Website application communications and automated reports
1 Controller and scope
Alexander Many Ndengue, trading as mynubi, is the controller for the processing described in this Policy. Address: Baierbrunner Str. 89, 81379 Munich, Germany. Email for privacy enquiries and requests: support@mynubi.app. Telephone: +49 176 38747782. This Policy covers mynubi.app, the public website hosted with Framer; plan.mynubi.app, the application built with Bubble; and related account, billing, reporting, support, email and push notification processing. It describes processing under the EU General Data Protection Regulation. Additional mandatory rights may apply where you live.
2 Information we process
Account information includes your email address, Bubble account identifier, authentication and verification status, locale, time zone, account dates, subscription status and preferences. If you choose Google sign in, the information described in section 6 also applies. Portfolio information includes the holdings, quantities or values, asset classes, currencies, totals, target allocations, tolerance ranges, selected examples, market state rules, contributions, DCA schedules, decision records and related dates, amounts, directions, sources, destinations, notes and outcomes that you enter or generate through your use of the service. Derived information includes percentage allocations, portfolio history, Plan Health, range breaches, rule comparisons, target based scenarios, activity timelines, reports and retrospective behavioural descriptions. These remain personal data when linked to your account. Billing information received from Stripe includes the references and status needed to provide Premium, such as Stripe customer, subscription and price identifiers, billing interval, current period end, cancellation status, payment and invoice status and limited webhook event records. Standard Stripe Checkout processes payment method information. mynubi does not store full card numbers or card security codes in its portfolio database. Communication information includes support requests and attachments, recipient email addresses, notification preferences, message and delivery identifiers, delivery or failure status and timestamps. A notification may contain the asset class, allocation percentage, tolerance threshold, DCA schedule or report information needed for the requested message. Technical information can include IP address, browser, operating system, device and push subscription identifiers, session information, requested page or endpoint, referrer, timestamps, security events and diagnostic logs. Optional Google Analytics information is described in section 11.
We do not request wallet addresses, seed phrases, exchange credentials, bank or brokerage connections or transaction imports for the current service. Do not enter passwords, payment credentials or unnecessary sensitive information in notes or support messages.
3 Purposes and legal bases
We process information objectively necessary to create and authenticate an account; store your portfolio and plan; provide checks, contribution records, notifications and Premium features; administer subscriptions; and respond to pre contract requests under Article 6 paragraph 1 letter b GDPR. We process invoices, accounting records and information needed for tax compliance under Article 6 paragraph 1 letter c GDPR. We process proportionate security, fraud prevention, troubleshooting and operational logs under Article 6 paragraph 1 letter f GDPR based on our interests in protecting accounts and infrastructure and maintaining reliable service. We use the same basis where necessary to establish, exercise or defend legal claims, subject to your rights. Newsletters, promotional messages and Google Analytics depend on consent under Article 6 paragraph 1 letter a GDPR and applicable device storage or access rules. Consent is separate from registration and the core service and can be withdrawn at any time. We retain limited consent and suppression evidence where required to demonstrate or respect your choice. Requested service notifications are processed to provide the relevant feature. Push delivery additionally depends on your device permission and in app preferences. We do not use legitimate interests as a substitute where consent is required.
4 Bubble Framer and Render
Bubble Group Inc provides the application platform, account authentication, database and related infrastructure. It processes account, portfolio, activity, report, billing reference and technical information to operate plan.mynubi.app. Bubble and its subprocessors may process information in the United States and other countries under the applicable contractual safeguards. Framer BV provides hosting and website functionality for mynubi.app. It processes technical visit information and any information submitted through website functions that we enable. Optional Google Analytics is controlled as described below. Render Services Inc hosts the Python rebalancing and market engines in the Frankfurt region. For a rebalancing calculation, Bubble sends the portfolio reference, asset class values, currency, targets, ranges, contribution context and user selected calculation rules required for the calculation. The result is returned to Bubble. Render may process operational and diagnostic information outside the selected compute region through its account, support or logging systems under its applicable terms.
5 Market and price data providers
The Market Engine obtains general Bitcoin market and on chain indicators from BGeometrics and sends calculated global market classifications to Bubble. Market Regime and Bitcoin Long Term
Trend are the same for all users. The intended data flow does not send a user’s portfolio or identity to BGeometrics. We also obtain general price and exchange rate information through gold-api.com, CoinGecko, marketstack and exchangerate.host. These integrations are intended to run on the backend and request market data rather than customer portfolio information. The providers receive the technical connection information generated by the request.
