At Sumant we care about your data. This document explains clearly what information we collect, what we use it for, who we share it with, and what you can do about it.
1. Data controller
The owner of the Sumant project. Contact: hello@sumant.app.
This processing is governed by the General Data Protection Regulation (GDPR, EU 2016/679) and Spanish Organic Law 3/2018 on Data Protection.
2. Data we process
Sumant requires an account to work — we need an email to identify you and sync your data across devices. The data we handle:
- Account data: your email and the credential managed by Supabase using a secure hash; Sumant never sees your password in plain text.
- Financial data you enter: accounts, categories, movements, budgets, goals, recurring entries, manual net worth and notes. Stored first in IndexedDB in your browser and, while signed in, synced with Supabase over HTTPS and encrypted at rest.
- CSV/XLSX imports: the original file is read and transformed in your browser; we do not upload it as a file. The resulting movements, accounts or categories are stored like any other Sumant data and sync while you are signed in.
- Local categorisation: Sumant can suggest categories by comparing the description with your own history through a self-hosted model running on the device. Derived vectors stay on that device and are not synced.
- Analytics and technical diagnostics: if you accept analytics, Umami (hosted on our own server in the EU, at stats.sumant.app) processes every pageview and the usage events we define: it receives the URL without query string or hash, the domain, the referring page, the title, the screen resolution and the browser language. From the request the server derives browser, operating system, device type and approximate country, and uses the IP and User-Agent to group the session; Umami states it does not store the IP. In the app, if you are signed in, we associate your account identifier with the session. We do not send amounts, notes, descriptions or category names, and no third party receives this data: the server is ours. Its dashboard shows aggregated metrics. Sentry may receive errors, URLs, browser details and technical stack traces; it is configured without replay, tracing or default PII.
- Payment data (only if you buy PRO): handled by Stripe. Sumant does not store your card number at any time. We only receive a payment identifier and the plan contracted.
- Communications: if you write to us, we keep your email and message to reply.
- Newsletter signup: if you join the list, we keep your email and, optionally, your feedback message.
What we do NOT process: we don't connect to your bank, we don't process banking credentials, we don't track your browsing outside the app, we don't profile you for third parties.
3. Purposes
- Provide the service (record and display your finances).
- Sync your data across your devices.
- Import movements and suggest categories within your device.
- Measure product use only if you accept analytics.
- Detect errors and protect the service.
- Manage your PRO subscription if you contract one.
- Reply when you contact us.
- Send you product updates, only if you've subscribed.
- Comply with legal obligations (invoicing, tax).
4. Legal basis
- Contract performance: by creating an account you accept the Terms; we process your data to provide the service.
- Consent: for Umami, newsletters or marketing communications. You can withdraw it anytime.
- Legal obligation: invoicing and tax regulations.
- Legitimate interest: service security and fraud prevention.
5. Who accesses your data
You. Internally, only personnel strictly necessary to operate the service can access your synced data, always for technical purposes and never commercial.
6. Processors
We work with these providers for the functions shown:
- Supabase (European region in Ireland) — synced data storage and authentication.
- Cloudflare — app hosting and CDN.
- Vercel — landing hosting and forms.
- Stripe — payment processing. PCI-DSS Level 1 compliant.
- Resend — transactional emails and newsletter delivery.
- Umami (hosted on our own server in the EU, at stats.sumant.app) — product analytics: pageviews, usage events and an account identifier, only after you accept analytics. No third party is involved.
- Sentry — technical error diagnostics, without replay or default PII.
- Upstash — IP-address processing to rate-limit abuse of public forms, without its additional analytics enabled.
- Frankfurter — exchange-rate queries. The request includes the currencies queried and the technical metadata needed to serve it.
7. International transfers
Supabase stores synced data in Ireland and analytics are processed on our own server in the EU. Cloudflare, Vercel, Stripe and Resend may process data outside the EEA for the functions described. We have not verified the effective account region for Sentry and Upstash, so those services may also involve international transfers. Frankfurter requests are served through Cloudflare and may include technical metadata. Where applicable, processing relies on adequacy decisions, Standard Contractual Clauses or other safeguards permitted by GDPR according to the provider's contractual documentation.
8. Retention period
We keep your data while your account is active. When you delete it, the app clears the device and closes the session only after the server confirms deletion of the account and active data. Retention periods for technical copies and logs depend on the provider, the contracted plan and legal obligations; there is no single period controlled by Sumant. You can write to hello@sumant.app to ask which period applies to your request.
9. Your rights
You can exercise the rights of access, rectification, erasure, objection, restriction and portability at any time. The fastest way:
- From the app: Settings → Account → Delete account.
- By writing to hello@sumant.app.
If you believe we haven't respected your rights, you can file a complaint with the Spanish Data Protection Agency.
10. Security
We apply appropriate technical and organizational measures: encryption in transit (HTTPS), encryption at rest in the database, Row Level Security to isolate your data, and secure authentication. No system is 100% inviolable, but we do everything reasonable to protect your information.
11. Cookies and similar
The landing and app use technical storage needed for language, session, preferences and the consent choice itself. Umami loads only if you accept analytics; at stats.sumant.app it processes every pageview and the events we define, with the URL without query string or hash, the domain, the referring page, the title, the screen resolution and the language, and derives browser, operating system, device and approximate country, without autocapture or session recording. If you are signed in to the app, it associates your account identifier. If you reject it, we do not load the tool or store analytics identifiers. We do not use advertising tracking or sell data.
12. Minors
Sumant is for those aged 16+. We do not knowingly process minors' data.
13. Changes to this policy
If we update this policy we'll let you know here and by email (if you have an account) with at least 15 days' notice when changes are material.
14. Contact
For any inquiry about how we process your data, write to hello@sumant.app.