Legal
Privacy Policy
Last updated · August 28, 2026
Centmond is a personal finance app that runs in your web browser. We built it on a simple principle: your money is yours, your data is yours, and the optional assistant that helps you understand them is yours to switch on or leave alone. This policy sets out, for each thing we do with your data, what is processed, why, on what legal basis, who receives it and how long it is kept. Native iPhone and Mac apps are in development; this policy will be updated before they are released.
The short version
- The assistant is optional. When you use it, only the specific data your question needs is sent to our inference provider, never your whole account. It reads your data and can prepare changes to it, but it never applies one without your confirmation.
- Your financial data is encrypted in transit and at rest and stored on EU-hosted infrastructure. Access is restricted per user by database row-level security, and bank identifiers are additionally encrypted at the field level.
- We do not sell data, run advertising networks, or run cross-site trackers. We do use one cookie-free analytics tool, and it only loads if you allow it.
- Bank connections are optional. When you use them, a regulated third-party AISP (Enable Banking, registered in Finland) handles the bank login and holds your consent. We never see your online banking credentials.
Data controller
The controller responsible for processing your personal data under the EU General Data Protection Regulation (GDPR) is:
Seyedmani Hosseinighahroodi
Centmond (sole proprietor, Einzelunternehmen)
Germany
Email: mani.scs.gh@gmail.com
The full postal address required by § 5 DDG is on the Imprint page. We have not appointed a data protection officer: a one-person business below the thresholds of Art. 37 GDPR and § 38 BDSG is not required to, and the address above reaches the controller directly.
What we process, and why
Each card below is one processing operation. Anything not listed here we do not do, and if that changes, this page changes with it.
Account and sign-in
- Data
- Email address; a password hash, or the account identifier your sign-in provider returns; display name and avatar URL if you sign in with Google; language preference; session and refresh tokens; two-factor factors if you enable them.
- Purpose
- Creating your account, signing you in, keeping you signed in, and protecting the account from takeover.
- Legal basis
- Art. 6 (1) (b) GDPR: performance of the contract. An email address is required: without one we cannot create an account for you.
- Recipients
- Supabase (EU). Google, only if you choose Sign in with Google.
- Retention
- For as long as the account exists. Sessions expire far sooner; everything is deleted with the account.
Your financial data
- Data
- Accounts, transactions, balances, budgets, subscriptions, goals, investments and holdings, categories and rules, household settings, and any notes you write.
- Purpose
- Providing the product itself: showing, organising and analysing your finances, and syncing them between the devices you sign in on.
- Legal basis
- Art. 6 (1) (b) GDPR: performance of the contract.
- Recipients
- Supabase (EU). Bank identifiers are additionally encrypted at the field level with AES-256-GCM.
- Retention
- Until you delete the item. On account deletion, removed from the live database within 30 days.
Bank connection (optional)
- Data
- Bank name and country; account names, IBANs, balances and currencies; booked and pending transactions for the period your bank exposes, typically the last 90 days. Your online-banking credentials never reach us.
- Purpose
- Importing your transactions automatically instead of by hand.
- Legal basis
- Art. 6 (1) (b) GDPR for the import, plus the separate PSD2 consent you grant to Enable Banking in your bank's own flow. Entirely optional: connect no bank and none of this happens.
- Recipients
- Enable Banking Oy (Finland, EU), Supabase (EU).
- Retention
- Bank consent expires after the period your bank set, commonly 90 days. Imported transactions stay in your dashboard until you delete them or close your account.
AI assistant (optional)
- Data
- The question you type, the rest of that conversation, the assistant memory you allow it to keep, and only the specific rows it looked up in order to answer. Never your whole account, and never a credential.
- Purpose
- Answering your question about your own data, and preparing changes that you then confirm or discard.
- Legal basis
- Art. 6 (1) (a) GDPR: consent, given by opening the assistant and withdrawable at any time by leaving it switched off; Art. 6 (1) (b) for storing the conversation in your own account.
