Privacy Policy and Cookie Policy
Last updated: July 21, 2026
1. Who is the data controller
The data controller is:
RevOps Labs s.r.o.
Company ID (IČO): 21705534
VAT ID (DIČ): CZ21705534
Registered office: Hlaváčkova 1334/19, Košíře, 150 00 Prague, Czech Republic
Registered with the Municipal Court in Prague, file no. C 405326
(the "Provider", "we", "us")
The Provider operates an online personal finance tracking service available at meethugo.co (the "Service" or "Hugo").
For any questions regarding the processing of your personal data, including cookies, contact us at: support@meethugo.co
Given the scope and nature of processing, the Provider is not required to appoint a Data Protection Officer under Art. 37 GDPR. The contact above serves as the point of contact for all privacy-related requests.
2. What data we process
2.1 Account and registration data
- first and last name,
- email address,
- sign-in history (sign-in count, last sign-in time),
- IP address and the country derived from it, recorded at account signup,
- internal user and account identifiers.
This data is managed through our authentication provider Clerk (see Section 6).
2.2 Financial data you enter
The Service is a manual personal finance tracking tool — we do not connect to your bank accounts. You enter yourself:
- names of financial institutions and products (accounts, investments),
- balances, deposits and withdrawals for each product over time,
- physical assets (e.g. real estate) and their valuations over time,
- liabilities (debts, loans) and their balances,
- recurring income and expenses,
- the financial goal you set in the Service,
- the currency and country selected in settings.
We treat this data as sensitive by nature (although it does not constitute a "special category of data" under Art. 9 GDPR) and handle it with corresponding care.
2.3 Data generated by using the Service
- interactions with in-app offers and banners (impressions, clicks) — used to target content by country, language and financial goal,
- subscription data (tier, status, and possibly a Stripe identifier — see Section 9),
- technical logs necessary for operating and securing the Service.
2.4 Data processed by the AI insights feature ("Hugo")
If you use this feature, we send aggregated financial metrics of your account (e.g. net worth, cash and investment totals, currency exposure %, savings rate, financial goal) to our processor OpenAI to generate a text summary. We do not send your name, email, or the identity of specific financial institutions.
2.5 Cookies and similar tracking technologies
A full list of the cookies we use, their purpose and duration, is set out in Section 4. We group cookies into three categories: necessary, analytics, and marketing.
3. Why and on what legal basis we process your data
| Purpose | Legal basis |
|---|---|
| Creating and managing your account, providing the Service | performance of a contract (Art. 6(1)(b) GDPR) |
| Storing and displaying the financial data you enter | performance of a contract |
| Generating AI insights via OpenAI | performance of a contract / legitimate interest in improving the Service |
| Billing and subscription management | performance of a contract, legal obligation (accounting, tax) |
| Security, abuse prevention, IP/country logging at signup | legitimate interest (Art. 6(1)(f) GDPR) |
| Customer support, including temporary account access | legitimate interest in resolving support and technical issues |
| Targeting in-app offers and banners | legitimate interest in relevant content; no data shared with third parties |
| Analytics cookies (Google Analytics) | consent (Art. 6(1)(a) GDPR) — set only after you opt in |
| Marketing cookies (Google Ads remarketing, Meta Pixel) | consent (Art. 6(1)(a) GDPR) — set only after you opt in |
| Compliance with legal obligations (accounting, VAT) | legal obligation (Art. 6(1)(c) GDPR) |
4. Cookies — detailed overview and consent management (cookie policy version: 2026-07-21.1)
Cookies are small text files stored in your browser. We use three categories of cookies:
4.1 Necessary cookies (no consent required)
Required for the Service to function and stay secure. They cannot be disabled without breaking core functionality (e.g. login). Under Section 89 of Act No. 127/2005 Coll., on Electronic Communications, consent is not required for these.
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
| Clerk session cookies | Clerk, Inc. | Keeps the User's session logged in | per Clerk's configuration, typically for the session/several days |
session_seen | RevOps Labs s.r.o. (first party) | Prevents double-counting sign-ins | 30 days |
| Support (impersonation) cookie | RevOps Labs s.r.o. (first party) | Time-limited support session for account troubleshooting | 12 hours |
| Cookie consent preference | RevOps Labs s.r.o. (first party) | Remembers your cookie banner choice | 12 months |
4.2 Analytics cookies (consent required)
We use Google Analytics (GA4) to measure traffic and usage of the Service (e.g. most-visited pages, traffic sources, engagement). Data is processed in aggregate/pseudonymized form; per Google's statements, GA4 does not store IP addresses — they are used momentarily to derive an approximate location.
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
_ga | Google Ireland Limited | Distinguishes unique users | 2 years |
_ga_<measurement ID> | Google Ireland Limited | Persists session state for GA4 | 2 years |
4.3 Marketing cookies (consent required)
We use:
- Google Ads remarketing (Google Ireland Limited) — to re-target visitors of the Service with ads across Google's ad network (Search, Display, YouTube).
- Meta (Facebook) Pixel (Meta Platforms Ireland Limited) — to measure conversions and build remarketing/lookalike audiences for ads on Facebook and Instagram.
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
_gcl_au | Google Ireland Limited | Links conversions from Google Ads | 90 days |
_fbp | Meta Platforms Ireland Limited | Browser identifier for Meta Pixel | 90 days |
_fbc | Meta Platforms Ireland Limited | Stores the click identifier from a Meta ad | 90 days |
fr | Meta Platforms Ireland Limited | Ad delivery and measurement on Meta platforms | 90 days |
Note on Meta Pixel: under Meta's Controller Addendum to its Business Tools Terms, Meta Platforms Ireland Limited is a joint controller for certain processing of data collected by the base Pixel code. See Meta's Privacy Policy and Meta's Cookie Policy for details of Meta's own processing.
