Security by design
Encryption at rest and in transit, threat modelling, and supplier reviews are embedded in every release.
Trust & safety
Wealth.app designs its services with GDPR compliance, minimization, and transparency at the core. This policy also clarifies how prompts and responses processed via the OpenAI API are handled on your behalf.
Encryption at rest and in transit, threat modelling, and supplier reviews are embedded in every release.
We only capture the minimum personal data required to deliver and secure the service.
Self-serve controls let customers review, export, or delete data directly from the console.
Roch & Cie (operating as Wealth.app) determines the purposes and means of processing personal data for the portfolio copilot platform.
Identification data (name, email, role), organization metadata, customer support history, and the account connections required to synchronize portfolios.
To create and secure accounts, aggregate financial institutions, generate analytics, bill for subscriptions, and provide support. Wealth.app never sells or brokers personal data.
Processing relies on contract execution, legitimate interest in securing the service, and explicit consent for optional beta functionality or marketing updates.
Customer data is kept for the duration of the agreement plus 24 months unless a shorter period is requested. Regulatory accounting data follows French statutory retention schedules.
Infrastructure is hosted within the EU with audited providers. Wealth.app relies on vetted subprocessors covering cloud infrastructure, email delivery, analytics, customer support, and the OpenAI API that powers assistant responses.
When transfers outside the EU are required, we rely on EU Standard Contractual Clauses, encryption, and continuous monitoring of data flows.
You can access, correct, delete, or port your data, and object to or restrict processing where applicable. Requests are handled within 30 days via privacy@wealth.app.
Essential cookies maintain sessions and security. Optional analytics cookies remain disabled until you opt in via the consent banner.
Send any request for data access, deletion, or clarification to our privacy team.