Privacy Policy

Last updated: September 2026

Only the German version is authoritative. This translation is provided for ease of understanding. If it differs from the German version, the German version prevails.

1. Controller

Alexander Seibold
Sole proprietorship

Lohningerweg 44

8240 Thayngen

Switzerland

E-mail: info@batzi.ch

2. Principles

We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP). We collect only the data needed to run the app and do not pass it on to third parties unless described in this policy.

What this policy covers: Batzi is aimed at households in Switzerland. The provider has neither a registered office nor a branch in the EU, bills exclusively in Swiss francs and does not advertise the service in EU member states. The Swiss FADP therefore applies, and we have not appointed an EU representative under Art. 27 GDPR. If you use Batzi from within the EU, we will handle your requests for access, correction, deletion, data portability and objection on equal terms with the rights set out in clause 11, without thereby acknowledging that the GDPR applies.

Why Batzi comes in ten languages: A good quarter of the people living in Switzerland do not hold a Swiss passport. Batzi is therefore available not only in German, French and Italian but also in English, Spanish, Portuguese, Albanian, Serbian, Turkish and Ukrainian. These are the languages of the largest population groups in the country, so that people who do not speak German can understand their own household budget too. Four of them, namely Albanian, Serbian, Turkish and Ukrainian, belong to countries outside the EU. Languages that would be obvious for an EU offering but concern only small population groups here, such as Polish, Dutch or Romanian, are deliberately not offered. The choice of languages is therefore an offer to people resident in Switzerland and not a targeting of foreign markets.

3. Which personal data we process

  • Registration: name, e-mail address, password (stored only as a hash), the key of your two-factor login and your backup codes (stored encrypted). If you set up a passkey, we store its public key, an identifier, a counter against cloning and the name you chose; the private key stays on your device.
  • Payment: payments are handled by Stripe. We store only a Stripe customer ID and the payment status. Card details are processed exclusively by Stripe.
  • Use of the app: budget data you enter yourself: household names, names of people and their income, accounts, budget items (category, amount, frequency, split), actual expenses, savings goals, and the summaries calculated from them (snapshots).
  • Bank statements you upload: booking date, amount, currency and the direction of the transaction, meaning expense, credit or internal transfer. From the booking text we keep only a short name of the counterparty, at most three words and no digits, plus the assigned category and a check value by which we recognise the same transaction on a second import. In addition the period covered by the statement and the file name, from which we remove account and IBAN numbers beforehand. If the app remembers an assignment as a rule, we do not store the name for it in plain text but only its check value. Such a rule is created only if you agree when taking lines over. For the category suggestion we additionally compare the name with a list of well-known Swiss companies that we maintain; it contains no private individuals and no health-care providers, learns nothing from your data and is not shared with other households. If your bank supplies the transaction type, we use it only in the preview and do not store it. We do not store the payment reference. It is discarded already during the preview. This data comes exclusively from the file you upload yourself, it is stored only once you have confirmed the preview, and the import requires your express consent.
  • Calculated savings potential: if you use the comparison calculators, we store the amount you could save per month, together with the time of the calculation and a short check value that lets us detect an unchanged recalculation. We store this only where a switch is actually possible; today that means health insurance alone. Location-based comparisons (taxes, rent, electricity, ancillary costs) and the model calculations for commuting costs and mortgages are not stored. Nor do we store what you type into the calculator itself.
  • Shared household: if you share a household, we store who is a member and with which role (owner, editor or viewer), together with the time of joining. For an invitation we store a random token, the intended role, the expiry time and, if you enter it, the e-mail address of the invited person. If you record who paid an expense, we store that assignment too; it is the basis of the settlement.
  • Technical data: on every login we store the IP address and user agent in order to secure your account (session management). Security-relevant events on your account (sign-in with second factor or passkey, new backup codes, password change, passkey added or removed, devices signed out, recovery request) are logged with time, IP address and browser identifier, shown to you in the settings and deleted after 180 days. If you request recovery of your two-factor sign-in, we store the request with status, deadline, IP address and browser identifier until it is settled.
  • E-mail delivery: your e-mail address is used for password reset messages and, if you enable them, for notifications (e.g. budget reminders). Delivery runs through Brevo (formerly Sendinblue), a GDPR-compliant e-mail service with servers in the EU.
  • Push notifications: if you enable push notifications, we store a technical endpoint (push subscription) and cryptographic keys provided by your browser. They contain neither your name nor your e-mail address, but they do identify your browser on this device, and they serve solely to deliver notifications (details in clause 7). You can switch them off at any time in the app settings or in your browser settings.
  • Feedback: if you send us feedback through the app, we store your text and, if you attach them, a screenshot and a short screen recording. These attachments sit on the same Swiss server as the rest of the data and are used solely to process your report. Please pay attention to what is visible in a screenshot.