The maximum duration a visitor can remain in a Google Ads remarketing audience is 540 days (the actual value is configured in Google Ads and may be shorter).
4.4 Cookie consent and how to withdraw it
- Analytics and marketing cookies are set only after you give explicit consent via the cookie banner shown on your first visit. Without consent, these cookies do not fire.
- Consent can be given per category (analytics / marketing separately); rejecting consent must not be harder than granting it.
- You can change or withdraw your consent at any time via the "Cookie settings" link in the footer of the website/app. Withdrawing consent does not affect the lawfulness of processing based on consent given before its withdrawal.
- Necessary cookies cannot be disabled through this tool.
5. Customer support access to your account
For troubleshooting and support purposes, a limited group of authorized Provider staff may temporarily access your account interface through an internal support tool. Sensitive financial figures (specific balances, amounts, and similar values) are anonymized/masked during this access, and support staff do not see them in unmasked form. Access is time-limited, logged, and used solely for support and security purposes.
6. Who we share data with (processors and recipients)
| Processor / recipient | Purpose | Location / transfer basis |
|---|---|---|
| Clerk, Inc. | authentication, user account management | USA — SCCs or another adequate mechanism under Art. 46 GDPR |
| Neon, Inc. | database hosting | EU — depending on the selected database region |
| Vercel Inc. | application hosting, storage of marketing images | USA / global CDN — SCCs |
| OpenAI OpCo, LLC | generating AI insights from aggregated financial metrics | USA — SCCs |
| Google Ireland Limited / Google LLC | Google Analytics (analytics cookies), Google Ads remarketing (marketing cookies) — only with consent | EU/USA — EU-US Data Privacy Framework, SCCs as fallback |
| Meta Platforms Ireland Limited | Meta Pixel (marketing cookies) — only with consent; joint controller with the Provider for certain processing | EU/USA — EU-US Data Privacy Framework, SCCs as fallback |
An up-to-date list of processors is kept in the Provider's internal records and will be provided on request.
We never sell your data to third parties or use it for advertising outside the scope described in this document.
7. International data transfers
Some processors listed above are located in, or process data in, the USA. Transfers are secured through the European Commission's Standard Contractual Clauses, or, for providers certified under the EU-US Data Privacy Framework (currently Google LLC and Meta Platforms, Inc.), through that mechanism. A copy of the relevant safeguards is available on request.
8. How long we keep your data
| Data category | Retention period |
|---|---|
| Account and financial data while the account is active | for the duration of the account |
| Data after account closure/deletion | anonymization or deletion within 30 days of confirmed account closure |
| Accounting and tax records (invoices, etc.) | 10 years under the Czech Accounting Act and VAT Act |
| IP address and sign-in logs | 12 months from the record date |
| Customer support communications | 24 months from resolution, or longer if necessary for legal claims |
| Analytics cookies (Google Analytics) | 14 months at the event level (GA4 default) |
| Marketing cookies (Google Ads remarketing, Meta Pixel) | 90 days (cookie); remarketing audiences up to 540 days |
| Cookie consent/rejection record | 12 months from being given, then re-requested |
9. Subscriptions and payments
Once the Service launches paid subscriptions, payments will be processed through a payment gateway (planned: Stripe). At that point, Stripe will be added to the processor list in Section 6 and this policy updated before payments go live.
10. Your rights
As a data subject, you have the right to:
- access the personal data we process about you,
- rectify inaccurate data,
- erasure ("right to be forgotten"), except for data we must retain due to a legal obligation,
- restrict processing,
- data portability — a CSV export of your data is available in the Service under Settings,
- object to processing based on legitimate interest,
- object at any time and unconditionally to processing for direct marketing purposes (Art. 21(2) GDPR), including profiling connected to marketing cookies — in that case we will stop processing your data for that purpose,
- withdraw consent to analytics and marketing cookies at any time via the "Cookie settings" tool,
- lodge a complaint with a supervisory authority — in the Czech Republic, the Office for Personal Data Protection (www.uoou.cz); if you reside in another EU member state, you may also contact your local supervisory authority.
You can exercise your rights by emailing support@meethugo.co. You can also opt out directly with the analytics/marketing providers: Google Analytics opt-out, Google Ads settings, Meta ad preferences.
Additional notice for California residents (CCPA/CPRA)
If you are a California resident, you have the right under the CCPA/CPRA to know what personal information we collect, to request its deletion, and to opt out of its "sale" or "sharing" with third parties, including sharing for targeted advertising purposes (Google Ads, Meta Pixel), which may constitute "sharing" under the CPRA. You can opt out via the "Cookie settings" tool or by emailing support@meethugo.co.
11. Age restriction
The Service is intended for individuals aged 18 and older. We do not knowingly collect data from individuals under 18, including via analytics or marketing cookies. If we learn that we have collected such data, we will delete it.
12. Data security
We take reasonable technical and organizational measures to protect your data (encryption in transit, access controls, limited support access as described in Section 5). However, no method of transmission or storage is 100% secure.
13. Changes to this policy
We may update this policy from time to time, for example when adding new tracking tools or processors. We will notify you of material changes by email or an in-Service notice, and may ask you to renew your cookie consent. The current version is always available at meethugo.co.
14. Contact
RevOps Labs s.r.o., Hlaváčkova 1334/19, Košíře, 150 00 Prague, Czech Republic
Email: support@meethugo.co