1. Data controller
Ferrari Jose' Carlos Neto, the developer and operator of Patrimonio, is responsible for the data processed through the service. The controller is based in Italy and can be reached at the support address below.
Patrimonio is operated by an individual without a VAT registration. If you need a postal address, contact us by email first.
Contact: supporto@patrimoniototale.com.
2. Data we process
Account data: your email address, credentials encrypted by our authentication provider (email and password, or Google sign-in), a technical identifier, registration date and most recent sign-in.
Financial information you enter: accounts, account type, currency, opening balance, transactions, amounts, dates, categories, descriptions, notes, recurring entries and receipt images. This also covers the tangible assets you record in the vault (category, name, current value, purchase date and optional notes).
Shared accounts: if you generate a sharing code or join someone else's account, we store the link between that account and the participating users, the role (admin or editor) and the code in protected form. Participants see that account's balance and transactions only, not the rest of your net worth.
Patrimonio never connects to your bank. There is no open-banking connection and no access to your real-world accounts.
- Preferences such as language, theme, currency, PIN lock and reminder frequency.
- App lock: only a salted, hashed PIN is stored on our side. Fingerprint or face data never leaves your device and is never sent to us; only a technical credential identifier and the app domain remain on the device.
- A push-notification token, only when you enable notifications.
- Essential technical data such as IP address, device, browser and error logs, used for security and reliability.
- Optional feedback submitted when an account is deleted, stored without a link to your profile.
3. Purposes and legal bases
Your financial information is never used for advertising profiles and is never sold.
- Providing accounts, transactions and analytics: performance of our agreement under Article 6(1)(b) GDPR.
- Sending notifications and reminders when requested: consent under Article 6(1)(a) GDPR.
- Preventing abuse and resolving technical issues: legitimate interests under Article 6(1)(f) GDPR.
- Meeting legal obligations where applicable: Article 6(1)(c) GDPR.
4. Where data is stored
Accounts and content are stored with carefully selected cloud providers supporting our database, authentication, hosting, delivery and push notifications. They act as processors and are contractually required to comply with data-protection law.
Where a provider processes data outside the European Economic Area, transfers rely on European Commission Standard Contractual Clauses or equivalent safeguards.
5. Data stored on your device
To work offline, Patrimonio keeps a local copy in IndexedDB and stores a small number of preferences on your device. This copy only powers offline access and delayed syncing; it is removed when you sign out or clear the app's data.
We do not use advertising or profiling cookies. Only the session, service worker and caches required to run the app remain in use.
6. Retention
- Account content remains available while your profile is active.
- Deleting an account also removes its linked transactions and any sharing links for that account.
- Leaving a shared account ends your access to its data, which stays with the account owner.
- Deleting your profile permanently removes account data, tangible assets, attachments, preferences and notification tokens; technical backups are overwritten within 30 days.
- Security logs are retained for no longer than 12 months.
7. Your rights
Articles 15–22 GDPR give you rights to access, correct, erase, restrict and transfer your data, object to certain processing and withdraw consent.
You can manage accounts and transactions, disable notifications, export data and delete your profile from Settings. We answer other requests within 30 days.
You may also lodge a complaint with the Italian Data Protection Authority or your local supervisory authority.
Contact: supporto@patrimoniototale.com.
8. Security
Traffic is encrypted using HTTPS/TLS. Authentication and per-user access controls isolate each person's data: an account is readable only by its owner and by the people they explicitly invited with a sharing code, and those codes are rate-limited against abuse.
On your device you can enable a PIN lock and, where supported, biometric unlock with fingerprint or face: verification happens on the device and no biometric data is sent to or stored by the app. The same check is required to reveal a hidden balance again.
9. Children
Patrimonio is not intended for anyone under 16. A parent or guardian may contact us to request deletion of an account created by a child.
10. Changes to this notice
We update this notice when features or legal requirements change. The date above always shows the latest revision, and material changes will be announced in the app or by email.