Trust & safety

Privacy policy

Wealth.app designs its services with GDPR compliance, minimization, and transparency at the core. This policy also clarifies how prompts and responses processed via the OpenAI API are handled on your behalf.

Security by design

Encryption at rest and in transit, threat modelling, and supplier reviews are embedded in every release.

Limited collection

We only capture the minimum personal data required to deliver and secure the service.

Transparent control

Self-serve controls let customers review, export, or delete data directly from the console.

1. Data controller

Roch & Cie (operating as Wealth.app) determines the purposes and means of processing personal data for the portfolio copilot platform.

2. Data we process

Identification data (name, email, role), organization metadata, customer support history, and the account connections required to synchronize portfolios.

3. Why we process data

To create and secure accounts, aggregate financial institutions, generate analytics, bill for subscriptions, and provide support. Wealth.app never sells or brokers personal data.

4. Legal bases

Processing relies on contract execution, legitimate interest in securing the service, and explicit consent for optional beta functionality or marketing updates.

5. Retention & deletion

Customer data is kept for the duration of the agreement plus 24 months unless a shorter period is requested. Regulatory accounting data follows French statutory retention schedules.

6. Subprocessors & hosting

Infrastructure is hosted within the EU with audited providers. Wealth.app relies on vetted subprocessors covering cloud infrastructure, email delivery, analytics, customer support, and the OpenAI API that powers assistant responses.

7. International transfers

When transfers outside the EU are required, we rely on EU Standard Contractual Clauses, encryption, and continuous monitoring of data flows.

8. Your rights

You can access, correct, delete, or port your data, and object to or restrict processing where applicable. Requests are handled within 30 days via privacy@wealth.app.

9. Cookies

Essential cookies maintain sessions and security. Optional analytics cookies remain disabled until you opt in via the consent banner.

Need help with privacy?

Send any request for data access, deletion, or clarification to our privacy team.