6 Google sign in
If you choose Google sign in, Google authenticates your account and provides Bubble with the information required to identify and connect your Google account. This includes your Google account identifier and email address and may include basic profile information such as your first name, last name and profile picture as part of Google’s standard profile permission. mynubi uses and stores your email address for account creation, authentication and account communication. The Google account identifier is processed by Bubble to maintain the authentication connection. mynubi does not store your Google first name, last name or profile picture as separate user profile fields. mynubi does not receive your Google password or access your Gmail messages through Google sign in. Disconnecting mynubi in your Google account settings does not itself delete your mynubi account or cancel an active subscription. Google sign in is separate from Google Analytics. Analytics is governed by the consent choices described in section 11. Google Ireland Limited is the principal Google provider for users in the EEA, with relevant affiliates and subprocessors involved under Google’s terms.
7 Stripe payments
Stripe receives contact and billing details, payment method information, the selected subscription, amount, currency and technical information required for checkout, invoicing, subscription administration, refunds, fraud prevention and payment security. Stripe returns subscription and payment status to mynubi. For a German Stripe account, the applicable contracting entity is Stripe Payments Europe Limited and, where the relevant service terms provide, Stripe Technology Europe Limited. Stripe affiliates, financial institutions and payment partners may also process transaction information. Stripe acts as a processor for certain activities and as an independent controller for its own legal, regulatory, security and fraud prevention purposes. Its own privacy information explains its roles and retention.
8 Email support and push notifications
Postmark, provided by AC PM LLC within the ActiveCampaign group, sends account and service emails and, if you opt in, newsletters and promotional offers. It receives the recipient address, message content and delivery metadata. We have disabled individual open tracking and tracked link rewriting. Under Postmark’s default retention setting, message content and related activity and metadata are retained for 45 days before expiry and deletion processing. Aggregated statistics and
suppression information may be retained separately to operate the service and prevent unwanted or abusive email. Newsletter consent is voluntary and separate from account registration. You can unsubscribe through the link in a marketing email or by contacting us. We keep the minimum suppression record needed to respect the choice. Essential account, security, payment and legal messages are not newsletters. Proton AG in Switzerland hosts support@mynubi.app. Support correspondence may contain contact details, account references and information you choose to send. Ordinary email to our Proton mailbox is not necessarily end to end encrypted from your email provider. OneSignal Inc provides push delivery. We send your Bubble unique user ID as an external identifier. Depending on the SDK, device and permissions, OneSignal also processes a push token or subscription ID, browser and device information, IP address and delivery or interaction events. Notification content passes through the relevant push infrastructure. You can disable push in the app or device settings. Account deletion separately removes the mynubi association and initiates deletion of related notification identifiers where available.
9 Automated Premium reports and profiling
Premium customers receive an automatically generated quarterly behaviour review. The review analyses relevant historical portfolio activity to describe allocation changes, consistency with the targets and ranges entered by the user, contribution patterns, recorded decision patterns and other retrospective developments during the reporting period. Before information is submitted to the AI provider, our own reporting backend calculates and aggregates the relevant metrics. The information sent for language generation is limited to the report period; asset class allocations; user entered targets and tolerance ranges; aggregated portfolio range statistics; contribution completion and timing statistics; aggregated decision and rebalancing activity; relevant general market classifications; and calculated consistency metrics. Bitcoin and Ethereum may be included as asset classes. Other investments are normally represented only by their broader asset class. Where possible, amounts are expressed as portfolio percentages or aggregated values rather than complete holding level records. We do not submit your name, email address, Google account information, Bubble user ID, OneSignal ID, Stripe identifiers, payment information, IP address, device information, support communications, passwords, credentials or unrestricted free text notes to the AI provider. We do not submit the names of individual shares, ETFs, funds or other specific holdings where the broader asset class is sufficient. A randomly generated report job identifier may be used to process and return the report. It is not intended to allow OpenAI to identify you directly, but the submitted information remains personal data where mynubi can link it back to your account.
OpenAI API
We use the commercial OpenAI API to generate the written report from the aggregated information described above. We do not use personal ChatGPT consumer accounts for this processing. OpenAI Ireland Limited and authorised OpenAI subprocessors process submitted information on our behalf under the applicable business terms and Data Processing Addendum.
The integration uses a stateless API request with application storage disabled. We do not use OpenAI conversations, assistants, file storage, vector stores or similar persistent OpenAI features for the quarterly report. OpenAI states that data submitted through its business and API services is not used to train its models unless the customer expressly opts in. mynubi does not opt report information into model training or model improvement. Under OpenAI’s standard API data controls, report inputs and generated outputs may be retained in abuse monitoring logs for up to 30 days. Disabling application storage does not eliminate this limited abuse monitoring retention. We therefore do not describe the OpenAI processing as zero retention. If separately approved Zero Data Retention controls are activated for the mynubi API project, this Policy will be updated to reflect the verified configuration. OpenAI and its subprocessors may process information outside the EEA, including in the United States. International transfers are governed by the OpenAI Data Processing Addendum and applicable safeguards, including the European Commission’s Standard Contractual Clauses where required.
