Privacy Policy
Last updated: July 22, 2026
Privacy isn't a box we tick for compliance — it's the reason Patriq exists. Most free wealth trackers are funded by selling data or insights about your finances to third parties. Patriq isn't. This policy explains, plainly, what data we handle, why, where it's stored, and what control you have over it.
1. Who is responsible for your data
Cristian Jimenez, private individual. Patriq is a personal project, currently free and without registered economic activity.
• Contact email: info@patriq.finance
• Scope: this document applies to your use of patriq.finance and its subdomains.
2. What data we handle
Patriq only processes the data you enter directly into the app, plus the minimum technical data needed to keep your session working:
• Account data: email and password (managed by Supabase Auth; your password is never stored in plain text, only as a hash). If you enable passkey sign-in, your device generates a WebAuthn credential whose private key never leaves your device — only the associated public key is stored against your account.
• Wealth data: whatever you manually record about your assets (funds, stocks, crypto, gold, real estate, vehicles, cash, pensions, other) and liabilities (mortgages, loans) — amounts, labels, dates, notes, and, if you provide it, the cadastral reference or address of a property.
• Third-party credentials you connect: if you link Indexa Capital or Revolut X, the access token you give us is encrypted at rest (pgcrypto, PostgreSQL) before it's stored, and it's only used server-side to fetch your positions — it never reaches your browser or any party other than the corresponding provider. You can disconnect any integration at any time from Settings, which deletes the stored token.
• Minimal technical data: your authentication session (Supabase cookies — see the Cookie Policy) and, aggregated and cookie-free, usage statistics via Vercel Analytics (see section 6).
3. What we do NOT do
• We don't connect to your bank. Patriq doesn't use bank scraping or Open Banking/PSD2 — we don't have or ask for your banking credentials.
• We don't sell or share your data with third parties for commercial, advertising, or scoring purposes.
• We don't show ads or use advertising-tracking cookies.
• We don't share your wealth data, even in aggregated or anonymized form, with anyone beyond the providers strictly necessary to operate the service (section 5).
4. Why we use your data, and the legal basis
• To provide the service (performance of a contract, GDPR art. 6.1.b): calculating your net worth, showing projections, managing your session.
• To keep prices updated automatically (legitimate interest, GDPR art. 6.1.f): for assets with a market price (stocks, funds, crypto, gold), we query external APIs using a market identifier only — never your identity. See section 5 for detail.
• To send essential operational communications (performance of a contract): for example, sign-in links or account security notices. We don't do marketing emails.
• To comply with legal obligations where applicable (GDPR art. 6.1.c).
5. Who we share data with (processors and third parties)
These are the providers involved in running Patriq, and exactly what they receive:
• Supabase (PostgreSQL database, authentication): stores all your account and wealth data. It's our infrastructure provider (data processor). The project is hosted in the eu-west-1 region (Ireland) — your data stays within the European Economic Area.
• Vercel (hosting and deployment): serves the application from the us-east-1 region (Washington D.C., USA). This means an international data transfer outside the EEA; Vercel includes EU Standard Contractual Clauses in its Data Processing Agreement as a safeguard for these transfers.
• Finnhub, GoldAPI.io, Stooq/ECB, CoinGecko: receive only a market identifier (ticker, ISIN, or coin id) to return a price. They never receive your name, email, or anything that identifies you.
• Indexa Capital and Revolut X: only if you explicitly connect your account. We use your encrypted token to query your positions on your behalf; the provider sees the request as if it came from your own session on their platform.
• Sede Electrónica del Catastro (Spanish public land registry) and INE (Spanish national statistics institute): if you add a cadastral reference or address for a property, we query it to bring in surface area, type, and cadastral value. INE only gives us aggregated, area-level price indices — it never receives any data about you.
• Vercel Analytics: aggregated, cookie-free usage statistics (see section 6).
We don't share data with data brokers, ad networks, or for commercial profiling.
6. Analytics and cookies
We use Vercel Analytics, a cookie-free tool that doesn't track individual users across sites or build profiles — it only aggregates visit statistics (page views, approximate country, device) to understand overall product usage.
The app uses technical cookies (session cookies, managed by Supabase Auth) that are essential to keep you signed in. These are strictly necessary and don't require consent under cookie regulations. See the Cookie Policy for detail.
7. How long we keep your data
We keep your data for as long as your account is active. If you stop using Patriq, your data stays tied to your account until you request its deletion.
There is currently no self-service "delete account" button in the app — to exercise your right to erasure, email info@patriq.finance and we'll delete your data manually within a reasonable period (30 days max). We want to automate this; until then, this is the path.
8. Your rights
As a user in the EU/Spain you have the right to access, rectify, erase, restrict processing, object to processing, and request portability of your data. You can exercise these by writing to info@patriq.finance.
You also have the right to file a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es) if you believe the processing doesn't comply with the regulation.
9. Security
Every user can only see and modify their own data: the database enforces Row Level Security (RLS) at the PostgreSQL level on every table, not just in application code. Third-party tokens are encrypted at rest with pgcrypto before being stored and are never sent to the browser. No personal data or credentials are written to application logs.
10. Minors
Patriq is not directed at anyone under 18, and we don't knowingly collect data from minors.
11. Changes to this policy
If we make a substantial change to how we handle your data, we'll reflect it on this page by updating the "last updated" date, and, when the change is significant, we'll notify you by email.
12. Contact
For any question about this policy or your data: info@patriq.finance.