Privacy Policy
Finance — a private, non-commercial application. Last updated 9 August 2026.
1. Who runs this application
Alwin Paul operates this application as a private person. It is not a business, and it is not offered to the public. Contact: alwin.paulpv@gmail.com.
2. What the application does
The application reads the operator's own bank accounts and shows the operator a summary of income and expenses. It has exactly one user, who is also the operator.
3. What data it processes
- Bank account identifiers, including the IBAN and the account name.
- Account balances.
- Transaction records: date, amount, currency, counterparty name, counterparty IBAN, and the payment reference text.
- Categories and rules that the operator creates.
The application processes no data belonging to any other person.
4. Why it processes this data
The single purpose is a personal overview of the operator's own income and expenses. The data is not used for profiling, for advertising, for training a model, or for any other purpose.
5. Legal basis
Article 6(1)(a) GDPR: consent. The operator gives explicit consent to each bank during the authorisation step. The operator can withdraw that consent at any time, in the bank's own interface or by deleting the connection in the application.
6. Who receives the data
- The banks that hold the accounts, as the source of the data.
- Enable Banking Oy, a licensed account information service provider, which transports the data from the banks. See their own privacy notice at enablebanking.com/privacy-policy.
Nobody else receives the data. The application uses no analytics service, no advertising network, no error reporting service, and no artificial intelligence service.
7. Where the data is stored
On a private server operated by the operator, located in Germany. The database is not reachable from the public internet. Transport uses HTTPS only.
8. How long the data is kept
Until the operator deletes it. There is no automatic deletion, because the purpose is a long-term personal record. Deleting the database removes all of it.
9. Rights
The only data subject is the operator, who holds full and direct control over the database. The rights under Articles 15 to 21 GDPR — access, correction, deletion, restriction, portability, and objection — are exercised directly on that database.
10. Changes
This page changes when the application changes. The date at the top always shows the current version.