Version 2.0 — June 3, 2026

Privacy Policy

Last updated: June 3, 2026 · Replaces the March 30, 2026 version.

Changes from the previous version (March 30, 2026)

  • Removed Google Sign-In (not available in version 2.0).
  • Updated list of data processors (infrastructure migrated to Render, Frankfurt EU).
  • Added new data fields: alias, UX preferences, anonymised IP, push token, receipt OCR metadata.
  • New section on Apple App Tracking Transparency (ATT).
  • New section on marketing communications.
  • Enhanced security measures section.

1. Data Controller

  • Controller: Iván Sevilla Ruano
  • Tax ID (NIF): 06287255K
  • Trade name: Neto App
  • Contact email: hello@netoapp.es
  • Website: netoapp.es
  • Mobile app: Neto — Finances & Wealth (iOS, Bundle ID: com.createinc.e3ed99440d084fe9869c816f65118368)
  • Current version: 2.0 (published on the App Store on June 3, 2026)

2. Personal data we collect

We collect only the data strictly necessary to provide the service:

DataPurposeSource
Email addressRegistration, authentication and identificationProvided by the user
Alias / nicknamePersonalisation and in-app greetingProvided by the user (mandatory from v2.0; optional for legacy accounts)
Password (argon2 hash)Secure authentication — never stored in plain textProvided by the user
Language, currency, timezoneUser experience preferencesConfigured by the user
Daily budget (optional)Spending control featureConfigured by the user
Visual theme (light/dark/auto)Interface preferenceConfigured by the user
Anonymised IP (/24 IPv4, /48 IPv6)Security and rate limiting — not linked to accountHTTP connection (anonymised automatically)
iOS push notification tokenService and local notificationsApple Push Notification Service (APNs)
Declarative financial dataCore personal finance and wealth management serviceEntered manually by the user
Receipt metadata (amount, date, merchant)Quick expense logging via on-device OCROn-device processing (Apple Vision). Receipt image is NOT uploaded to the server.
Session tokenSingle-session enforcementGenerated automatically on the server

What we do NOT collect

  • We do not connect to or access real bank accounts. All data is declarative.
  • We do not collect credit card or payment credentials (only via Apple).
  • We do not collect biometric data (Face ID/Touch ID is a system-level iOS feature — the app does not read it).
  • We do not collect geolocation data.
  • We do not access device contacts.
  • We do not upload receipt images to any server (on-device OCR only).
  • We do not use third-party trackers (no Analytics, Sentry, Firebase, or similar).
  • We do not build advertising profiles.

3. Processing purposes

  • Manage registration, authentication and access to the app via email and password.
  • Provide the personal finance management, wealth tracking and investment analysis service.
  • Manage Neto PRO subscriptions via the Apple App Store and RevenueCat.
  • Send transactional communications: email verification, password reset, security alerts, legal changes.
  • Retrieve public market price data from external providers (no personal data is sent to those providers).
  • Maintain service security via IP-based rate limiting (anonymised).

4. Legal basis (GDPR)

Contract performance (art. 6.1.b GDPR)

To provide the service you agreed to when creating your account.

Legitimate interest (art. 6.1.f GDPR)

For service security and rate limiting, balanced against your rights.

Legal obligation (art. 6.1.c GDPR)

When required to comply with applicable legal requirements.

Consent (art. 6.1.a GDPR)

For non-essential communications, where applicable.

5. Data retention

  • We retain your data while your account remains active.
  • You may request full account and data deletion at any time from within the app or by emailing hello@netoapp.es.
  • After a deletion request, we will erase your data within 30 days, unless a legal retention obligation applies.
  • PRO subscription data is retained for the minimum period required by Spanish tax and commercial law (at least 5 years).
  • Anonymised IPs used for rate limiting are automatically deleted after 24 hours.

