Waismo is operated by S7 Business Solutions under SIGMA7 BUSINESS CONSULTANCY SERVICES. For privacy questions, contact [email protected]. This notice covers our website, Android companion, and social-page and community activities.
1. What Waismo does
Our website helps people compare credit products, explore promos, and read financial information. The Android companion supports manual tracking of selected cards, balances, income, debts, payment obligations, and plans. It does not automatically connect to your bank, read bank transactions, monitor purchases, or make payments.
Android availability: the app is in development and testing. Features depend on the build and provider configuration available to you. New email/password, verification, and reset flows are implemented but are not yet confirmed as publicly released or fully tested on a phone. This notice describes their handling when enabled, not a public app-launch announcement.
Waismo does not currently submit credit-card or loan applications to banks or lenders. The website's application-readiness screen is a local preview, not a submission service. Do not enter bank passwords, full card numbers, CVVs, government ID numbers, or financial application documents into messages, reports, or free-text fields.
2. Accounts and sign-in
Android account features use Supabase Auth. For email/password registration or login, the app sends the email address and password you enter to this authentication service. Supabase handles the account, credential verification, and session. Verification and reset emails use our configured email delivery service. Older builds may use email links or codes instead.
Choosing Google or Facebook opens the provider's web sign-in flow. The provider authenticates you and returns authorized identity information through Supabase. Waismo does not receive your Google or Facebook password. A separate Waismo email/password is not your provider password.
Account information includes a Supabase user ID, email address, and display name when supplied. Supabase also handles the provider's account identifier, returned profile metadata (which can include a profile image and email-verification status), and session/authentication records. The current Android account profile reads the user ID, email, and name; it does not display or require all returned metadata.
We use this information to recognize your account, maintain sign-in, support verification and recovery, and control access to account-enabled screens. Session information is stored on the device to restore sign-in. Signing in does not back up your financial tracker.
3. Google user data
The implemented Google sign-in requests email and basic profile access for authentication. It does not request Gmail messages, Drive files, contacts, calendars, or Google financial/payment information.
Google identity data is processed by Google and Supabase Auth and used by Waismo for the account purposes above. It is not used to read spending, populate bank accounts, target advertising, train the on-device assistant, or send finances to banks. It is not sold. Service providers handling sign-in and account support receive information needed for those functions, not authorization for unrelated uses.
You can review or revoke Waismo's connection in your Google Account's third-party connections settings. Revocation is different from deleting information already held in your Waismo account; see retention and deletion.
4. On-device financial records and preferences
The reviewed Android implementation stores these in app-private local storage: selected cards/products; optional last four card digits; manually entered balances, limits, rates and due dates; debts and loans; income and assets; payment records and notes; payoff strategies; budgets and split bills; payment handles or links; and planning/share drafts. They support local tracking, estimates, reminders, and planning.
Saved promo IDs, reminder preferences, and onboarding selections are also local. They are not currently synchronized to cloud saved-promo or preference tables. Public catalog downloads are separate from the private tracker. Account login does not automatically upload, sync, or restore local financial records.
This does not mean everything stays on the device. Sign-in, online searches, correction reports, public-content requests, and information you choose to email or share have the separate flows below.
5. Online searches, location, and reports
When online Deal Finder is configured, it sends search text and chosen category, area/locality, and channel to a Supabase-hosted function. The service converts the query into a search representation using Supabase's embedding runtime and searches the public catalog. The request does not automatically attach private balances, income, debt records, payment schedules, or your account profile.
If you choose nearby-area lookup and allow approximate location access, Android location/geocoding facilities obtain a locality that can be included in your search. Android or its geocoding service may process location for that lookup. You can decline permission and enter an area instead.
A correction report sends the public offer identifier, report type, and your note to Supabase, where it is stored for review with status and timestamps. Reports are not just temporary local messages. Avoid private account or financial details: free-text reports are not guaranteed to be automatically redacted.
The reviewed search function does not write raw search bodies into a Waismo query-history table. Infrastructure may still retain request or diagnostic information. We do not promise that searches leave no server records or that service-provider logs are immediately deleted.
6. Assistant and public downloads
The reviewed Android assistant processes questions and recent conversation context on the device, using local knowledge, calculations, and an on-device model when available. Tracker values may support a local answer. This path does not send conversations or Google profiles to a cloud chatbot. Conversation state is held in the current screen session, not a cloud chat-history account.