- Recipients
- Groq (US) runs the model; Supabase (EU) stores the conversation. Groq's API terms state that inputs and outputs are not used to train its models.
- Retention
- Conversations and assistant memory stay until you delete them or close your account. The provider processes the prompt for that request only.
Receipt scanning
- Data
- A SHA-256 fingerprint of the photo, plus the merchant, date and total you confirm on screen. The photo itself is read on your own device. It is stored only if you tick “Keep the photo with this transaction” on that screen, and what is then stored is a re-encoded copy with its EXIF metadata (including any GPS coordinates) removed.
- Purpose
- Filling in a transaction from a receipt, recognising the same photo if you pick it twice so you do not get a duplicate, and, at your request, keeping the photo with the transaction as your record of the purchase.
- Legal basis
- Art. 6 (1) (b) GDPR (performance of the contract) for the fingerprint and the details you confirm; Art. 6 (1) (a) (consent) for keeping the photo itself, given per receipt and withdrawable by deleting the photo from the transaction.
- Recipients
- Supabase (EU) stores the transaction and, only if you asked for it, the photo. No image is ever sent to an OCR or AI provider. The reading happens in your browser.
- Retention
- The fingerprint lives as long as the transaction it belongs to. A photo you chose to keep stays until you delete it, delete the transaction, or close your account.
- Data
- Your email address and the full content of the message. For the monthly export, that includes a CSV or PDF of your transactions as an attachment.
- Purpose
- Account email (sign-up confirmation, password reset, security and policy notices) and the optional weekly digest and monthly export.
- Legal basis
- Art. 6 (1) (b) GDPR for account email; Art. 6 (1) (a) GDPR for the optional notifications, which you switch on and off in Settings.
- Recipients
- Resend (US).
- Retention
- We keep no copy of a sent message. Delivery logs at the provider expire on its own schedule.
Website analytics (only if you allow it)
- Data
- Page URL, referrer, coarse country, device type, and page-load timings. No cookie is set and no cross-site identifier is created.
- Purpose
- Seeing which pages are used and how quickly they load, in aggregate.
- Legal basis
- Art. 6 (1) (a) GDPR and § 25 (1) TDDDG: consent. Nothing loads before you allow it, and refusing changes nothing about the product.
- Recipients
- Vercel (US company, global edge network).
- Retention
- Aggregate reports at the provider. There is no per-visitor record for us to look up.
Bot protection and security logs
- Data
- IP address, user agent and a challenge token on the sign-up, sign-in, password-reset and confirmation-resend forms; request metadata (IP, user agent, URL, timestamp) in server logs.
- Purpose
- Telling a person from a bot on the four account endpoints, and detecting abuse of the service.
- Legal basis
- Art. 6 (1) (f) GDPR: our legitimate interest in stopping account takeover and automated abuse. Weighed against it: the processing is limited to four form endpoints and to server logs, builds no profile, and is not used for any other purpose. § 25 (2) No. 2 TDDDG covers the technical storage this requires, so it is not consent-based and cannot be switched off.
- Recipients
- Cloudflare (Turnstile), Vercel (server and edge logs).
- Retention
- Short: the providers' operational log retention, days rather than months.
Error monitoring
- Data
- Error type and stack trace, the route that failed, runtime and version, and a pseudonymous account identifier. IP addresses, cookies and request headers are not attached, and secrets and personal data are stripped before the report is sent.
- Purpose
- Finding and fixing failures that hit real accounts.
- Legal basis
- Art. 6 (1) (f) GDPR: our legitimate interest in a service that works. Weighed against it: the report carries no transaction data and no assistant content, and identifies you only by an internal id.
- Recipients
- Sentry, on its EU region (Germany).
- Retention
- The provider's default event retention, 90 days.
Backups
- Data
- Everything above, as part of an encrypted database backup.
- Purpose
- Restoring the service after a failure or a mistake.
- Legal basis
- Art. 6 (1) (f) GDPR and Art. 32 GDPR: security and availability of processing.
- Recipients
- Supabase (EU).
