Skip to content

Privacy policy

Last updated: 18 August 2026

Who is the data controller

Navefi is the controller of the personal data collected through this website and the application. For any privacy question, write to [email protected].

What data we collect

Account data: name, email address and a hashed password.

Financial data you connect or upload: accounts, balances, transactions, categories, budgets, investments and any documents you choose to store.

Minimal technical data: IP address, device type and error logs, used for security and diagnosis.

On what legal basis

Performance of the contract, to provide the service you asked for.

Explicit consent, for connecting bank accounts under PSD2, which you may withdraw at any time.

Legitimate interest, for security, fraud prevention and service improvement.

Who we share it with

Only the providers the service needs to run: European Union hosting, the licensed bank aggregation provider, the payment processor and the transactional email service.

We do not sell, rent or share financial data for advertising or resale.

For how long

For as long as the account exists. After account deletion, personal data is erased within 30 days, except what the law requires us to keep, such as billing records.

Your rights

You have the right of access, rectification, erasure, restriction, objection and portability. Access, export and erasure can be exercised directly in the application settings.

You also have the right to lodge a complaint with the Portuguese data protection authority, the CNPD.

Questions? Write to [email protected].