1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is: Finanzbrew GmbH, [Straße und Hausnummer], [PLZ] [Stadt] Email: privacy@finanzbrew.eu
We have not appointed a data protection officer, as the thresholds in Art. 37 GDPR and § 38 BDSG are not currently met. For all data protection matters please contact privacy@finanzbrew.eu.
2. Scope
This policy covers this website and the Finanzbrew mobile app (together, the "Service"). Where processing differs between the website and the app, this is stated explicitly below.
3. Visiting the website (server logs)
When you open this website, our hosting provider processes technically necessary connection data. This processing is unavoidable in order to deliver the page at all.
- IP address of the requesting device
- Date and time of the request
- Requested URL and volume of data transferred
- Referrer URL, browser type and version, operating system
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the stable, secure and uninterrupted provision of the website and the prevention of attacks. The website is hosted by Netlify (Netlify, Inc., USA) and delivered via its content delivery network under a data processing agreement. Log files are deleted or anonymised after 30 days at the latest.
5. Google Analytics
Subject to your consent, we use Google Analytics 4, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The service sets cookies and transmits usage data (including truncated IP address, pages viewed, time on page, approximate location, device and browser data) to Google. We use Google Analytics solely for audience measurement and to improve our offering.
The legal basis is your consent under Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG. Without consent no Google Analytics script is loaded and no cookie is set. Transfer to Google LLC in the USA cannot be excluded; Google LLC is certified under the EU-US Data Privacy Framework and standard contractual clauses apply in addition. Data is deleted automatically after 14 months.
6. Web fonts
This website embeds the "Plus Jakarta Sans" typeface via Google Fonts (Google Ireland Limited). When the font files load, your IP address is transmitted to Google. The legal basis is Art. 6(1)(f) GDPR — our legitimate interest in a consistent and accessible presentation.
7. Account, sign-in and profile
To operate a user account we process your email address, your name and the credentials you set. Authentication runs through Supabase; data is stored on servers in the European Union (Frankfurt region). If you sign in with "Sign in with Apple", Apple provides us only with a user identifier and — depending on your choice — either your real address or an anonymised relay email address.
The legal basis is Art. 6(1)(b) GDPR, as the processing is necessary to perform the user agreement.
8. Content you create in the app
- Watchlist, portfolios, interests and preferences
- Device data such as model, OS version and language, for diagnostics
- A push token, if you enable notifications
We do not collect contacts, photos, health data or location data. If you upload a file or screenshot to import a portfolio, we process it solely to extract the positions; the image is not stored permanently after evaluation. The legal basis is Art. 6(1)(b) GDPR, and Art. 6(1)(a) GDPR for push notifications.
9. Subscriptions and payments
If you take out a paid subscription on this website, payment is processed by Stripe (Stripe Payments Europe, Ltd., Ireland). Your payment details — card data in particular — are collected and processed directly by Stripe; we neither receive nor store complete payment data, only contract status, billing period and the Stripe customer identifier.
If you subscribe in the mobile app instead, billing runs through the App Store or Google Play, with entitlement management by RevenueCat. The legal basis in each case is Art. 6(1)(b) GDPR, and Art. 6(1)(c) GDPR together with § 147 AO and § 257 HGB for the statutory retention of invoices.
10. AI features
Finanzbrew generates summaries, explanations and scores using language models. The underlying requests contain market data and the relevant context (for example the security being viewed), but no real names, email addresses or account identifiers. The legal basis is Art. 6(1)(b) GDPR.
11. Diagnostics and product analytics
To keep the Service stable we use Sentry (crash and error reporting). It processes error messages, stack traces, device and version information and a pseudonymous user identifier. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is detecting and fixing faults.
For in-app product analytics we use PostHog. This processing is expressly consent-based and stays switched off in the app settings until you enable it. The legal basis is Art. 6(1)(a) GDPR.
12. Recipients and processors
We use carefully selected service providers who act on our documented instructions under Art. 28 GDPR. An up-to-date overview with purpose, location and transfer basis is on the "Subprocessors" page. We do not sell, rent or share personal data with advertisers.
13. Transfers to third countries
Core processing takes place in the European Union (Frankfurt region). Where individual processors handle data outside the EEA — the USA in particular — we base the transfer on an adequacy decision (EU-US Data Privacy Framework, Art. 45 GDPR) or on standard contractual clauses under Art. 46(2)(c) GDPR together with supplementary safeguards.
14. Retention
- Account data: for as long as the account is active and up to 90 days after deletion (backup restoration).
- Server log files: 30 days maximum.
- Invoices and accounting records: 10 years under § 147 AO and § 257 HGB.
- Consent records: up to 3 years after withdrawal, to meet the accountability obligation (Art. 5(2) GDPR).
- Aggregated, non-identifiable statistics: indefinitely.
15. Your rights
- Access to the data we process about you (Art. 15 GDPR).
- Rectification of inaccurate data (Art. 16 GDPR).
- Erasure (Art. 17 GDPR) — available any time in the app under Profile → Delete account.
- Restriction of processing (Art. 18 GDPR).
- Data portability in a structured, commonly used format (Art. 20 GDPR).
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR).
An informal message to privacy@finanzbrew.eu is enough to exercise any of these. We respond without undue delay and within one month at the latest (Art. 12(3) GDPR).
16. Right to lodge a complaint
Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence or of the alleged infringement (Art. 77 GDPR). The authority responsible for us is: Berliner Beauftragte für Datenschutz und Informationsfreiheit Alt-Moabit 59-61, 10555 Berlin https://www.datenschutz-berlin.de
17. Automated decisions and profiling
Finanzbrew personalises content — the Daily Brew, alerts and recommendations, for example — based on your watchlist and interests. This evaluation serves only to assemble content. There is no automated decision in an individual case producing legal effects concerning you or similarly significantly affecting you (Art. 22(1) GDPR). In particular, we carry out no creditworthiness assessment and give no investment advice.
18. Whether you must provide data
You are under no statutory or contractual obligation to provide your data. However, without an email address and password no account can be created and the Service cannot be used in a personalised way; without payment data no paid subscription can be concluded.
19. Minors
The Service is not directed at children under 16. If we learn that a child has provided us with personal data, we delete it. Please report any such case to privacy@finanzbrew.eu.
20. Changes to this policy
We update this policy when our processing or the legal position changes. We will notify you of material changes the next time you open the app, or here. The version published on this page is the one that applies.