Privacy Policy
Last Updated: November 1, 2025
Table of Contents
Introduction
Welcome to Notwerth. We are committed to protecting your privacy and ensuring the security of your personal and financial information. This Privacy Policy explains how we collect, use, store, and protect your data when you use our personal finance planning platform.
Notwerth is a free personal finance tool that helps you track your net worth, plan for retirement, manage budgets, and achieve your financial goals. We take your privacy seriously and will never sell your personal information to third parties.
What Data Do We Collect?
Personal Information
When you create an account with Notwerth, we collect:
- Email address (used as your username)
- Password (stored securely using industry-standard encryption)
- Profile information (name, birth date, country, retirement age)
- Financial preferences (marginal tax rate, growth rate assumptions, life expectancy)
Financial Information
To provide our services, we collect and store:
- Bank account information (if you choose to connect via Plaid)
- Asset details (investment accounts, retirement accounts, real estate, vehicles, etc.)
- Liability information (mortgages, loans, credit cards, etc.)
- Budget and expense tracking data
- Transaction history (if connected via Plaid)
- Net worth calculations and historical data
Authentication Data
We support multiple authentication methods:
- Email/password credentials
- Passkey (FIDO2/WebAuthn) authentication data
- Social authentication tokens (Google, GitHub) if you choose to sign in via these services
Usage Information
We automatically collect:
- Browser type and version
- Device information
- IP address
- Pages visited and features used
- Session duration and interaction patterns
How We Use Your Data
Notwerth uses your data exclusively to provide and improve our services:
- Account Management: To create and maintain your account, authenticate your identity, and provide customer support
- Financial Planning: To calculate your net worth, generate retirement projections, track your budget, and provide personalized financial insights
- Bank Integration: To securely connect to your financial institutions via Plaid and automatically import transactions and account balances
- Service Improvement: To analyze usage patterns, identify bugs, and develop new features
- Security: To detect and prevent fraud, unauthorized access, and other security threats
- Communication: To send important service updates, security alerts, and respond to your inquiries (we do not send marketing emails)
We do not:
- Sell your personal information to third parties
- Share your financial data with advertisers
- Use your data for marketing purposes without explicit consent
- Share your information except as described in this policy
How We Store Your Data
Notwerth takes data security seriously:
- Encryption: All data is encrypted in transit using SSL/TLS and at rest using industry-standard encryption
- Secure Storage: Data is stored on secure servers with restricted access
- Password Security: Passwords are hashed using bcrypt and never stored in plain text
- Access Controls: Only authorized personnel have access to systems, following the principle of least privilege
- Regular Backups: Data is regularly backed up to prevent loss
Data Retention: We retain your personal data for as long as your account is active. If you delete your account, we will remove your personal information within 30 days, though we may retain anonymized analytics data and data required for legal compliance.
Third-Party Services
Plaid
If you choose to connect your bank accounts, we use Plaid, a secure third-party service, to access your financial data. Plaid uses bank-level security and encryption. Your bank credentials are never shared with Notwerth – they are only used by Plaid to establish a secure connection. Please review Plaid's Privacy Policy for more information.
Social Authentication
If you sign in using Google or GitHub, we receive limited information from these services (typically your name and email address). We do not have access to your Google or GitHub passwords. Please review the privacy policies of these services:
Your Data Protection Rights
You have the following rights regarding your personal data:
Right to Access: You can request a copy of all personal data we hold about you.
Right to Rectification: You can update or correct your personal information at any time through your account settings.
Right to Erasure: You can request deletion of your account and all associated data. Go to your account settings and select "Delete Account" or contact us directly.
Right to Data Portability: You can export your data in a standard format (CSV/JSON) through the account settings.
Right to Restrict Processing: You can request that we limit how we process your data.
Right to Object: You can object to certain types of data processing.
To exercise any of these rights, please contact us at the email address provided below. We will respond to your request within 30 days.
Cookies
Notwerth uses cookies to provide and improve our services:
Essential Cookies
These are necessary for the website to function:
- Session Cookie: Keeps you logged in as you navigate the site
- CSRF Token: Protects against cross-site request forgery attacks
- Authentication Cookies: Remember your login state and preferences
Functional Cookies
- Remember your preferences and settings
- Store temporary data during multi-step processes (like registration)
Analytics Cookies
We use basic analytics to understand how our service is used and identify areas for improvement. This data is anonymized and aggregated.
Managing Cookies
You can control and delete cookies through your browser settings. However, disabling essential cookies may prevent you from using certain features of Notwerth. Visit allaboutcookies.org for information on managing cookies in different browsers.
Data Security
We implement multiple layers of security to protect your data:
- SSL/TLS Encryption: All data transmitted between your browser and our servers is encrypted
- Secure Authentication: Support for passkeys (FIDO2/WebAuthn), a phishing-resistant authentication method
- Regular Security Audits: We regularly review our security practices and update them as needed
- Secure Development: We follow secure coding practices and conduct security testing
- Incident Response: We have procedures in place to respond to any security incidents
While we strive to protect your data, no method of transmission over the internet is 100% secure. We encourage you to use strong passwords and enable passkey authentication for additional security.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons. We will notify you of any material changes by:
- Posting the updated policy on this page with a new "Last Updated" date
- Sending an email notification to your registered email address for significant changes
- Displaying a notice on the website
We encourage you to review this Privacy Policy periodically. Your continued use of Notwerth after any changes constitutes your acceptance of the updated policy.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please contact us:
Complaints
If you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection authority.
This Privacy Policy is effective as of November 1, 2025. By using Notwerth, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.