Last updated: 1 September 2026
Vaultie respects your privacy. This policy explains what data we collect, how we use it, and the choices you have.
Vaultie is operated by MB ZIVITOMA, company code 304754869, Vytauto g. 118-4, LT-00153 Palanga, Lithuania — the data controller for the purposes of this policy.
When you create an account we collect your email address (via Firebase Authentication — email/password, Google, or Apple). Your financial data — transactions, balances, recurring payments and categories — is stored only on your device, encrypted, with the key held in the phone's own secure keychain. We keep no copy of it on our servers. When you buy Vaultie Pro, our provider RevenueCat processes your App Store purchase to unlock your entitlement. If you choose to connect a bank (an optional Pro feature), we access your account information — see “Bank connection” below.
Connecting a bank is an optional Vaultie Pro feature. If you use it, we access your account information through Enable Banking, a licensed open-banking provider operating under PSD2, with your explicit consent: account details, balances, and transaction history. We use this solely to detect your recurring payments. You sign in and approve access on your bank’s own page — we never see your bank password. Transactions are processed transiently on our server (Firebase Cloud Functions) and are NOT stored; only the recurring payments you choose to import are saved on your device. Consent is time-limited and can be revoked at any time through your bank or by no longer using the feature.
We use your email to sign you in, verify your account, and send essential account messages. Subscription data powers reminders and spending insights on your device.
We use Google Firebase for authentication, plus Sign in with Apple if you choose it. In-app purchases are handled by RevenueCat, which receives your App Store transaction data. If you connect a bank, Enable Banking (a licensed PSD2 provider) securely retrieves your account data on our behalf. If the app crashes, Firebase Crashlytics receives a crash report: your device model, OS version and a technical stack trace, so we can fix it. Your Vaultie account identifier is included — no email, no name, no bank data. Brand logos are bundled in the app itself — no third-party requests are made for them. We do not sell your data.
The AI chat, monthly summaries, receipt scanning, and merchant categorisation all use the Anthropic AI service (our sub-processor for this purpose) — and all four are OFF by default and only ever activate after you give explicit, informed consent in the app, naming Anthropic and describing exactly what is sent, before anything is shared. To answer questions or write a summary we send ONLY a summary: bank balances, spending by category, and the names of your recurring payments (e.g. “Netflix”). We do NOT send individual transactions, IBANs, or card numbers. For receipt scanning, we send the photographed receipt itself, used only to recognise the items and total — the photo is never stored anywhere. Anthropic does not use any of this data to train AI models, and we do not store the chat/summary data — it exists only for that single request. For merchant categorisation, when a bank is connected and you have turned this on, we send business merchant names (e.g. a shop) to the AI to recognise the category. Only business names are sent — never people’s names, amounts, dates, or IBANs (a person-name filter applies). The result is stored on our server for reuse, so the same merchant is never sent twice. You can turn any of these features off at any time in Settings.
Account data (your email) and subscription status are processed to perform our contract with you (GDPR Art. 6(1)(b)) — without them we cannot provide the service. Bank account data and the AI features are processed solely on the basis of your consent (GDPR Art. 6(1)(a)). You can withdraw consent at any time by disconnecting your bank, switching an AI feature off in Settings, or ceasing to use the feature — withdrawal does not affect processing carried out beforehand. Crash reports and app security rely on our legitimate interest (GDPR Art. 6(1)(f)) in keeping the app working and fixable.
With your permission we send notifications: before a recurring payment is charged, a week ahead of an expensive annual renewal, before your bank access expires, when a monthly report is ready, and as your spending approaches a budget you have set. Permission is asked once, after you first connect a bank.
These are local notifications: they are scheduled on your device and sent by it. Nothing about them is transmitted to us or to any third party, and the amounts and payee names they contain never leave your phone. You can turn them off in Settings or in your device settings at any time.
You can delete your account and its email at any time via Settings → Delete account, or follow the steps at vaultie account deletion. Subscription data is removed when you uninstall the app. You can revoke bank access at any time through your bank; we do not store your bank transactions.
Under the GDPR you have the right to: access your data; have it corrected; have it erased (the “right to be forgotten”); restrict processing; object to processing; receive your data in a portable form; and withdraw consent at any time. You can exercise most of these yourself — your data sits on your own phone, and you can delete your account together with all of it in Settings → Delete account. For anything else write to support@vaultieapp.com — we reply within 30 days at the latest. If you believe we process your data unlawfully, you have the right to complain to the Lithuanian State Data Protection Inspectorate (vdai.lrv.lt), L. Sapiegos g. 17, Vilnius, or to the supervisory authority in your own country.
