Last updated: March 2026
Protecting your personal data is a core priority. This Privacy Policy explains what data we collect when you use WonderFunds, how we process it, and what rights you have.
WonderFunds is a privacy-first personal finance management service. We do not connect to bank accounts, we delete uploaded raw files after processing, and we encrypt financial data using a DEK/KEK scheme that prevents linking data to your identity even in the event of a database breach.
The data controller within the meaning of the GDPR is:
SKAJ Ventures GmbH
Sonnenlandstraße 4
14471 Potsdam
Germany
Managing Director: Stefan Köhn
Email: datenschutz@wonderfunds.app
We collect and process the following categories of personal data:
| Data Category | Examples | Purpose |
|---|---|---|
| Account data | Name, email address, hashed password | Authentication, account management |
| Financial data | Transactions (merchant, amount, date), categories, tags | Core service functionality |
| Usage data | Page views, feature usage, device type | Service improvement |
| Payment data | Subscription status, billing history (via Stripe) | Subscription management |
We do not collect bank account numbers, PINs, TANs, or any other banking credentials.
We process your data based on the following legal grounds under the GDPR:
During registration, we collect your name, email address, and a password. The password is stored exclusively as a bcrypt hash — we never have access to your plaintext password.
Authentication is handled via NextAuth v5 with JWT-based session management. You can optionally enable two-factor authentication (TOTP or email OTP).
Your email address is used for:
Your financial data (transactions, categories, rules) is not directly linked to your user account. Instead, we use a pseudonymous token (userDataToken) protected by a DEK/KEK encryption scheme:
We store only: merchant names, amounts, dates, categories, and tags. No account numbers, IBANs, or other account identifiers.
When you upload a file (CSV or PDF), the following happens:
This process ensures that sensitive banking documents do not remain on our servers.
WonderFunds uses artificial intelligence for:
AI processing is user-specific. Your data is not mixed with other users' data or used to train general AI models. The AI learns exclusively from your own corrections and rules.
AI-generated results are not shared with third parties and are not used for advertising purposes.
WonderFunds uses only strictly necessary cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie | Authentication (JWT) | Session / max. 30 days |
| Locale cookie | Language preference (en/de) | 1 year |
We do not use tracking cookies, third-party analytics cookies, or advertising cookies.
We use the following third-party services:
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Vercel | Hosting and serving the web application | IP address, request data | EU (Frankfurt) |
| PostgreSQL hosting | Database operations | Encrypted account and financial data | EU (Frankfurt) |
| Stripe | Payment processing | Email, subscription status, payment method | EU (Ireland) |
Data processing agreements pursuant to Art. 28 GDPR are in place with all processors. No personal data is transferred to countries outside the EU.
All personal data is processed and stored on servers in the European Union, primarily in Frankfurt am Main, Germany.
No data is transferred to countries outside the European Economic Area (EEA).
We retain your data only as long as necessary for the respective purpose:
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion |
| Financial data (transactions, categories) | Until account deletion |
| Uploaded files | Deleted immediately after processing |
| Billing data | 10 years (statutory retention obligation per § 147 AO) |
| Server logs | Max. 30 days |
Upon account deletion, all data — including encryption keys — is permanently and irreversibly deleted. Billing data is retained in accordance with statutory requirements.
Under the GDPR, you have the following rights:
WonderFunds is intended for persons aged 18 and older. We do not knowingly collect personal data from minors. If we become aware that a minor has created an account, we will promptly delete the account and associated data.
We reserve the right to update this Privacy Policy as needed, particularly when the Service or legal requirements change. Material changes will be communicated to you via email or a notice within the Service.
The current version is always available at wonderfunds.app/privacy.
For questions about data protection or to exercise your rights, please contact:
SKAJ Ventures GmbH
Sonnenlandstraße 4
14471 Potsdam
Email: datenschutz@wonderfunds.app
This Privacy Policy was last updated in March 2026. For questions, please contact datenschutz@wonderfunds.app.