Legal
Sub-processors
Last updated · August 28, 2026
Centmond uses the following third parties to deliver the service. We pick the smallest set we can run on; if we add or remove one, we will update this page. Not all of them are sub-processors in the strict sense because the role each one plays is stated on its card, and it decides who you go to about your data.
How to read this list
- Processor means the provider acts only on our instructions under an Art. 28 GDPR contract. We stay responsible for your data, and you can bring any request to us.
- Independent controller means the provider decides its own purposes for what it receives. Its own privacy policy governs that part, and we cannot instruct it on your behalf.
- No personal data means nothing that could identify you is sent, such as a currency code or a public ticker symbol.
- Optional means the provider is only used when you switch on a related feature. If you never connect a bank, never open the assistant, and never enable email notifications, those providers receive nothing.
Current sub-processors and recipients
Supabase
ProcessorEU (eu-west-1, Ireland)- Purpose
- Database, authentication, and storage for user accounts and everything you sync.
- Data accessed
- Email address, authentication tokens, profile fields; accounts, transactions, balances, budgets, subscriptions, goals, investments, categories and rules, household settings; receipt-photo hashes; assistant conversations and assistant memory; notification settings; and operational logs. Bank identifiers are additionally encrypted at the field level.
- Transfer
- None required: the project runs in the EU region and the data stays there.
- Privacy policy
- https://supabase.com/privacy
Vercel
ProcessorGlobal edge network; company in the US- Purpose
- Hosting for the Centmond website and web app, plus cookie-free Web Analytics and Speed Insights when you allow the analytics category.
- Data accessed
- Request metadata for every page load (IP address, user agent, URL, timestamp) in edge and function logs, plus aggregate page-view counts and page-load timings. Analytics and Speed Insights set no cookies and do not identify you, but the request logs do contain your IP address, which is personal data.
- Transfer
- EU-US Data Privacy Framework, backed by Standard Contractual Clauses.
- Privacy policy
- https://vercel.com/legal/privacy-policy
Cloudflare
ProcessorGlobal edge network; company in the US- Purpose
- Turnstile bot protection on the sign-up, sign-in, password-reset and confirmation-resend forms. Strictly necessary: without it those endpoints can be attacked at scale.
- Data accessed
- IP address, user agent, and a challenge token, at the moment one of those four forms is opened or submitted. Cloudflare states that Turnstile does not use this to track visitors across sites and does not set an advertising cookie.
- Transfer
- EU-US Data Privacy Framework, backed by Standard Contractual Clauses.
- Privacy policy
- https://www.cloudflare.com/privacypolicy/
Sentry
ProcessorEU (Germany)- Purpose
- Server-side error monitoring, so a failure that hits your account can be found and fixed.
- Data accessed
- Error type and stack trace, the route that failed, runtime and version, and a pseudonymous account identifier. IP addresses, cookies and request headers are not attached, secrets and personal data are stripped from the event before it is sent, and no transaction data or assistant content is included.
- Transfer
- None required: the project runs on Sentry's EU region and events stay there.
- Privacy policy
- https://sentry.io/privacy/
Resend
ProcessorUS- Purpose
- Delivers account email (sign-up confirmation, password reset) and the optional notification emails you can enable in Settings: the weekly digest and the monthly data export.
- Data accessed
- Your email address and the full contents of the email, which for the digest includes account and spending summaries and for the monthly export includes a CSV or PDF attachment containing your transactions.
- Transfer
- EU-US Data Privacy Framework, backed by Standard Contractual Clauses.
- Privacy policy
- https://resend.com/legal/privacy-policy
Groq
ProcessorOptionalUS- Purpose
- Runs the model that generates answers for the optional AI assistant. Reached only through Centmond's own backend, never from your browser.
- Data accessed
- The question you type and only the specific rows the assistant looked up to answer it, never your whole account, and never any credential. Groq's API terms state that inputs and outputs submitted through the API are not used to train its models.
