Skip to content
← BackLegal

Privacy policy

How Sumant handles your data. Plain language, no legal jargon.

Last updated: 20 September 2026

In short

  • Your financial data belongs to you. We never sell it or use it for advertising.
  • Synced data lives in Supabase’s European region in Ireland, encrypted in transit and at rest.
  • Sumant does not connect to your bank. You add movements manually or import a CSV, Excel (.xlsx) or Norma 43 file.
  • You can export your data from Settings → Data and delete your account from Settings → Account.
  • No advertising tracking or data sales. Product analytics starts only with your consent.

At Sumant we care about your data. This document explains clearly what information we collect, what we use it for, who we share it with, and what you can do about it.

1. Data controller

The owner of the Sumant project. Contact: hello@sumant.app.

This processing is governed by the General Data Protection Regulation (GDPR, EU 2016/679) and Spanish Organic Law 3/2018 on Data Protection.

2. Data we process

Sumant requires an account to work — we need an email to identify you and sync your data across devices. The data we handle:

  • Account data: your email and the credential managed by Supabase using a secure hash; Sumant never sees your password in plain text.
  • Optional Google sign-in: if you choose this option, Google authenticates your account and shares your identifier, verified email and basic profile information, such as your name and photo, with Supabase. This sign-in does not send your movements, amounts or categories to Google and does not request Gmail or Drive access. Google handles access to your account under its privacy policy.
  • Financial data you enter: accounts, categories, movements, budgets, goals, recurring entries, manual net worth, categorisation rules and notes. Stored first in IndexedDB in your browser and, while signed in, synced with Supabase over HTTPS and encrypted at rest.
  • File imports (CSV, Excel .xlsx and Norma 43): the original file is read and transformed in your browser; we do not upload it as a file. The resulting movements, accounts or categories are stored like any other Sumant data and sync while you are signed in.
  • Local categorisation: Sumant can suggest categories by comparing the description with your own history through a self-hosted model running on the device. Derived vectors stay on that device and are not synced.
  • Add from text or a screenshot: what you type or paste is read on your device. When you choose a screenshot or a photo, the app sends it, oriented and re-encoded, to our AI provider (Cloudflare Workers AI) together with today's date and your time zone, to propose the transactions shown in it: amount, type, date and description. The image includes any other detail visible in it. We do not send your financial history or your categories; the category is proposed on your device. Neither we nor the provider keep the image or the reading, and Cloudflare does not use them to train models: we only store the number of readings per day and per account and technical data about each reading (duration and usage) to cap usage. For a text, when local analysis is not enough and smart assistance is enabled, a limited fragment of the text may be sent to the same provider together with today's date; account numbers, cards, phone numbers, emails and balance lines are removed first, and the fragment is cut to a maximum size. When the reading is unavailable, you can type the transaction or add it manually.
  • App settings: theme, language, primary currency, first day of the week and the name we greet you with, if you set one. They sync with your account just like a movement does.
  • Analytics and technical diagnostics: if you accept analytics, Umami (hosted on our own server in the EU, at stats.sumant.app) processes every pageview and the usage events we define: it receives the URL without query string or hash, the domain, the referring page, the screen resolution and the browser language. Page titles are sent only from the public website; app page titles are excluded. From the request the server derives browser, operating system, device type and approximate country, and uses the IP and User-Agent to group the session; Umami states it does not store the IP. We use technical identifiers to distinguish journeys and a temporary identifier to relate the steps of an import attempt. We do not send your account identifier, amounts, notes, descriptions or category names. The Umami dashboard shows aggregated metrics. On the landing, the same consent enables Vercel Web Analytics and Speed Insights: Vercel receives page views and performance metrics, with the page URL without query parameters or a hash and technical browsing, device and approximate location data. You can withdraw that consent from the footer. Sentry receives reduced technical diagnostics: error type, release and location in application files. We filter original messages, navigation actions, account identifiers and financial content. We do not enable session recordings or performance tracing. Connecting to the provider involves technical network metadata.
  • Payment data (only if you buy PRO): handled by Stripe. Sumant does not store your card number at any time. We only receive a payment identifier and the plan contracted.
  • Communications: if you write to us, we keep your email and message to reply.
  • Support tickets: if you open a ticket from the app, we keep the subject, the category, the messages in the thread and four technical details that help reproduce the problem: app version, whether you use it installed or in a browser, the User-Agent and your language. We attach no financial data: no amounts, no descriptions, no notes, no category names, no accounts, no balances. The thread is seen by you and us; we email you that there is a reply, but the notice does not include its content.
  • Newsletter signup: if you join the list, we keep your email and, optionally, your feedback message.

