This Privacy Policy explains how mealheiro ("we", "us") processes your personal data when you use the mealheiro application (the "Service"). We process personal data in accordance with the EU General Data Protection Regulation ("GDPR").
1. Controller and contact
The data controller is the mealheiro project operator. Contact: support@mealheiro.app.
2. What data we collect
Account data
- Email address, first name and last name (provided at sign-up).
- Your password, stored only as a cryptographic hash — we never store or see your plain-text password.
- The version and timestamp of the Terms of Service and Privacy Policy you accepted at registration.
Financial records you enter
- Accounts, transactions (title, description, value, type, date), categories and labels that you create manually in the Service.
- This data is entered by you; the Service does not connect to your bank or any third-party financial institution.
Technical data
- An authentication cookie (
accessToken) and a session-scoped browser storage entry holding your profile name and email. Both are strictly necessary to operate the Service. - Server logs, traces and metrics needed to run and secure the Service (which may include IP addresses in transport logs).
- Optional, consent-based front-end performance monitoring (see section 5).
3. Purposes and legal bases
- Providing the Service (account management, storing and displaying your financial records): performance of a contract, Art. 6(1)(b) GDPR.
- Security and abuse prevention (server logs, authentication): legitimate interest, Art. 6(1)(f) GDPR.
- Proof of consent (accepted terms version and date): legal obligation / accountability, Art. 6(1)(c) and 7(1) GDPR.
- Front-end performance monitoring: consent, Art. 6(1)(a) GDPR — only active if you opt in, and you can withdraw at any time in Settings.
We do not sell your personal data, we do not use it for advertising, and we do not use it for automated decision-making or profiling that produces legal effects.
4. Cookies and local storage
accessToken— httpOnly cookie that keeps you signed in. Strictly necessary; expires with your session token.NEXT_LOCALE— cookie remembering your language choice. Strictly necessary for the requested functionality.user-storage— sessionStorage entry with your name and email for display; cleared when the browser session ends or you log out.telemetry-consent— localStorage entry remembering your monitoring consent choice.theme— localStorage entry remembering your light/dark theme choice.color-theme— localStorage entry remembering your accent colour choice.
Because the strictly necessary items are exempt from consent under the ePrivacy rules, the only consent we ask for is the optional performance monitoring below.
5. Performance monitoring (optional)
If you opt in, we use Grafana Faro real-user monitoring to collect error reports, page-load timings and request traces from your browser. This helps us find bugs and slowness. The data is pseudonymous session telemetry; we do not use it to build user profiles. You can grant or withdraw this consent at any time on the Settings page — withdrawing stops collection from your next page load.
6. Recipients and processors
We use the following providers to run the Service, acting as processors under Art. 28 GDPR data-processing agreements:
- Hetzner Online GmbH (Germany) — hosts the backend API and the PostgreSQL database where your account and financial records are stored, in its Helsinki (Finland) datacentre. Your data stays in the EU.
- Vercel Inc. (USA) — hosts the web front-end that serves the application to your browser.
- Cloudflare, Inc. (USA) — provides DNS and acts as a network proxy in front of the Service; it sees IP addresses and traffic metadata in transit.
- Grafana Labs (USA) — receives the optional, consent-based performance telemetry described in section 5. Nothing is sent unless you opt in.
We disclose personal data to public authorities only where legally required.
Where a processor is located outside the EU/EEA, transfers rely on an adequacy decision (such as the EU–US Data Privacy Framework) or the European Commission's Standard Contractual Clauses.
7. Retention
- Account and financial data: kept while your account exists; erased when you delete your account.
- Operational logs and traces (including opt-in telemetry): kept for 30 days, then deleted. Aggregated, non-identifying performance metrics are kept for up to 13 months.
- Backups: deleted data leaves database backup rotations within 30 days at the latest.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- rectify inaccurate data (Art. 16);
- erasure — delete your account and data yourself in Settings, at any time (Art. 17);
- restrict or object to processing (Arts. 18, 21);
- data portability — download a machine-readable JSON export of all your data from Settings (Art. 20);
- withdraw any consent at any time, without affecting prior processing (Art. 7(3));
- lodge a complaint with a supervisory authority — in Portugal, the CNPD (Comissão Nacional de Proteção de Dados, cnpd.pt), or the authority of your country of residence (Art. 77).
For anything you cannot do self-service, contact support@mealheiro.app; we respond within one month.
9. Security
We protect your data with TLS encryption in transit, hashed passwords, per-user data isolation enforced on every request, and access controls on production systems. No system is perfectly secure; if a breach is likely to result in a risk to you, we will notify you and the supervisory authority as required by Arts. 33–34 GDPR.
10. Children
The Service is not directed at children and may not be used by anyone under 16 years of age. We do not knowingly collect data from children.
11. Changes to this policy
The version and effective date are shown at the top of this page. For material changes we will notify you in the application or by email. See also our Terms of Service.