6. Recipients and data processors

We do not sell, rent, or share your personal data with third parties for commercial purposes. Our data processors are:

ProviderRoleLocation / Safeguard
Render Services Inc.Backend & databaseFrankfurt, Germany (EEA) — intra-EEA transfer
Hostinger International Ltd.Web hosting & corporate email @netoapp.esVilnius, Lithuania (EEA) — intra-EEA transfer
Resend Inc.Transactional email (verification, password reset)USA — Standard Contractual Clauses (SCC 2021/914)
RevenueCat Inc.PRO subscription managementUSA — Standard Contractual Clauses (SCC 2021/914)
Apple Distribution International Ltd.App Store payments, Apple Push Notifications, KeychainIreland (EEA) — intra-EEA transfer
Twelve Data (WSS Group Inc.)Stocks, ETF, UCITS funds & FX pricesUSA — SCC 2021/914. Only receives asset symbol, NO personal data.
CoinGeckoCryptocurrency pricesSingapore — SCC 2021/914. Only receives asset symbol, NO personal data.
Yahoo FinanceAdditional public reference pricesUSA — public queries; no personal data sent.
Competent authoritiesLegal obligation or court order

7. International data transfers

The core service (backend and database) is hosted within the European Union (Frankfurt, Germany) and does not involve any transfer outside the EEA.

For providers located outside the EEA (Resend, RevenueCat, Twelve Data), transfers are covered by the Standard Contractual Clauses (SCC) approved by the European Commission via Implementing Decision 2021/914 of 4 June 2021. You may request a copy of the applicable safeguards by writing to hello@netoapp.es.

8. Your rights (GDPR)

Access

Know what data we hold about you.

Rectification

Correct inaccurate or incomplete data.

Erasure

Request deletion of your data ('right to be forgotten').

Objection

Object to processing in certain circumstances.

Restriction

Restrict processing while a complaint is resolved.

Portability

Receive your data in a structured, machine-readable format.

To exercise your rights, email us at hello@netoapp.es, including proof of identity. We will respond within one month (extendable by two further months for complex cases).

If you believe your data is being processed unlawfully, you may lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.

9. Cookies and similar technologies

The web version of Neto uses only strictly necessary technical cookies:

  • Session cookie: keeps your session securely active.
  • Authentication cookie: manages your encrypted access token.

We do not use tracking, analytics, or advertising cookies. We do not perform cross-site tracking.

10. Apple App Tracking Transparency (ATT)

Neto App does NOT track users across third-party apps or websites under Apple's App Tracking Transparency (ATT) framework. We do not request the AppTrackingTransparency permission.

Web cookies are strictly technical and limited to what is necessary for the service to function — no advertising or cross-site tracking purposes.

11. Security measures

  • Passwords are stored using argon2 hashing — never in plain text.
  • All communications are encrypted via HTTPS/TLS.
  • The backend and database are hosted within the European Union (Frankfurt, Germany — Render Inc.). Core service data does not leave the EEA.
  • The authentication token is stored in Apple Keychain with the kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly attribute, preventing it from entering iCloud backups and binding it to the physical device.
  • The app applies a neutral overlay in the app switcher so account balances are not visible in multitasking.
  • IPs are anonymised before any storage (/24 for IPv4, /48 for IPv6).
  • Sessions have time-based expiration and single-session enforcement.

In the event of a security incident affecting your personal data, we will notify you as required by GDPR articles 33 and 34.

12. Minors

Neto App is not intended for users under 16 years of age. We do not knowingly collect data from minors. If you are a parent or guardian and believe a minor has provided us with personal data, please contact us at hello@netoapp.es and we will promptly delete it.

13. Marketing communications

We only send transactional communications (email verification, password reset, security alerts, material legal changes). Occasionally, we may send a single communication announcing a major version release — considered essential service information and grounded in contract performance (art. 6.1.b GDPR). We do not run email marketing campaigns or newsletters without your explicit consent.

14. Changes to this policy

We may update this Privacy Policy to reflect legal, technical, or service changes. Substantial changes will be communicated through the app or by email with reasonable advance notice. The last update date is always shown at the top of this document.

15. Contact

For any privacy or data protection queries: hello@netoapp.es