PRIVACY
Privacy Policy
This notice explains what the private preview processes, why it is needed, who receives it and the choices available to you.
Last updated: 7 October 2026Controller
Private preview. Registration and paid access are not open to the public. Verified operator identity, postal address and registration details must be configured before public launch.
Information processed
- Account identity and authentication data, including email, user identifier, session security information and MFA state.
- Workspace and financial data you enter or authorize, including accounts, balances, transactions, counterparties, assets, liabilities, classifications and planning assumptions.
- Connection metadata and provider evidence needed to synchronize Open Banking and broker sources.
- Security, audit and operational logs needed to diagnose failures and protect the service.
We do not ask for online-banking passwords. Bank authorization occurs with the bank and the Open Banking provider.
Purposes and legal bases
- Provide the requested service: authenticate you, store your workspaces, synchronize authorized sources and generate requested views. This is necessary to perform the service agreement.
- Protect and operate the service: prevent abuse, enforce access boundaries, investigate faults and maintain audit evidence. This relies on legitimate interests in security and reliability, balanced against user rights.
- Comply with law: retain or disclose limited information when a binding legal obligation applies.
Marketing and optional analytics are not part of the current preview. Consent is not bundled into sign-in.
Recipients and providers
Information is shared only where needed to operate the service. Current categories include database and authentication hosting (Supabase), web hosting (Vercel), API hosting (Render), Open Banking connectivity (Enable Banking), and an identity provider only when you choose social sign-in. Financial information is not sold to advertisers or data brokers.
International transfers
Some providers may process data outside Romania or the European Economic Area. Where required, the operator must use an applicable transfer mechanism and make details of the safeguard available on request. Provider locations and safeguards must be rechecked before public launch.
Retention and minimisation
We collect fields needed for authentication, financial aggregation, traceability and security. Financial history is retained while the workspace remains active or as needed for requested historical reporting. Authentication, audit and backup data follow provider retention and security schedules. Data that is no longer necessary must be deleted or anonymised unless law or the defence of legal claims requires retention.
Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection, and may complain to the Romanian data-protection authority (ANSPDCP). A request may require identity verification. Disconnecting a provider stops future access but does not automatically erase previously imported records; deletion is a separate request.
Automated decisions
Classifications, forecasts and suggestions support the user’s own review. The current service does not make solely automated decisions that produce legal or similarly significant effects.
Cookies, tracking and changes
See the Cookies and browser storage policy. Material changes to this notice must be published before the new processing begins where required.