Privacy policy

Hezia Core is currently in closed beta. This policy explains in plain terms which data we process, why, with whom, for how long, and how to exercise your rights.

Who is responsible for your data?

The service is published by 2sevi-informatique (sole proprietorship — full identity and contact details in the legal notice). Contact for any question about your data: contact@heziacore.com.

Our principle: data minimisation

We only collect what the features you use actually need. The fact that a third-party service makes some information available is never, in itself, a reason to collect it. Hezia Core is funded by subscriptions and clearly disclosed partnerships — never by selling, renting or using your personal or financial data for advertising.

Data processed and purposes

  • Account: email address, hashed password (never readable), technical identifier “HC-ID” (formerly “PZ-ID”), two-factor authentication if you turn it on. We ask for no name, address, phone number or income. Purpose: creating and securing your account.
  • Financial data you enter or import: accounts, institutions, operations, holdings, assets, goals. Purpose: tracking your wealth — the core of the service.
  • Budget: operation labels are cleaned before being stored (IBANs, card numbers, references and people's names removed); an encrypted, non-reversible fingerprint may be used to recognise the same counterparty.
  • Personal wallets (optional): public addresses only, read-only. Never a recovery phrase, a private key or a signature.
  • Discord connection (optional): only your Discord identifier is kept, while the connection is active, to assign your roles on the community server.
  • Payment: the closed beta is free; no real payment is processed. Our technical tests use Stripe's test environment. Card data is never stored by Hezia Core.
  • Support: the messages you send us by email, in order to answer them.

Legal bases: performance of the service you request (account, tracking, Budget, wallets, payment); your consent for the Discord connection; our legitimate interest in the security of the service and in anonymised audience measurement, which you can object to at any time (see below).

Imported files

Files you import (PDF, CSV, OFX…) are stored in a private area while they are analysed, then deleted as soon as the analysis ends, whether it succeeds or fails. If the analysis cannot complete, an automatic purge deletes them at the latest when the import expires (24 hours by default). The formats we recognise (including text recognition, or OCR, of scanned statements in those formats) are read on our servers, with no third-party service.

A PDF statement that none of our readers recognises may be sent to Mistral AI, a provider specialised in document analysis, solely to extract its transactions, which you always review before anything is saved. It goes through Mistral AI's European endpoint, as stateless processing (the document is sent with the request, without being stored in a storage area of the provider). Zero Data Retention is enabled for the Hezia Core organisation, use of the data to train models is disabled, and so are experimental features (Labs). On our side, the file stays temporary and follows the deletion rules described above. Apart from this document reader, no artificial-intelligence assistance is enabled.

Optional participation in improving imports. When a PDF statement could not be validated automatically, Hezia Core may offer you, with no obligation, to keep a copy of this PDF in order to analyse its format and improve its support. If you accept it (a checkbox, never pre-ticked): the document is kept encrypted, in a dedicated area, only accessible to authorised Hezia Core staff, for 7 days at most after your consent; it is deleted earlier as soon as it is no longer needed, and you can withdraw your consent and delete it immediately from “My imports”. Declining has no consequence on your use of the service. During the beta, technical backups of the test server may contain an encrypted copy of the document; in production, this storage will be excluded from backups. After deletion, we may keep technical information that does not contain the content of your statement (bank concerned, type of failure, reader version, number of pages, format structure), as well as the link between your account and this case, so we can let you know when your bank's import has been improved. This text describes how the product works; it will be legally reviewed before the service opens to the public.

Recipients and providers

  • Hosting of the service: see the legal notice.
  • OVH (sending the service's emails: verification, password reset).
  • Stripe (payments — test environment only during the beta).
  • Discord (only if you link your account; Discord is a US company).
  • Matomo, an audience measurement tool installed on our own servers.
  • Mistral AI (reading PDF statements we do not recognise, see “Imported files”).

To value your assets, our servers query price providers (Twelve Data, Binance, CoinMarketCap) with instrument identifiers only, never data about you. If you track a wallet, its public addresses are sent, without your email or identity, to the blockchain reading providers needed (for example Alchemy). Exchange rates come from the European Central Bank through a service we host ourselves.

A Partner or referrer never sees your email, identity, wealth or portfolio.

Cookies and local storage

Hezia Core uses no advertising cookie and no social-network tracker. Only cookies needed for the service are set: sign-in cookies (secured, not readable by scripts) and the language cookie. Your display preferences (theme, chart period) and your audience-measurement choice are kept in your browser's local storage, never sent to our servers.

Audience measurement

We measure traffic with Matomo, installed on our own servers — never Google Analytics or Meta Pixel. Measurement works without cookies, honours your browser's “Do Not Track” setting, and page addresses are anonymised (no identifier, no financial data, never your email). You can turn it off here:

Audience measurement

Anonymised visit statistics are measured with Matomo, hosted by Hezia Core, without cookies. You can turn this measurement off at any time.

Retention periods

  • Account and financial data: as long as your account exists; deleted with it.
  • Imported files: until their analysis ends (24 hours at most by default).
  • Discord identifier: until you disconnect Discord.
  • Sign-in session: expires at the latest 7 days after your last use.
  • After an account is deleted, the following are kept, without your email: billing and credit history, referrals and Partner commissions, and security logs (technical HC-ID) — for our accounting obligations and the security of the service. Their retention period is not set yet; it will be stated here before the commercial launch.
  • Audience statistics: period not set yet, stated here before the commercial launch.

Your rights

You have the rights of access, rectification, erasure, restriction, objection and portability regarding your data.

  • Export your data: from your “Account” area, download at any time a ZIP archive (JSON and CSV files, with a manifest) containing the data associated with your account: profile, accounts, operations, holdings, wallets, Budget, imports, subscription and referrals.
  • Delete your account: from your “Account” area (irreversible, confirmation required).
  • Any other request: contact@heziacore.com. We answer within one month.

Complaint to the CNIL

If, after contacting us, you believe your rights are not respected, you can lodge a complaint with the French data protection authority, the CNIL (Commission nationale de l'informatique et des libertés): cnil.fr/fr/plaintes (in French).

Updates

This policy will evolve with the service, in particular before the commercial launch. Last updated: 2026-09-29.