Privacy & Cookie Policy
Last updated:
1. Who we are
Pulget turns the receipts, statements, and payment screenshots you already have into a clean money inbox with useful spending insights. Cublya(“we”, “us”) is the controller for the personal data described here. You can reach us at privacy@cublya.com about anything in this policy.
Pulget does not connect to your bank and does not use open banking. Nothing reaches us until you upload it.
2. What we process
- Documents you upload: the receipts, invoices, bank or card statements, exports, and payment screenshots you choose to add, plus everything extracted from them: transactions, merchants, amounts, dates, account and card numbers shown on the document, and any other detail the document contains.
- Account data: your name, email address, and password (stored only as a hash by our authentication provider).
- Consent records: which version of these documents you agreed to and when, together with the IP address and browser string of the request that recorded it. We are required to be able to demonstrate this.
- Preferences stored on your device: settings, theme, and your cookie choice, held in your browser rather than sent to us.
- Technical data: IP address, browser and device type, and time zone, processed by our hosting providers to deliver and secure the service.
- Usage data: pseudonymous product analytics, only if you accept optional cookies.
- Communications: the content of any email you send us.
Documents like receipts can incidentally reveal sensitive things: a pharmacy purchase, a payment to a clinic, a donation to a political party or religious organisation. We do not seek this data out or use it to categorise you, but you should know it can be present in what you upload, and you decide what to upload.
3. Why we process it, and on what basis
- Running the service (extracting, organising, and displaying your transactions and insights): performance of our contract with you, Art. 6(1)(b). This is not optional; without it there is no service.
- Creating and securing your account, including authentication, abuse prevention, and rate limiting: performance of the contract, and our legitimate interest in keeping the service available and safe, Art. 6(1)(f).
- Keeping our own service working: error logs, uptime monitoring, and diagnosing failures. Legitimate interest in operating a reliable service, Art. 6(1)(f). You can object to this at any time, see section 9.
- Product analytics: consent, Art. 6(1)(a), given through the cookie banner and withdrawable at any time. Nothing is collected until you accept.
- Product update emails: consent, Art. 6(1)(a), given by ticking the optional box at sign-up. Every such email carries an unsubscribe link.
- Proving consent and acceptance: legal obligation, Art. 6(1)(c), read with Art. 7(1).
We do not train any model on your documents, and nobody at Cublya reads them to improve extraction. Where we measure extraction quality we do it on our own test documents. What the extraction providers in section 6 may do with a document while they process it is governed by our agreements with them, and we use their no-retention and no-training settings where they offer them.
Providing this data is a contractual requirement in the sense that Pulget cannot work without the documents you choose to give it. There is no consequence to not providing them other than having nothing to show you.
4. Automated processing and AI
Extraction and categorisation are automated. A language model reads the document you upload and returns structured figures, which the app then shows you for review. This does not produce legal or similarly significant effects and is not automated decision-making in the sense of Art. 22: nothing is decided about you, and you can edit or delete every value it produces.
Pulget does not assess creditworthiness, score you, or make lending decisions, and we do not sell or share any profile of you.
5. Cookies and similar technologies
This covers anything stored on or read from your device, not only cookies: local storage counts too.
- Strictly necessary: keeping you signed in, remembering your cookie choice, and holding your in-app preferences and theme. These need no consent and cannot be switched off without breaking the app.
- Optional analytics:PostHog (hosted in the EU) and Vercel Analytics, used to understand which parts of the app get used. These load only after you choose “Accept all”, and stop the moment you withdraw.
Closing the banner without choosing rejects optional cookies. You can change your mind at any time under Cookie settingsin the footer, or in Privacy & data inside the app; withdrawing is exactly as easy as accepting. Your choice is re-asked at least once a year.
If your browser sends a Global Privacy Control signal, we treat it as a refusal of optional cookies and of any sale or sharing of personal information, and we honour it without you having to touch the banner.
6. Who else processes your data
We do not sell your personal data and we do not share it for advertising. We do use service providers, who process it on our instructions under a data processing agreement:
- Supabase: authentication, database, and file storage. Holds your account data, your uploaded documents, and everything extracted from them.
- Google Cloud: the servers the application runs on. Data passes through in the course of processing.
- Google (AI Studio) and OpenRouter: document extraction. The contents of a document you upload are sent to whichever of these answers, and OpenRouter may route the request to a further model host, currently Google or Amazon Bedrock. We use zero-retention or no-training configurations where the provider offers them.
- PostHog and Vercel: product analytics. Only with your consent, and never with the contents of your documents.
We may also disclose data where the law requires it, or to establish or defend legal claims.
7. International transfers
Some of the providers above are established outside the EEA, mainly in the United States. Where personal data is transferred there, we rely on the European Commission’s Standard Contractual Clauses, which form part of our agreements with those providers, together with additional technical measures such as encryption in transit and at rest. Write to privacy@cublya.com for a copy of the relevant safeguards.
8. How long we keep it
- Documents, transactions, and everything derived from them: until you delete them, or until you delete your account.
- Account data: for as long as your account exists. Deleting your account removes it immediately.
- Consent records: for the life of the account, and deleted with it. Once the relationship ends there is nothing left to demonstrate consent for.
- Backups: deleted data can persist in encrypted backups for up to 30 days before those backups age out.
- Server and access logs: 30 days.
- Support email: 12 months after the conversation ends.
9. Your rights
Wherever you live, you can ask us to:
- give you a copy of your data, and of this policy’s details (access)
- correct anything wrong (rectification)
- delete it (erasure)
- hand it over in a portable format (portability)
- pause processing while a dispute is resolved (restriction)
- stop processing based on legitimate interests (objection), which you can do at any time and for reasons particular to your situation
- withdraw a consent you gave, without affecting what happened before you did
Two of these are buttons rather than emails: Exports in settings downloads your whole workspace, and Privacy & data deletes your account and everything in it. For anything else, write to privacy@cublya.com. We answer within one month.
If you are unhappy with how we have handled your data, you have the right to complain to your local data protection supervisory authority. You do not have to come to us first, though we would rather you did.
10. If you are in the United States
We do not sell your personal information and do not share it for cross-context behavioural advertising, as those terms are used in US state privacy laws. We honour the Global Privacy Control signal as an opt-out request. The rights listed in section 9 cover the access, correction, deletion, and portability rights those laws give you, and we will not discriminate against you for exercising them.
11. Security
Data is encrypted in transit and at rest, access is limited to the people who need it, and the database enforces that one account’s data cannot be read from another. No system is perfect; if a breach affects you and carries a high risk, we will tell you.
12. Children
Pulget is not for anyone under 16. We do not knowingly collect data from children, and we delete it if we find we have.
13. Changes to this policy
We update this page when our practices change, and revise the “Last updated” date above. When a change is material, we will not simply post it: you will be asked to read and accept the new version the next time you sign in, and until you do, the version you accepted is the one that applies to you.
14. Contact
Questions about this policy or our data practices go to privacy@cublya.com. See also our Terms of Service.