The uploaded file is not stored. It is read in memory on our server in the Swiss data centre, shown to you as a preview and then discarded. What is stored permanently is exclusively the transactions you confirm in the preview, plus a log entry recording when and for which period the import happened. There is no connection to your bank, no field for banking credentials and no account retrieval.

If Batzi does not recognise the format of your file, you may voluntarily send us the header row and two sample rows with the amounts overwritten so that we can add your bank. You see the exact wording of what would be sent beforehand. Without that explicit click, none of it leaves your browser, and in this case too the file itself is not stored.

4. Purpose of the processing

  • Providing and operating the budget app
  • Running a household jointly with people you invite yourself (see clause 4a)
  • Authentication and account security
  • Payment processing (subscription)
  • Communication (password reset, optional notifications)
  • Automated hints about your budget (see clause 12)
  • Anonymised, aggregated statistics on Swiss household budgets (see clause 13)
  • Measuring advertising effectiveness and analysing user behaviour (only after your express consent via the cookie banner)

We do not process your data for other purposes. We do not sell personal data, do not rent out addresses, do not display third-party advertising in the app and do not build profiles for third parties. We advertise only on our own behalf, to make Batzi known; that advertising is measured only if you consented in the cookie banner.

4a. If you share a household

You can share a household with other people, so that a couple or a flat share can keep the same figures without sharing a login. This happens only if you trigger it yourself: through an invitation that you create and pass on. Whoever accepts the invitation becomes a member of your household. You can see who is a member at any time and can remove any member again.

A shared household shares figures, not lines. Budget, settlement and monthly overview are totals and visible to all members. Your individual account transactions, by contrast, remain hidden, because they name shops, places and times, and therefore they say where you have been. They become visible only if you explicitly release them for a plan, and you can withdraw that release at any time. Without a release, the default is: hidden.

The invitation itself consists of a random link with limited validity. It can only be redeemed with a registered account and can be withdrawn at any time. If you enter an e-mail address when inviting, it serves purely your own overview and is not a condition for redeeming. If you leave a household or are removed, your access ends immediately; the figures already recorded stay with the household.

5. Third-party services and transfers abroad

Stripe (payment processing)

Stripe Inc., USA. Stripe is certified under the Swiss-U.S. Data Privacy Framework. Only the data needed for the payment is transmitted.

Stripe privacy policy

Brevo (e-mail delivery)

Brevo (formerly Sendinblue), France/EU. Used to send password reset messages, verification messages and e-mail notifications. Brevo is GDPR-compliant and processes the data in the EU. Only your e-mail address and the content of the message are transmitted.

Brevo privacy policy

Meta Pixel (advertising)

Meta Platforms Ireland Ltd. We use the Meta pixel to measure the effectiveness of our ads on Instagram and Facebook. The pixel is loaded only after your express consent (cookie banner). It records pseudonymised usage data such as page views and completed purchases. Meta may link this data to your Meta profile.

Server-side purchase measurement (Conversions API): if you buy Premium access and have previously allowed advertising cookies, our server additionally reports the completed purchase directly to Meta. What is transmitted is your e-mail address in irreversibly hashed form (SHA-256), your IP address, your browser identifier (user agent), the Meta cookie values as well as the amount and currency. The sole purpose is to avoid counting the same purchase twice and to measure the effectiveness of our advertising. Without your advertising consent this transfer does not happen, not even in hashed form. The purchase itself works entirely independently of it.

Meta privacy policy

Google Analytics 4 (analytics)

Google Ireland Ltd. We use Google Analytics 4 to analyse website usage. GA4 is loaded only after your express consent (cookie banner). IP addresses are anonymised. Google may process the data on servers in the USA (standard contractual clauses).

Google privacy policy

Note on transfers abroad: some of the services named process data in countries whose level of data protection does not match the Swiss one, in particular the USA. We base these transfers on standard contractual clauses or on the Swiss-U.S. Data Privacy Framework. Even so, it cannot be ruled out that authorities of the country concerned, for instance intelligence services, access this data, and that your rights cannot be enforced there as effectively as in Switzerland. Your budget data is not affected by this: it is stored exclusively in Switzerland. The only figures that go abroad are those contained in an e-mail reminder you have switched on yourself, and they go to Brevo in the EU, whose level of data protection the Federal Council recognises as adequate.

