Privacy Policy
Last updated: January 2025
Our Commitment to Your Privacy
At Fogru, we believe your financial data is deeply personal. We collect only what we need to provide our service, we never sell your data, and we give you full control over your information. This policy explains exactly what we collect, why, and how we protect it.
Minimal Collection
We only collect data essential to providing the service
Secure by Design
Bank-grade encryption protects all your data
You're in Control
Export or delete your data at any time
Information We Collect
We collect information necessary to provide our group fund management service. This includes information you provide directly and information we receive from connected services.
Types of Data Collected
- โขAccount Information: Name, email address, and authentication data when you create an account
- โขFinancial Data: Transaction history, account balances, and payment information from connected bank accounts
- โขUsage Data: How you interact with Fogru, including features used and pages visited
How We Use Your Information
We use your information to provide and improve our service, process transactions, communicate with you about your account, ensure security, and comply with legal obligations. We do not use your data for advertising or sell it to third parties.
Bank Account Connections
When you connect a bank account, we use PSD2-compliant third-party providers (licensed Account Information Service Providers). We never see or store your banking credentials. We only receive read-only access to transaction history and balances that you explicitly authorize.
Information Sharing
We share your information only with: group members you've explicitly invited, service providers necessary to operate Fogru (hosting, analytics), and legal authorities when required by law. We never sell your personal data to advertisers or data brokers.
Data Storage and Retention
Your data is stored on secure servers within the European Union. We retain your information for as long as your account is active. When you delete your account, we remove your personal data within 30 days, except where retention is required by law.
Security Measures
We implement industry-standard security measures including encryption in transit and at rest, regular security audits, access controls, and secure development practices. While no system is perfectly secure, we continuously work to protect your data.
Your Rights
Under GDPR and applicable privacy laws, you have specific rights regarding your personal data. You can exercise these rights at any time by contacting us or through your account settings.
Right to Access
Request a copy of all data we hold about you
Right to Rectification
Correct any inaccurate or incomplete data
Right to Erasure
Request deletion of your personal data
Right to Portability
Export your data in a standard format
Right to Object
Object to certain types of data processing
Right to Withdraw Consent
Withdraw consent for optional data processing
Cookies and Tracking
We use essential cookies to keep you logged in and remember your preferences. We use minimal analytics to understand how the service is used and improve it. We do not use advertising cookies or track you across other websites.
Children's Privacy
Fogru is not intended for children under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.
International Transfers
Your data is primarily stored within the European Union. If we transfer data outside the EU, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via email or through a prominent notice in the application. Your continued use after changes constitutes acceptance.
Contact Us
For privacy-related questions, concerns, or to exercise your rights, please contact our privacy team. We aim to respond within 30 days as required by GDPR.