Legal
Last updated: 29 September 2026
This Privacy Policy explains how Deco ("Deco", "we", "us") collects, uses, discloses, and protects personal data when you use the Deco mobile application, website, dashboard, and related services (the "Service").
Deco is the controller of personal data processed for the Service. Contact us at usedecoapp@outlook.com for privacy questions or requests.
Account and profile data may include:
Financial and user content may include:
Technical and usage data may include:
Website and billing data may include:
Live bank connections and Deco Plus purchases are not available in the current public app. The connection and billing disclosures in this policy apply where you have an existing, test, or future enabled service; they do not mean that it is currently available to buy or use.
For an enabled connection, Stripe Financial Connections or Synci and their financial-data partners process your authorization with your financial institution. Deco receives the account details, balances, transactions, connection identifiers and refresh status you authorize. Deco does not receive or store your online-banking password. For Synci managed connections, Deco sends your email address, Deco user identifier and, where available, your name to create a provider profile linked to your Deco account. You do not need to create a separate Synci login.
We receive data directly from you, from files you upload, from supported sign-in providers, and from services you choose to connect. We also receive limited technical information automatically from the app, website, and service providers, plus market, exchange-rate, and merchant-enrichment information used to provide requested features.
We process data to:
Where applicable, our legal bases are performance of our contract with you, our legitimate interests in operating and securing Deco and improving categorization, your consent for optional functions, and compliance with legal obligations.
You choose the accounts and permissions in the provider-hosted flow before connecting. Deco uses connected account details, balances and transactions to provide your financial overview, budgets, recurring-cost detection and planning. This permission does not authorize payments, transfers or trades. We do not use connected financial data for advertising, sale, or credit, employment, housing or insurance eligibility decisions. New data permissions require a new consent flow.
We do not sell personal data, use financial data for advertising, or share it for cross-context behavioral advertising.
Deco uses one protected cloud-sync model. Deco's service processes stored financial data to provide the features you request. Data is protected in transit with TLS/HTTPS and at rest by the storage provider. Authentication, row-level security and operational controls restrict access to records. Server functions verify the signed-in user before processing connected-account actions.
Sensitive local financial caches use authenticated encryption with a key held in secure device storage. If secure key storage is unavailable, new sensitive cache values remain in memory instead of being persisted in plaintext.
For a live connection, the selected provider, its financial-data partners, your financial institution and Deco's authenticated server functions necessarily process the account details, balances and transactions you authorize during connection and sync. Deco does not receive or store your online-banking password.
Older accounts with device-encrypted data may need a one-time security update. The update uses the existing key on an unlocked device or asks for the existing recovery code to restore the data to protected cloud sync. Those older fields remain encrypted until recovery; Deco cannot recover them if both the key and recovery code are lost.
Automatic contributions of readable categorization-learning samples are disabled in the current app. Importing a statement or correcting a category does not submit a new sample to the shared learning table. Your transactions and corrections are still processed as needed to provide your own account features. Older app versions may continue submitting samples until updated.
Older versions may have contributed separate samples containing merchant or payment-reference text, amount, currency, date, transaction type, source type, and the category assigned or corrected. Those samples excluded user ID, account ID, email, device ID and source filename, and used a server-keyed pseudonymous sample key. These controls reduce linkability, but transaction descriptions or combinations of date and amount can be distinctive. We do not claim these samples are impossible to re-identify.
Historical samples were collected for categorization, quality, and abuse prevention. They have not been deleted by the current app update. They are stored separately and may remain after account deletion because there is no retained user or account link with which to locate them. Contact usedecoapp@outlook.com with questions or objections about historical samples.
Optional PostHog usage analytics is off by default. Deco asks once per app installation after the app is ready; switching accounts on the same device does not ask again. You may also change the choice in Settings > Security. A new device starts with analytics off. We record the choice, timestamp and notice version. Enabling analytics is not required to use Deco.
With consent, PostHog receives feature-event names, a service user identifier and limited technical metadata. Custom event properties such as names, emails, financial details and onboarding answers are removed. Automatic lifecycle collection, touch autocapture and session replay are disabled. Withdrawal discards queued events; data already sent is subject to retention and deletion requests.
With your permission, optional PostHog website analytics records public page paths, language, a search/referral category, calculator completion and App Store handoffs. It does not record calculator inputs, query strings, financial records or authenticated workspace activity. An anonymous session identifier lasts for the browser tab session; your allow/decline preference is stored locally and can be changed using Analytics preferences in the footer. Browser Do Not Track and Global Privacy Control disable this optional analytics. Consenting organic-search visitors may follow an Apple campaign link with a campaign label for their selected website language; no visitor identifier is included. Apple reports aggregate downloads subject to privacy thresholds.
