Privacy Policy
Last updated: June 17, 2026
This Privacy Policy explains how Welfi (“Welfi,” “we,” “us”) collects, uses, shares, and protects your information when you use our web and mobile applications. By using Welfi you agree to the practices described here.
Zero-knowledge encryption
Your financial data — transactions, balances, budgets, accounts, and forecasts — is encrypted on your device with a key we never see. We store only ciphertext. Even if our database were breached, the financial values inside would be unreadable. See How we protect your money data for the full technical explanation.
1. Who we are
Welfi is operated by TK, an individual developer. For privacy questions or requests, contact us at info@welfi-app.com.
2. Data we collect
- Account data: your name and email, obtained when you sign up directly or via Google or Apple sign-in (note: Apple may provide a private relay email address).
- Financial data you enter: accounts, balances, transactions, budgets, categories, savings goals, assets, gold holdings, forecasts, and currency/exchange-rate settings. For password-based accounts, this data is encrypted on your device before it reaches us.
- AI conversations: the questions you ask the in-app assistant and the data sent to power its answers. Data is sent only when you actively ask a question — never in the background.
- Technical data: device and usage information, and crash/diagnostic logs.
3. How we use your data
We use your data to provide budgeting, forecasting, and reporting features; to power the educational AI assistant; to maintain and secure your account; and to improve the app. We do not sell your personal data.
4. Third parties and subprocessors
We share data with the following service providers only as needed to operate Welfi:
- Anthropic (Claude) and any other AI provider you configure — processes the financial data you submit to the AI assistant. Data is sent only after you give consent in-app, and only in response to a specific question you ask.
- Google — authentication (Sign in with Google).
- Apple — authentication (Sign in with Apple).
- Neon — database hosting. For password-based accounts, only encrypted ciphertext is stored there — Neon cannot read your financial values.
- Vercel — application hosting and content delivery.
- Frankfurter / European Central Bank — currency exchange-rate data (no personal data is sent).
- Sentry — error tracking and crash reporting. Crash reports may include device metadata but never your financial data.
- PostHog — product analytics. Loaded only when you accept analytics cookies via the cookie consent banner.
5. International transfers
Your data may be stored and processed in countries other than your own. Where required, we rely on appropriate safeguards for such transfers.
6. Your rights
Depending on where you live, you may have rights to access, correct, delete, export, or object to the processing of your data (GDPR), to know/delete/opt out (CCPA/CPRA), and equivalent rights under the UAE PDPL. You can permanently delete your account and all associated data at any time from Settings → Danger zone → Delete account inside the app. To exercise other rights, contact info@welfi-app.com.
7. Data retention
We keep your data for as long as your account is active. When you delete your account, your personal and financial data is erased from our systems within 30 days, except where we are legally required to retain limited records. For zero-knowledge accounts, the encrypted data is deleted; because we hold no key, the deleted ciphertext is permanently unreadable even before deletion completes.
8. Security
For password-based accounts, Welfi uses zero-knowledge encryption: your financial data is encrypted on your device with a key derived from your password before it is stored on our servers. We cannot read it; neither can our hosting providers or anyone who might breach the database. See How we protect your money data for the full explanation, including what this protection does and does not cover.
For Google and Apple sign-in accounts, encryption in transit (TLS) and access controls protect your data. Client-side encryption is not available for these accounts because there is no password from which to derive a key.
9. Children
Welfi is intended for users aged 18 and older. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected such data, please contact us at info@welfi-app.com and we will delete it promptly.
10. Changes and contact
We may update this policy from time to time; we will revise the “last updated” date above and, where appropriate, notify you in-app. For any questions, contact info@welfi-app.com.