Effective date: 8 July 2026
Version: 1.1
At SORVA, we treat your financial information as yours, not a product to monetize. Your financial data is encrypted on your device before it reaches our systems, and it stays encrypted in normal use; our staff do not access it in the ordinary course. You choose how your vault is secured, Standard or Sovereign. We explain exactly what each mode means, including who can access what, in section 3 below.
Primary infrastructure stores your data in Switzerland (Supabase on AWS Zurich, eu-central-2). We design the service so your primary data residency stays Swiss.
Your vault (the encrypted store of your financial simulation data) is encrypted on your device using AES-256-GCM before sync. In Sovereign mode we hold no key that can decrypt it. In Standard mode we keep a separately-encrypted recovery key, which we use to help you recover access when you reset your password. We do not otherwise access it, except where we are legally required to (see section 3).
We do not sell your personal data, and we do not use Facebook or Google advertising pixels. We use privacy-oriented analytics and, where the referral programme is active, an affiliate-attribution tool, both listed in section 6.
You can download a data export from Settings. You can delete your account from Settings; deletion removes your account and financial data from our active systems and is intended to be irreversible.
SORVA ("we", "our", "us") is operated by Shreevya GmbH, a company registered in the Canton of Aargau, Switzerland (Commercial Register no. CHE-429.715.642; contact: contact@sorva.ch). SORVA is a Swiss wealth, tax, and pension simulation platform for educational estimates, not a bank and not individualized advice.
This Privacy Policy describes how we process personal data primarily under the revised Swiss Federal Act on Data Protection (revFADP / nDSG, SR 235.1). SORVA is a Swiss service. The Service is offered to users in Switzerland and processed under Swiss law.
Your detailed financial simulation data is encrypted on your device and is not stored by us in readable form. When you run a simulation, your inputs are processed by our computation layer only to produce your projection, and are not persisted there. Because your stored data is encrypted before it reaches us, and who holds the key depends on your vault mode (see section 3), support relating to specific stored records may be limited where decryption is not technically available to us.
We split information into account-level data we need to run the service, and simulation data that is designed to stay under your control.
Needed for login, security, and (if offered) billing status.
Salary, pillars, assets, and similar inputs used for projections.
This information is encrypted on your device before it is stored, so it reaches us only as scrambled data that needs a key to open. What differs between the two vault modes is who holds that key (see section 3). In Sovereign mode, only you hold the key, so we can never open your data, not even to help you. In Standard mode, your data is encrypted on your device the same way, but we also keep a separate, encrypted recovery key so we can help you back in if you lose your Master Key; your data stays private in normal use and our staff do not access it in the ordinary course, though unlike Sovereign it is not sealed to you alone. When you run a simulation, your inputs are used only to calculate your projection and are not stored.
Your religious affiliation (confession) is sensitive personal data under the revFADP (Art. 5(c)), and is used only to estimate your church tax. The field does not disclose a confession by default. When you actively choose a specific confession, after a clear notice at the field, that choice is your express consent to process it under the revFADP (Art. 6(7)), and we record that consent. You can change or remove it at any time, which withdraws that consent and clears the value. Other household details, including your children's birth years, are not sensitive data: you provide them voluntarily and we use them only for family-tax logic. Your inputs are encrypted on your device and processed transiently on our servers only for the calculation, and you can leave them blank or delete them at any time. The service is intended for adults (18+).
Your financial data is encrypted on your device before it reaches our systems. Your financial vault data travels to us as scrambled ciphertext that requires a key to unlock. What differs between the two modes is who holds the recovery key.
Standard Vault (default): convenience and privacy. Your data is encrypted on your device using AES-256-GCM. We store your encrypted data and also keep a separate, encrypted recovery key (your Master Key wrapped with our public key, stored encrypted in the database). This means: (1) Your financial data is encrypted at rest; our staff do not access it in normal operation. (2) If you forget your password, we can use the recovery key to help you reset your access without losing your data. (3) We technically can decrypt your vault using the server-side recovery key, but we do so only on your explicit recovery request (e.g. password reset) via a secure, rate-limited recovery path, or where we are legally required to. (4) This mode prioritizes both privacy and recovery convenience, and if the worst happens, we can help you.
Sovereign Vault: maximum privacy. Your data is encrypted on your device using the same AES-256-GCM. You choose a separate, strong Vault Key (distinct from your login password): (1) We store only your encrypted data; we store no recovery key that can unlock your vault. (2) We literally cannot decrypt your vault, even if you ask us to, not even to help you recover. (3) If you lose your Vault Key AND your recovery PDF (24-word phrase), your data is permanently inaccessible; this is an irreversible loss. (4) This mode prioritizes your sole control: only you hold every key; we are cryptographically prevented from ever reading your data.
