Your data and your rights

Last updated: 2026-09-07

What this page is

The Privacy Policy says what we collect and why. This page says how you exercise your rights over it: getting a copy of your data, deleting your account, and knowing what happens to your records afterwards.

Everything described here is something you can do yourself, signed in, from Settings, then Privacy. You never need to email us to get your data or to delete your account, although you can (see the end of this page).

What we hold about you

Your account (name, email address, the language and currency you chose), your wallets, transactions, categories, budgets, events and income sources, the files you uploaded and the text we read out of them, your setup chat, the import jobs you ran, the people you are connected with, the emails we sent you, the sign-in history for your account, and a record of which terms you accepted and when.

We do not hold your bank credentials. SavingStat never connects to your bank.

Get a copy of your data

  1. Open Settings, then Privacy and choose Request a copy of my data.

  2. We email you a 6-digit code. Enter it within one hour. This proves the request comes from the person who controls the email address, not from someone sitting at an unlocked screen.

  3. We email you again to confirm the request is accepted and being prepared.

  4. When the archive is ready, usually within minutes and never later than 30 days, we email you once more. Download it from the same Privacy page.

The archive is a zip file. Inside is one JSON file per kind of record (transactions.json, wallets.json, budgets.json and so on) and a manifest.json listing what is included. files.json lists every document you uploaded, with its name, type, size and the text we read out of it. The documents themselves are not in the archive: you can download each original from the Files page at any time, and you should do that before deleting your account.

It contains your data only. In a shared budget or event, other people's transactions are their data, not yours, so they are not in your archive; the other members appear by first name, never by email address.

Each download link works for 15 minutes; open the Privacy page again for a fresh one. The archive itself is deleted 7 days after it is ready. You can request a new one at any time.

Delete your account

  1. Open Settings, then Privacy and choose Delete my account.

  2. We email you a 6-digit code. Enter it within one hour.

  3. Your account is now scheduled for deletion 14 days from that moment. We email you the exact date. Until then the account works exactly as before. Download any files you want to keep from the Files page before the date; uploaded documents are not part of the data export.

  4. We remind you 7 days and 1 day before the date. Each email, including the first, has a Keep my account button.

  5. On the date, the deletion runs. We send one final email to confirm it is done. After that we hold nothing that identifies you and nothing can be restored.

What is deleted: your account, wallets, transactions, income, categories, uploaded files and their read-out text, chats, import history, connections, the emails we sent you, your sign-in history, and any connected-app access. Our AI processing service is told to remove its copies too.

What changes hands instead: a budget, event or category you own and share with someone who has accepted is not deleted. It passes to one of those people (a co-owner first, otherwise a member), because it is their data as well. Your own transactions inside it are still removed, so its totals change; the new owner is told.

Staff accounts cannot be deleted this way; they go through the administrator.

Cancel a deletion

Any time before the date, either sign in and choose Keep my account on the Privacy page, or press Keep my account in any of the emails. The button needs no sign-in, so it works even if you have lost access to the account.

Cancelling deletes nothing and changes nothing. We email you to confirm. If you receive that email and did not cancel, change your password and contact us.

We record which version of the Terms and Conditions you accepted, when, and from where. When the terms change, we ask you to accept the new version before you continue, and that acceptance is recorded the same way. The record is part of your data export.

How long we keep things

Most of your records exist for as long as your account does, then go with it. A few kinds are removed earlier, automatically, every night:

  • Sign-in history: the IP address and browser details are removed after 90 days; the entry itself after 1 year.

  • Copies of emails we sent you: 30 days.

  • Verification codes and reset links: 7 days after they are used or expire.

  • Data export archives: 7 days after they are ready.

  • Accounts that never verified their email address: deleted 30 days after registration.

  • Server logs: 30 days.

The full list, generated from the code that enforces it, is kept with the service's technical documentation.

Connected apps and AI assistants

An app or assistant you connected to SavingStat can read and change your financial records within the access you granted. It can not request a copy of your data, delete your account, or accept terms on your behalf. Those actions exist only here, for you, signed in, with a code sent to your email address.

You can see and revoke every connected app from Settings, then Connections.

Contact and complaints

For anything this page does not cover, or if you would rather we did it for you, email support@savingstat.com. We answer within one month.

If you believe we handle your data unlawfully, you can complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or to the supervisory authority of the country where you live.