Skip to content
CapyCents
Open Banking AI Privacy Get early access
← Back to CapyCents

Privacy Policy

Last updated: 3 July 2026

CapyCents is a personal-finance app developed by Fausto Genga, based in Belgium. This policy explains what data CapyCents handles, why, where it lives, and the rights you have over it.

For any privacy question, or to exercise the rights below, contact faustogengaalfaro@gmail.com.

We are the data controller for the personal data described here.

🚧 Heads-up — bank connection is a planned feature, not yet live.

CapyCents today is a self-contained budget app: you log expenses yourself and organise them into ponds. The Open Banking integration described below (and the related email-import feature) is on the roadmap — we’re publishing the privacy details upfront so you know what to expect. We’ll announce it on the waitlist the moment it goes live.

The short version

  • We only process the financial data you choose to bring into the app — by typing it, or (in the future) by connecting a bank or enabling email import.
  • When bank access ships, it will be read-only and run over regulated Open Banking (PSD2). The app can read transactions; it can never move your money.
  • Everything is stored in the EU (Frankfurt, Germany), encrypted in transit and at rest.
  • We do not sell your data, show you ads, or train AI models on your finances.
  • You can export or permanently delete everything at any time.

What data we process

1. Data you enter yourself

Wallet names and balances, categories and sections, transactions (date, amount, merchant, notes, tags), monthly budgets, and an optional display name (defaults to “Cappy”).

2. Bank transaction data (planned — not yet enabled)

This feature is on the roadmap and not currently active in the app. When it ships, and only if you choose to connect a bank account, CapyCents will retrieve, on a read-only basis:

  • Account identifiers (IBAN, account name, currency, current balance).
  • Transaction history (typically the last 90 days at first connect, then ongoing), including amount, dates, counterparty name, and the remittance/reference text your bank provides.

We access this through Enable Banking, a regulated Open Banking provider acting as our Account Information Service Provider (AISP) under PSD2. We connect under read-only (AISP) permissions only — there is no payment-initiation access, so CapyCents cannot transfer, withdraw, or spend any money.

You authorise this access directly with your own bank, using your bank’s own secure login (Strong Customer Authentication). CapyCents and Enable Banking never see or store your bank login credentials. Bank authorisation expires and must be renewed at least every 90 days, in line with PSD2 — you can also revoke it instantly from within the app or from your bank at any time.

3. Email-import data (planned — not yet enabled)

Also on the roadmap, not currently active. When this optional BAC email-import feature ships, CapyCents will read only the transaction-notification emails from your bank in order to extract the amount, merchant, and date. We will request the narrowest Gmail scope needed for this and will not read, store, or transmit the rest of your mailbox. The feature will be entirely opt-in and off by default.

4. Authentication data

By default CapyCents creates an anonymous account on first launch — no email, no password — bound to your device’s keychain. If you opt in to Sign in with Apple, your account is linked to your Apple ID; Apple shares only an opaque identifier and, if you allow it, an email address. We never receive your Apple password.

The email you give us to join the waitlist on this website is used solely to notify you about access and is stored with our form provider; it is not linked to any in-app account.

What we do NOT collect

  • Your bank login credentials, passwords, or card PINs (we never see them).
  • Your real name (unless you type it as a display name), phone number, or postal address.
  • Your location (GPS, IP-based, or otherwise).
  • Advertising identifiers (IDFA / GAID) or cross-app tracking data.
  • Browsing/usage analytics tied to your identity.

CapyCents does not implement App Tracking Transparency prompts because there is no tracking to disclose.

How we use your data

We process your data only to:

  • Show you your wallets, transactions, budgets, and insights.
  • Import and de-duplicate bank/email transactions and match them to your wallets and categories.
  • Suggest a category for a transaction (see “AI categorisation” below).
  • Keep your account secure and the service working.

We do not sell, rent, or trade your data, use it for advertising, or feed it into AI/ML training pipelines.

AI categorisation

To suggest a spending category for a transaction, CapyCents sends only the merchant name and the transaction’s location (city/country) to Anthropic (the Claude API) for classification. Amounts, balances, and account identifiers are never sent. This is used only to return a suggested category. Per Anthropic’s API terms, this data is not used to train their models, and it is not retained beyond what’s needed to process the request.

Where your data is stored

Your in-app data is stored on Supabase (managed PostgreSQL) in Frankfurt, Germany (eu-central-1) — entirely within the EU.

  • Encryption at rest: AES-256.
  • Encryption in transit: TLS 1.2+.
  • Backups: encrypted snapshots, retained per Supabase’s policy.
  • Access: only the developer (Fausto Genga) and Supabase’s automated systems, under a signed Data Processing Agreement (DPA), where Supabase acts as a sub-processor.

Who we share data with (sub-processors)

We rely on a small set of processors, each under a DPA, strictly to deliver the service:

ProcessorPurposeData involvedPrivacy policy
Supabase, Inc.Hosting (database + auth), EU regionAll in-app datasupabase.com/privacy
Enable Banking Oy (planned)Open Banking (AISP) bank access — not yet enabledBank account + transaction dataenablebanking.com/privacy-policy
Anthropic, PBCAI category suggestionsMerchant name + location (city/country) only — never amounts or balancesanthropic.com/legal/privacy
Google LLC (planned)Gmail import — not yet enabledBank notification emails onlypolicies.google.com/privacy
Apple, Inc.Sign in with Apple (optional)Opaque ID, optional emailapple.com/legal/privacy
Netlify, Inc.This website + waitlist formWaitlist emailnetlify.com/privacy

We will update this list and the “Last updated” date whenever we add or change a processor.

How long we keep it

We keep your in-app data for as long as your account exists. When you delete your account, it is erased within seconds (see below). Bank authorisation tokens are deleted as soon as you disconnect a bank or the 90-day authorisation lapses. Waitlist emails are kept until launch or until you ask us to remove them.

Your rights under the GDPR

You are in the EU, so the GDPR applies. Your rights:

  • Access & portability: Settings → “Export my data” produces a CSV of every transaction, wallet, category, and budget. Free, immediate.
  • Erasure (“right to be forgotten”): Settings → “Delete my account” irreversibly erases all your data within seconds. See Delete your data.
  • Rectification: edit anything in-app at any time.
  • Restriction / objection / withdraw consent: disconnect your bank, disable email import, or delete the app and your account.
  • Lodge a complaint: you may complain to the Belgian Data Protection Authority — dataprotectionauthority.be.

Our legal bases are: consent (connecting a bank, enabling email import, AI suggestions) and performance of a contract (running the app you asked for).

Children

CapyCents is not directed at children under 16 (the GDPR age of consent in Belgium). We do not knowingly collect data from minors. If you believe a minor has used the app, contact us and we will delete their data.

Changes to this policy

If we change anything material — such as adding a processor or a new data flow — we will update this page and the in-app Privacy section, and revise the “Last updated” date above.

Contact

  • Developer / data controller: Fausto Genga, Belgium
  • Email: faustogengaalfaro@gmail.com
  • Belgian Data Protection Authority: dataprotectionauthority.be
CapyCents

Calm money, one pond at a time.

Product

Features Privacy Join the waitlist

Legal & support

Privacy Policy Terms of Service Delete your data Support

Contact

Questions or feedback? We’d love to hear from you.

✉️ faustogengaalfaro@gmail.com
© 2026 Fausto Genga faustogenga.app