Last updated: September 17, 2026
This policy fulfils our information obligations under GDPR Arts. 12–14. It describes how BeCleva ApS ("BeClevr", "we", "us", or "our") processes personal data. The service brand name is BeClevr. It is not a substitute for individual legal advice. Your statutory rights remain unchanged.
BeCleva ApS is the controller for personal data processed in connection with the BeClevr service. Company: BeCleva ApS (BeClevr), CVR 46636538, address: Vejlevej 86, 6000 Kolding, Danmark.
Privacy contact: support@becleva.com.
We have not appointed a Data Protection Officer (DPO), as we assess it is not required (not a public authority; no large-scale systematic monitoring; no large-scale processing of special-category data). Privacy questions: support@becleva.com.
EU representative (Art. 27): Not applicable — we are established in the EU (Denmark). Supervisory authority: Datatilsynet (Danish Data Protection Agency).
Identity and account: Email, username and any name or profile details you provide; technical identifiers related to sign-in. Sign-in via Supabase Auth (email/password or “Sign in with Google”).
Email from us: Necessary and service emails (e.g. welcome, password reset, and — if enabled — subscription or savings reminders) via Resend.
Budget and finances: Budgets, income and expenses; subscriptions; receipts and images/metadata; savings goals; file imports (e.g. CSV/Excel/JSON).
Payments: Payment and subscription status via Stripe. We do not store full card numbers on our servers.
Bank (when enabled): Account name/IBAN, bank name, balances, transaction history (amount, date, description), merchant names/logos and categories via Subaio ApS (AISP) — see section 3.
Household: when you share budgets or bank accounts, invited members can see the shared data (including postings on shared accounts).
AI: Text/image excerpts needed for the feature you use (typically descriptions and amounts for categorisation; image excerpts for receipt scanning).
Community categorisation: Anonymised merchant tokens, short text samples and category votes to improve categorisation for all users — without exposing your email or account number in the consensus layer.
Anonymous spending averages: we compute a per-category median across users (at least 8, DKK only, no name, email or user id) so you can see what others typically spend. The client only receives the aggregates.
Technical: With consent, error/performance data (Sentry) and web analytics (Vercel Analytics/Speed Insights). Necessary local storage/cookies for sign-in and preferences. On the native app: optional push tokens (Firebase Cloud Messaging) and local app lock (biometrics/PIN stay on the device). Optional two-factor authentication (TOTP) via Supabase Auth.
We do not intentionally process special categories of personal data (Art. 9). We do not make solely automated decisions with legal or similarly significant effects (Art. 22).
Directly from you: When you create an account, enter budget data, upload files/receipts, vote on categories or contact support.
From you via third parties you choose: — Google: if you sign in with Google. — Subaio ApS (AISP, CVR 37766585, supervised by the Danish FSA): if you connect a bank. Explicit PSD2 consent is given to Subaio; you typically authorise via MitID or the bank’s secure login. We are not an AISP. We receive forwarded account/transaction data (including merchant and categories when Subaio sends them), have read-only access, cannot move money and do not store bank login/MitID. The connection typically renews about every 180 days. Subaio’s PSD2 privacy policy: https://subaio.com/psd2-privacy-policy/ — Stripe: payment-related information for Premium.
Household members you invite get access to the budgets and accounts you share.
Automatically generated: Technical log/device data as needed for operations and (with consent) error analysis.
Account, budget, import, receipts, savings, in-app subscriptions and Premium delivery: performance of contract (Art. 6(1)(b)).
Bank data after you connect: contract (b) to deliver the bank-connected service; PSD2 consent to Subaio is separate.
Household: contract (b) for data you choose to share with invited members.
AI features you actively use: contract (b).
Community categorisation (anonymised tokens/votes): contract (b) as part of categorisation and/or legitimate interests (f) in improving accurate categories — balanced because email/IBAN are not shared in the consensus layer.
Anonymous spending averages (category median without identifiers, at least 8 users): contract (b) as part of the overview and/or legitimate interests (f) in providing a shared comparison — balanced because raw postings and identity are never published.
Optional cookies/analytics/error reporting (Sentry, Vercel Analytics) and marketing (YouTube embeds): consent (a) via the cookie banner; withdrawable.
Optional reminder emails: consent or contract depending on the setting; you can turn them off in the app.
Security, abuse prevention, operations and rate limiting: legitimate interests (f) in protecting the service and users. You may object — see section 8.
Accounting and mandatory retention of our own sales records (not your bank transactions as an archive): legal obligation (c), typically the Danish Bookkeeping Act.
To create an account and enter into the service agreement you must provide at least a valid email (and password or social login). Without that we cannot provide the account.
Budget, import, receipt and bank data are voluntary in that you choose what to enter or connect — but without them the corresponding features cannot be used fully.
Premium payment requires the information Stripe needs for payment. Cookie consent for statistics and marketing is optional; declining does not affect core sign-in.
