your bank, via Enable Banking, after you authorise it | To categorise your spending and produce your monthly budget view. |
| Budget data you create (categories, rules, manual entries, notes) | You, while using the app | To run the budgeting features you asked for. |
3. Where the data is stored
- Your browser (localStorage) — primary copy, on your own device.
- Supabase (cloud database, EU region) — optional sync copy, so your data is available across your devices. Stored under your authenticated user account; not visible to other THRIVE users.
- Bank credentials (passwords, PINs, mTokens) are never seen, requested, or stored by THRIVE — your bank handles those during the Strong Customer Authentication step.
4. Who we share data with
THRIVE relies on a small number of providers strictly necessary to operate. We do not sell, rent, or share your data for advertising or marketing.
| Provider | Role | What they see |
|---|---|---|
| Enable Banking Oy (Finland) | PSD2 account-information aggregator | Your authorisation grant, the account IDs and transactions retrieved from your bank. |
| Supabase (EU region) | Cloud database + authentication | Your email, encrypted session, and the budget data you choose to sync. |
| Cloudflare (Pages) | Static hosting + CDN for the THRIVE website | Standard web-server logs (IP, browser, request paths). |
5. Legal basis (GDPR)
- Your consent (Art. 6(1)(a) GDPR + PSD2): for accessing your bank-account data via Enable Banking. You give this consent through your bank's Strong Customer Authentication, and you can withdraw it at any time.
- Contract / your request (Art. 6(1)(b) GDPR): for operating the account, sync and budgeting features you choose to use.
6. How long we keep it
- Bank consent: 90 days per PSD2; you renew it by re-authorising.
- Account & budget data: kept until you delete it from the app or ask us to delete your account.
- Web-server logs: retained by the hosting provider per their policy (typically up to 30 days).
7. Your rights
Under the GDPR you may at any time request:
- access to your personal data;
- correction of inaccurate data;
- erasure ("right to be forgotten");
- restriction or objection to processing;
- portability of your data in a machine-readable format;
- withdrawal of consent for bank-data access (this also stops further transaction sync).
To exercise any of these, email vinkovic.inge@gmail.com. You also have the right to lodge a complaint with the Croatian data-protection authority (AZOP).
8. Security
Data in transit is protected by HTTPS/TLS. Data at rest in Supabase is encrypted by the provider. Bank credentials are handled exclusively by your bank during SCA and never reach THRIVE. Because this is a personal app, please understand that the operator does not provide 24/7 monitoring; use of the app is at your own discretion.
9. International transfers
All providers used by THRIVE are in the EU/EEA, or process data under Standard Contractual Clauses where applicable.
10. Changes to this notice
If this notice changes materially, the updated version will be published at this URL with a new "Last updated" date.