GROVIA English version below

Політика приватності

Чинна з 10 вересня 2026 року.

GROVIA — застосунок для обліку особистих і сімейних фінансів. Ця сторінка каже прямо, які дані ми беремо, навіщо, де вони лежать і як їх забрати або видалити. Без юридичного туману: якщо щось написано тут, воно так і працює в коді.

Коротко. Ми не збираємо ваше ім'я. Ми не продаємо дані й не показуємо реклами. Ми не робимо розсилок — усі листи є відповіддю на вашу дію. Файл виписки не зберігається. Мовна модель не отримує ні тексту ваших запитань, ні описів операцій.

Хто відповідає за дані

GROVIA, Україна. Питання про дані, запит на копію чи на видалення — hello@grovia.com.ua. Відповідаємо протягом 30 днів, зазвичай швидше.

Які дані ми збираємо

Обліковий запис

ЩоНавіщо
Адреса поштиВхід, підтвердження адреси, відновлення пароля, запрошення до сімейного кабінету
ПарольЗберігається лише як хеш (Argon2id). Самого пароля в нас немає й відновити його ми не можемо — тільки замінити
Рік народженняПеревірка на 18+. Дата запитується один раз і після перевірки не зберігається — лишається тільки рік
Країна і моваВалюта, формат дат, мова листів і застосунку

Ім'я та прізвище ми не збираємо взагалі — ні при реєстрації, ні згодом. Номер телефону не обов'язковий.

Фінансові дані

Рахунки, операції, категорії, бюджети та фінансовий стан, який ви заповнюєте самі. Це те, заради чого застосунок існує, і воно належить вам.

Дані живуть у кабінеті. Кабінети розділені на рівні бази даних: запит без вашого кабінету не поверне жодного рядка — це правило самої бази, а не перевірка в коді, яку можна забути написати. У спільному кабінеті ролі визначають, хто що бачить: спостерігач читає, але не пише, а особисті рахунки лишаються особистими.

Журнал подій

Вхід, зміна пароля, підключення другого фактора, запрошення й виключення учасників, підключення банку. Він потрібен, щоб ви могли побачити, що з кабінетом робили, і щоб ми могли розібратися з чужим доступом. Журнал незмінний: записи в ньому не редагуються й не видаляються.

Листи

Ми надсилаємо три види листів, і кожен — відповідь на вашу дію: підтвердження адреси після реєстрації, посилання для відновлення пароля на ваш запит, запрошення до сімейного кабінету, коли власник кабінету ввів вашу адресу.

Розсилок, новин і рекламних листів немає. Списків адрес ми не купуємо, не орендуємо й не імпортуємо. Відписуватися нема від чого: припинити листи можна, видаливши обліковий запис.

Технічно листи йдуть через Amazon SES у регіоні eu-central-1 (Франкфурт). Тіло листа лежить у нашій черзі зашифрованим і стирається після відправлення.

ІІ-помічник

Помічник відповідає на запитання про ваші власні гроші. Він працює на зовнішній мовній моделі (OpenAI), і саме тому тут важливо, що саме туди йде.

До моделі не потрапляє ні текст вашого запитання, ні опис операції, ні назва вашої категорії. Туди йде код наміру із закритого переліку (наприклад «куди пішли гроші»), період і вже пораховані числа. Ваше запитання розбирає застосунок у вас на пристрої.

Модель не пише чисел сама: у її відповіді стоять посилання на пораховані величини, а підставляє їх застосунок. Зберігання запитів на боці провайдера вимкнене. Розмову з помічником можна стерти в застосунку однією дією — рахунки й операції при цьому лишаються на місці.

Виписки з банку

Файл, який ви завантажуєте, розбирається в пам'яті й зникає разом із запитом. Ми його не зберігаємо: видаляти через добу нема чого, його вже немає. У кабінет потрапляють тільки самі операції — ті, які ви підтвердили на екрані зіставлення.

Підключення банку

Пряме підключення банків планується через ліцензованого агрегатора, за вашою окремою згодою і на її строк. Токени доступу зберігаються на сервері й ніколи не потрапляють на пристрій. Відкликати згоду можна в застосунку: ми закриваємо підключення в себе й повідомляємо агрегатора.

Ця можливість ще не увімкнена для користувачів.

Де і як довго зберігаються дані

Сервери — Amazon Web Services, регіон eu-central-1 (Франкфурт, Німеччина). Дані кабінету зашифровані окремим ключем кабінету; сам ключ зберігається зашифрованим і видається лише службі, яка обробляє ваш запит. Копія бази без ключа марна.

