← Back to Twolly

Privacy Policy

Last updated: 2026-10-01. Draft for review — this text describes what Twolly actually does with your data today and is written to meet Articles 13 and 14 of the GDPR. It becomes final when the controller approves it.

1. Who is responsible for your data

The controller of your personal data is Tymoteusz Kasina, a private individual operating Twolly as a non-commercial, closed-beta service. Contact: contact@twolly.app.

Postal address: [to be added before the service opens publicly].

2. What data we process

We only process data that you give us or that the service needs to work:

  • Account data — your first and last name and email address, held by our self-hosted identity service (Keycloak) and mirrored in Twolly's own user record, plus the record that you acknowledged this policy at registration.
  • Financial data you enter — transactions, categories, tags, budgets, savings goals, planned purchases, annual plans, recurring payments and vehicle records (odometer readings, fuel-ups, service records). This data belongs to a wallet; everyone you have invited into a shared wallet can see it.
  • Usage dates — one record per calendar day on which you opened the app, used for the streak indicator. No locations, no device identifiers.
  • Technical data — the application's server logs hold your user id, wallet id, the request path and a request id, with your email partially masked; the identity service keeps sign-in events (IP address and time) and logs failed sign-in or registration attempts with the email entered and the IP address.

3. Why we process it and on what legal basis

  • To provide the service you asked for — authenticating you, storing and showing your financial data, exporting it, deleting it: performance of a contract (Art. 6(1)(b) GDPR).
  • To keep accounts secure and detect abuse — sign-in events and server logs: our legitimate interest in running a secure service (Art. 6(1)(f)).
  • To send you the emails the service needs — address verification and password reset: performance of a contract (Art. 6(1)(b)).
  • The checkbox at registration confirms you have read this policy and the terms. It is not the legal basis for processing; you may leave the service at any time by deleting your account.
  • Your name and email are required to create an account — without them there is no account. All financial data is optional: enter as much or as little as you like; the app simply shows less.
  • We make no automated decisions about you and build no profiles. Every figure Twolly shows is arithmetic over what you entered.

4. Who else sees your data

We do not sell your data, do not use it for advertising and do not run analytics or tracking. The sign-in pages load no third-party fonts or scripts. Two providers process data on our behalf:

  • OVH SAS (France) — hosts the servers and database. Data stays in the European Union.
  • Resend, Inc. (United States) — sends transactional email (verification, password reset). Your email address and the message content are transferred to the United States. The transfer relies on the European Commission's Standard Contractual Clauses as provided by Resend; the controller is confirming this basis and will update this section.

5. How long we keep it

  • Account and financial data — for as long as your account exists. When you delete your account, deletion of your identity and of all data you solely own starts immediately and completes within minutes; data in a wallet you share stays with the remaining members.
  • Backups — compressed database dumps, stored on the same EU server with the same access controls, taken daily; dumps older than 14 days are deleted, so deleted data disappears from backups within that period.
  • Sign-in events (including IP addresses) — 30 days.
  • Server logs — rotated by size: at most the most recent 350 MB per service are kept and older entries are discarded automatically.

6. Your rights

  • Access and portability — export your transactions as CSV from Settings at any time; ask us for a copy of any other data.
  • Rectification — edit any entry in the app; ask us to correct account data.
  • Erasure — Settings → Delete account removes your identity and your data permanently.
  • Restriction and objection — email us and we will restrict processing while we assess the request.
  • Complaint — you may complain to the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.

7. Cookies and browser storage

Twolly uses only what is strictly necessary to sign you in and remember your preferences — no advertising or analytics cookies, so no cookie banner is shown.

  • Session cookies set by the identity service on auth.twolly.app to keep you signed in.
  • Your sign-in token, held in the browser's session storage and cleared when the tab closes.
  • Your theme choice (light, dark, pink or system), the language of these legal pages and small interface preferences such as a dismissed banner, held in the browser's local storage; the sign-in library keeps its transient sign-in state (the redirect handshake) in local storage as well.

8. Security

All traffic is encrypted in transit (TLS). Every read and write is scoped to the wallets you are a member of. Servers are hosted in the EU and administered by the controller alone; the firewall admits only web traffic and SSH with a key — the administrator's, and a deployment key used by the controller-triggered release automation on GitHub.

9. Age

Twolly is for people aged 16 and over. We do not knowingly process data of younger users; if you believe we do, contact us and we will delete it.

10. Beta status

Twolly is in a closed beta. New accounts are enabled manually by the controller after registration. The service may change or be withdrawn; you can export and delete your data at any time.

11. Changes to this policy

We will update this page when the service changes and note the date above. Material changes are announced by email before they take effect.

See also: Privacy Policy · Terms of Service