Privacy Policy
Cifrova Personal reads your bank movements, so this policy matters more than most. It says what we hold, why, for how long, who else touches it, and how you get it back or gone. Marquez Consulting Unipessoal Lda, NIF 516048538, Rua Ilha de Santiago, Lote A46C, 8200-317 Albufeira, Portugal, is the controller. Write to [email protected] for anything here.
1. What we hold
| Data | Where it comes from | Why |
|---|---|---|
| Your email, name, sign-in times | You, at sign-in | To run your account and send the sign-in link and the emails you asked for |
| Bank accounts (name, IBAN, balance) and movements (date, amount, description, counterparty) | Your bank, through Fintable, with the consent you gave there; or files you import; or what you type | The whole point of the Service: the budget, the categories, the forecast, net worth |
| Categories, budgets, rules, notes, goals, loans, holdings, valuations | You | To keep your budget and net worth |
| Merchant names derived from bank text | Computed by us | So movements read cleanly and group |
| Questions you ask the Advisor and its answers | You | To answer them, and so you can read the thread again |
| Plan, invoices, payment status | Stripe | Billing and tax records |
| Server logs (IP address, time, page) | Your browser | Security and keeping the Service up; kept 30 days |
We do not hold your bank credentials, card numbers, or any data about children. We use one cookie, the session cookie that keeps you signed in; no analytics or advertising trackers.
2. Legal bases
- Contract (GDPR art. 6(1)(b)): almost everything above is needed to provide the Service you asked for.
- Consent (art. 6(1)(a)): the bank connection, which you give to Fintable and can withdraw there at any time; the optional emails beyond the ones the Service needs.
- Legal obligation (art. 6(1)(c)): keeping invoices and tax records.
- Legitimate interest (art. 6(1)(f)): security logs, preventing abuse, and improving the Service using aggregated, de-identified figures that cannot be traced back to a household.
3. Artificial intelligence
To suggest categories, write the weekly summary and answer Advisor questions, the Service sends the relevant movements (date, amount, description, merchant), your category list and, for the Advisor, summaries of your budget and net worth to Anthropic's Claude API. Anthropic acts as our processor, does not use API data to train its models, and retains it briefly for abuse monitoring under its terms. The AI is asked once per new merchant, not on every movement, and every automatic decision is visible and reversible in the app. If you prefer, you can bring your own Anthropic key in Settings; then the data goes under your own agreement with Anthropic.
4. Who else touches the data
Only processors bound by contract, listed with their role and location on the subprocessors page: the bank aggregator, the hosting provider, the email service, the AI provider, the payment provider and the network provider. Price feeds (CoinGecko, Yahoo Finance) receive only ticker symbols, never personal data. We do not sell data and we do not share it with advertisers.
Where a processor is outside the European Economic Area (Anthropic and Stripe have US entities), transfers rest on the EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
5. How long
- Your household's data: while the household exists. When you delete it, everything is erased at once from the live database and within 30 days from backups.
- An unpaid household after the trial: kept 90 days so you can come back, then deleted.
- Invoices and payment records: 10 years, as Portuguese tax law requires.
- Server logs: 30 days. Sign-in links: 15 minutes.
- Advisor threads: until you delete them or the household.
6. Your rights
You can access, correct, export and erase your data, restrict or object to processing, and withdraw consent, at any time. Most of it you can do yourself: Settings exports the whole household as files and deletes it. For anything else write to [email protected]; we answer within 30 days. You may also complain to the Portuguese authority, the CNPD (cnpd.pt), or to the authority of your own country.
7. Security
Everything travels over TLS. Bank and AI tokens are stored sealed with a key held outside the database. Access to servers is by key only, backups are encrypted and tested, and each household's data is separated by design so one household can never read another's. Should a breach ever affect your data we tell you and the CNPD within 72 hours as the law requires. Please keep the email account you sign in with secure: it is your key.
8. Children
The Service is for adults. We do not knowingly hold data about anyone under 18 except as it appears in your own movements (a school fee, for instance), which is yours to enter.
9. Changes
We update this policy when the Service or the law changes, with the date above and an email to the household's owner for anything material.