We do not sell your personal data. We share it with processors who process it on our instructions under DPAs where required:
— Supabase: database, Auth, Edge Functions, storage. — Stripe: payments. — Resend: email. — Google: only for “Sign in with Google” (independent controller for its login flow). — OpenAI: AI input when you use AI features. — Sentry: errors/performance (only with cookie consent). — Vercel: hosting; Analytics/Speed Insights only with consent. — Trigger.dev: background jobs. — Upstash: cache/rate limiting. — Subaio ApS: AISP when you connect a bank (PSD2 consent to them; independent controller for that retrieval). See https://subaio.com/psd2-privacy-policy/ — Google (Firebase Cloud Messaging): push notifications on native devices while you are signed in (device token). — Usercentrics (Cookiebot): cookie consent, consent log and cookie declaration (DPA is concluded in Cookiebot Manager). — Google/YouTube: independent controller for video embeds, only after marketing consent.
Household members you invite are not processors — they receive the access you grant to shared budgets and accounts.
Privacy policies: Supabase (https://supabase.com/privacy), Stripe (https://stripe.com/privacy), Resend (https://resend.com/legal/privacy-notice), Google (https://policies.google.com/privacy), OpenAI (https://openai.com/policies/privacy-policy), Sentry (https://sentry.io/privacy/), Vercel (https://vercel.com/legal/privacy-policy), Trigger.dev (https://trigger.dev/legal/privacy), Upstash (https://upstash.com/trust/privacy), Subaio (https://subaio.com/psd2-privacy-policy/), Cookiebot (https://www.cookiebot.com/en/privacy-policy/), Firebase (https://firebase.google.com/support/privacy).
Transfers to third countries (e.g. USA for OpenAI, Stripe, Sentry, Vercel): we rely on the EU Commission’s standard contractual clauses (SCCs) or other approved mechanisms under GDPR Chapter V. Contact us for more information on the safeguards.
Account and app data (budget, receipts, import, bank data in our systems): for as long as the account is active. After account deletion we aim to delete from active systems within 30 days; temporary backups may briefly retain residues.
Supabase Auth login: deleted as part of the account-deletion flow. Contact support@becleva.com if you want confirmation.
Stripe/payment and accounting records for us or Stripe: as long as the law requires (typically up to 5 years under the Bookkeeping Act) — not your bank transactions as a budget archive.
Sentry error data: typically up to about 90 days, only with consent.
Vercel Analytics: per provider standard (typically 30–90 days), only with consent.
Trigger.dev/Upstash logs/cache: short-lived (minutes to about 30 days for logs).
Push tokens (FCM): while the device is registered; deleted for this device on sign-out and on account deletion.
Community consensus (token/sample/category): retained while relevant for categorisation; vote linkage follows your account and is deleted/anonymised on account deletion to the extent the system supports.
AI input at OpenAI: processed to deliver the response; we aim for no-retention/API settings where possible — see also OpenAI’s terms.
Under the GDPR you have rights including: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21) — including objection to processing based on legitimate interests (f).
Where processing is based on consent, you may withdraw consent at any time (cookies via cookie settings; optional emails in the app; PSD2 bank access via app/Subaio/your bank). Withdrawal does not affect the lawfulness of processing before withdrawal.
You can export data and delete your account in settings, or contact support@becleva.com. We respond without undue delay and within 1 month (extendable by up to 2 months for complex cases — we will inform you).
You may lodge a complaint with Datatilsynet: Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark. Phone +45 33 19 32 00. Email dt@datatilsynet.dk. Web: www.datatilsynet.dk. We encourage you to contact us first so we can try to resolve the matter.
We use appropriate technical and organisational measures: TLS in transit, access control, Row Level Security (RLS) on user data, service-role keys only in serverless/backend — never in the client. No online service is 100% risk-free; we work continuously to reduce risk. In the event of a serious breach we notify Datatilsynet and affected users when the law requires.
Necessary (always on): sign-in session, language, theme, currency, selected budget, cookie choice and security. Strictly necessary under the cookie rules — no consent required. Cookiebot’s “preferences” category is not used for anything else; language and theme are already necessary.
Statistics (optional): Sentry (errors and performance) and Vercel Analytics/Speed Insights. Loaded only if you turn Statistics on.
Marketing (optional): YouTube videos on the landing page and in the app (youtube-nocookie.com). Google/YouTube is an independent controller for its content. Videos load only after consent.
Consent is given in Cookiebot’s banner on the web (Allow all, necessary only, or customised choices). Cookiebot (Usercentrics) logs consent and scans cookies on becleva.com. You can change or withdraw consent at any time via “Cookie settings” in the footer or Cookiebot’s icon. Withdrawal applies going forward.
The cookie declaration below lists name, purpose, duration and provider from Cookiebot’s scan. The data processing agreement (DPA) with Usercentrics is concluded in Cookiebot Manager. Native app: a matching consent banner without Cookiebot; the choice is stored locally on the device.
Under our terms of service you must generally be at least 18 to create an account and enter a Premium agreement. The service is not directed at children. We do not knowingly collect personal data from persons under 15 without parental/guardian consent under applicable rules. Contact us if you believe we have processed a child’s data without a lawful basis — we will delete it.
We may update this policy. For material changes we endeavour to give reasonable notice (typically at least 14 days) by email and/or in the app, unless faster effect is required by law or security. The “Last updated” date changes when the policy is revised. The current version is always on this page.
Have questions about our privacy policy? Email support@becleva.com.
We use cookies to make the site work. You can accept all or only the necessary ones.