Дані живуть, поки живе ваш обліковий запис. Після видалення ми стираємо кабінет і його вміст; у резервних копіях дані зникають протягом 30 днів разом зі звичайним циклом копій. Записи журналу подій, потрібні для безпеки, і бухгалтерські записи про оплату зберігаються довше — стільки, скільки вимагає закон.

Кому ми передаємо дані

Нікому, крім тих, без кого застосунок не працює:

Ми не продаємо дані, не обмінюємося ними з рекламними мережами й не вбудовуємо в застосунок сторонніх лічильників поведінки.

Ваші права

Діти

Застосунок для повнолітніх. Вік перевіряється при реєстрації, дитячих облікових записів ми не заводимо.

Зміни

Якщо ця політика зміниться по суті, ми повідомимо листом і оновимо дату вгорі. Дрібні правки формулювань показуємо тільки зміною дати.


Privacy Policy

Effective 10 September 2026. This is the English version of the policy above.

GROVIA is a personal and family finance application for Ukraine. This page states plainly what data we take, why, where it lives and how to get it back or delete it.

In short. We do not collect your name. We do not sell data and we show no advertising. We send no newsletters — every email is a direct response to something you did. Uploaded bank statement files are not stored. The language model receives neither the text of your questions nor any transaction descriptions.

Who is responsible

GROVIA, Ukraine. For questions about your data, a copy of it, or deletion: hello@grovia.com.ua. We answer within 30 days, usually sooner.

What we collect

Account

WhatWhy
Email addressSign-in, address confirmation, password reset, household invitations
PasswordStored only as an Argon2id hash. We do not hold the password itself and cannot recover it — only replace it
Year of birthAge check (18+). The full date is asked once and is not stored after the check — only the year remains
Country and languageCurrency, date format, language of the app and of emails

We do not collect names at all. A phone number is optional.

Financial data

Accounts, transactions, categories, budgets and the financial profile you fill in yourself. It belongs to you.

Data lives in a household. Households are separated at the database level: a query without your household returns no rows at all — that is a rule of the database itself, not a check in application code that someone could forget to write. In a shared household, roles decide who sees what.

Security log

Sign-ins, password changes, second-factor enrolment, invitations and removals, bank connections. It exists so you can see what was done to your household and so we can investigate unauthorised access. The log is append-only.

Email

We send three kinds of message, each a direct response to an action: address confirmation after registration, a password reset link you requested, and a household invitation sent to an address the household owner typed in.

There are no newsletters, announcements or promotional emails. We do not buy, rent or import address lists. There is nothing to unsubscribe from; deleting the account stops all email.

Technically, email is sent through Amazon SES in eu-central-1 (Frankfurt). The message body sits encrypted in our own queue and is erased once the message is sent.

The AI assistant

The assistant answers questions about your own money. It runs on an external language model (OpenAI), which is exactly why what goes there matters.

The model receives neither the text of your question, nor any transaction description, nor the names of your own categories. What it receives is an intent code from a closed list (for example, "where the money went"), a period, and already-computed numbers. Your question is interpreted by the app on your own device.

The model does not write numbers itself: its answer carries references to computed values, and the app substitutes them. Prompt retention on the provider's side is switched off. You can erase the whole conversation in the app with one action; accounts and transactions are untouched.

Bank statement files

A file you upload is parsed in memory and disappears with the request. We do not store it. Only the transactions you confirmed on the mapping screen enter your household.

Bank connections

Direct bank connections are planned through a licensed aggregator, under your separate consent and for the term of that consent. Access tokens live on the server and never reach the device. You can revoke consent in the app: we close the connection on our side and notify the aggregator.

This feature is not yet enabled for users.

Where data lives and for how long

Servers are Amazon Web Services, region eu-central-1 (Frankfurt, Germany). Household data is encrypted with a per-household key; the key itself is stored encrypted and released only to the service handling your request. A copy of the database without the key is useless.

Data lives as long as your account does. After deletion we erase the household and its contents; backups age out within 30 days on the normal backup cycle. Security log entries and payment records are kept longer, as long as the law requires.

Who we share data with

No one, except those without whom the application does not work:

We do not sell data, do not share it with advertising networks, and embed no third-party behavioural analytics in the application.

Your rights

Children

The application is for adults. Age is checked at registration and we do not create accounts for children.

Changes

If this policy changes in substance, we will say so by email and update the date at the top.