Privacy policy
Last updated: 2026-09-07
1. Who is responsible
The data controller is Daniel Kulinski, a natural person, reachable at daniel.kulinski.dev@gmail.com. This application is a personal, non-commercial project with a single user: the controller, who is also the only data subject whose bank data is processed.
2. What data is processed
- Account identifiers of the controller's own payment accounts (IBAN, account name, currency, and the technical account UIDs assigned by Enable Banking).
- Account balances.
- Transaction history (dates, amounts, counterparties, payment references) of those accounts.
- Technical session identifiers and consent validity dates.
The data is obtained from the bank via Enable Banking Oy (Finland), a licensed account information service provider, under the EU Second Payment Services Directive (PSD2). Access happens only after the account holder gives explicit consent at the bank using the bank's own strong customer authentication.
3. Purpose and legal basis
The data is used solely for the controller's personal financial overview and analysis, including analysis performed by AI tools operated by the controller. The legal basis is the data subject's consent (GDPR Art. 6(1)(a)); since the controller and the data subject are the same person, no other individual's data is intentionally collected. Counterparty names appearing in transactions are processed only incidentally, as part of the controller's own records, on the basis of legitimate interest (GDPR Art. 6(1)(f)).
4. Where and how data is stored
- This application stores only session identifiers, account UIDs and consent validity dates in its
database, hosted on Railway. The deployment region is chosen as EU (Amsterdam,
europe-west4) where available. - Balances and transactions are fetched from Enable Banking on demand and are not persisted by this application unless the controller explicitly exports them (for example as CSV) to their own devices.
- Enable Banking Oy processes the data as a PSD2 service provider under its own privacy policy and end-user terms, which the account holder accepts during the bank authorisation flow.
5. Retention
Session records are kept until the bank consent expires (at most 180 days from authorisation, often 90 days depending on the bank) or until the controller deletes them manually, whichever is earlier. Exported data is retained on the controller's own devices at the controller's discretion.
6. Revoking consent
Consent can be withdrawn at any time by: (a) revoking the third-party access in the bank's online or mobile banking consent management, and/or (b) closing the session through Enable Banking, which revokes the consent at the bank, and/or (c) deleting the session record in this application. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
7. Sharing
Data is not sold, not used for advertising and not shared with any third party, except for the processors needed to run the application: Enable Banking Oy (the PSD2 provider that connects to the bank) and Railway Corporation (the hosting provider). No transfers to other recipients take place.
8. Your rights
Under the GDPR the data subject has the right of access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to withdraw consent at any time. To exercise these rights, contact daniel.kulinski.dev@gmail.com. A complaint may be lodged with the supervisory authority: the President of the Personal Data Protection Office in Poland (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.
9. Changes
This policy may be updated; the date at the top reflects the latest version.