Skip to content
TenthwiseKeep · Grow · Guard
How it worksBuild a planTemplatesLearnPricing
More
Money MapMethodAffiliates
PrivacyTermsCookiesFinancial disclaimerAccessibility
EnglishEspañolPortuguêsFrançaisDeutschItalianoNederlandsPolskiRomânăČeštinaΕλληνικάTürkçeРусскийУкраїнськаالعربيةעבריתفارسیहिन्दीবাংলাاردوBahasa IndonesiaBahasa MelayuTiếng Việtไทย简体中文繁體中文日本語한국어KiswahiliFilipino
Sign inOpen app
Privacy

Privacy notice

Effective and last updated: 25 August 2026

Tenthwise is designed as a local-first personal finance workspace. You can use the core workspace without creating an account; optional services add only the data flows described below.

Production-preview notice. The operator’s legal name, business address, privacy contact, VAT/tax identifiers and DPO status are pending and must be completed before commercial launch. This draft does not claim that an unnamed operator or an unfinished service is compliant. Italian/EU counsel and the final vendors, settings and contracts must be reviewed before paid use.
On this pageControllerData and purposesLegal basesLocal and cloud dataProcessors and transfersRetentionSecurityYour rightsContact

1. Who is responsible

The data controller will be the person or entity operating Tenthwise. Before commercial launch, this section must state:

  • Operator / controller legal name: pending.
  • Registered or business address: pending.
  • Privacy contact: pending.
  • VAT, tax and company-registration details: pending, if applicable.
  • Data Protection Officer: appointment assessment pending. If a DPO is appointed, direct contact details will appear here.

Until those details and an operational contact route are published, this page is a transparent preview and not a complete Article 13 GDPR notice for a paid launch.

2. What data we use and why

Local workspace

Budget categories and limits, transactions, income, account and debt balances, goals, preferences and derived financial metrics are stored in your browser by default. The operator does not receive that local record merely because you use the app. Your browser, device backup, extensions or device administrator may still have access outside Tenthwise’s control.

Optional account and sync

If Firebase is configured and you choose to sign in, we process an account identifier, email address, display name, authentication-provider details, regional preferences and the workspace you sync. Google sign-in or an email sign-in link may be offered. We use this data to authenticate you, sync your workspace, support account controls and prevent abuse.

Public sharing

If you deliberately create a reduced snapshot, selected fields are encoded in the URL fragment and become available to anyone with the full link. The fragment is not sent to Tenthwise as part of the web request, but recipients can retain it and it cannot be remotely revoked. The sharing screen lets you review what is included before copying.

Website and service operations

Cloudflare may process IP address, request headers, device/browser information, timestamps, requested URLs, security signals and short-lived logs to deliver and protect the site and any API. Support requests contain the information you send. We do not intentionally ask for bank credentials, government IDs, health data or special-category data in the workspace.

Billing and communications

If paid plans launch, Stripe is intended to process card checkout, payment status, billing contact and fraud signals. Tenthwise should receive transaction and entitlement information, not full card details. If Wise transfer is offered, it will be a manually reconciled route and may reveal payer, account and transfer-reference details. Brevo is contemplated for service or marketing email but is not enabled in this release; marketing email would require a valid opt-in or other lawful basis and an unsubscribe route.

Analytics

Optional analytics is off by default. It may run only after an affirmative choice. The final analytics provider, events, retention and recipient details must be added here before activation. Tenthwise does not currently describe or authorize advertising profiling.

3. Legal bases

Depending on the feature, the intended bases under Article 6 GDPR are:

  • Contract or pre-contract steps: providing an account, sync, paid plan, billing support and requested service features.
  • Consent: optional analytics, non-essential device access and marketing communications. Consent may be withdrawn at any time without affecting earlier lawful processing.
  • Legitimate interests: narrowly necessary security, abuse prevention, troubleshooting and service improvement, balanced against user rights. Optional analytics will not rely on this basis where consent is required.
  • Legal obligation: accounting, tax, consumer-law, fraud-prevention and regulatory records where applicable.
  • Legal claims: establishing, exercising or defending claims when necessary.