Encrypted transport & server security: Regardless of mode, data in transit is protected by TLS. If our database is compromised, the encrypted payload remains ciphertext. In Sovereign mode, that ciphertext is completely unreadable without your Vault Key (which we never see). In Standard mode, it could theoretically be decrypted only if both the encrypted vault data AND the private key that unwraps the recovery key were compromised together. That private unwrap key is held separately in Supabase secrets, never in the application database, and the recovery path is protected by recovery-grade authentication and rate-limiting (maximum 5 attempts per user per 15 minutes). For maximum privacy with zero server key access, users can choose Sovereign Vault mode instead.
We use data we can access to:
Optional newsletter: if you choose to subscribe to our optional newsletter, it is opt-in, confirmed by email (double opt-in), and every message includes a one-click unsubscribe. You receive it only after you subscribe and confirm, and you can withdraw your consent at any time.
We do not:
We may process your data on the following bases: to perform our contract with you (operating the service and syncing your encrypted vault); with your explicit consent (for the sensitive data above); and for our legitimate interests in security and in fraud and abuse prevention. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.
SORVA’s engine automatically analyses the inputs you provide to generate your projections and educational insights. This is automated analysis of your own data; it does not make any automated decision producing legal or similarly significant effects about you (revFADP Art. 21): you decide what to do with the estimates.
Account data and encrypted simulation payloads are stored using infrastructure located in Switzerland (Supabase on AWS Zurich, eu-central-2), subject to our configuration and provider terms. Simulations are computed on application infrastructure in the EU (Frankfurt, Germany): your inputs are processed there transiently during a calculation and are not persisted outside Switzerland.
We keep account and encrypted vault data while your account is active, until you delete it. Concrete periods: consent records are kept while your account is active as proof of your consent and are removed when you delete your account; security and abuse-prevention logs for a short rolling window (up to 12 months); contact and support records up to 24 months after your request is resolved; billing records as required by Swiss law (generally up to 10 years, Art. 958f CO) where paid plans apply. Referral-attribution IP addresses are removed after 90 days, and processed notification signals after 90 days. After account deletion, residual copies may remain in provider backups for a limited period (typically up to 30 days) before aging out.
We limit subprocessors to what is needed to run SORVA.
| Partner | Role | Data / region notes |
|---|---|---|
| Supabase (AWS Zurich) | Database, authentication, storage of encrypted blobs | Switzerland (eu-central-2); account metadata and ciphertext |
| Resend | Transactional email, and the optional newsletter if you subscribe | Email address; may involve processing outside CH (safeguards per section 9) |
| Vercel | Application hosting, serverless compute, and cookieless Web Analytics | Hosting and compute run in the EU (Frankfurt, Germany); IP and request data (and your simulation inputs) are processed transiently during a calculation. Web Analytics is cookieless and aggregate (a 24-hour hash, no stored IP, no cross-site identifier) with no financial values or account identifiers; it is operated by Vercel (a US company), so any processing outside Switzerland relies on the safeguards in section 9 |
| Rewardful (US) | Affiliate / referral attribution, only when the referral programme is active | United States; IP address and referrer. Covered by the Swiss-U.S. Data Privacy Framework if certified, otherwise Standard Contractual Clauses with the Swiss addendum |
We do not share data with advertisers or ad networks for profiling. Some features are not active at launch: when paid plans go live, payments will be processed by Stripe; when the referral programme is active, affiliate attribution is handled by Rewardful (US). We will add each to this list and disclose it before it processes your data.
You may exercise the following, subject to law and technical limits. You may also object to processing based on our legitimate interests (for example security and fraud prevention), and ask us to restrict processing while we handle a request. To the extent the GDPR applies to your use of the Service, we comply with it to that extent. For anything you cannot complete in Settings, email contact@sorva.ch; we respond within 30 days. Your rights include:
Primary data residency for storage is Switzerland. Our application and computation layer runs on EU infrastructure (Frankfurt, Germany), recognised as providing adequate protection. Some providers (usage analytics via Vercel Web Analytics, email delivery, and (when active) payments and affiliate attribution) may process data in the United States; this is covered by the Swiss-U.S. Data Privacy Framework (recognised adequate since 15 September 2024) where the provider is certified, otherwise by Standard Contractual Clauses with the Swiss addendum. Vercel Web Analytics data points are cookieless and aggregate (no stored IP, no cross-site identifier), so any such transfer carries no directly identifying data.
We may update this policy for legal or technical reasons. The current version and effective date always appear at the top. We will flag significant changes by appropriate means before they take effect, for example an in-product notice, and your continued use after the effective date constitutes acceptance. Version 1.0 (29 June 2026) aligns this policy with our Terms of Service v1.0, completes our company identity, adds concrete retention periods, and clarifies our processor disclosures. Version 1.1 (8 July 2026) corrects how the Standard recovery key is described, refines the analytics and referral disclosures, and focuses this policy on Swiss data protection law (the revFADP).
Questions about this Privacy Policy: Shreevya GmbH, Seemattstrasse 44, 4332 Stein AG, Switzerland:
Email: contact@sorva.ch