Processing on our behalf (Art. 9 FADP): Infomaniak (hosting), Brevo (e-mail delivery) and Stripe (payment) process data for us and on our instructions. The necessary data processing agreements are in place with all three, they may not use the data for their own purposes and may not bring in further sub-processors without our consent. Stripe additionally processes card data on its own responsibility, insofar as this is necessary for fraud prevention and regulatory obligations.

With Meta and Google it is different, and we say so openly: for advertising measurement these two are not pure processors but also pursue their own purposes with the data collected. We cannot issue them instructions there. That is precisely why both are loaded exclusively after your express consent, can be deselected individually and withdrawn at any time. Neither of them ever has access to your budget data.

For the import of your bank statements no further service provider is involved. Neither the providers named above nor an account data aggregator nor any other third party gains access to the file or to the transactions taken from it. The processing takes place entirely on our own server.

To convert transactions in a foreign currency, our server fetches the monthly average rates of the Swiss National Bank (data.snb.ch). That request contains nothing about you: no amounts, no currencies, no identifier. The whole table is loaded and cached for 24 hours.

6. Cookies and local storage

For anonymous usage statistics we use Umami, a privacy-friendly analytics tool. Umami sets no cookies, stores no IP addresses and collects no personal data. It runs on our own server in Switzerland.

In addition, and only after your consent (cookie banner), we use tracking cookies from Meta (Facebook/Instagram pixel) and Google (Analytics 4). They serve to measure advertising effectiveness and to analyse user behaviour. In the cookie banner you can choose separately whether to allow statistics cookies (Google Analytics) and/or advertising cookies (Meta pixel).

Withdrawal: you can withdraw your consent at any time by clicking “Cookie settings” in the footer. The cookie banner then appears again and you can change your selection.

The app also uses technically necessary cookies for logging in. The login cookie stays valid for up to seven days and is extended while you keep using the app, so that you do not have to log in again on every visit. It is removed when you log out, and likewise when you end a session in the settings. It is not a pure session cookie: it survives closing the browser. If you choose “Trust this device” when signing in, we set a further cookie that skips the code prompt on this browser for 30 days; a password reset or a recovery deletes it.

On top of that comes your browser's local storage (localStorage). It holds not only the colour scheme, language, your cookie choice and the interim state of the budget wizard, but also the entries you make in the comparison and planning calculators, so that you do not have to type them again in every calculator: postcode, age, deductible, insurance model and accident cover, income and partner's income, wealth, marital status, number of children, religious denomination, and details of your commute, flat, mortgage and property. The religious denomination is sensitive personal data; it is used solely for the church tax in the tax comparison. This storage sits on your device and is not read out by us; for the calculation the necessary values go to our server, which uses them only to compute and does not store them. You can delete it at any time through your browser settings. If you click on an ad, the address contains a click identifier (gclid, fbclid) or campaign parameters. We store these on the device only with your advertising consent; without it they are not stored, and when you withdraw consent we delete them again.

NameProviderPurposeDurationCategory
batzi-consentBatzi (localStorage)Stores your cookie consentUntil you change itNecessary
budget-app.session_tokenBatziAuthentication (login)7 days, extended while in useNecessary
budget-app.session_dataBatziShort cache of the session, saves database queries60 secondsNecessary
budget-app.two_factorBatziBridges the step between password and code at loginUntil the code is enteredNecessary
batzi-utmBatzi (localStorage)Remembers which ad or campaign brought you here30 daysAdvertising
_ga, _ga_*GoogleVisitor statistics (GA4)2 yearsStatistics
_fbpMetaAdvertising measurement (pixel)90 daysAdvertising
_fbcMetaClick attribution90 daysAdvertising

Over HTTPS our own cookies additionally carry the prefix __Secure-, so they are only transmitted over encrypted connections.

7. Push and e-mail notifications

In the app settings you can manage push notifications and e-mail notifications. E-mail notifications are enabled by default; push notifications have to be enabled manually.

  • Push notifications: when you enable them, your browser asks for your consent. We store the push subscription generated by the browser (a technical endpoint and encryption keys). Delivery runs over the web push standard (VAPID): the content and title of every message are end-to-end encrypted between our server and your browser.