Storage by mynubi
After generation, the completed quarterly review is stored with your account in Bubble. We may also store the supporting aggregated metrics, report period, creation date, selected model identifier, prompt and schema version, processing status and a cryptographic hash of the report input. This information lets us display the report, investigate errors and document how it was generated. We do not separately retain the complete raw API request or an additional copy of the unprocessed API response after the report has been successfully returned and stored. The reporting backend is designed not to include report contents or API request bodies in routine logs. Content free operational and error metadata may be retained for security and troubleshooting. Reports and associated metadata are deleted with the account, except for limited information required by law or necessary to establish, exercise or defend legal claims.
Profiling limitations and legal basis
The quarterly review is profiling within Article 4 paragraph 4 GDPR because software automatically evaluates aspects of recorded behaviour. It is limited to retrospective description of activity within mynubi. The review does not determine risk tolerance, financial capacity, investment experience or whether an investment or allocation is suitable. It does not recommend future trades, create targets, select investments, predict individual financial outcomes, determine prices or subscription eligibility or control access to financial products. It does not make a decision producing legal or similarly significant effects within Article 22 GDPR. Language model output can contain an inaccurate inference or unsupported statement and may be generated without prior human review. You remain responsible for checking it against your records. You can ask us to correct inaccurate underlying information and to review, correct or delete inaccurate personal information in a report.
Processing objectively necessary to provide the defined quarterly reporting feature included in Premium relies on Article 6 paragraph 1 letter b GDPR. This does not permit unrelated model development, advertising profiles, general purpose behavioural analysis or transfer of information merely because it exists in the mynubi database.
10 Essential storage
Essential cookies and similar storage support functions requested by you, including sign in, session security, privacy choices and payment functionality. Where storage or access on a device is strictly necessary for that purpose, it is used under the applicable exception in section 25 paragraph 2 TDDDG. Subsequent personal data processing requires the GDPR basis described in this Policy. The live Cookie Settings panel identifies the actual essential storage technologies, provider, purpose, name and duration used on each domain. Blocking essential storage can prevent requested functions from working.
Cookie and similar-storage directory
Google Tag Manager manages the configured Analytics tags but does not set a separate GTM cookie in this configuration. If you choose Stripe Checkout, Stripe may use its own strictly necessary cookies and similar technologies on Stripe-hosted pages to provide payment, security and fraud-prevention functions. Those provider-controlled technologies are described in Stripe’s own privacy and cookie information.
11 Google Analytics
With your consent, we use Google Analytics 4 through Google Tag Manager to measure use of public pages and the completion of registration and Premium subscription purchases. Google Tag Manager deploys the configured tag and is not a separate permission for data collection. We use Basic Consent Mode. Google Analytics tags are blocked until you grant analytics consent. If you refuse or have not yet made a choice, the tags do not load and no consent state, cookieless measurement ping or other analytics event is sent to Google. Direct visits to either domain are covered by the consent mechanism before Analytics can run. The permitted events are public page views, completed registration and completed Premium subscription purchase. A purchase event may contain the price, currency, billing interval, generic product name and a random deduplication identifier. We do not use Analytics User ID, user provided data collection, enhanced conversions, Google Signals, advertising personalisation, automatic form field collection or automatic extraction of login or account data. Analytics can process the event name, generic page URL and referrer, timestamp, browser and device information, approximate location derived from the IP address, consented cookie identifier and campaign information. For users in the EU, Switzerland and the United Kingdom, Google states that it discards IP addresses before logging and uses them only to derive coarse location information. Google and its authorised subprocessors may process information internationally under the applicable Google data protection terms. We do not send raw or hashed email addresses, names, telephone numbers, postal addresses, Bubble or OneSignal identifiers, Stripe customer or subscription identifiers, holdings, portfolio values, targets, ranges, contributions, DCA records, decisions, rebalancing outputs, market rules, reports, notes or other portfolio content to Google Analytics. URLs, page titles, referrers, data layer values and event parameters must not contain this information. Analytics tags are not used on dashboard, portfolio, holdings, Decision Check, rebalancing, report or account settings screens. User level and event level data controlled by the Google Analytics property retention setting is retained for fourteen months, with reset on new activity disabled. Google explains that standard
aggregated reports are not affected by this setting and may remain available longer. We retain our own limited consent record for as long as needed to demonstrate and respect the choice. You can reject Analytics and still use the service. You can change or withdraw consent at any time through Cookie Settings on both domains. Withdrawal stops future consent based processing but does not affect prior lawful processing. The live Cookie Settings panel contains the actual Analytics cookie and storage inventory and durations for the deployed configuration.
