Skip to main content

Legal and privacy

Privacy Policy

This policy explains how Reditus processes your personal data when you visit reditus.app, create an account, or use its investment management tools.

Last updated: August 11, 2026

You control your data

You can update your profile, delete your account, and exercise your data protection rights.

Limited use

We process the data needed to provide, secure, and improve Reditus; we do not sell personal data.

No invasive advertising

The audited code contains no advertising cookies or behavioral analytics tools.

Data controller

Reditus is the controller of the personal data described in this policy.

  • Identity used by the service: Reditus.
  • Website: https://reditus.app.
  • Privacy contact: [email protected].

Data we process

The categories depend on the features you use:

  • Account and identity: internal identifier, email address, first and last name, password hash when you use local sign-in, authentication provider, Google identifier, base currency, roles, account status, and creation and last-sign-in dates.
  • Portfolio and investments: platforms, assets, tickers, transaction dates and types, quantities, prices, fees, currencies, scheduled transaction rules, imported records, and metrics or snapshots calculated from them.
  • Subscription and billing: plan, status and subscription periods, and Stripe customer, subscription, and session identifiers. Reditus does not store full card numbers or complete payment details.
  • Communications: name, email, subject, and message submitted through the contact form; also titles, descriptions, replies, and status of feedback submitted from an account.
  • Technical and security data: IP address used temporarily for rate limiting, request identifiers, requested method and path, user identifier in authenticated logs, and session data contained in the JWT.
  • Browser preferences: language, theme, and a local indication that an authenticated session exists.

Sources of data

We obtain data from the following sources:

  • Directly from you when you register, complete your profile, record or import transactions, purchase a plan, or contact support.
  • From Google, if you choose that sign-in method, and from Stripe when a subscription starts or changes status.
  • From service activity, such as security logs, positions, performance, projections, and other metrics derived from portfolio data.

Purposes and legal bases

We process data only where an applicable legal basis exists:

  • Providing the service, authenticating you, maintaining your account, and calculating portfolio views: performance of a contract or pre-contractual steps (GDPR Article 6(1)(b)).
  • Managing trials, subscriptions, payments, and the billing portal: performance of a contract (Article 6(1)(b)) and, where applicable, compliance with legal obligations (Article 6(1)(c)).
  • Responding to inquiries, recovering passwords, and handling feedback: performance of a contract, pre-contractual steps, or our legitimate interest in supporting users (Articles 6(1)(b) and 6(1)(f)).
  • Preventing abuse, enforcing rate limits, protecting sessions, investigating errors, and maintaining backups: our legitimate interest in securing the availability and integrity of the service (Article 6(1)(f)).
  • Fixing issues and improving features using technical information and feedback: our legitimate interest in improving Reditus (Article 6(1)(f)), balanced against your rights.
  • Meeting legal duties and responding to claims or authority requests: compliance with a legal obligation or our legitimate interest in establishing and defending claims (Articles 6(1)(c) and 6(1)(f)).

Recipients and service providers

We do not publish your data. We may disclose it to providers that need it to deliver their services:

  • Google: optional authentication. We receive the account identifier, verified email, first name, and last name associated with the identity token.
  • Stripe: payments and subscriptions. We send your email, an internal user identifier, and session metadata; Stripe collects payment details directly.
  • SMTP provider: delivery of password recovery emails and messages submitted through the contact form.
  • Grafana: production observability through technical logs and metrics, which may include request and user identifiers.
  • Cloudflare R2: encrypted backup storage in the European Union jurisdiction.
  • Yahoo Finance, Frankfurter, FRED, and EODHD: retrieving prices, exchange rates, and market data. The service design sends them market references, not your identity or complete portfolio contents.
  • Hosting, database, and communications providers needed to operate Reditus under the controller's instructions.
  • Government bodies, courts, or law enforcement where required by law or necessary to protect legitimate rights.

Reditus does not sell your personal data or use it for personalized advertising.

International transfers

Google, Stripe, Grafana, or other providers may process data outside the European Economic Area. Their locations and subprocessors may change over time.

Where applicable, we require a valid transfer mechanism, such as an adequacy decision, the EU-US Data Privacy Framework, or Standard Contractual Clauses, together with appropriate supplementary measures. Reditus backups are configured in Cloudflare R2's European jurisdiction.

Retention periods

We retain each category only for as long as needed for its purpose:

  • Account and portfolio data remains while the account is active. Account deletion removes associated records from the active database unless a legal duty applies or limited information is needed for legal claims. When you delete your account, Reditus automatically and immediately cancels correlated recurring subscriptions.
  • Subscription cancellation does not erase Stripe's billing records. Stripe may retain those records and payment evidence for applicable legal, tax, accounting, or fraud-prevention periods.
  • Recovery links expire after 60 minutes by default; tokens are stored as hashes and expired tokens are deleted daily.
  • Technical identifiers for processed Stripe events are retained for 45 days to detect resends and prevent duplicate processing.
  • Contact messages and feedback are retained as needed to respond, manage the issue, and address potential liabilities.
  • Backups are encrypted and subject to automatic lifecycles: daily backups expire after 35 days and monthly backups after 400 days. Deleted data may remain in a backup until that backup expires.
  • Technical logs are kept for the operational period needed for security, diagnostics, and incident investigation, with restricted access.

Cookies and local storage

The audited version of Reditus uses only necessary or preference technologies:

  • access_token: essential JWT authentication cookie. It is HttpOnly, Secure in production, SameSite=Lax, and limited to the configured session duration.
  • authenticated: a technical localStorage hint that helps manage redirects and is removed when you sign out; it does not contain the access token.
  • The browser may remember your chosen language and theme to preserve your preferences.
  • No advertising cookies or behavioral analytics tools were identified in the audited code. If this changes, we will update this policy and request consent where required.

Your rights

Under the GDPR and applicable law, you may request:

  • Access to your data and a copy of the information processed.
  • Correction of inaccurate or incomplete data.
  • Erasure where the data is no longer needed or another legal ground applies.
  • Restriction of processing in the circumstances provided by law.
  • Objection to processing based on legitimate interests for reasons related to your particular situation.
  • Portability of data you provided where processing is automated and based on contract or consent.
  • Withdrawal of consent at any time without affecting the lawfulness of prior processing.
  • A complaint to the Spanish Data Protection Agency (aepd.es) or the supervisory authority where you live or work.

You can update some data and delete your account from your profile. For any other request, email the contact listed below. We may request reasonable information to verify your identity.

Security

We apply technical and organizational measures proportionate to risk: BCrypt password hashing, HttpOnly cookies that are secure in production, role-based access control, per-user data isolation, IP rate limiting, webhook signature verification, HTTPS connections, encrypted backups, and production access controls. No system can guarantee absolute security.

Children

Reditus is not directed to anyone under 18 and does not knowingly seek to collect their data. If you believe a child has provided information, contact us to request its review and deletion.

Automated decision-making

Reditus calculates metrics, rankings, and projections from portfolio data, but it does not make solely automated decisions that produce legal or similarly significant effects on you. These features are informational and do not constitute financial advice.

Changes to this policy

We may update this policy to reflect legal, technical, or service changes. We will publish the current version on this page and change the update date; if a change is significant, we will provide a reasonable additional notice.

Contact

To exercise your rights or ask any privacy question, email:

[email protected]