Privacy at Puchi
In effect since 9 August 2026.
The short version
Puchi holds numbers about your life, so it should hold as few of them as it can and be plain about the rest. We do not sell your data, we do not run ads on it, and we do not use it to train AI models. You can export everything or delete everything, from inside the app, without asking us.
Who is responsible
The data controller for both this website and the Puchi app is:
- Name: Ronald Chumaceiro, self-employed (autónomo), registered in Spain.
- Tax number: NIF Y5947826V (EU VAT ESY5947826V)
- Address: Paseo del Pintor Rosales 30, 2B, 28008 Madrid, Spain
- Email: hola@getpuchi.com
Puchi is small enough that it is not required to appoint a data protection officer, and it has not appointed one. Anything to do with your data goes to the address above and reaches a person rather than a queue.
Two different places
This website and the app collect very different things, so they are described separately. If you have only joined the waitlist, only the first list applies to you.
What this website collects
- Your email address, if you join the waitlist.
- Your language, and how you arrived (for example that a link came from TikTok), so we know where to say thanks.
- Product analytics through PostHog, running without cookies: nothing is stored on your device and nothing is tied to your name.
- Audience measurement through Google Analytics, which does set cookies in your browser. See the cookies section below.
What the app collects
- Your email address and password, to sign you in. Passwords are stored hashed, never in readable form.
- Your first name and the colour you picked, so your partner can tell your entries apart.
- Which household you belong to, and who the other person in it is.
- The money information you enter: income, expenses, categories, budgets, savings goals, and the rhythm you chose.
- Bank export files you choose to upload, so Puchi can read the transactions out of them.
- A device token, if you turn notifications on, so a reminder can reach your phone.
- Whether your household has an active subscription, which comes back to us from RevenueCat.
- Product analytics tied to an account identifier, plus crash reports. This is not anonymous, and we would rather say so than pretend otherwise.
- The questions you ask the Referee, and the answers it gives.
What Puchi never collects
- Your bank login details. Puchi has no connection to your bank and never asks for one.
- Your card number. Apple takes the payment and we never see it.
- Your location, your contacts, or your photos.
- Advertising identifiers. Puchi does not track you across other apps or sites, and shows no ads.
Why we are allowed to use it
- To give you the service you signed up for. That covers your account, your household, and everything the app does with the numbers you enter.
- Because you said yes. That covers notifications, the waitlist email, and uploading a bank file.
- Because we have a legitimate interest in keeping Puchi working, secure, and improving. That covers analytics and crash reports.
- Because the law requires it. That covers the tax records that come with selling a subscription.
Who else touches your data
Puchi is run by one person, which means it leans on a small set of providers. Each one is bound by a data processing agreement, and none of them may use your data for their own purposes.
- Supabase: the database, sign-in, and the private storage where an uploaded bank file sits while it is read.
- Anthropic: the AI model that drafts budgets and answers as the Referee. What we send is described on the AI page.
- PostHog: product analytics and crash reports.
- RevenueCat: subscription status.
- Resend: the few emails Puchi sends, such as a reminder that a trial is ending, and the waitlist list itself so those emails can go out.
- Apple: payments, receipts, and delivery of notifications.
- Vercel and Sanity: hosting and content for this website.
- Google: audience measurement on this website only. It has no access to anything in the app.
Data that leaves Europe
Some of those providers are based in the United States. Where that is the case, the transfer runs on the European Commission’s standard contractual clauses, or on the EU-US Data Privacy Framework where the provider is certified under it. We send the minimum each provider needs to do its job.
Where your data comes from
Most of it comes from you, because you typed it in. Some of it comes from your partner: when they log a shared expense, set a goal, or upload a statement, information that concerns both of you enters the household. That is how a shared plan works, and it is worth knowing that the other person can put data into it that relates to you.
A little comes from elsewhere. Apple and RevenueCat tell us whether a subscription is active, and your device tells us it is willing to receive a notification.
No profiling, no automated decisions
Puchi does not score you, does not rank you against anyone else, and makes no decision about you automatically that produces a legal effect or anything similarly significant. The AI drafts suggestions and the two of you decide. Nothing about your money is settled by a machine acting on its own.
If something goes wrong
If your data is exposed in a way that is likely to put your rights at risk, we will report it to the Spanish data protection authority within 72 hours of finding out, and we will tell you directly when the risk to you is high. We would rather send an uncomfortable email than leave you to hear it from somewhere else.
What your partner can see
This deserves its own heading, because it is the question people actually have. Joining a household means sharing a plan: the budget, the categories, the goals, the spending logged into it, and the rhythm you chose. Your partner sees that shared picture.
Puchi is built so that neither of you can itemise or audit the other. It will not show one person a line-by-line breakdown of what the other spent. That is a product decision, and it is not going to change.
How long we keep it
- An uploaded bank file is deleted once Puchi has read the transactions out of it. The transactions stay, the document does not.
- Your account data stays until you delete your account.
- If you delete your account while your partner still uses theirs, your sign-in and personal fields are erased and your name becomes "Former partner". The shared spending history stays with the household.
- If you were the only person left, deleting your account removes the household and everything in it.
- A waitlist email is kept until Puchi launches, or until you ask us to remove it, whichever comes first.
- Records tied to a sale are kept as long as Spanish tax law requires, which is longer than we would otherwise keep anything.
Your rights
Under the GDPR you can ask to see your data, correct it, delete it, take it elsewhere, limit what we do with it, object to some of it, and withdraw any consent you gave.
Two of those are built into the app: Profile has an export that writes out everything we hold, and an account deletion that runs immediately. For anything else, write to hola@getpuchi.com and we will deal with it within 30 days.
If you think we have handled your data poorly, you can complain to the Spanish data protection authority, the Agencia Española de Protección de Datos, at aepd.es. We would rather you told us first, but that route is yours and we are not going to pretend it is not there.
Cookies
The app uses no cookies at all. On this website, PostHog runs in cookieless mode and stores nothing on your device.
Google Analytics is the one thing here that does store something, so it is the one thing we ask about. Until you say yes, the tag is not loaded and no request goes to Google. Saying no is a single click, in the same size button as saying yes.
Your answer is kept on your own device so we do not have to ask again. You can change it whenever you like from the Cookies link at the foot of any page, and changing your mind takes exactly as few clicks as the first answer did.
Age
Puchi is for adults. You need to be 18 or older to have an account, and Puchi is not designed for or directed at children.
How your data is kept safe
- Every request is checked against the household it belongs to, in the database itself, so one household can never read another’s rows.
- Uploaded files sit in private storage scoped to your household, never in a public bucket.
- Everything travels encrypted.
- The AI provider is reached from our backend, never from your phone, so no key or credential ever sits on your device.
Changes
If this policy changes, the date at the top changes with it. If a change actually matters, we will say so clearly rather than leaving you to spot it.