12 Recipients and international processing
The controller accesses personal data where needed for administration, support, security and legal obligations. Service providers and their authorised personnel or subprocessors access information within their contracted roles. We may disclose necessary information to professional advisers, courts or authorities where legally required or justified for claims. They are not given routine access to the entire portfolio database. The controller may administer mynubi while temporarily in Thailand. This is access by the same controller rather than disclosure to a separate Thai provider. Remote access is protected through appropriate account and device security. It does not mean that mynubi data is hosted in Thailand. Where a provider processes information outside the EEA, we use an applicable adequacy decision or appropriate safeguards such as the European Commission’s Standard Contractual Clauses and supplementary measures where required. An EU US Data Privacy Framework basis is used only where the relevant recipient and processing are covered by a current certification. You may request information about applicable safeguards from support@mynubi.app.
13 Retention and deletion
We retain personal data only for the purpose and period described or where a lawful exception applies. Active account, portfolio, plan, activity and report information is kept while needed to provide the account and selected history. Cancelling Premium leaves the Free account and its history in place unless you delete the account or request erasure. When you permanently delete the account, we stop new reports and notifications, cancel the subscription and future collection and remove associated data from active systems without undue delay, except where retention is required by law or justified for a claim. The process covers the User record, portfolios, holdings, decisions, contributions, DCA schedules, snapshots, executions, timelines, reports, notification records, files and provider identifiers. Scheduled workflows are stopped and later billing webhooks must not recreate the deleted account. Invoices and accounting vouchers are generally retained for eight years, qualifying business correspondence for six years and books and annual accounts for ten years under applicable German rules. Certain VAT records can require ten years. Periods generally start at the end of the relevant calendar year, and an audit, dispute or legal hold can require longer retention of affected records. Our routine technical logs are retained for up to 30 days, notification delivery logs for up to 90 days and ordinary support correspondence for up to twelve months after closure, unless a shorter period is sufficient or a longer period is necessary for security, a legal obligation or a specific claim.
Consent and suppression records are limited to what is required to demonstrate or respect the choice. Postmark and OpenAI retention are described above. Restricted backup copies may remain until the provider’s documented rotation or overwrite. They are not used to continue the deleted service, and deletion is reapplied if a backup is restored. Providers acting as independent controllers, including Stripe for its own legal processing, determine their lawful retention for those purposes.
14 Your rights
Subject to applicable conditions, you can request access and a copy, correction, erasure, restriction and portability in a structured commonly used machine readable format. Portability applies to qualifying data you provided or that was observed from your use where processed automatically on consent or contract; it does not necessarily cover every generated inference. Access rights can still apply to personal data inferences. Where processing relies on legitimate interests, you may object based on your situation. We stop the processing unless applicable law permits continuation, for example because of compelling grounds or legal claims. You may object to direct marketing at any time, including related profiling. You may withdraw consent at any time without affecting prior lawful processing. Send requests to support@mynubi.app. We may request proportionate information to verify identity and do not routinely require an identity document. We respond without undue delay and normally within one month. A lawful extension of up to two further months may apply for complexity or volume, in which case we explain it within the first month. Requests are normally free subject to statutory exceptions. You may complain to a supervisory authority, particularly where you live, work or believe an infringement occurred. The authority for our establishment is the Bayerisches Landesamt fuer Datenschutzaufsicht, Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.
15 Required information security and age
An account requires the information needed for authentication. Premium requires billing information, and personalised functions require the portfolio and plan inputs on which they operate. Optional newsletter and Analytics consent is not required for registration. We use technical and organisational measures appropriate to the risks, including access restrictions and protected provider communications. No internet service is absolutely secure. Protect your device, mailbox and sign in account and do not enter credentials in notes or messages. mynubi is intended only for people aged 18 or older. We do not knowingly offer accounts to children. Contact us if you believe a child has provided personal data.
16 Other jurisdictions and changes
Privacy laws outside the EEA may grant additional rights. Before actively targeting a jurisdiction that requires additional notices or opt out mechanisms, we will implement the applicable supplement and controls. This Policy does not waive mandatory local rights.
We update this Policy when processing changes or law requires it. We identify the effective date, draw material changes to your attention where required and obtain new consent where a new consent based purpose is introduced.
17 Provider information
Further information is available from the providers: Bubble privacy and DPA at bubble.io; Framer privacy and DPA at framer.com; Render privacy and DPA at render.com; Stripe privacy and DPA at stripe.com; Google privacy and data processing terms at policies.google.com and business.safety.google; Postmark DPA at postmarkapp.com; Proton privacy at proton.me; OneSignal privacy at onesignal.com; and the OpenAI Data Processing Addendum, API data controls and subprocessor list at openai.com.