← Hoard

Privacy Policy

Last updated 4 Oct 2026

Hoard (personal-finance-tracker.povilaskirna.com) is a private, non-commercial tool operated by Povilas Kirna to track personal subscriptions and recurring payments. Access is limited to its owner. This policy explains what data the app processes and why.

Who is responsible

Povilas Kirna is the controller of the data processed by this app. For any privacy question or request, contact the contact details at povilaskirna.com.

What data is processed

  • Transaction data: date, amount, currency, merchant or counterparty name, payment description and transaction type. It comes from bank statements the owner uploads (CSV) or from the owner's bank account through Open Banking, with explicit consent.
  • Account details returned by the bank when access is granted: account name, currency, and an IBAN shown only masked (last 4 digits).
  • Derived data: detected subscriptions, renewal dates, price changes, and the owner's own edits (names, categories, statuses).
  • Technical data: one strictly necessary session cookie that keeps the owner logged in, and standard server logs from the hosting provider (IP address, user agent, timestamps).

Bank login credentials are never seen or stored by this app. You authenticate directly with your bank.

Why it is processed

Only to show the account owner their own subscriptions, recurring spending and upcoming charges. Data is never sold, shared for advertising, or used to profile anyone. The legal basis is the owner's consent (in particular for bank account access under PSD2) and the legitimate interest of running the service the owner asked for.

Service providers

  • Enable Banking Oy (Finland), a licensed account information service provider, connects to the bank with the owner's consent and returns account and transaction data. It has read-only access and cannot initiate payments.
  • Vercel Inc. hosts the application.
  • Turso (ChiselStrike Inc.) hosts the application database.

These providers process data on the app's behalf, under their own security and data protection terms.

Service logos (for well-known services like Netflix and Spotify, or a website the owner enters) are fetched by the server from Google's and DuckDuckGo's public favicon services, using only the service's website address. Logos of stocks and funds are fetched the same way from Trading 212's public logo images, using only the instrument's ticker. No transaction data, amounts or anything identifying the owner is sent, and the browser never contacts these services directly.

How long data is kept

  • Transaction and subscription data is kept until the owner deletes it.
  • Bank access lasts at most 180 days per consent and can be revoked earlier at any time.
  • Hosting providers' logs follow their own retention periods.

Your rights and controls

  • Export: download all stored data as JSON in Settings → Data & sync.
  • Delete: "Delete all data" in Settings → Data & sync permanently removes all transactions and edits.
  • Withdraw consent: disconnect the bank in Settings → Data & sync, or revoke access from within your banking app.
  • You can also request access, correction or erasure by contacting the contact details at povilaskirna.com, and you may lodge a complaint with your data protection authority.

Security

All traffic is encrypted with HTTPS. The app is protected by a password, sessions use signed, HTTP-only cookies, and secrets are stored as encrypted environment variables. Access to bank data is read-only.

Cookies

The app sets a single strictly necessary cookie (st_session) after login. There are no analytics, advertising or third-party tracking cookies.

Changes

If this policy changes, the date at the top of this page will be updated.