What we do NOT process: we don't connect to your bank, we don't process banking credentials, we don't track your browsing outside the app, we don't profile you for third parties.

3. Purposes

  • Provide the service (record and display your finances).
  • Sync your data across your devices.
  • Import movements and suggest categories within your device.
  • Interpret a text or a screenshot to propose a movement, on the device and, only when that is not enough, with a text fragment sent to our AI provider.
  • Measure product use only if you accept analytics.
  • Detect errors and protect the service.
  • Manage your PRO purchase if you buy it.
  • Reply when you contact us.
  • Send you product updates, only if you've subscribed.
  • Comply with legal obligations (invoicing, tax).
  • Contract performance: by creating an account you accept the Terms; we process your data to provide the service.
  • Consent: for Umami analytics and, on the landing, Vercel Web Analytics and Speed Insights, as well as newsletters or marketing communications. You can withdraw it anytime.
  • Legal obligation: invoicing and tax regulations.
  • Legitimate interest: service security and fraud prevention.

5. Who accesses your data

You. Internally, only personnel strictly necessary to operate the service can access your synced data, always for technical purposes and never commercial.

6. Processors

We work with these providers for the functions shown:

  • Supabase (European region in Ireland) — synced data storage and authentication.
  • Cloudflare — app hosting, CDN and the AI model (Workers AI) that reads screenshots and photos and, when smart assistance is enabled, the text fragment described in section 2; it keeps neither the image nor the fragment and does not use them for training. When active, Turnstile checks connection, browser and origin signals, including the IP address, to protect forms. Cloudflare also uses these signals to improve bot detection. See its Turnstile privacy notice.
  • Vercel — landing hosting and forms; landing page-view and performance measurement only if you accept analytics. Read the information for Web Analytics and Speed Insights.
  • Stripe — payment processing. PCI-DSS Level 1 compliant.
  • Resend — transactional emails and newsletter delivery.
  • Umami (hosted on our own server in the EU, at stats.sumant.app) — product analytics: pageviews, usage events and technical journey and import-attempt identifiers, only after you accept analytics. We manage that server ourselves.
  • Sentry — filtered technical diagnostics, without session recordings.
  • Upstash — IP-address processing to rate-limit abuse of public forms, and internal account identifiers for authenticated operations, including import usage, support notifications and account deletion. Its additional analytics is not enabled.
  • Frankfurter — exchange-rate queries. The request includes the currencies queried and the technical metadata needed to serve it.

7. International transfers

Supabase stores synced data in Ireland and Umami analytics are processed on our own server in the EU. Cloudflare, Vercel, Stripe and Resend may process data outside the EEA for the functions described. We have not verified the effective account region for Sentry and Upstash, so those services may also involve international transfers. Frankfurter requests are served through Cloudflare and may include technical metadata. Where applicable, processing relies on adequacy decisions, Standard Contractual Clauses or other safeguards permitted by GDPR according to the provider's contractual documentation.

8. Retention period

We keep your data while your account is active. When you delete it, the app clears the device and closes the session only after the server confirms deletion of the account and active data. Retention periods for technical copies and logs depend on the provider, the contracted plan and legal obligations; there is no single period controlled by Sumant. You can write to hello@sumant.app to ask which period applies to your request.

9. Your rights

You can exercise the rights of access, rectification, erasure, objection, restriction and portability at any time. The fastest way:

  • From the app: Settings → Account → Delete account.
  • By writing to hello@sumant.app.

If you believe we haven't respected your rights, you can file a complaint with the Spanish Data Protection Agency.

10. Security

We apply appropriate technical and organizational measures: encryption in transit (HTTPS), encryption at rest in the database, Row Level Security to isolate your data, and secure authentication. No system is 100% inviolable, but we do everything reasonable to protect your information.

11. Cookies and similar

The landing and app use technical storage needed for language, session, preferences and the consent choice itself. Umami loads only if you accept analytics; at stats.sumant.app it processes every pageview and the events we define, with the URL without query string or hash, the domain, the referring page, the screen resolution and the language. Page titles are sent only from the public website; app page titles are excluded. The server derives browser, operating system, device and approximate country, without autocapture or session recording. Technical analytics identifiers are not your account identifier. When you withdraw consent, we stop sending activity and discard events waiting to be sent; this does not delete history already received. If you reject analytics before enabling it, we do not load the tool or store analytics identifiers. We do not use advertising tracking or sell data.

12. Minors

Sumant is for those aged 16+. We do not knowingly process minors' data.

13. Changes to this policy

If we update this policy we'll let you know here and by email (if you have an account) with at least 15 days' notice when changes are material.

14. Contact

For any inquiry about how we process your data, write to hello@sumant.app.

Privacy policy | Sumant