No solely automated decision is intended to produce legal or similarly significant effects. Workspace scores and prompts are educational interface outputs, not credit, insurance or investment decisions.

4. Local-first is a choice, not a slogan

The current workspace record is kept under bw_finance_v4 in browser local storage. An older bab_v3_state record may be read to support migration. The app may also store a sign-in email temporarily under bw_email_for_signin while an email link is completed. Clearing site data, using private browsing, resetting a device or losing a browser profile can erase local data. Export a JSON backup if you need a portable copy.

Cloud storage begins only when the cloud service is configured and you sign in. Signing out does not necessarily delete the cloud copy. The signed-in deletion and account-closure control is deliberately disabled in this preview until it can remove the identity and workspace, terminate any billing relationship, and record the request as one verified server-side workflow. It must be operational before cloud accounts or checkout are enabled. Separately clear local browser data if desired. Self-contained fragment links already given to recipients are outside that deletion flow.

5. Recipients, processors and international transfers

The launch operator must confirm its final processor list, locations, data-processing agreements and sub-processors. The intended stack is:

  • Cloudflare: website/API delivery, security and infrastructure.
  • Google Firebase: optional authentication and Firestore cloud sync.
  • Stripe: intended card billing and subscription records.
  • Wise: optional manual bank-transfer handling where offered.
  • Brevo: contemplated email provider, not enabled in this release.
  • Professional advisers and authorities: only where necessary for support, accounting, legal obligations or claims.

Some providers or sub-processors may handle data outside the EEA. Before launch, Tenthwise must document the actual data locations and use an applicable safeguard, such as an adequacy decision or Standard Contractual Clauses, with supplementary measures and transfer assessments where required. Provider names alone do not establish a lawful transfer.

We do not intend to sell personal data. A processor may use data only under the relevant agreement and its own legally defined roles; payment and authentication providers may also act as independent controllers for some fraud, compliance or account activities.

6. Retention

Local workspace data remains on your device until you delete it, clear site data or the browser removes it. The following are launch targets, not verified production periods: cloud workspace and account data until account deletion, followed by deletion from active systems without undue delay; disaster-recovery copies isolated until overwritten on a documented cycle; security logs kept only as long as proportionate; support records kept until the issue and reasonable follow-up close; and billing/tax records retained for the statutory period that applies to the operator.

Before commercial launch, the operator must replace those targets with validated periods, including backup deletion, log retention and any legal holds. Reduced fragment snapshots are not stored as hosted public profiles in this release; copies retained by recipients remain usable.

7. Security and incidents

The intended controls include HTTPS, provider access controls, least-privilege rules, separated environments, authenticated cloud access, account deletion, export tools, dependency maintenance and incident handling. The production configuration and rules must be tested before launch. No online service can guarantee absolute security; use a protected device, keep backups secure and avoid entering data the app does not need.

If a personal-data breach creates a legal notification duty, the controller will notify the competent authority and affected people within the GDPR’s applicable conditions and time limits.

8. Your GDPR rights

Where applicable, you may request access, correction, deletion, restriction and portability; object to processing based on legitimate interests; withdraw consent; and ask for information about transfers. You may also complain to the Garante per la protezione dei dati personali or another competent supervisory authority, and seek a judicial remedy.

Requests should receive a response without undue delay and normally within one month, subject to lawful extensions and identity verification. An export or deletion control can be faster for workspace data, but it does not replace rights that require human review.

9. Children, changes and contact

Tenthwise is not directed to children and is not intended to be used to create an account for a child. The operator must set and document the applicable age threshold before launch.

Material changes will be dated and, where required, communicated in the service. A new purpose incompatible with the one originally stated will require a valid legal basis and notice, and consent where necessary.

Privacy request and operator contact: pending before commercial launch. No paid service should be offered until a monitored, accessible contact channel and complete controller identity are published.

TenthwisePrinciples into practice

A private-by-default workspace for building the habits behind lasting financial security. Educational tools, not personal investment advice.

Open appPlansGuidesPrivacyTermsCookiesFinancial disclaimerAccessibility
© 2026 TenthwiseMade for patient, deliberate progress.