Privacy Policy
Bankfolio is a personal finance tool. We access your bank transaction data only to display it in your spreadsheet. We do not sell your data, share it with advertisers, or use it for any purpose other than operating the service.
1. Who we are
Bankfolio is operated by Anish Nagesh ("we", "us", "our"), trading as Bankfolio. We are the data controller for personal data processed through this service.
Contact: bankfolio1@gmail.com
If you have a question, complaint, or wish to exercise your rights, please email us. We will respond within 30 days.
2. What data we collect
Account data
- Email address and encrypted password (via Supabase Auth)
- Account creation date
Bank connection data
- Your Open Banking access token and refresh token — stored encrypted using AES-256-GCM. We never store or see your bank login credentials.
- Bank account display name and last four digits of account number
- The date your tokens expire
Transaction data
- Transaction date, description, amount, currency
- Running balance
- AI-assigned category (e.g. "Groceries", "Transport")
- The original raw transaction record from your bank (stored as JSON)
Usage and billing data
- Your subscription plan (Free or Pro) and payment status
- Stripe customer ID and subscription ID (no card numbers — Stripe handles those)
- The spreadsheet ID of your linked Google Sheet
3. How we use your data
- Providing the service: Writing transactions to your Google Sheet, running daily sync, categorising transactions with AI.
- Billing: Processing subscription payments via Stripe.
- Service communications: Sending transactional emails (e.g. email verification, sync failure alerts).
- Security: Detecting and preventing fraud or abuse.
We do not use your transaction data for profiling, advertising, or any purpose unrelated to operating Bankfolio.
4. Legal basis for processing (UK GDPR)
- Contract performance (Art. 6(1)(b)): Processing your account and transaction data is necessary to provide the service you signed up for.
- Legitimate interests (Art. 6(1)(f)): Security monitoring, fraud prevention, service improvement.
- Consent (Art. 6(1)(a)): When you connect your bank via Open Banking, you explicitly consent to TrueLayer accessing your transaction data on our behalf.
5. Third-party services we use
We share your data with the following processors only to the extent necessary to operate the service:
- TrueLayer — Open Banking provider. Accesses your bank data under your explicit consent. Regulated by the FCA (FRN: 793171). TrueLayer Privacy Policy.
- Supabase — Database and authentication. Data is stored in AWS eu-west-1 (Ireland). Supabase Privacy Policy.
- Vercel — API hosting. Processes API requests in edge and serverless functions. Vercel Privacy Policy.
- Stripe — Payment processing. We share your email address; Stripe handles all card data. Stripe Privacy Policy.
- Anthropic — AI categorisation and the transaction chat feature. When you run AI categorisation or use the chat feature, your transaction descriptions are sent to Anthropic's API for processing. Anthropic does not store or train on your data under our API agreement. Anthropic Privacy Policy.
- Resend — Transactional email delivery (email verification, alerts). Resend Privacy Policy.
6. Data transfers
Your data is primarily stored in the EU (AWS eu-west-1, Ireland). Where data is transferred outside the UK/EEA (e.g. Anthropic processes in the US), we rely on the UK International Data Transfer Agreement or equivalent safeguards.
7. How long we keep your data
- Account and transaction data: Retained until you delete your account.
- Billing records: Retained for 7 years for legal/tax compliance.
- Backups: Purged within 30 days of account deletion.
8. Your rights under UK GDPR
You have the right to:
- Access a copy of the personal data we hold about you.
- Rectification of inaccurate data.
- Erasure ("right to be forgotten") — delete your account and all associated data at any time from the Bankfolio sidebar. We also respond to erasure requests by email.
- Data portability — your transaction data is already in your Google Sheet. Contact us for a machine-readable export.
- Objection to processing based on legitimate interests.
- Restriction of processing in certain circumstances.
- Withdraw consent — you can disconnect your bank at any time from the Bankfolio sidebar, which removes your Open Banking consent.
To exercise any of these rights, email bankfolio1@gmail.com. We will respond within 30 days.
9. Complaints
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113
10. Security
We take security seriously:
- Bank access tokens are encrypted at rest using AES-256-GCM with a random IV per encryption.
- All data is transmitted over HTTPS/TLS.
- Our API uses JWT authentication; your credentials are never stored in browser local storage.
- We never see your bank login credentials — Open Banking consent is handled directly by TrueLayer.
11. Cookies
The Bankfolio Google Sheets add-on does not use cookies. The bankfolio.co.uk landing page does not set tracking cookies.
12. Children
Bankfolio is not intended for use by anyone under 18 years of age. We do not knowingly collect data from minors.
13. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email or by a notice in the Bankfolio sidebar. The "last updated" date at the top of this page reflects the current version.