Privacy Policy
How we collect, use, and protect your personal data.
Last updated: August 1, 2026
1. Who we are and how to reach us
The controller of your personal data is:
Pavol Džama, a natural person, of Juh 1052/30, 093 01 Vranov nad Topľou, Slovak Republic.
Contact for all privacy matters, including requests to exercise your rights: hello@talero.app
We operate Talero, an independent personal finance tracker (the "Service"). We have not appointed a Data Protection Officer, because we are not required to. Privacy requests are handled by us personally at the address above.
2. What we process, why, and on what legal basis
| What | Why | Legal basis | | --- | --- | --- | | E-mail address, hashed password, display name, locale and interface preferences | To create and secure your account, sign you in, and show the Service in your language | Performance of the contract — Art. 6(1)(b) GDPR | | Google account identifier and e-mail, if you use social sign-in | To let you sign in without a separate password | Performance of the contract — Art. 6(1)(b) | | Two-factor authentication secrets and recovery codes, trusted-device records | To protect your account | Performance of the contract — Art. 6(1)(b); our legitimate interest in account security — Art. 6(1)(f) | | Financial records you enter or import: accounts, transactions, categories, budgets, tax settings, imported statements | To provide the core functionality of the Service to you | Performance of the contract — Art. 6(1)(b) | | Documents you upload for AI extraction (bank statements in PDF) | To extract a transaction table from the document, which is only technically possible with AI | Your explicit consent — Art. 6(1)(a). See section 3 | | Workspace membership, roles, invitations you send or receive | To operate shared workspaces | Performance of the contract — Art. 6(1)(b) | | Records of which version of the Terms and this Policy you accepted, and when, with the IP address used | To demonstrate that consent and acceptance were obtained, as the law requires us to | Legal obligation and accountability — Art. 6(1)(c), Art. 5(2), Art. 7(1) | | Server and application logs: IP address, timestamp, request path, user agent, error traces. Collected on our servers and forwarded to our log-management provider (see section 4) | To keep the Service secure and available, to detect and investigate abuse, failed sign-in attempts and technical faults | Our legitimate interest in the security and availability of the Service — Art. 6(1)(f) | | Aggregate usage and performance measurements (page views, response times, error rates) | To understand how the Service performs and to find faults. No cookies, no cross-site tracking, no profiles. See section 5 | Our legitimate interest in operating and improving the Service — Art. 6(1)(f) | | E-mail correspondence you send to our support address | To answer you and keep a record of the matter | Performance of the contract, or our legitimate interest in handling enquiries — Art. 6(1)(b) / (f) | | Marketing e-mail address, if you opt in | To send you product news and tips | Your consent — Art. 6(1)(a), withdrawable at any time | | Waitlist e-mail address, if you join the waitlist | To notify you when a place becomes available | Your consent — Art. 6(1)(a) | | Referral records, if you invite someone or were invited | To attribute and grant referral rewards | Performance of the contract — Art. 6(1)(b) |
We do not process special categories of personal data (Art. 9 GDPR) and we ask you not to enter any into the Service. We do not carry out automated decision-making producing legal or similarly significant effects on you within the meaning of Art. 22 GDPR: AI categorisation produces suggestions that you review and confirm.
We do not sell your personal data, and we do not use your financial data to train AI models.
3. Artificial intelligence, PDF import, and automated categorisation
Talero uses a third-party AI model (Google Gemini) in two related ways: to extract data from bank PDF statements, and to suggest categories during import.
- PDF import, extraction and consent. Extracting data from a bank PDF relies exclusively on AI. Before your first PDF upload we ask for your explicit, separate consent. Once given, the uploaded PDF is transmitted to Google's Gemini API, which returns a structured transaction table. The whole document is sent, including any personal data it contains — account numbers, counterparty names, payment references. The file is ephemeral in Google's processing environment and is not retained there after extraction. PDF import is not available without this AI step. You can withdraw your consent at any time in your settings; PDF import then stops being available to you, and withdrawal does not affect processing that already happened.
- Automated categorisation (all formats). When you import structured financial data (PDF, CSV, Excel or other formats), AI-assisted categorisation is enabled by default. Before sending, the payload is reduced: IBANs, BICs and long digit sequences are scrubbed, and raw descriptions and external identifiers are dropped. What is sent is the cleaned description text, amount, date and your category tree.
