Privacy Policy

Last updated: 13 June 2026

This is a personal, non-commercial application operated by a private individual ("the operator") for the sole purpose of accessing the operator's own bank account information. It is not offered to other users and processes no other person's data.

1. Data controller

The operator is the data controller. Contact for privacy matters: stianaiserver@gmail.com.

2. What data is accessed

Through Enable Banking (a regulated Account Information Service Provider under PSD2), the application accesses, on a read-only basis, the operator's own: account details (IBAN, account name), balances, and transaction history. The application does not initiate payments and cannot move money.

3. Purpose and legal basis

The data is used only to give the operator a private overview of their own finances via a personal AI assistant. The legal basis is the operator's explicit consent, granted through their bank's strong customer authentication (e.g. BankID).

4. Sharing

The data is not shared, sold, or disclosed to any third party. It is processed and stored only on a private server controlled by the operator.

5. Storage and retention

Account data is fetched on demand and cached only transiently. Access (consent) tokens expire automatically after at most 90 days as required by PSD2, after which renewed consent is required. Cryptographic keys and tokens are stored with restricted file permissions.

6. Your rights

As the data concerns only the operator's own accounts, the operator may revoke consent at any time via their bank or by deleting the stored tokens, which immediately ends all access.

7. Contact

For any question about this policy: stianaiserver@gmail.com.