- Retention
- Backup copies age out on the backup schedule. Deleting your account removes the live data within 30 days; the backups that still contain it are not restored to bring it back.
What we do not collect
- Assistant conversations for resale or profiling. Every query the assistant runs on your behalf is restricted by database row-level security to your own rows. When you ask a question, only the specific data that question needs is sent to our inference provider (never your whole account), and we never sell it or use it to profile you. Background jobs that run without you present (the nightly bank sync, the digest mailer) use a service role rather than your session, and are scoped in code to the one account they are working on.
- Receipt photos, unless you ask us to keep one. When you scan a receipt, in the browser or in the iPhone app, the photo is read entirely on your own device. It is never sent to an optical-character-recognition service, to an AI model, or to any other company: the reader runs inside your browser, which is the reason that page takes a moment to start the first time. By default nothing leaves your device but the handful of details you confirm on screen (the merchant, the date, the total), and the individual line items are read on your device and deliberately not saved anywhere. One further thing leaves with those details: a fingerprint of the photo (a SHA-256 hash, a fixed string of letters and numbers from which the picture cannot be reconstructed), which we store alongside the transaction for as long as it exists, so that picking the same photo again is recognised and does not create a second copy of the same purchase.
- The exception, and it is yours to make. The confirm screen offers “Keep the photo with this transaction”. It is off unless you turn it on, and it is the only thing in Centmond that puts a receipt image on a server. Tick it and a copy is stored in a private area of our storage that only your own account can read, attached to that one transaction. The copy is re-encoded before it is sent, which removes the EXIF metadata a phone writes into a photo, including the GPS coordinates of where it was taken. You can delete it from the transaction at any time, and it goes with the transaction and with your account.
- Device or behavioural profiles. We do not fingerprint your device, build a behavioural profile, or follow you across other sites. The bot check on the account forms reads an IP address and a user agent to tell a person from a script, and is not used for anything else.
- Your bank credentials. When you use the bank connection feature, you authenticate directly with your bank through Enable Banking's consent flow. Your username, PIN, and 2FA codes never touch Centmond's servers.
Bank connections
Connecting a bank account inside Centmond is optional. When you choose to connect a bank, we use Enable Banking Oy, a Finnish Account Information Service Provider (AISP) authorised and supervised by the Finnish Financial Supervisory Authority (FIN-FSA), as the regulated open-banking gateway.
Clicking Connect bank redirects you to your bank's own authentication flow via Enable Banking. Your bank credentials and any 2FA challenge live entirely inside that flow. Enable Banking holds the resulting consent under their AISP licence and is an independent controller for that part; Centmond never sees or stores your online-banking credentials.
You can disconnect a bank at any time from Accounts → Bank connections → Remove; that revokes the Enable Banking session and stops further fetches. Existing transactions stay in your dashboard unless you delete them. Enable Banking's own privacy policy applies in addition to ours and is available at enablebanking.com/privacy-policy.
Investments price data
If you record a holding in the Investments section, Centmond queries public market-data providers to keep its current price up to date. We only send each provider the public symbol of the asset (e.g. AAPL, BTC). We never send your identity, holdings, or any account-level data, so no personal data leaves the EU for this.
- Finnhub for stock and ETF quotes, company logos, and symbol search.
- CoinGecko for crypto prices and coin icons. No API key, no account, plain HTTPS lookup by symbol.
- Alpha Vantage as a fallback for stock and ETF symbols Finnhub doesn't cover.
- Frankfurter for daily currency reference rates, so balances in several currencies can be shown in one.
Who receives your data
The complete list, with the role each provider plays, the data it receives, where it stores that data and the transfer mechanism that covers it, is on the Sub-processors page. Not all of them are processors acting on our instructions: Google, Apple and Enable Banking decide their own purposes for part of what they receive and are independent controllers for that part, which means their own policies govern it and we cannot instruct them on your behalf.
We do not use third-party advertising networks, third-party analytics platforms beyond the one named above, or any cross-site trackers, and we do not sell personal data to anyone.
