Privacy Policy
Last updated: [date]
Who this is
mijnVast is operated by iVisdom, [registered address], Netherlands (KvK: [number]). For any privacy question, contact [contact email].
What we collect
Account: email address, password (stored hashed by our authentication provider, never in plain text), and your name if you provide one.
Subscription data: whatever you enter or upload about your insurance policies, utilities, and subscriptions, including provider names, amounts, dates, policy or account numbers, and any contact details or notes you add.
Documents: contracts or policy documents you upload are stored so you can refer back to them. Bank or card statements uploaded for bulk import are processed and then deleted. They are not kept.
Usage data: how many AI imports you've used, to enforce fair usage limits. We don't log the content of what you import, only that an import happened and when.
What we don't collect
We don't ask for or store payment card details ourselves. If paid plans launch, that will go through a payment processor who handles your card details directly, not through our servers.
We don't link to your bank account. Statement import works from a file you upload yourself, once. We never get live or ongoing access to your bank.
Why we collect it
To provide the service: storing your subscriptions, sending you reminders before things renew, and using AI to read documents you upload so you don't have to type everything by hand.
Who else sees it
We use a small number of service providers to run the app, each only for what they need to do their job.
Supabase: database, authentication, and file storage. Google (Gemini API): reads uploaded documents and statements to extract structured data. Resend: sends reminder emails and receives emails you forward to your personal forwarding address. Vercel: hosts the application.
We don't sell your data, and we don't share it with advertisers. We don't have any advertisers.
How long we keep it
For as long as your account is active. Uploaded bank or card statements are deleted immediately after processing. Contact us to request deletion of your account and data; see "Your rights" below.
Your rights
Under GDPR, you can ask us to access, correct, export, or delete your personal data at any time. Email [contact email] and we'll act on it. There's no self-service delete button yet, so for now this is a manual request we handle directly.
Cookies
We use a minimal session cookie/local storage entry to keep you signed in. No advertising or tracking cookies.
Changes
If this policy changes materially, we'll update the date above and, for significant changes, email active accounts.