PRIVACY POLICY
Your data.
Clear information.
How this version of the website works and what still needs to be confirmed before the app launches.
Last reviewed: 5 October 2026
Scope and controller
This preliminary version distinguishes the presentation website from the Ravnu app. It is not an approved privacy policy for a production service.
The legal identity, address and contact details of the data controller are not confirmed in the project materials. These details and, where applicable, the data protection officer's contact details must be included in the final version.
On this website
The website does not require an account or accept payments. Its support form collects your name, email, subject, messages and acceptance of the conditions. Calculator inputs are processed in your browser; the website code does not send them to a server or save them in persistent storage.
Support data is used to reply and retain conversation history. A private session and an email link let you resume the conversation for 30 days. After 2 minutes away, unread replies may be sent by email. Resolved conversations are deleted after 90 days; encrypted backups are retained for 30 days on the VPS. You can contact [email protected] with requests about your data.
No external advertising services or tracking cookies are integrated. Aggregate website counts are described in the statistics section. Fonts and images are served as website files. When you open an external link, that destination's rules apply.
The server delivering the page may process technical request data, such as IP address, date and requested resource. The website is hosted on Cloudflare Pages; support is served separately at api.ravnu.com. The purposes and retention periods of technical logs and the identities of the controllers need to be confirmed for the final policy. See also the page on cookies and storage.
In the app
The app implementation processes account identifiers, registered device information and financial records entered by the user. Goals, transactions and preferences support its organisation features.
The app uses authenticated API access. This does not mean data is processed only on the device or that end-to-end encryption exists. The actual production security measures must be described and verified before launch.
SPARK and providers
When you use SPARK, submitted messages and images may be sent to the configured AI provider. The project currently uses a Groq integration. The financial context preference controls the inclusion of that context, not the sending of the message or image you choose to submit.
The project also includes external market data services and a Stripe payment integration for the app. The final list of providers, their roles, locations, transfers and safeguards must be confirmed. None of these operations is performed by this website's simulator.
Purposes and retention
App data supports account management, records, budgets, goals and requested analyses. The legal basis for each processing activity, what is required or optional, and retention periods or criteria still need to be identified.
No unconfirmed deletion period is stated. The implementation includes account export and deletion mechanisms, but the final policy must clarify their effects on shared data, backups and records retained by providers.
Your rights
Depending on the processing and applicable legal conditions, the GDPR provides rights of access, rectification, erasure, restriction, objection and portability. Where processing relies on consent, it can be withdrawn without affecting the lawfulness of earlier processing.
The final version must provide an effective contact for exercising these rights. You can read the CNPD information and lodge a complaint with the competent supervisory authority.
Before publication
This text needs to be completed and reviewed by the controller and qualified legal support. Missing information cannot be replaced by a general assurance of compliance.
Reference: data protection information obligations — European Commission.
Launch notification.
This list is separate from the app and support. With your permission, we collect your name, email, chosen platform and campaign source when it belongs to an identified channel. We also record the date and consent version. The purpose is to register your interest, send a welcome email and notify you of launch; it does not enrol you in advertising campaigns or create an account.
Registration becomes active when you submit the form with your consent, without email confirmation. Contacts expire after 365 days unless removed earlier. Older unconfirmed requests keep their original 24-hour deadline. The service deletes expired records during daily maintenance, by its next run, or when it receives a request. You can withdraw consent using the email link or ask for help at [email protected].
The list's hosting and database use Cloudflare. The list is presented by the RAVNU brand; the data enquiries contact is [email protected]. The controller's legal identity remains to be completed in this preliminary policy. Welcome and launch emails are sent by Ravnu's own email service from [email protected]. We do not use an external campaign provider for this list. Only aggregate daily sign-up and removal counts by channel are recorded, retained for up to 90 days. Calculator inputs are not collected for these counts.
To prevent abuse, the service uses Turnstile verification and limits by email and network address. Limit keys are derived using a hash with a server secret and expire after one hour. These are not advertising cookies. Removal uses a link containing a private token; do not share it.
Website statistics.
We count page openings, registrations and removals by day and identified source for 90 days. Statistics do not include names, emails, financial figures, full referring URLs or persistent identifiers. Repeated openings count again and do not represent unique people.
We do not use cookies or browser storage for these counts. We respect Do Not Track and Global Privacy Control signals; pages with private resume or removal links are not counted. A temporary network limit uses a hashed key with a server secret, which stops being used after one hour; expired records are deleted during daily cleanup. Network requests pass through Cloudflare hosting, which may process technical information as described in this policy.