Vercel Analytics measures website use without analytics cookies and provides aggregate page, referrer, device, and coarse location information. These analytics are not used for advertising.
We disclose only what is needed to providers acting for us or at your direction:
For financial data processed through a Synci managed profile, Deco is the controller and Synci acts as our processor under its Data Processing Agreement. Stripe also processes certain data as an independent controller under its consumer terms and privacy notice. Each provider’s own notices explain its independent processing, subprocessors and international transfers.
Providers process data under their own terms and privacy notices where they act independently. The selected bank-connection provider and financial institution necessarily process the financial data you authorize during their connection flow. We do not otherwise disclose an individual's financial dashboard to third parties for their own purposes.
The mobile app uses device storage and secure key storage for sessions, preferences, cached data, encryption keys, and recovery state. It does not use browser cookies.
The website uses necessary Supabase authentication cookies and an access-gate cookie where enabled, plus local storage for recent account switching. Preference cookies remember your chosen website language and calculator currency for up to one year. Approximate country information from the hosting provider helps choose initial defaults. Vercel Analytics is cookie-free. Deco does not use advertising cookies, advertising identifiers, or cross-app tracking.
Our primary Supabase project is hosted in Ireland in the European Union. We generally keep user-linked data while your account is active and as needed to provide the Service. Operational and security logs are kept only as reasonably necessary for reliability, fraud prevention, and legal compliance. Provider retention can vary by service and configuration.
When you delete your account, Deco removes the live authentication account and user-linked profile, preferences, financial records, feedback, privacy recovery envelope, and stored avatar. The app also clears its local account cache.
If your account has a managed Synci profile or linked bank-provider access, account deletion also requests removal of that profile and revocation of that access. Provider-held records are subject to the provider's own retention obligations and privacy notice. Disconnecting alone does not erase historical records; you can request their deletion separately.
Residual copies may remain temporarily in provider-managed, time-limited disaster-recovery backups and expire through the provider's backup cycle. They are not used as active product data. We may retain information when legally required, and de-identified aggregates or historical categorization samples described in Section 6 may remain.
Delete your account in the iPhone app under Help & Support > Delete account, or email usedecoapp@outlook.com from the address associated with your account. Follow usedeco.app/delete-account for instructions. Access to the private web preview is not required. Deletion is permanent.
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or obtain a portable copy of personal data, withdraw consent, and appeal or complain to a regulator. California and other eligible U.S. residents may also request details about collection and disclosure and may not be discriminated against for exercising rights.
Because Deco does not sell personal data or share it for cross-context behavioral advertising, there is no sale or advertising-sharing opt-out to exercise.
Manage a connected account from Deco. Synci opens its hosted portal for connection settings and consent renewal. Disabling a connection pauses future syncing while retaining existing records. Deleting a Synci connection removes its accounts and linked imported transactions from Deco when the deletion is reconciled on the next successful sync. To revoke access or request removal of previously obtained connected data, use the provider controls and Deco’s account deletion controls, or contact usedecoapp@outlook.com. Revoking access and cancelling a paid subscription are separate actions.
Sync times describe when Deco retrieved data from its provider, not when the bank last updated its records. Refresh frequency, available history and consent renewal depend on the institution. Check important figures against your bank. Provider terms and privacy notices also apply: https://stripe.com/legal/end-users, https://stripe.com/privacy, https://synci.io/terms and https://synci.io/privacy.
We may verify your identity before acting on a request. We will respond within the period required by applicable law, generally one month under GDPR or 45 days under applicable U.S. state laws, subject to lawful extensions. EU/EEA and UK users may complain to their local data-protection authority.
We use TLS/HTTPS in transit, provider encryption at rest, authenticated access, row-level security, least-privilege service access, secure device storage and authenticated encryption for sensitive local caches. No security measure is perfect. If a breach requires notice, we will notify affected people and authorities as required by law.
Our primary database is in the EU, while Deco and its providers may process data in other countries. Where required, providers use recognized transfer mechanisms and safeguards. Local law in a processing country may differ from the law where you live.
Deco is for adults and is not directed to anyone under 18. If we learn that a minor created an account, we will delete the account and associated personal data.
We may update this policy as the Service or law changes. We will give notice of material changes as required and request fresh consent when required. The date above identifies the current version.
Questions, rights requests, or complaints: usedecoapp@outlook.com