Some of our providers (Google Firebase, RevenueCat, Anthropic) are based in the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses or the EU–US Data Privacy Framework. Bank transaction data is processed inside the EU (Firebase region europe-west1) and is not transferred outside it.
Vaultie is not intended for users under 13 years of age.
For privacy questions, contact us at support@vaultieapp.com.
Atnaujinta: 2026-09-01
Vaultie gerbia tavo privatumą. Ši politika paaiškina, kokius duomenis renkame, kaip juos naudojame ir kokias teises turi.
Vaultie valdo MB ZIVITOMA, įmonės kodas 304754869, Vytauto g. 118-4, LT-00153 Palanga — duomenų valdytojas šios politikos prasme.
Susikuriant paskyrą renkame tavo el. pašto adresą (per Firebase Authentication — el. paštas, „Google“ arba „Apple“). Tavo finansiniai duomenys — operacijos, likučiai, pasikartojantys mokėjimai ir kategorijos — saugomi tik tavo įrenginyje, užšifruoti, o raktas laikomas paties telefono saugioje raktinėje. Mūsų serveriuose jų kopijos nelaikome. Kai perki „Vaultie Pro“, mūsų teikėjas „RevenueCat“ apdoroja „App Store“ pirkimą, kad atrakintų prieigą. Jei pasirenki prijungti banką (neprivaloma Pro funkcija), gauname tavo sąskaitos informaciją — žr. „Banko prijungimas“ žemiau.
Banko prijungimas yra neprivaloma „Vaultie Pro“ funkcija. Jei ją naudoji, per licencijuotą atviros bankininkystės teikėją „Enable Banking“ (veikiantį pagal PSD2) su tavo aiškiu sutikimu gauname tavo sąskaitos informaciją: sąskaitų duomenis, likučius ir operacijų istoriją. Tai naudojame tik pasikartojantiems mokėjimams aptikti. Prisijungi ir patvirtini prieigą savo banko puslapyje — mes niekada nematome tavo banko slaptažodžio. Operacijos apdorojamos laikinai mūsų serveryje (Firebase Cloud Functions) ir NĖRA saugomos; įrenginyje išsaugomi tik tie pasikartojantys mokėjimai, kuriuos pats pasirenki importuoti. Sutikimas galioja ribotą laiką ir gali būti bet kada atšauktas per savo banką arba nustojus naudotis funkcija.
El. paštą naudojame prisijungimui, paskyros patvirtinimui ir svarbiems pranešimams. Prenumeratų duomenys naudojami priminimams ir išlaidų apžvalgai tavo įrenginyje.
Autentifikacijai naudojame Google Firebase ir „Sign in with Apple“ (jei pasirenki). Programinius pirkimus tvarko „RevenueCat“, gaunantis tavo „App Store“ operacijų duomenis. Jei prijungi banką, „Enable Banking“ (licencijuotas PSD2 teikėjas) saugiai gauna tavo sąskaitos duomenis mūsų vardu. Programai nulūžus, „Firebase Crashlytics“ gauna klaidos ataskaitą: įrenginio modelį, sistemos versiją ir techninį klaidos pėdsaką, kad galėtume ją pataisyti. Kartu siunčiamas tavo Vaultie paskyros identifikatorius — be el. pašto, vardo ar banko duomenų. Prekių ženklų logotipai saugomi pačioje programoje — jokių užklausų trečiosioms šalims dėl jų nesiunčiama. Neparduodame tavo duomenų.