- Smart mapping and auto-rules. The AI proposes a category and a permanent matching rule. If you do not dismiss or edit the suggested rule during the import review, it is saved to your workspace when you finalise the import — so future imports match locally without sending those rows to the AI again.
- Categorisation is optional. You can disable AI categorisation before starting any import, or dismiss individual suggestions during review. If it is off, you assign categories using your local rules or manually.
- Zero retention. All Gemini processing operates under Google's zero-retention terms. Your financial data, PDF contents, transaction payloads and category structures are not stored by Google and are not used to train Google's models.
- You are in control of the output. AI output is probabilistic and can be wrong. Nothing the AI produces is written to your records until you confirm it in the review step.
4. Who processes your data for us, and where
We do not sell your data. We use the following processors and sub-processors to run the Service:
| Provider | Role | Location of processing | | --- | --- | --- | | Neon | Managed PostgreSQL database and backups | Germany (EU) | | Hetzner Online GmbH | Application servers and compute | Germany (EU) | | Vercel Inc. | Web application hosting, edge delivery, cookieless usage and performance measurement | Global edge network; EU region primary | | Functional Software, Inc. (Sentry) | Error and performance monitoring, configured to the EU region with personal-data scrubbing enabled (send_default_pii=False) | European Union | | Better Stack, Inc. / Better Stack s.r.o. | Log management — centralised collection and storage of our server and application logs, delivered to the provider's EU ingest region | European Union | | Google LLC / Google Ireland Limited | Optional OAuth sign-in provider; AI sub-processor for document extraction and categorisation (Gemini API) | United States and EU | | Resend | Delivery of transactional e-mail (sign-up confirmation, password reset, invitations) | United States / EU | | Zoho Corporation | Support mailbox at our contact address | EU data centre |
International transfers. Where a provider processes data outside the EEA — in practice Google, Vercel and Resend — the transfer is safeguarded by the European Commission's Standard Contractual Clauses together with the provider's data processing addendum and supplementary technical measures (encryption in transit and at rest, and personal-data minimisation before transmission). You may request a copy of the relevant safeguards from us at hello@talero.app.
We enter into a data processing agreement under Art. 28 GDPR with each processor. We will update this section before adding a new sub-processor that materially changes where or how your data is processed.
5. Cookies, analytics and similar technologies
5.1 Cookies we set. Talero sets only cookies that are strictly necessary to provide the service you have asked for:
- a session cookie that keeps you signed in;
- a CSRF token cookie that protects your requests against cross-site request forgery;
- an optional trusted-device cookie if you enable two-factor authentication and choose to trust a device for 30 days;
- in Demo Mode, two short-lived cookies described in section 12.5.
These cookies are exempt from the consent requirement under Art. 5(3) of the ePrivacy Directive (and § 109(8) of Slovak Act No. 452/2021 Coll.) because they are strictly necessary to provide the service you requested. We do not ask for your consent to set them, and the Service cannot function without them.
5.2 Usage and performance measurement — no cookies, no consent. We use Vercel Analytics and Vercel Speed Insights to see how many people visit which pages and how fast those pages load, and Sentry to be told when something breaks.
These tools do not set cookies and do not store or read anything on your device. Because there is no access to information stored in your terminal equipment, the consent requirement of Art. 5(3) of the ePrivacy Directive is not triggered at all. This is why you will not find an analytics toggle in the Service: there is nothing to consent to.
They do process your IP address and technical request metadata on our servers, which is personal data. We process that on the basis of our legitimate interest in operating, securing and improving the Service (Art. 6(1)(f) GDPR). We have assessed this against your interests and consider it proportionate because: no cookies or identifiers are stored on your device, no cross-site or cross-session profile is built, IP addresses are not used to identify you and are not enriched with data from other sources, the data is aggregated, and error reports are configured to strip personal data before they leave our servers.
You have the right to object to this processing at any time on grounds relating to your particular situation (Art. 21(1) GDPR). Write to hello@talero.app and we will stop it for you.
5.3 What we never do. We do not use advertising cookies, remarketing pixels, social media trackers, fingerprinting, or any cross-site tracking technology. We do not share your data with advertising networks or data brokers. There is no third party building a profile of you through Talero.
5.4 If this changes. If we ever introduce a technology that stores or reads information on your device beyond what is strictly necessary — or that builds a profile of you — we will ask for your consent first, through a cookie banner with a genuine and equally easy refusal option, and we will not activate it until you agree.
