Gylder
← Back

Privacy Policy

Last updated: August 31, 2026

1. Who we are

Gylder is a personal net worth tracking service. Gylder is a trademark of cdum B.V., a company registered under Dutch law.

  • Registered address: Boxmeerstraat 129, 5043ZC Tilburg, The Netherlands
  • Gylder is registered at the Dutch Chamber of Commerce under number 93033613

cdum B.V. is the data controller for all personal data processed through Gylder. For any privacy-related questions, send an email with your question to legal@gylder.nl or contact us via post on the registered address.

2. What data we collect and why

DataLegal basisPurposeRetention
Email addressContract performanceAccount login, notificationsUntil account deletion
Name (optional)Contract performancePersonalisation (e.g. sidebar greeting)Until account deletion
Phone number (optional)Contract performanceAccount personalisationUntil account deletion
Financial data (balances, positions, transactions)Contract performanceCore product — net worth calculationUntil account deletion. Crypto-shredded on deletion.
Provider credentials (OAuth tokens, API keys)Contract performanceSyncing connected financial accountsUntil provider disconnected or account deleted
Payment informationContract performanceSubscription billingManaged by Stripe. Invoices retained 7 years.
Marketing email preferenceConsentProduct updates and tipsUntil withdrawn
Referral code and the link between inviter and invited userContract performanceRunning the referral programme, crediting free months, preventing abuseUntil account deletion
Waitlist registration (email address, phone number)ConsentLetting you know when a plan becomes availableUntil withdrawn or the waitlist is closed
Survey and feedback responsesConsentImproving the serviceUntil account deletion

We do not collect device fingerprints and do not use advertising trackers. We do not sell your data to third parties, ever. We use Google Analytics to understand how our website is used (e.g. which pages are visited). Google Analytics is only loaded if you explicitly accept analytics cookies — it is never loaded without your consent. IP addresses are anonymised before being sent to Google. We use PromptWatch, a cookieless analytics tool, to see which websites and AI search engines refer visitors to us. It stores nothing on your device and builds no profile of you.

3. How we protect your data

Your financial data is encrypted with a key unique to your account, and that key is itself protected by a separate key service. A copy of our database on its own therefore reveals nothing. The key can be unlocked by the app while it serves your request, and by a small number of named administrators who need it to run and support the service. Every use is recorded in an audit log we cannot alter.

All personal and financial user data is stored exclusively in AWS data centres in Frankfurt, Germany (eu-central-1), operated by Amazon Web Services EMEA SARL, a Luxembourg-based entity. User data is never replicated to non-EU regions.

Bank connections use PSD2-regulated Open Banking APIs via Enable Banking. Gylder has read-only access — we can never initiate payments, transfers, or modifications to your bank accounts.

All connections to Gylder are encrypted in transit using TLS 1.2 or higher. Two-factor authentication (TOTP) is mandatory for all accounts.

Application code is compiled on Vercel's build infrastructure, which may be located outside the EU. Builds process only source code and public configuration — no personal or financial data.

4. Who we share data with

We use the following sub-processors to operate Gylder. We have Data Processing Agreements (DPAs) in place with each processor. We do not sell or share your data with third parties for marketing or advertising purposes.

ProcessorPurposeLocation
Amazon Web Services EMEA SARLInfrastructure, database, encryption key management, authenticationEU (Frankfurt, Germany)
StripePayment processing, subscription managementEU / US (SCCs in place)
Enable Banking OyOpen Banking — bank account linking (PSD2)EU (Finland)
VercelFrontend hostingEU edge network (US origin, SCCs in place)
ResendTransactional email delivery (notifications, alerts)EU (Ireland)
Google LLCAnalytics (consent-gated Google Analytics)US (SCCs in place, IP anonymised)
Promptwatch B.V.Cookieless AI-referral analytics (which sites and AI engines send us visitors)Netherlands (EU)

5. International data transfers

Your financial data is stored exclusively in AWS eu-central-1 (Frankfurt, Germany) and never leaves the EU. The contracting AWS entity is Amazon Web Services EMEA SARL, based in Luxembourg.

Some sub-processors (Stripe, Vercel) may process limited data in the United States. These transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission, and where applicable, supplementary technical measures (encryption in transit and at rest).

