Privacy Policy
What we process, why we need it, and the choices you have.
- Version
- 2026-09-30
- Effective date
- Last updated
1. Who is responsible
Prathamesh Shedge, an individual based in Germany, operates FinoVera under the WaffleBerry brand and is responsible for the personal data processed to operate it. WaffleBerry is not a separate registered company. Contact waffleberry.app@gmail.com for privacy requests, account/data questions or legal notices.
Public legal contact address: Prathamesh Shedge, Kurt Schumacher Str. 34A, 21629 Neu Wulmstorf, Germany.
2. Account and authentication information
We store your username, normalized email address where supplied, account and verification status, creation/update timestamps, and authentication records. Passwords are processed to create a one-way Argon2 password hash; the application does not store plaintext passwords. Verification links contain a secret token whose hash, expiry and consumption state are stored by FinoVera.
When you use Google Sign-In, we request the openid and email scopes. We store Google's issuer and account identifier, email address, whether Google verified that email, and linking timestamps. We do not request your Google contacts, calendar or files. Google access, refresh and ID tokens are not persisted in the FinoVera account database. Short-lived sign-in state, nonce and PKCE data are retained to complete and protect the authentication flow.
For accounts created after the consent rollout, we store Terms and Privacy version identifiers and server timestamps of your acceptance/acknowledgement. We do not collect extra IP or device information solely for that record. Existing accounts are marked as exempt from the new-account requirement; this does not fabricate past acceptance.
3. Your simulated financial life
We store the life configuration you enter, such as a character name, simulated age/birthday, city, profession, salary, expenses and opening balances. We also store simulated transactions, holdings, investments, loans, insurance, property, businesses, career events, progress and activity history.
Mirror mode lets you manually enter opening financial circumstances that may resemble your actual finances. Treat those inputs as personal information even though the resulting activity is a simulation. We do not obtain them by connecting to a bank or brokerage. You can use fictional information and should not enter account numbers or credentials.
4. AI advisors and OpenAI
Available advisor features send OpenAI your message, selected recent conversation history, advisor instructions and selected simulation context, such as balances, loans, holdings, relevant market information and activity. Personalized advisor news or tips may also be generated when those features are used, without an explicit chat message. Account passwords, verification tokens and Google tokens are not deliberately included in the AI context.
FinoVera stores advisor questions, financial-context snapshots, generated responses, interaction status and usage metadata in your account's database records. Context can contain information you entered manually, so it should not be considered anonymous. We do not automatically delete older chats on a fixed schedule while the account exists.
Our OpenAI Responses API requests set store=false. This controls response application-state storage, not all provider retention. OpenAI documents separate abuse-monitoring and caching retention and says API data is not used for training by default unless a customer opts in. Provider handling depends on its current terms and account configuration; we do not promise zero retention. Consult OpenAI's API data-controls documentation linked below.
AI results are educational simulation content, may be wrong, and do not execute real financial transactions or make legal, credit, employment or similarly significant real-world decisions about you.
5. Why we process information
We process account, simulation and requested advisor data to provide and maintain the service you request. Where applicable under the GDPR, the legal basis is performance of the service agreement or steps you request before it (Article 6(1)(b)). We use necessary technical and security data to protect accounts, prevent abuse and maintain reliability, relying on legitimate interests (Article 6(1)(f)), balanced against your rights. Where a specific legal obligation requires processing, Article 6(1)(c) applies.
Terms acceptance records evidence account setup and agreement. Privacy acknowledgement records that the notice was presented and acknowledged; it is not blanket data-processing consent. We do not use it to authorize marketing or optional tracking. If a future optional feature needs consent, it must have an appropriate separate choice and withdrawal mechanism.
Required account fields and acceptance are necessary to create a new account. Without verified email or a completed Google identity flow, new accounts cannot receive normal access. Choosing not to use an optional advisor avoids that feature's AI processing.
6. Cookies, logs and security data
FinoVera uses essential authentication and temporary Google sign-in cookies. Production session cookies are HttpOnly, Secure and SameSite=Lax. Session tokens are stored as hashes on the server. Session lifetimes are configurable; the application defaults are 24 hours for standard sessions and 30 days when Remember me is selected. Logout, deletion and security controls can end access earlier. Google flow cookies normally expire after 10 minutes.
The browser also stores functional preferences and state, such as read-news markers and temporary filters or scroll positions. These support the application rather than advertising. We currently use no dedicated behavioral/product analytics platform, advertising pixel or marketing tracker and send no marketing newsletters.
Requests expose network information to hosting and security providers. FinoVera uses source information for abuse prevention, stores hashed rate-limit identifiers and expiring counters, and records sanitized operational events and request identifiers. Hashing security identifiers does not make all such data anonymous. AI quotas may be associated with your account identifier. Infrastructure providers may maintain their own operational and security logs.
