Privacy Policy

Last updated: March 9, 2026

This Privacy Policy explains how MyWidgets collects, uses, stores, and protects your personal data, and describes your rights under the General Data Protection Regulation (GDPR) and other applicable privacy laws.

1. Data Controller

MyWidgets operates as the data controller for the personal data processed through this Service. If you have any questions about how your data is handled, please contact us through the application's support channels.

2. Data We Collect

We collect the following categories of personal data:

Account Data

  • Email address — used to identify your account and for authentication.
  • Name — used to personalise your experience.
  • Password (hashed) — stored securely; we never store plaintext passwords.
  • Google OAuth token — if you choose to sign in with Google, we receive a token to verify your identity but do not store your Google password.

Financial Data (User-Provided)

  • Account names, balances, and types (e.g., savings, checking, investment).
  • Transaction records including amounts, dates, descriptions, and categories.
  • Budget amounts and savings goals.
  • Asset valuations and related details.
  • Currency preferences.

This financial data is provided entirely by you. We do not connect to any bank or financial institution on your behalf.

Technical Data

  • Authentication tokens (stored in your browser's local storage).
  • User preferences (theme, display currency, privacy mode settings).

3. Legal Basis for Processing (GDPR)

We process your personal data on the following legal bases under Article 6 of the GDPR:

  • Contract performance (Art. 6(1)(b)) — processing your account and financial data is necessary to provide the Service you have signed up for.
  • Legitimate interests (Art. 6(1)(f)) — to maintain the security and integrity of the Service, and to prevent fraud or abuse.
  • Consent (Art. 6(1)(a)) — where you have explicitly consented, such as linking a Google account for sign-in.

4. How We Use Your Data

  • To authenticate you and maintain your account.
  • To store and display your financial data within the application.
  • To calculate aggregated summaries (net worth, budget progress, goal tracking) shown in your dashboard.
  • To provide currency conversion using exchange rate data.
  • To ensure the security and proper functioning of the Service.

We do not use your data for advertising, profiling, or sale to third parties.

5. Data Sharing & Third Parties

We do not sell, rent, or trade your personal data. We may share data with:

  • Google OAuth — if you choose to sign in with Google, authentication is handled via Google's OAuth 2.0 service. Google's Privacy Policy applies to that interaction.
  • Infrastructure providers — hosting and database services required to operate the application, bound by data processing agreements.
  • Legal obligations — if required by law, regulation, or court order.

6. Data Retention

We retain your personal data for as long as your account is active. If you delete your account:

  • Your account data and all associated financial data are permanently deleted within 30 days.
  • Backups are purged on a rolling basis within the same period.

You may request deletion at any time — see your rights in Section 8 below.

7. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encrypted data transmission (HTTPS/TLS).
  • Passwords stored using industry-standard hashing algorithms.
  • Authentication tokens with expiry to limit exposure from stolen tokens.
  • Access controls limiting who can access production data.

However, no method of transmission or storage is 100% secure. In the event of a data breach affecting your rights and freedoms, we will notify you and the relevant supervisory authority as required by the GDPR.

8. Your Rights Under GDPR

If you are located in the European Economic Area (EEA) or the UK, you have the following rights regarding your personal data:

  • Right of access (Art. 15) — you can request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16) — you can correct inaccurate or incomplete data directly within the app or by contacting us.
  • Right to erasure (Art. 17) — you can request deletion of your personal data. You may delete your account at any time from the account settings.
  • Right to restriction of processing (Art. 18) — you can ask us to restrict processing in certain circumstances.
  • Right to data portability (Art. 20) — you can export your financial data in JSON or CSV format from the Data Management section in Settings.
  • Right to object (Art. 21) — you can object to processing based on legitimate interests.
  • Right to withdraw consent — where processing is based on consent (e.g., Google sign-in), you can withdraw consent at any time via Settings.

To exercise any of these rights, contact us through the application. We will respond within 30 days.

9. Right to Lodge a Complaint

You have the right to lodge a complaint with your national data protection supervisory authority if you believe your rights have been violated. A list of EU supervisory authorities is available at edpb.europa.eu.

10. Cookies & Local Storage

MyWidgets does not use tracking cookies. We use browser local storage solely to maintain your authentication session (auth token) and persist UI preferences (theme, display currency). No data is shared with advertisers or analytics platforms.

11. International Data Transfers

If your data is transferred outside the EEA, we ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses) as required by Chapter V of the GDPR.

12. Children's Privacy

The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes by updating the "Last Updated" date. We encourage you to review this policy regularly.

14. Contact Us

For questions, requests, or concerns about your personal data, please contact us through the in-app support channels or via the account settings page.