Last updated: 28 June 2026
Grova (“we”, “us”) is a personal-finance tracking app. This policy explains what personal data we process, why, and the rights you have under the EU General Data Protection Regulation (GDPR). The data controller is IT_Watermelon; you can reach us at info@grova.finance.
What we collect
- Account data — your email address and an encrypted (hashed) password, handled by our authentication provider. We never store your password in readable form.
- The financial data you enter — transactions, recurring items, categories, portfolio holdings, your safety-net settings, and your display-currency preference. You provide this; we store it so the app works.
- Essential cookies — a session cookie that keeps you signed in. We do not use advertising or cross-site tracking cookies.
How we use it
We use your data solely to provide the app: to authenticate you and to store, display, and compute over the records you enter. The legal basis is performance of our agreement with you (providing the service) and, where applicable, your consent. We do not sell your data or use it for advertising.
Where it is stored & who processes it
Your data is stored in a managed PostgreSQL database with row-level security, so each account can only read and write its own rows. We rely on the following processors:
- Supabase — database, authentication, and storage (hosting region: Central EU (Frankfurt)).
- Vercel — application hosting and delivery.
- Finnhub — stock/ETF market quotes. Only the ticker symbols you add are sent to fetch a price; your amounts, holdings quantities, and personal data are never sent.
- Frankfurter (ECB) and gold-api.com — currency-exchange and precious-metal spot rates. These receive no personal data (only generic currency/metal codes).
- GlitchTip — error monitoring (hosting region: United States). Technical error reports may include limited diagnostic context; we configure it to avoid capturing the contents of your financial records.
Retention
We keep your data for as long as your account exists. When you delete your account, all of your data is erased immediately and permanently (see below).
Your rights
Under the GDPR you can, at any time:
- Access & export your data — Settings → Export backup downloads everything in JSON.
- Rectify data — edit or delete any record directly in the app.
- Erase your account and all data — Settings → Delete account. This cascades across every record and cannot be undone.
- Data portability — the JSON/CSV exports are machine-readable.
- Object / restrict / withdraw consent, and lodge a complaint with your national data-protection supervisory authority.
Security
We enforce per-user isolation at the database level (row-level security), keep all API keys and service credentials server-side only, and serve the app over TLS. No system is perfectly secure, but we take reasonable measures to protect your data.
Not financial advice
Grova is for tracking and information only. Market prices shown may be delayed or inaccurate. Nothing in the app is financial, investment, or tax advice.
Changes
We may update this policy; we will revise the “last updated” date above and, for material changes, notify you in the app. Questions? Email info@grova.finance.
Privacy · Terms