How we handle your data
Last updated: July 7, 2026
The data you put into Wealthos (your account balances, income and expenses, financial goals, plans, forecasts, and chats with the assistant) is among the most sensitive material you'll hand to any software tool. This page explains, in plain language, exactly what happens to it: where it lives, who can see it, which third parties are involved, and how you can take it all back.
This is the readable overview. For the full legal detail, see our Privacy Policy.
The short version
Your data is not used to train AI models. The AI assistant runs on commercial API plans from Mistral AI and Anthropic. Both contractually commit that data sent over their APIs is not used to train their models.
Your data stays in the EU. Accounts, balances, goals, and chat history are stored on EU-based infrastructure. Sensitive financial values are encrypted at rest.
We don't sell your data. We never sell your personal or financial data, and we don't share it beyond the handful of sub-processors listed below that are needed to run the product.
We never see your bank login. When you connect an account through Open Banking, you authenticate directly with your bank. Wealthos only receives read-only balance information, so we can't move money, initiate payments, or view your credentials.
You can delete everything, yourself, instantly. Deleting your account from settings permanently and irreversibly removes all of your data right away. No email, no waiting period.
Where your data lives
All data in transit between your browser and our servers is encrypted with TLS. Data at rest is encrypted by our infrastructure provider, and sensitive financial values are additionally encrypted at the field level.
| Data | Where it lives | Region |
|---|---|---|
| Account info (email, name, preferences) | Supabase (Auth & Postgres) | European Union |
| Financial data (balances, income, expenses, goals, plans, forecasts) | Supabase Postgres, encrypted at rest | European Union |
| AI assistant chat history | Supabase Postgres | European Union |
| Bank connection tokens | GoCardless (Open Banking provider) | European Union |
| Usage & analytics events | PostHog (cookieless) | European Union |
When you connect a bank account
Bank connections use PSD2-compliant Open Banking APIs provided by GoCardless, a regulated third party. Here's exactly what that means:
- You authenticate directly with your bank. Your login credentials are never shared with, or stored by, Wealthos.
- We receive read-only access to balance information. We cannot see your transaction history in detail, move money, or initiate payments.
- You can disconnect a bank at any time, from within Wealthos or directly through your bank, which immediately removes the connection.
- Prefer not to connect a bank at all? You can add and update balances manually instead.
When you chat with the AI assistant
When you send a message to the assistant:
- Your message, plus any of your financial context needed to answer it, is sent over the API to our model provider (Mistral AI or Anthropic).
- The provider returns a response, which Wealthos streams back to you.
- We store the conversation so your chat history persists and the assistant stays context-aware.
Not used for training. We use commercial API plans, so your conversations are not used to train the providers' models. See Mistral AI and Anthropic for how each handles API data.
How we measure usage
We use PostHog to understand how people use Wealthos so we can improve it. Our analytics are deliberately cookieless: we don't set analytics cookies or use persistent browser storage, and usage is tracked with in-memory identifiers that don't persist across sessions. PostHog processes this data in the EU. We use it to see broadly how features are used, never to read your balances, goals, or conversations.
Who can see your content
By default, your financial data is private to you. It becomes visible to someone else only when:
- You share it, for example by generating a shareable link to a plan or forecast.
- You ask us for help, and we may temporarily access your account, with your permission, to debug an issue.
- A court orders it, in which case we comply with legally valid requests and notify you where we're permitted to.
There is no admin dashboard that exposes your balances or conversations for casual browsing by our team.
Sub-processors
These are the third-party services we rely on to operate Wealthos. Each handles a specific part of the system.
| Provider | Purpose | What they see |
|---|---|---|
| Supabase | Authentication, database & hosting (EU) | Account info, financial data, chat history |
| GoCardless | Open Banking connections (PSD2) | Read-only balances of accounts you connect |
| Mistral AI | AI assistant model | Chat messages & context, when selected |
| Anthropic | AI assistant model (Claude) | Chat messages & context, when selected |
| Stripe | Payment processing | Billing info (we never see your card number) |
| PostHog | Product analytics (cookieless, EU) | Usage events, never your financial content |
Exporting and deleting your data
- Account deletion: You can delete your account yourself from your account settings. All of your personal data (account info, financial data, goals, and AI conversation history) is permanently and irreversibly deleted immediately. This can't be undone.
- Bank connections: Disconnect any connected bank at any time, which immediately revokes access and removes the associated connection data.
- Access & portability: You can request a copy of your data in a machine-readable format by emailing us. See your rights under GDPR.
Getting in touch
Questions, criticisms, or something on this page you think we've gotten wrong? Telling us makes it better.
Wealthos
Email: support@wealthos.cc
For the legal version of everything here, see our Privacy Policy and Terms of Service.