Privacy Policy

Last updated: 31 August 2026

1. What this service is

This is a private, self-hosted installation of Firefly III, a personal finance manager. It is operated by one individual for managing their own household finances. It is not a public service, it is not offered to other people, and no accounts are available to anyone else.

2. Data controller

Matej Ajster — an individual acting in a personal capacity.
Contact: matej.ajster@gmail.com

3. Whose data is processed

Only the operator's own data. There is exactly one user of this service, and that user is also the sole data subject. No data belonging to any other person is collected, imported, or processed.

4. What data is processed

5. Where it is stored

On a single virtual server rented from Hetzner Online GmbH, located in Nuremberg, Germany. All data remains within the European Union. The database is not exposed to the internet and is reachable only from within the server.

6. Third parties involved

The following services necessarily receive some data in order to function:

ProviderWhat it receivesWhy
Hetzner Online GmbH (Germany) All stored data, as the hosting provider Runs the server
Enable Banking Oy (Finland) Account access authorisation and the transaction data it returns Retrieves transactions from the operator's own bank under PSD2
Google (Gemini API) Transaction descriptions, merchant names, and amounts Suggests a spending category for each transaction
Backblaze Inc. Backups, encrypted on the server before upload Off-site backup storage

Data is not sold, rented, shared for advertising, or disclosed to anyone else. There are no analytics, trackers, or advertising services on this site.

7. Automated categorisation

Transaction descriptions and amounts are sent to Google's Gemini API to suggest a category. Only the transaction text and amount are sent — no account numbers, names, or credentials. Every transaction changed this way is tagged, so the operator can review or reverse it. This feature can be turned off entirely, in which case nothing is sent to Google.

8. Retention and deletion

Financial records are kept until the operator deletes them. Bank access consent expires automatically under PSD2 rules (typically every 90–180 days) and must be renewed deliberately. Consent can be withdrawn at any time through Enable Banking or by deleting the application, which immediately stops any further access to bank data.

9. Data subject rights

As the sole data subject is also the operator and administrator of this system, rights of access, rectification, erasure, and portability are exercised directly through full administrative control of the server and its data. Enquiries may be sent to the contact address above.

10. Security

All traffic is served over HTTPS. Administrative access is restricted to SSH key authentication with passwords disabled. Backups are encrypted before leaving the server. Credentials are stored outside version control.

11. Changes

This policy may be updated if the setup changes. The date at the top reflects the current version.