The application avoids logging passwords, tokens and OAuth callback parameters; this is a security measure, not a guarantee that every provider's infrastructure retains no personal information. Essential cookies and processing are not optional advertising consent. Browser cookie blocking may prevent sign-in from working.
7. Providers and sharing
Vercel serves the frontend. Railway runs the backend and hosts the private PostgreSQL database. These providers process service requests and operational information. Google processes the optional sign-in flow; OpenAI processes the selected AI inputs described above; Resend processes email addresses and verification-message content to deliver transactional email. Cloudflare R2 stores encrypted database backups.
Verification emails normally use FinoVera <noreply@waffleberry.app>, with replies directed to waffleberry.app@gmail.com. Replies and privacy/support messages are handled through that Google-hosted mailbox. Do not email passwords or full verification links.
We share the information needed for these services to function. We do not sell personal information, operate advertising profiles or send promotional emails as part of the current product. We may disclose information where legally required or reasonably necessary to address a concrete security incident or legal claim, subject to applicable law. We do not promise that data is never shared with providers.
8. International processing
FinoVera uses third-party service providers including Vercel, Railway, Google, OpenAI, Resend and Cloudflare. Depending on the provider and service, personal data may be processed outside Germany or the European Economic Area (EEA).
Where legally required, applicable safeguards are expected to be provided through the relevant provider terms and legal framework. The arrangements depend on the provider, service and applicable law; this notice does not assert that the operator has executed a particular transfer mechanism or that processing is confined to the EEA. Contact waffleberry.app@gmail.com for information about relevant processing and safeguards.
9. Retention and encrypted backups
Account and linked simulation/advisor records remain in the active database while your account exists unless removed by a supported deletion action. There is currently no scheduled purge of inactive accounts, unverified accounts or old advisor conversations. Contact us to request deletion or review of retention. We assess additional retention needs by purpose, security, applicable legal obligations and specific disputes; we do not claim an unspecified indefinite legal requirement.
Verification tokens have a configured expiry (30 minutes by default); their database records may remain until replaced or the account is deleted. Google pending/attempt records expire after 10 minutes and are cleaned opportunistically when sign-in starts. Expired sessions and security records are not necessarily physically removed at the instant access expires. Expiring abuse counters are pruned opportunistically. Provider log and support-correspondence retention is separate from these application lifetimes.
The database backup job is scheduled daily. It encrypts backups before uploading them over HTTPS to a private Cloudflare R2 bucket. After a successful verified backup it prunes eligible backups older than 14 days. Failed jobs, storage restrictions or operational interruptions can extend actual retention; 14 days is a pruning target, not a guarantee of deletion at that exact time.
10. Account deletion and your rights
The authenticated account-deletion control requires recent sign-in and deletes your active user record and linked simulation, advisor, session, identity, verification and consent records. Deleting only a simulated life leaves your account and legal-acceptance history intact. Some temporary pre-account OAuth records, security counters, provider logs and correspondence are separate from the account graph and may remain under their respective lifetimes.
Deletion does not selectively rewrite previously encrypted backups. Those copies age out through the retention process and are restricted to recovery. A restore may recover older data; deletion requests must be reapplied before resumed use of restored data. Contact us if you need help deleting an account or exercising rights.
Depending on applicable law, you can request access, correction, deletion, restriction and a portable copy of your personal data, and object to processing based on legitimate interests. If processing is based on consent, you can withdraw it without affecting earlier lawful processing. These rights have legal limits, and we may need proportionate identity verification to protect your account. Contact waffleberry.app@gmail.com; never send your password.
Where the GDPR applies, we normally respond within one month and will explain any lawful extension. You may complain to a competent data-protection supervisory authority, including in the EU country of your habitual residence, work or an alleged infringement. Contacting us first is not a condition of that right.
11. Security and younger users
Measures include HTTPS, password hashing, protected session cookies, account ownership checks, origin/host protections, rate limits, private database networking and encrypted off-platform backups. No online service or encryption arrangement can guarantee absolute security. Protect your login details and report concerns promptly.
FinoVera is for users aged 16 or older. Users under 16 are not permitted to create an account. Simulated character ages are not real-user age verification. If you believe an under-16 user's information was submitted, contact us so we can investigate and take appropriate action.
12. Changes and contact
This notice has a version, effective date and last-updated date. We will communicate material changes appropriately. Monetization, marketing, advertising or materially different tracking must undergo policy and consent/cookie review before introduction; none is authorized merely by acknowledging this notice.
For privacy requests, account/data questions, legal notices or questions about these documents, contact Prathamesh Shedge at waffleberry.app@gmail.com.
Provider reference
OpenAI API data controls (opens in a new tab). Provider terms may change; our application setting does not replace the provider's own rules.
Questions? We're here.
Contact waffleberry.app@gmail.com.
Read our Terms of Service.