Privacy policy

Last updated: 2026-09-07

1. Who is responsible

The data controller is Daniel Kulinski, a natural person, reachable at daniel.kulinski.dev@gmail.com. This application is a personal, non-commercial project with a single user: the controller, who is also the only data subject whose bank data is processed.

2. What data is processed

The data is obtained from the bank via Enable Banking Oy (Finland), a licensed account information service provider, under the EU Second Payment Services Directive (PSD2). Access happens only after the account holder gives explicit consent at the bank using the bank's own strong customer authentication.

3. Purpose and legal basis

The data is used solely for the controller's personal financial overview and analysis, including analysis performed by AI tools operated by the controller. The legal basis is the data subject's consent (GDPR Art. 6(1)(a)); since the controller and the data subject are the same person, no other individual's data is intentionally collected. Counterparty names appearing in transactions are processed only incidentally, as part of the controller's own records, on the basis of legitimate interest (GDPR Art. 6(1)(f)).

4. Where and how data is stored

5. Retention

Session records are kept until the bank consent expires (at most 180 days from authorisation, often 90 days depending on the bank) or until the controller deletes them manually, whichever is earlier. Exported data is retained on the controller's own devices at the controller's discretion.

6. Revoking consent

Consent can be withdrawn at any time by: (a) revoking the third-party access in the bank's online or mobile banking consent management, and/or (b) closing the session through Enable Banking, which revokes the consent at the bank, and/or (c) deleting the session record in this application. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

7. Sharing

Data is not sold, not used for advertising and not shared with any third party, except for the processors needed to run the application: Enable Banking Oy (the PSD2 provider that connects to the bank) and Railway Corporation (the hosting provider). No transfers to other recipients take place.

8. Your rights

Under the GDPR the data subject has the right of access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to withdraw consent at any time. To exercise these rights, contact daniel.kulinski.dev@gmail.com. A complaint may be lodged with the supervisory authority: the President of the Personal Data Protection Office in Poland (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.

9. Changes

This policy may be updated; the date at the top reflects the latest version.