AWS is a subsidiary of Amazon.com, Inc., a US-based company. Under the US CLOUD Act, US law enforcement could theoretically request data from AWS. However, all financial data stored in Gylder is encrypted with per-user keys managed through AWS KMS, so access to the stored database alone does not reveal your financial information. Decryption requires a separate, separately audited key service, as described in section 3.

6. Your rights

Under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data. To exercise any of them, email legal@gylder.nl. We will respond within 30 days.

  • Access (Art. 15)Request a copy of all personal data we hold about you. You can also download it directly from Settings → Data → Export my data (JSON format).
  • Rectification (Art. 16)Correct inaccurate personal data. You can update your name and email in Settings → Profile. Financial data is sourced from your connected providers — corrections should be made at the provider level.
  • Erasure (Art. 17)Request deletion of your account and all data. You can initiate this from Settings → Data → Delete Account. Your records are deleted and your encryption key is destroyed with them (crypto-shredding). Encrypted database backups are kept on a rolling 7-day window; once the last backup predating your request expires, the data cannot be reconstructed.
  • Portability (Art. 20)Download your data in a structured, machine-readable JSON format from Settings → Data.
  • Restriction (Art. 18)Request that we stop processing your data in certain ways. You can disconnect individual providers at any time to stop data syncing for that account.
  • Objection (Art. 21)Object to processing based on legitimate interest.
  • Withdraw consentFor processing based on consent (e.g., marketing emails), you can withdraw at any time from Settings → Alerts & Notifications, without affecting the lawfulness of prior processing.

If you believe we are not handling your data correctly, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens): autoriteitpersoonsgegevens.nl.

7. Data retention

DataRetention periodBasis
User financial data (balances, positions, snapshots)Until account deletionContract performance
Provider credentials (OAuth tokens, API keys)Until provider disconnected or account deletedContract performance
Stripe invoices and payment records7 years after creationDutch fiscal retention obligation
Waitlist registrations (email address, phone number)Until withdrawn or the waitlist is closedConsent
Application logs (no PII)90 daysOperational / security
Account deletion audit record (pseudonymised — SHA-256 of user id only)5.5 years after deletionLegitimate interest (fraud prevention, Dutch civil claim limitation period Art 3:307 BW + 6-month buffer)

When you delete your account, all encrypted financial data is destroyed via crypto-shredding: your personal encryption key is deleted, leaving the data unreadable. This is a legally recognised GDPR deletion strategy. Encrypted database backups are retained on a rolling 7-day window, so the last copy expires within a week of your request.

8. Cookies

Gylder uses essential cookies that are strictly necessary for the service to function. We also use Google Analytics cookies to understand how our website is used — these are only placed if you explicitly accept them via our cookie banner. We do not use advertising cookies.

CookiePurposeDuration
gylder_sessionAuthentication — keeps you logged in60 minutes
gylder_accessAuthentication — session management60 minutes
gylder_refreshAuthentication — extends your session30 days
gylder_auth_state / gylder_auth_userTemporary — two-factor authentication flow5 minutes
gylder_oauth_reconnectTemporary — bank reconnection flow10 minutes
gylder_localePreference — remembers your chosen language (en/nl)1 year
gylder_themePreference — remembers your chosen appearance (light/dark/system)1 year

Authentication cookies are HttpOnly (not accessible to JavaScript). Preference cookies (language, theme) are readable by JavaScript so the in-page toggles can update them, and they contain only a short, non-sensitive value (a language code or 'light'/'dark'/'system'). All essential cookies use the Secure flag in production (HTTPS only) and are set with SameSite=Lax. Essential cookies do not require consent under GDPR (Recital 32, ePrivacy Directive Art. 5(3)). Google Analytics cookies are only placed after you explicitly give consent via our cookie banner. You can withdraw your consent at any time by clearing your browser cookies — the banner will reappear on your next visit. PromptWatch (AI-referral analytics) is cookieless and requires no consent.

9. Changes to this policy

We may update this privacy policy from time to time. The date of the most recent update is shown at the top of this page, and the current version is always available at gylder.nl/privacy.

10. Contact

For any privacy-related questions, data access requests, or to exercise your rights: legal@gylder.nl

Gylder has appointed an internal Data Protection Officer (DPO) who can be contacted at the same address: legal@gylder.nl

cdum B.V.
Boxmeerstraat 129
5043ZC Tilburg
The Netherlands