Privacy Policy
Wacha helps you manually record personal finances. It does not connect to banks, custody assets, transfer money, or execute trades.
Local-only use
You can use Wacha without an account. In local-only mode, finance records stay in the app’s local database unless you export a backup or enable cloud sync.
Optional cloud sync
If you opt in, Wacha sends your Books, accounts, categories, transactions, transfer entries, recurring rules, holdings, holding lots, base currency, and related notes to our Supabase-hosted database. This makes the data available across your devices and to integrations you explicitly authorize. Cloud data is encrypted in transit and by the hosting provider at rest, but it is server-readable and is not end-to-end encrypted.
Connected assistants
If you authorize the Wacha integration for ChatGPT or Codex, the assistant can request narrowly scoped information through Wacha’s MCP service. Aggregate tools do not return individual transaction notes. Transaction-level and recurring-expense tools can transmit relevant notes, and write tools can save an optional note that you requested. Notes are treated as untrusted descriptive data, never as instructions to the service.
What we do not collect
Wacha’s integration does not ask for bank passwords, card numbers, government identification, brokerage credentials, or crypto wallet secrets. Do not put sensitive authentication secrets into a transaction note.
Service and security data
We process authentication identifiers and operational events needed to synchronize safely. The MCP service logs a request ID, tool name, outcome, latency, and a one-way hashed user identifier. It does not log access tokens, finance payloads, notes, quantities, balances, or tool results.
Retention and deletion
Synchronization events, recovery history, and deletion tombstones are retained for up to 30 days. Active cloud records remain until you delete them or delete your account. You can delete your cloud account in Wacha settings; deletion removes the authentication account and its active cloud finance data. See account deletion.
Processors and disclosures
Supabase provides authentication and database hosting. Cloudflare provides the public site and stateless MCP and market-price Workers. OpenAI processes data returned to ChatGPT or Codex under your relationship with OpenAI after you authorize that connection. We do not sell personal finance data.
Your choices
You can remain local-only, disconnect cloud sync, omit transaction notes from supported requests, revoke a connected application, export a backup, remove the local cloud copy, or delete your cloud account.
Contact
Privacy questions: support@octaman.xyz.