Privacy notice
Draft, pending legal review before public launch. This privacy notice explains which personal data Fixum Budget processes, for what purpose, and on what basis. Fixum Budget stores only the data you enter yourself, uses no third-party tracking or analytics, and processes your data in the EU. The details are in the sections below.
Controller
The controller for data processing in the sense of the GDPR is the operator of this application. Contact details are in the imprint.
What data we store
Fixum Budget only stores the data you enter yourself: household configuration, people, categories, recurring income and expenses, and reconciliation entries. We do not use tracking cookies or third-party analytics tools.
Where your data sits
Your application data is stored in a PostgreSQL database operated by Supabase in Frankfurt am Main (Germany). The application runs on Vercel in the Frankfurt region (fra1). Auth emails (sign-in, password reset, email change, invites) are sent by Resend from an EU region, which processes your email address, delivery logs included. Backups stay within the EU.
Cookies
Fixum Budget sets four cookies, all first-party: `sb-<ref>-auth-token` (sign-in session, strictly necessary), `active_household` (remembers your active household, one year, strictly necessary), `theme` (remembers your light/dark choice, one year, set after an explicit action), and `fixum-locale` (remembers your language choice, one year, set after an explicit action). No cookie is used for tracking, advertising, or third-party analytics. Because only strictly necessary and explicitly chosen preference cookies are set, no consent banner is required under § 25 (2) TTDSG.
Your rights
You have the right at any time to access, correction, deletion, restriction of processing, data portability, and objection. A data export feature is available inside the app; for full deletion, contact the address listed in the imprint. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement (Article 77 GDPR).
Processors
We use Supabase Inc. (US company, database in Frankfurt am Main), Vercel Inc. (US company, function execution in the Frankfurt region, fra1), Cloudflare, Inc. (US company, Turnstile CAPTCHA for anti-abuse on auth and demo forms), and Resend, Inc. (US company, transactional email for login, password reset, email change, and household invites, EU region) as processors. All providers make Article 28 GDPR data processing agreements available as part of their contract terms; we document their execution or confirmation status internally.
Transfers to third countries
Your application data is stored and processed exclusively in the EU (Supabase eu-central-1, Vercel fra1, Resend in an EU region). The check on the auth and demo forms is served from Cloudflare's global network, so the challenge request (IP address, browser signals) can be processed outside the EU in normal operation. Because Supabase Inc., Vercel Inc., and Resend, Inc. are US companies, incidental access by personnel in the US (for example for troubleshooting or support) cannot be fully excluded either. Both transfer paths are governed by the EU Standard Contractual Clauses (SCCs) under Article 46 GDPR, which form part of the respective data processing agreements.