Legal

Privacy Policy

Last updated: June 29, 2025

This Privacy Policy explains how Haako ("we," "us," or "our") collects, uses, and protects your personal information when you use our portfolio intelligence application. By using Haako, you agree to this policy.

1. Information we collect

Account information

  • Name, email address
  • Authentication credentials (securely hashed — we never store plaintext passwords)
  • Subscription and billing information (processed by Stripe)

Financial data you enter

  • Portfolio holdings, transactions, and manual entries
  • Budget categories and spending goals you create
  • Decision journal entries and conviction notes

Usage information

  • Feature interactions and app usage patterns
  • Device type, operating system, and browser
  • IP address and general location
  • Performance and error logs (via Sentry)

2. How we use your information

We use your information solely to operate and improve Haako:

  • Provide personalised portfolio dashboards and financial tools
  • Process subscription payments through Stripe
  • Send important account, security, and billing notifications
  • Respond to support requests and inquiries
  • Diagnose bugs and improve performance
  • Share product updates with your consent
AI-assisted insights. Some optional features generate spending insights using a third-party AI provider (Google). We send only aggregated, pseudonymised data — category totals and amounts — and strip direct identifiers such as merchant and payee names before any data leaves our systems. Your data is not used to train AI models.
Not financial advice. Haako provides tools and information only. We do not provide investment, tax, or legal advice. Always consult qualified professionals.

3. Data protection

We apply industry-standard security practices:

Encryption in transit

All connections use TLS 1.3. Data is never sent unencrypted.

Encryption at rest

Database rows are encrypted at rest via AES-256 on Supabase.

No credential storage

We never store banking passwords or API keys on our servers.

SOC 2 infrastructure

Hosted on Supabase and Vercel, both with SOC 2 Type II compliance.

4. Information sharing

We do not sell your data. We never sell, rent, or trade your personal information to third parties for marketing purposes.

We may share information only with:

  • Stripe — to process subscription payments securely
  • Supabase — our database and auth infrastructure provider
  • Vercel — our hosting and edge infrastructure provider
  • Sentry — for error monitoring (anonymised where possible)
  • Resend — to deliver transactional and account emails
  • Google — to generate optional AI spending insights from pseudonymised, aggregated data (no model training)
  • Legal authorities — only when required by law or court order

5. Your privacy rights

Under GDPR and applicable privacy law, you have the right to:

Access

Request a copy of all personal data we hold about you

Correct

Fix any inaccurate or incomplete information

Delete

Request permanent deletion of your account and data

Export

Download your data in a portable, machine-readable format

Opt out

Unsubscribe from marketing communications at any time

Restrict

Limit how we process your data in certain circumstances

To exercise any of these rights, contact us at sethydeveloper@gmail.com.

6. Cookies & tracking

We use a minimal set of cookies required to operate the service:

  • Essential cookies — session authentication and CSRF protection
  • Analytics — anonymised usage data via Vercel Analytics (no personal identifiers)
  • Preferences — theme and UI settings stored in localStorage

We do not use third-party advertising cookies or tracking pixels.

7. Data retention

We keep data only as long as there is a specific purpose for it. The schedule below is technically enforced — automated jobs delete data on the timelines described.

  • Account & financial data — retained until you delete your account; deletion is immediate and permanent across all tables
  • Audit logs — rolling 12-month window; purged weekly
  • Request deduplication tokens — purged after 48 hours (daily cron)
  • Support enquiries — deleted 12 months after resolution (monthly cron)
  • Waitlist entries — deleted after 24 months (monthly cron)
  • Mobile device push tokens — purged 90 days after last active use (weekly cron). Erased immediately on account deletion. Device tokens are not included in data exports.
  • Error & performance traces — Sentry retains events for 90 days under our plan

8. Changes & contact

We may update this Privacy Policy to reflect changes in our practices or applicable law. We will notify you of significant changes via email or an in-app notice at least 30 days in advance.

Get in touch
sethydeveloper@gmail.com

Paris, France · We reply within one business day.