- Transfer
- Standard Contractual Clauses.
- Privacy policy
- https://groq.com/privacy-policy/
- Purpose
- Optional “Sign in with Google” authentication. Only used if you choose that button instead of an email and password.
- Data accessed
- Google learns that you are signing in to Centmond and returns your email address, display name and avatar URL. Google decides its own purposes for what it collects during that sign-in, so it acts as an independent controller and its own privacy policy governs that part.
- Transfer
- Governed by Google's own terms, not by a contract with us.
- Privacy policy
- https://policies.google.com/privacy
Frankfurter
No personal dataEU- Purpose
- Daily foreign-exchange reference rates used to convert mixed-currency balances and totals into your default currency.
- Data accessed
- No personal data: only public currency codes (e.g. EUR, USD) are sent. Rates are cached for 24h.
- Transfer
- Not applicable: no personal data is sent.
- Privacy policy
- https://www.frankfurter.app
Enable Banking
Independent controllerOptionalEU (Finland)- Purpose
- Open-banking gateway for the optional bank-connection feature. Enable Banking Oy is a Finnish AISP authorised and supervised by the Finnish Financial Supervisory Authority (FIN-FSA).
- Data accessed
- Bank name, IBAN, account balances, and booked / pending transactions for accounts you explicitly connect (typically the last 90 days, refreshed daily). Enable Banking holds the bank consent and the authentication session under its own licence (it is an independent controller for that, not our processor), and Centmond never sees your online-banking credentials.
- Transfer
- None required: the service is operated from the EU.
- Privacy policy
- https://enablebanking.com/privacy-policy
Finnhub
No personal dataOptionalUS- Purpose
- Primary stock / ETF price quotes, company logos, and symbol search for the optional Investments feature.
- Data accessed
- Only the public symbol of each asset you record (e.g. AAPL, MSFT). Finnhub responds with current price, 24h change, and a company profile (name, exchange, logo URL). Your identity and holdings are never sent.
- Transfer
- Not applicable: no personal data is sent.
- Privacy policy
- https://finnhub.io/policies/privacy
CoinGecko
No personal dataOptionalSingapore- Purpose
- Crypto price quotes and coin icons for the optional Investments feature.
- Data accessed
- Only the public symbol of each crypto asset you record (e.g. BTC, ETH). CoinGecko's free API requires no key and returns price, 24h change, and a coin image URL.
- Transfer
- Not applicable: no personal data is sent.
- Privacy policy
- https://www.coingecko.com/en/privacy
Alpha Vantage
No personal dataOptionalUS- Purpose
- Fallback stock / ETF price quotes for the optional Investments feature when Finnhub returns no match.
- Data accessed
- Only the public symbol of each asset you record. Alpha Vantage responds with current price; profile / logo data is not used from this provider.
- Transfer
- Not applicable: no personal data is sent.
- Privacy policy
- https://www.alphavantage.co/privacy/
Apple
Independent controllerGlobal- Purpose
- App Store and TestFlight distribution for the iPhone and Mac apps, once those are released.
- Data accessed
- Whatever Apple collects to deliver the app to your device. Apple decides its own purposes for that, so it is an independent controller and its own terms govern.
- Transfer
- Governed by Apple's own terms, not by a contract with us.
- Privacy policy
- https://www.apple.com/legal/privacy/
Transfers outside the EEA
Where a provider above is located outside the European Economic Area, the mechanism that covers the transfer is named on its card rather than described in general terms. You can request a copy of the safeguards we rely on for any of them (the relevant Standard Contractual Clauses, or the provider's Data Privacy Framework certification) by emailing the address below.
Notifications of changes
We will update this page whenever we add or remove a provider. For material changes (a new recipient of personal data, a change of role, or a change in where data is stored) we will also update the "last updated" date at the top of this page.
Questions
Email mani.scs.gh@gmail.com with any question about how we work with the providers above.
Questions? Email mani.scs.gh@gmail.com.