AI pokalbis, mėnesio santraukos, kvito skenavimas ir prekybininkų kategorizavimas naudoja „Anthropic“ AI paslaugą (mūsų subtiekėją šiam tikslui) — visos keturios funkcijos NUMATYTAI IŠJUNGTOS ir įsijungia TIK po to, kai programėlėje aiškiai ir sąmoningai sutinki: langas įvardina „Anthropic“ ir tiksliai aprašo, kas bus siunčiama, PRIEŠ pradedant siųsti. Kad atsakytų į klausimus ar parašytų santrauką, siunčiame TIK suvestinę: banko likučius, išlaidas pagal kategoriją ir tavo pasikartojančių mokėjimų pavadinimus (pvz. „Netflix“). NESIUNČIAME atskirų sandorių, IBAN‑ų ar kortelių numerių. Kvito skenavimui siunčiame nufotografuotą kvitą — jis panaudojamas tik prekėms ir sumai atpažinti, nuotrauka niekur neišsaugoma. „Anthropic“ nenaudoja šių duomenų dirbtinio intelekto treniravimui, o pokalbio/santraukos duomenų mes nesaugome — jie egzistuoja tik tos vienos užklausos metu. Prekybininkų kategorizavimui, kai prijungtas bankas IR esi tai įjungęs, verslo prekybininkų pavadinimus (pvz. parduotuvės) siunčiame AI, kad atpažintume kategoriją. Siunčiami TIK verslo pavadinimai — niekada žmonių vardai, sumos, datos ar IBAN‑ai (veikia žmonių vardų filtras). Rezultatas išsaugomas mūsų serveryje pakartotiniam naudojimui, kad tas pats prekybininkas nebūtų siunčiamas antrą kartą. Bet kurią iš šių funkcijų gali bet kada išjungti Nustatymuose.
Paskyros duomenis (el. paštą) ir prenumeratos būseną tvarkome sutarties vykdymo pagrindu (BDAR 6 str. 1 d. b p.) — be jų negalime suteikti paslaugos. Banko sąskaitos duomenis ir AI funkcijas tvarkome tik tavo sutikimo pagrindu (BDAR 6 str. 1 d. a p.). Sutikimą gali bet kada atšaukti — atjungdamas banką, išjungdamas AI funkciją nustatymuose arba nustodamas naudotis funkcija; atšaukimas negalioja atgaline data. Klaidų ataskaitas ir programos saugumą tvarkome teisėto intereso pagrindu (BDAR 6 str. 1 d. f p.) — kad programa veiktų ir būtų taisoma.
Su tavo sutikimu siunčiame pranešimus: prieš pasikartojantį mokėjimą, likus savaitei iki brangaus metinio atsinaujinimo, prieš pasibaigiant banko prieigai, kai paruošta mėnesio ataskaita, ir artėjant prie tavo nusistatyto biudžeto ribos. Leidimo prašome vieną kartą — prijungus pirmą banką.
Tai vietiniai pranešimai: jie suplanuojami tavo įrenginyje ir jo paties siunčiami. Niekas apie juos neperduodama nei mums, nei trečiosioms šalims, o juose esančios sumos bei gavėjų pavadinimai telefono nepalieka. Išjungti gali bet kada — programėlės arba įrenginio nustatymuose.
Paskyrą ir su ja susietą el. paštą gali ištrinti bet kada per Nustatymai → Ištrinti paskyrą arba pagal žingsnius paskyros trynimo puslapyje. Prenumeratų duomenys pašalinami išdiegus programą. Banko prieigą gali atšaukti bet kada savo banke; mes nesaugome tavo banko operacijų.
Pagal BDAR turi teisę: susipažinti su savo duomenimis; juos ištaisyti; ištrinti („teisė būti pamirštam“); apriboti tvarkymą; nesutikti su tvarkymu; perkelti duomenis; ir bet kada atšaukti sutikimą. Daugumą jų gali įgyvendinti pats programoje: duomenys guli tavo telefone, o paskyrą ir visus duomenis gali ištrinti Nustatymai → Ištrinti paskyrą. Bet kuriuo kitu atveju rašyk support@vaultieapp.com — atsakome ne vėliau kaip per 30 dienų. Jei manai, kad tvarkome tavo duomenis neteisėtai, turi teisę pateikti skundą Valstybinei duomenų apsaugos inspekcijai (vdai.lrv.lt), L. Sapiegos g. 17, Vilnius.
Kai kurie mūsų paslaugų teikėjai („Google Firebase“, „RevenueCat“, „Anthropic“) yra JAV. Perdavimai vyksta pagal Europos Komisijos patvirtintas standartines sutarčių sąlygas arba ES–JAV duomenų privatumo sistemą. Banko operacijų duomenys apdorojami ES (Firebase regionas europe-west1) ir už ES ribų neperduodami.
Vaultie neskirta jaunesniems nei 13 metų vartotojams.
Klausimais dėl privatumo rašyk: support@vaultieapp.com.