6. How long we keep your data
| Data | Retention period | | --- | --- | | Account and profile data | For as long as your account exists. Deleted when you delete your account | | Financial records in a Workspace you own | For as long as the Workspace exists. Destroyed when you delete your account (see section 8) | | Change history (audit trail of what changed, when, and by whom) | Up to 90 days | | Documents uploaded for AI extraction | Not stored by us after extraction; not retained by the AI provider | | Server and application logs (including IP addresses) | Up to 90 days, then deleted automatically. Held by our log-management provider (Better Stack, EU) | | Database backups | 30 days on a rolling basis, then overwritten. Backups are for disaster recovery only and are not searchable per user | | Records of consent and of Terms / Privacy Policy acceptance | For the life of the account plus 3 years, to be able to demonstrate compliance and to defend legal claims | | Support e-mail correspondence | 24 months from the last message in the thread | | Waitlist entries | 12 months, or until you ask to be removed, or until you register — whichever is first | | Marketing subscription | Until you withdraw consent or unsubscribe. The withdrawal itself is recorded so we do not contact you again | | Demo Mode data | Deleted automatically — see section 12.6 |
Where a longer period is required by law, or where data is needed to establish, exercise or defend a legal claim, we keep only what is needed for that purpose, and only for as long as it is needed.
7. Your rights
Under the GDPR you have the right to:
- Access — obtain confirmation of whether we process your data, and a copy of it. You can download a machine-readable export of your account at any time from your settings; it includes your profile, settings, consent history, workspace memberships, referral records, and the financial records in Workspaces you own.
- Rectification — have inaccurate data corrected. Most of it you can correct yourself in the application.
- Erasure — have your data deleted. There is a "Delete account" function in your settings; see section 8 for what it does.
- Restriction — ask us to stop processing while a dispute about accuracy or lawfulness is resolved.
- Portability — receive the data you provided to us in a structured, commonly used, machine-readable format (the JSON export), or ask us to transmit it to another controller where technically feasible.
- Object — object at any time to processing based on our legitimate interest, including the measurement described in section 5.2, on grounds relating to your particular situation.
- Withdraw consent — withdraw any consent you gave (AI PDF processing, marketing, waitlist) at any time, without affecting the lawfulness of processing before withdrawal.
To exercise any of these, write to hello@talero.app. We respond within one month; if a request is complex we may extend by two further months and will tell you why. We do not charge for this unless a request is manifestly unfounded or excessive. We may need to verify your identity before acting.
Right to complain. If you believe we have handled your data unlawfully, you may lodge a complaint with a supervisory authority — in particular:
Úrad na ochranu osobných údajov Slovenskej republiky Hraničná 12, 820 07 Bratislava 27, Slovak Republic https://dataprotection.gov.sk — statny.dozor@pdp.gov.sk
You may also complain to the supervisory authority in the EU state where you live or work, or where the alleged infringement took place. If you live in the Czech Republic, that is the Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7 (https://www.uoou.cz).
8. Deleting your account, and Workspace data
You may delete your account at any time from your settings. Deletion is immediate and irreversible. What happens depends on your role:
- As a member of someone else's Workspace: your personal data is deleted. Financial records you created in that Workspace remain, detached from your identity, so that the Owner's records stay intact.
- As the sole Owner (or after removing all members): deletion cascades — the Workspace and all financial data in it are permanently destroyed.
- As the Owner of a shared Workspace: deletion is blocked while other members remain. You must transfer ownership to another member (deletion stays blocked until they accept), or remove all members first, which means the Workspace data is destroyed when your account is deleted.
- Leaving voluntarily: Editors and Viewers may leave a shared Workspace at any time. Access is revoked immediately; data you entered stays in the Owner's Workspace.
Deleted data is removed from live systems immediately. It may persist in encrypted backups until those backups expire on the 30-day cycle described in section 6, after which it is gone. We do not restore individual accounts from backups.
9. Personal data about other people
If you enter data about other people into the Service — clients named on invoices, counterparties on transactions, members you invite to a Workspace — you are the controller of that data and we process it for you as a processor, on your instructions, under Art. 28 GDPR. This Policy, together with the Terms, sets out the subject matter, duration, nature and purpose of that processing, the types of data and categories of data subject, and our obligations.
It is your responsibility to have a lawful basis for entering that data, to inform those people where the law requires it, and to answer their requests. We will assist you, and we will not use that data for our own purposes.
