Privacy Policy
1. Data Controller
The controller of your personal data under Regulation (EU) 2016/679 (GDPR) is:
Jan Zítko Company ID (IČO): 76665496 Skuteckého 1383/8, 163 00 Prague - Řepy, Czech Republic Self-employed individual (OSVČ) Contact: info@treziqo.com
2. What Data We Collect
- Identification: first name, last name, nickname, email, phone (optional), secondary email (optional)
- Authentication: password (stored hashed — we never see plaintext), avatar (optional)
- Financial records you enter: accounts, transactions, categories, budgets, tags, liabilities, investments, notes
- Uploaded documents: photos and PDFs of receipts, bank statements submitted for import
- AI conversations: history of your questions and the assistant's answers (only if you use the feature)
- Billing: subscription ID, transaction IDs and amounts at PayPal or Stripe (we do not store card numbers — they stay with the payment provider)
- Preferences: language, theme, currency, transactions per page, default sorting
- Operational: registration date, last login, terms acceptance timestamp, IP address (server logs only)
3. Purpose and Legal Basis
- Service delivery (GDPR Art. 6(1)(b) — contract performance): all data you enter to use the app
- Billing (Art. 6(1)(b) + legal obligation under Czech accounting law 563/1991 Coll. — Art. 6(1)(c)): subscription and payment data, retained 10 years
- Security and fraud prevention (Art. 6(1)(f) — legitimate interest): server logs, login records
- Customer support (Art. 6(1)(b)): email communication
4. Who Else Sees Your Data (Processors)
We share your data only with providers necessary to operate the service:
Infrastructure
- Hetzner Online GmbH — server and database infrastructure (managed via Laravel Forge)
- SvetHostingu.cz, s.r.o. (Czech Republic) — SMTP server for transactional emails (password reset, email verification, billing, notifications)
Payments
- PayPal (Europe) S.à r.l. et Cie, S.C.A. — payment processing (own Privacy Policy at paypal.com)
- Stripe — card, Google Pay and Apple Pay processing (own Privacy Policy at stripe.com)
External account sign-in — only if you use it
- Google LLC (USA) — sign in with your Google account (OAuth 2.0). We pass only the email and name required to create or link the account. Nothing is sent to Google unless you actively use this option.
AI features — only if you use them, see Section 5
- Anthropic PBC (USA) — Claude model: AI assistant questions together with the relevant slice of your financial data, and uploaded receipts
Marketing — only if you have given consent
- Mailgun (Sinch) (USA) — marketing email and newsletter delivery
We do not sell, rent, or share your data with advertising or marketing partners.
Transfers Outside the EU
Anthropic, Mailgun and Google process data on servers in the United States. These transfers rely on the European Commission's Standard Contractual Clauses under Art. 46 GDPR, included in the data processing agreements concluded with these providers.
We use OpenAI (DALL·E 3) to generate illustration images for blog articles. No data of yours is sent to that service — the only input is the article title.
5. Processing by Artificial Intelligence (AI)
The application includes two optional AI features. You can turn either off at any time in /settings.
- AI finance assistant (PRO plan): your question and the relevant slice of your financial data (transactions, balances, budgets, liabilities, investments) are sent to the Anthropic API. The model has read-only access and sees only your own data — it never sees other users' data and cannot create, modify, or delete anything in the application. Conversation history is stored and you can delete it in the app.
- Receipt scanning (off by default, enabled in
/settings): an uploaded receipt photo or PDF is sent to the Anthropic API for item recognition. The result is always shown to you for review — no transaction is created automatically.
The model provider does not use your data to train its models.
AI output may contain errors and does not constitute financial or investment advice — always verify important decisions.
Blog articles are created with AI assistance and always undergo human editorial review before publication; this is stated on every article. No user data is used to create them.
6. Retention
- Active account: data kept while the account exists
- After account deletion: most data deleted immediately; billing records retained 10 years (accounting law)
- Server logs: 90-day rolling
7. Your Rights (GDPR)
- Access (Art. 15): see all data we have about you — via self-service export in /settings
- Rectification (Art. 16): correct data via /settings
- Erasure (Art. 17): delete account via /settings (billing records kept per legal duty)
- Portability (Art. 20): export all records as ZIP via /settings
- Object (Art. 21): contact us by email
- Complaint (Art. 77): Czech Data Protection Authority — www.uoou.cz
8. Cookies
See separate Cookie Policy.
9. Changes to This Policy
We may update this policy. Material changes will be notified by email and in-app banner at least 30 days before taking effect.
Version: 3.0 Effective from: 2026-08-17