Privacy Policy

Version 1 · effective 1 October 2026

Cifrova Personal reads your bank movements, so this policy matters more than most. It says what we hold, why, for how long, who else touches it, and how you get it back or gone. Marquez Consulting Unipessoal Lda, NIF 516048538, Rua Ilha de Santiago, Lote A46C, 8200-317 Albufeira, Portugal, is the controller. Write to [email protected] for anything here.

1. What we hold

DataWhere it comes fromWhy
Your email, name, sign-in timesYou, at sign-inTo run your account and send the sign-in link and the emails you asked for
Bank accounts (name, IBAN, balance) and movements (date, amount, description, counterparty)Your bank, through Fintable, with the consent you gave there; or files you import; or what you typeThe whole point of the Service: the budget, the categories, the forecast, net worth
Categories, budgets, rules, notes, goals, loans, holdings, valuationsYouTo keep your budget and net worth
Merchant names derived from bank textComputed by usSo movements read cleanly and group
Questions you ask the Advisor and its answersYouTo answer them, and so you can read the thread again
Plan, invoices, payment statusStripeBilling and tax records
Server logs (IP address, time, page)Your browserSecurity and keeping the Service up; kept 30 days

We do not hold your bank credentials, card numbers, or any data about children. We use one cookie, the session cookie that keeps you signed in; no analytics or advertising trackers.

2. Legal bases

  • Contract (GDPR art. 6(1)(b)): almost everything above is needed to provide the Service you asked for.
  • Consent (art. 6(1)(a)): the bank connection, which you give to Fintable and can withdraw there at any time; the optional emails beyond the ones the Service needs.
  • Legal obligation (art. 6(1)(c)): keeping invoices and tax records.
  • Legitimate interest (art. 6(1)(f)): security logs, preventing abuse, and improving the Service using aggregated, de-identified figures that cannot be traced back to a household.

3. Artificial intelligence

To suggest categories, write the weekly summary and answer Advisor questions, the Service sends the relevant movements (date, amount, description, merchant), your category list and, for the Advisor, summaries of your budget and net worth to Anthropic's Claude API. Anthropic acts as our processor, does not use API data to train its models, and retains it briefly for abuse monitoring under its terms. The AI is asked once per new merchant, not on every movement, and every automatic decision is visible and reversible in the app. If you prefer, you can bring your own Anthropic key in Settings; then the data goes under your own agreement with Anthropic.

4. Who else touches the data

Only processors bound by contract, listed with their role and location on the subprocessors page: the bank aggregator, the hosting provider, the email service, the AI provider, the payment provider and the network provider. Price feeds (CoinGecko, Yahoo Finance) receive only ticker symbols, never personal data. We do not sell data and we do not share it with advertisers.

Where a processor is outside the European Economic Area (Anthropic and Stripe have US entities), transfers rest on the EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.

5. How long

  • Your household's data: while the household exists. When you delete it, everything is erased at once from the live database and within 30 days from backups.
  • An unpaid household after the trial: kept 90 days so you can come back, then deleted.
  • Invoices and payment records: 10 years, as Portuguese tax law requires.
  • Server logs: 30 days. Sign-in links: 15 minutes.
  • Advisor threads: until you delete them or the household.

6. Your rights

You can access, correct, export and erase your data, restrict or object to processing, and withdraw consent, at any time. Most of it you can do yourself: Settings exports the whole household as files and deletes it. For anything else write to [email protected]; we answer within 30 days. You may also complain to the Portuguese authority, the CNPD (cnpd.pt), or to the authority of your own country.

7. Security

Everything travels over TLS. Bank and AI tokens are stored sealed with a key held outside the database. Access to servers is by key only, backups are encrypted and tested, and each household's data is separated by design so one household can never read another's. Should a breach ever affect your data we tell you and the CNPD within 72 hours as the law requires. Please keep the email account you sign in with secure: it is your key.

8. Children

The Service is for adults. We do not knowingly hold data about anyone under 18 except as it appears in your own movements (a school fee, for instance), which is yours to enter.

9. Changes

We update this policy when the Service or the law changes, with the date above and an email to the household's owner for anything material.

Contact. Marquez Consulting Unipessoal Lda · Rua Ilha de Santiago, Lote A46C, 8200-317 Albufeira, Portugal · [email protected]