    The route there, however, runs through the push service of your browser vendor, which your browser itself determines: Google for Chrome and Android, Apple for Safari, iPhone and iPad, Mozilla for Firefox. These services cannot read the content, but they do learn that a message was delivered to your endpoint at a given time. We transmit to them neither your name nor your e-mail address and no budget data. If you want to avoid even this marginal information, leave push notifications off and use the e-mail reminders.

  • E-mail notifications: when enabled, we use your existing e-mail address to send you reminders about your budget at most once or twice a month (e.g. budget check). Seasonal pointers to the comparison calculators (health insurance premiums in autumn, taxes in spring) are advertising and are only sent if you switch them on separately in the settings; they are off by default. Every e-mail carries an unsubscribe link that turns both kinds off with one click. Sending is handled by Brevo (EU).
  • Switching off: you can switch off both channels at any time in the app settings. With push notifications, your subscription is deleted immediately.

8. Hosting and encryption

The app and the database run on our own server at Infomaniak in Geneva, Switzerland (virtual server in the Infomaniak Public Cloud). This is not a US cloud solution (no AWS, Google Cloud or Azure).

  • Location: Infomaniak data centre, Geneva, Switzerland. Your data does not leave Switzerland (exception: e-mail delivery via Brevo, EU; payment processing via Stripe, USA).
  • Encryption: all connections are TLS-encrypted (HTTPS). Passwords are hashed with scrypt and never stored in plain text. The keys of two-factor login are stored encrypted as well. Database backups are encrypted with AES-256. Of passkeys we store only the public key; on its own it cannot be used to sign in.
  • Access: only the operator has server access, exclusively via SSH key; password login is switched off. The database cannot be reached from outside. No third-party provider has access to the database.

9. Data export

In the app settings you can export all of your data as a JSON file at any time. The export covers your profile, all households, people, accounts, budget plans, expenses, savings goals, historical summaries, your feedback submissions and the in-app messages, as well as the account transactions taken from bank statements and the associated import logs, plus the calculated savings potential including area and calculation date. On top of that comes a section on your account itself: your logins with time, IP address and device identifier, the verification and reset messages requested, your push subscriptions, the delivery log of the reminders and your sharing links. Credentials themselves are deliberately not included, meaning no tokens, no two-factor key, no backup codes and no full push address: delivering them in a file would be a security risk. This lets you back up your data or take it to another service.

For shared households there is a deliberate limit: households you created yourself are included in full. Of households you were merely invited to, the export contains the membership with name, role and joining date as well as the account transactions and import logs you recorded there yourself. Everything else from those households stays out. An access request covers your own data, not a copy of other people's data, but it does not stop at the household boundary either.

10. Retention and deletion

Your data is stored for as long as your account exists. You can delete your account yourself at any time in the app settings. Alternatively you can request deletion by e-mail to info@batzi.ch. In both cases all of your data is deleted irrevocably: profile, households, people, accounts, budgets, expenses, savings goals, analyses as well as any feedback reports including uploaded screenshots and screen recordings.

Limitations we want to disclose:

  • Backups: we create an encrypted backup of the database daily and keep the last 14 states. Deleted data can therefore still be contained in those backups for up to 14 days before it disappears for good. The backups serve solely to restore service after a technical failure and are not analysed.
  • Automatic clean-up: even without account deletion we remove daily whatever has served its purpose: expired login sessions including the IP address and browser identifier stored with them, expired verification and reset links as well as expired sharing links. Likewise settled or expired recovery requests after seven days and the security events of your account after 180 days.
  • Bank statements and account transactions: we do not keep the uploaded file at all, it is discarded after the preview. The account transactions you confirmed remain stored for as long as your account exists, because they are the point of using the app. The import logs, meaning the record of when and for which period you imported, are deleted automatically 24 months after the import. The name of an imported transaction is automatically replaced by its category as early as 90 days after the import; amount, date and category remain. You can delete individual transactions yourself at any time.
  • Shared household: a membership lasts as long as it lasts: it ends when you leave the household, when the owner removes you or when either of the two accounts is deleted. Open invitations are deleted automatically as soon as they have expired or been redeemed. If you own a shared household when deleting your account, we ask you explicitly beforehand whether we should hand it over to a remaining member or delete it together with all figures. Without your choice nothing happens.
  • Calculated savings potential: what the comparison calculators determined is deleted automatically 12 months after the calculation. Prices and premiums change annually, after which the figure would be out of date anyway. From 90 days on, the app already shows it dimmed and offers you a recalculation.
  • Payment records: if you bought Premium, we are required under accounting law to keep the receipt for ten years (Art. 958f Swiss Code of Obligations). For that, a purchase record stays in our database with amount, currency, date, the Stripe identifiers of the payment and your e-mail address for attribution. It is detached from your account and stays even after the account is deleted. It contains no name, address or card data. After ten years the daily cleanup deletes it. The payment receipt itself also remains with Stripe.