Invitations. When you invite someone to a Workspace, we process their e-mail address to deliver the invitation and to match it when they accept. Invitee e-mail addresses are not written to our diagnostic logs in identifiable form.
Referrals. If you refer someone, we record the referral to grant the reward. In your data export, referred users' e-mail addresses are shown masked (for example j***@example.com), so that you can see the referral without us disclosing another person's contact details to you.
10. Security
We protect your data with: encryption in transit (TLS) and at rest; password hashing with a modern algorithm; optional two-factor authentication; strict tenancy isolation so that queries cannot cross workspace boundaries; rate limiting and automated lockout on repeated failed sign-in attempts; a strict content security policy; and personal-data scrubbing in error reports before they leave our servers.
Access to production data is limited to us personally, is used only where necessary to operate the Service or to answer a support request from you, and is not used to browse your financial records.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours and, where the risk is high, notify you directly without undue delay.
11. Children
The Service is not intended for anyone under 16. We confirm your age at registration and we do not knowingly collect data from children. If you believe a child has given us personal data, write to hello@talero.app and we will delete it.
12. Demo Mode
12.1 What Demo Mode is. Demo Mode lets you use the Service for a limited period without creating an account or providing any personal data. Access it and we create a temporary demo workspace for you, pre-filled with a complete set of financial records.
12.2 The financial data is entirely synthetic. Every account, transaction, category, budget, tax rate and report in a demo workspace is generated by us from a fictional template. None of it relates to you, to any other user, or to any real person or business. It is not anonymised or pseudonymised real data — there is no real data underlying it. Any resemblance to actual figures is coincidental, and none of it may be relied on as financial information.
12.3 We infer nothing about you. We do not profile you, we do not derive your interests, location, device or behaviour from your visit, and we do not use Demo Mode for advertising, tracking or automated decision-making. The demo account created for you carries no name, no e-mail address you can be reached at, and no data about you: it is identified by a randomly generated token and an unusable address on a reserved, non-routable domain.
12.4 The only personal data we collect is your IP address. We record your IP address when a demo workspace is created, for one purpose: preventing abuse of the demo — rate-limiting how many demos a single source may create, and identifying automated or high-volume misuse. It is not used for any other purpose, is not enriched, and is not shared with third parties for their own purposes. Our legal basis is our legitimate interest in protecting the Service from abuse (Article 6(1)(f) GDPR). Two points of full disclosure. First, your IP address is also recorded in our ordinary server logs, as it is for every visitor to the Service, and those logs are governed by the log retention period in section 6 rather than by this section. Second, no other data about you is collected in Demo Mode — no analytics profile, no advertising identifier, no cross-site tracking.
12.5 Cookies. Demo Mode sets two cookies, both strictly necessary to provide the demo you requested and neither used for tracking: a session cookie that keeps you signed in to the demo workspace, and a signed cookie that lets your browser return to the same demo instead of consuming a second one if you reload. The second cookie contains only an internal reference to the demo workspace itself — nothing about you. Both are set to expire automatically two hours after the demo begins.
12.6 Everything is erased. Your access to the demo workspace ends automatically two hours after it is created. The session expires on its own and cannot be extended or renewed; both cookies expire at the same moment. The demo account, its workspace and every record in it — including the IP address recorded under 12.4 — are then permanently deleted from our database in the next scheduled deletion run, normally within 24 hours of expiry. Deletion is permanent: nothing is archived, and there is no backup from which a demo workspace could be restored.
12.7 There is no path from a demo to a real account. A demo account is permanent in nature: it cannot be upgraded, converted, claimed or migrated into a paid or free account, and its contents cannot be transferred to one. If you decide to continue with the Service, you register a new account and start from an empty workspace. Nothing you did in the demo is carried over, because there is nothing of yours in it.
12.8 Your rights. Because Demo Mode collects only your IP address and erases it on the schedule set out in 12.6, we hold nothing that would let us identify you or connect you to a past demo session. If you contact us about a demo session, we will not be able to locate it after erasure, and we cannot verify that a demo was yours. Your rights under the GDPR apply to the personal data we do hold, as described elsewhere in this Policy.
13. Changes to this Policy
We may update this Policy. If a change materially affects how we process your data, we will notify you by e-mail and in the application at least 14 days before it takes effect, and we will tell you what changed. The date at the top of this Policy always shows the current version, and we keep a record of the version you were shown.