The app and website download public catalogs and artwork from Waismo, Supabase, and issuer/content hosts. Android caches public content and model files where applicable. These requests expose ordinary connection information to the serving service; public catalog refreshes do not upload the private tracker.
7. Website, social pages, and technical information
Website filters, comparisons, recommendation choices, and application-readiness inputs are processed by the current page code to show a local result. The preview does not send an application to Waismo, Google Forms, banks, or affiliates. Your browser may separately retain form entries, history, or downloads under its settings.
Hosting and content services process technical information such as IP address, browser/device information, requested URLs, request times, and errors to deliver and protect the service. The reviewed Android app has no active third-party analytics-event sender; local diagnostic logging includes public-catalog refresh failures. This does not mean infrastructure providers keep no logs.
Social-page and community interactions may involve your name, public profile, comments, messages, and interaction metadata for replies, education, and moderation. Authorized page-management operations may process page IDs/names, post/comment metadata, permissions, and platform access tokens. Page-admin permissions are separate from a user's Facebook sign-in to Android.
8. Service providers and sharing
The reviewed services use Cloudflare for website hosting/delivery; Supabase for authentication, public data/search and correction-report storage; Google and Meta/Facebook for chosen login/social features; and the configured Zoho email service for outgoing Waismo account emails. Correspondence also passes through the email providers used by the sender and recipient. Website assets may load from jsDelivr and official issuer/content hosts. Providers process information needed for their service under applicable terms and privacy notices.
Authorized Waismo operators may access account, support, moderation, and correction information to operate the service. Disclosure may also be required by applicable law or a valid legal request. Provider processing may occur outside the Philippines; storage is not limited to the Philippines.
Waismo does not sell personal data. External issuer, Facebook, or other links take you to services with their own notices. The current website does not transmit application payloads or tracker finances to bank partners. Future personal-data sharing for referrals or applications needs a specific explanation and appropriate authorization before it begins. Using Waismo is not blanket consent to share your finances.
9. Device controls, exports, and backup
You can edit or remove local records and saved promos. Reminder and notification permissions are controlled in the app and Android settings. Notifications may be visible to people who can see your device or lock screen. Location permission is optional for nearby-area lookup.
A requested tracker export can include cards, optional last four digits, balances, debt/payment information, and planning records. Android sharing passes it to the receiving app you choose, which may store or transmit it. Deleting Waismo data later does not remove exported or shared copies.
The reviewed Android build disables Android app backup and excludes private stores from configured transfer rules. Waismo does not currently offer cloud backup or recovery of the local tracker. Keep exports you create in a place you control; do not assume another-device login will recover the tracker.
10. Retention, sign-out, and deletion
Signing out is not deletion. It clears the local authentication session and attempts remote sign-out, but does not erase tracker records, saved promos, the cloud account, or submitted reports. If remote sign-out cannot complete, server sessions remain subject to the authentication service's handling. Clear local tracker data before handing your device to another person or changing who uses it.
Delete all tracker data clears the local card/debt/payment/planning records, saved promos, and reminder preferences handled by that control and cancels their reminders. It leaves the cloud account signed in. App caches, model files, and exported copies are separate. Android's clear-storage or uninstall controls remove local app storage, not records held by providers or recipients.
The in-app account-deletion control does not currently delete the cloud account or send a deletion request. Contact [email protected] to request deletion and identify the account or report concerned. We may need to verify the request. Do not send passwords, verification codes, full card numbers, or identity documents in the initial message.
Account, correction, support, and moderation records are separate from local tracker data. No automatic expiry period is implemented for correction reports in the reviewed service. Deletion requests require assessment of what we hold and necessary legal or security retention; they do not promise immediate erasure of every provider log or backup. Contact us for the handling and timing of your specific request. See the data-deletion instructions.
11. Privacy rights and contact
Subject to applicable law, you may request access, correction, erasure or blocking, object to processing, and exercise applicable portability rights. The Philippine National Privacy Commission explains rights and complaint options on its data-subject rights page.
Contact [email protected] with enough information to identify the relevant interaction, avoiding unnecessary financial details. We may ask for proportionate verification before providing account information or acting on a request.
12. Security and changes
The reviewed implementation uses app-private storage and HTTPS service requests, avoids displaying raw authentication errors, and limits structured deal-search fields. These measures are not a guarantee of absolute security or a certification. Protect your device, credentials, and exports.
We will revise this notice when data handling changes and update the date above. New sync, analytics, assistant, or application-sharing behavior will be explained before being represented as available.