11. Your rights

You have the following rights under the Swiss Federal Act on Data Protection (FADP):

  • Access: you can request information about which data we hold about you.
  • Correction: you can request the correction of incorrect data.
  • Deletion: you can request the deletion of your data (in the app settings or by e-mail).
  • Data portability: you can export your data as JSON directly in the app settings. Alternatively you can request it by e-mail.
  • Withdrawal of consent: consent you have given (cookies, notifications) can be withdrawn at any time with effect for the future, without giving reasons.
  • Objection: you can object to the processing of your data, in particular to the automated hints under clause 12. We then stop the processing concerned, unless a legal obligation or an overriding interest stands in the way.

Send requests to info@batzi.ch. We usually answer within 30 days and free of charge. So that we do not hand data to the wrong person, we may ask for proof of your identity in the case of access and portability requests; normally a request from the e-mail address registered with us is sufficient.

Complaint: if you believe that we are breaching data protection law, you can contact the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, at any time. We would ask you, though, to come to us first; it is usually settled more quickly that way.

12. Automated analysis of your budget data

Batzi analyses the budget data you enter automatically in order to give you hints, for instance that your health insurance premium is above the Swiss median, that your rent burden exceeds a third of your income or that no savings amount is planned. The reminders by e-mail and push also arise from such analyses. Under data protection law this counts as profiling, which is why we disclose it here.

The following applies:

  • The analysis follows fixed rules and thresholds programmed by us. No self-learning system is involved.
  • Only data you entered in the app yourself and publicly available reference values (FOPH, FTA, FSO, ElCom and others) feed into it. We do not buy in data about you and do not draw on data from other sources.
  • The hints have no legal effect whatsoever and lead to no decision about you. No creditworthiness, credit or risk assessment takes place, and the results are not passed on to anyone.
  • A bank statement may contain entries that allow conclusions about particularly sensitive areas, such as the name of a pharmacy, a clinic, a parish or a political party. We do not analyse such entries specifically, do not form categories from them and do not enrich them with outside data. You can deselect any transaction in the preview already and delete any imported transaction individually later. The fact that you budget a health insurance premium tells us nothing about your health.
  • From your transactions Batzi detects recurring payments, such as a subscription or a quarterly bill, and shows you whether they are in your budget. The calculation uses an irreversible check value of the merchant name, not the name itself; only you and your household see the result, it is not passed on, and you can hide any finding.
  • You can object to the analysis and switch off the notifications at any time in the settings.

13. Anonymised statistics

We analyse budget data in anonymised and aggregated form in order to improve the app and to publish robust statements about Swiss household budgets, for example at the request of media. In doing so we bind ourselves to four rules that are anchored technically in the analysis tool:

  • Only totals and averages are analysed, never individual households.
  • Names, e-mail addresses, notes and identifiers are neither read nor published in the process.
  • Groups with fewer than 20 households are suppressed entirely.
  • Every published figure carries the number of cases it is based on.

Conclusions about you as a person are thereby ruled out. We do not sell data and do not pass anonymised datasets on to advertisers either.

14. Authorities and external links

We disclose personal data to authorities or courts only where we are legally obliged to do so or where it is necessary to assert or defend legal claims. Insofar as legally permitted, we inform you in advance.

The app and the website contain links to third-party pages, for example to sources of the comparison data or to the privacy policies of the services named above. We are not responsible for their content or for how they handle data. We currently do not operate profiles on social networks.

15. Changes

We may adapt this Privacy Policy. The current version is always available on this page. In the case of material changes, for instance when a new third-party service is added or a new processing purpose arises, we will inform you by e-mail or in the app at least 30 days before they take effect. That matches the notice period that also applies to changes of the General Terms and Conditions (GTC). This policy is information under Art. 19 FADP and not part of the GTC; adapting it is therefore not a change of the GTC and does not trigger renewed consent.