International transfers
Our primary infrastructure (Supabase, Sentry, Enable Banking) is hosted in the EU, and the data there stays there. Four recipients are outside the EEA: Vercel, Cloudflare, Resend and Groq for the assistant, plus Apple and Google under their own terms.
For Vercel, Cloudflare and Resend the transfer is covered by the EU-US Data Privacy Framework, backed by Standard Contractual Clauses; for Groq, by Standard Contractual Clauses. The mechanism is named per provider on the Sub-processors page rather than described in general terms, and you can request a copy of the safeguards we rely on for any of them by emailing the address at the bottom of this page.
Cookies and the website
The Centmond website does not set advertising cookies and does not run third-party trackers. Cookies set on the marketing site are strictly necessary for basic site function. The signed-in dashboard sets an authentication cookie so we can keep you logged in. These are exempt from consent under § 25 (2) No. 2 TDDDG (the successor to the TTDSG, renamed in May 2024) and Art. 5 (3) of the ePrivacy Directive.
On top of the legal minimum, we show a cookie banner on your first visit. You can accept all categories, reject everything optional, or open the customise view to toggle individual categories, where every optional category is off until you turn it on. Your choice, the version of the notice it was given against, and the time you gave it are stored locally in your browser; you can change it any time via Cookie preferences in the footer, and if we change what a category covers we will ask again.
The only optional category that currently loads anything is Analytics, which enables Vercel Web Analytics and Vercel Speed Insights. Both are cookie-free and do not track users across sites. Separately from consent, every request to the site reaches Vercel's edge network and appears in its server logs with an IP address. That is unavoidable for any hosted website, is covered by the security-logs row above, and is not what the analytics category controls.
Automated decision-making
We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you, within the meaning of Art. 22 GDPR. Centmond does analyse your data: it suggests a category for a transaction, flags a subscription, forecasts a balance, and the assistant answers questions about it. But these are suggestions inside your own account. Nothing here decides your access to a service, your creditworthiness, or any right, and every change the assistant prepares waits for you to confirm it.
Data retention
Retention is stated per processing operation in the table above rather than as a single number, because it genuinely differs: a security log lives for days, a transaction for as long as you keep it. As a general rule we keep your data for as long as your account is active.
When you delete your account, the live data is removed from our backend within 30 days. Encrypted backups that still contain it age out on the backup schedule and are never restored in order to bring deleted data back. Where the law requires us to keep something longer, we restrict its processing instead of deleting it, and use it only for that legal purpose.
Your rights
From inside the app you can, at any time and without asking us:
- Export your data (JSON, CSV, PDF), which is also how the right to data portability is served.
- Delete your account, which removes your data from our backend within 30 days.
- Switch the assistant off, which withdraws the consent it runs on and stops any data reaching the inference provider.
- Disconnect any bank from the Accounts page, which revokes the Enable Banking session immediately.
Under the GDPR you also have the right to access (Art. 15), rectify (Art. 16), erase (Art. 17), restrict processing of (Art. 18) and port (Art. 20) your personal data, and the right to object (Art. 21) to the processing we base on a legitimate interest: the security logs and error monitoring above. Where processing rests on consent, you can withdraw it at any time, which does not affect what was lawful before the withdrawal. To exercise any of these, email mani.scs.gh@gmail.com; we answer within one month.
You also have the right to complain to a supervisory authority. The one competent for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany. You may instead complain to the authority where you live or work.
Children
Centmond is not offered to anyone under 18, and the Terms require you to be 18 to open an account. We do not knowingly collect data from anyone under that age; if you believe a minor has provided us with personal information, contact us and we will delete it and close the account.
Changes to this policy
If we make material changes, we will update the "last updated" date at the top of this page and, where appropriate, notify you in the app or by email. Where a change needs your consent, we will ask for it rather than assume it. We will not silently broaden how we use your data.
Contact
For any privacy question, request, or complaint, email mani.scs.gh@gmail.com.
Questions? Email mani.scs.gh@gmail.com.