Privacy Policy
How we handle and protect your personal data.
Last updated : 20 August 2026
This policy describes how Tefin (“we”, “the application”) collects, uses, retains and protects your personal data when you use our mobile application and website (the “Service”), in accordance with the General Data Protection Regulation (GDPR, EU 2016/679) and the French Data Protection Act. It sets out in particular how your banking data is handled, through read-only tokenisation and encryption.
1. Data controller
The data controller is Virgil Haranger, sole trader (French micro-entreprise) trading as “Tefin”, company number (SIREN) 105 811 798, registered office at 31 rue Diderot, 91270 Vigneux-sur-Seine, France.
For any question about your personal data, contact us at contact@tefin.fr. No data protection officer has been appointed, as appointment is not mandatory given the nature and volume of the processing carried out.
2. Data we collect
Using the Service requires creating an account: there is no guest mode and no anonymous session. We collect the following categories of data.
- Account data: email address, account identifier and, if you provide one, a display name. They are created and managed through our authentication provider.
- Budget and asset data: income, charges, recorded transactions, categories, goals, time horizon, savings accounts and holdings. This data is encrypted before being stored in our database.
- Aggregated bank data: if you connect an account, we receive — through our authorised provider Powens (see §4 and §5) — read-only information: account identity and type, IBAN, balances, transaction history and, where applicable, holdings within your investment wrappers (French PEA, securities account, life insurance, employee savings). We never have access to your banking credentials or to any payment method, and we cannot carry out any operation on your accounts.
- Digital-asset data: if you choose to, the holdings on your cryptocurrency platforms, provided by the same aggregation provider as your bank accounts and on a read-only basis. Those platforms require a read-only key, which you enter in the provider's secure interface and which the provider stores: it is never passed on to us and we do not store it.
- Subscription data: plan status (free or Premium), where the subscription originated (website, App Store, Google Play), renewal date and free-trial status. These are managed through our payment providers. We neither collect nor store any payment card data.
- Household data: if you create or join a shared space, the shared expenses, splitting rules and balances between members are stored there in encrypted form and are visible to the other members of that household. You explicitly choose which savings accounts are shared; the others remain invisible. A household may include participants who have no Tefin account: in that case only the first name you enter is stored.
- Account security data: if you enable two-factor authentication, the associated secret and your recovery codes are stored in protected form. The mobile app lock (passcode, fingerprint or face recognition) is handled entirely on your device: neither the passcode nor any biometric data is ever sent to us.
- Technical data: push notification token (if you enable notifications), the name, model and system version of the device the app is installed on, the app version, and access and error logs required to operate and secure the Service. This device information is used to deliver notifications and to reproduce an issue you report. We collect no advertising identifier, no IMEI, no serial number — nothing that would let anyone follow you from one service to another.
Some settings stay on your device only and never reach us: light or dark theme, the app-lock state, and data cached for offline consultation.
3. Purposes and legal bases
We process your data for the following purposes:
- Providing the Service (budget tracking, account aggregation, simulations, synchronisation across your devices) — legal basis: performance of the contract (our terms of use).
- Connecting to your bank accounts — legal basis: your explicit consent, given during PSD2 authorisation with your bank and revocable at any time.
- Sharing within a household — legal basis: your consent, expressed by joining the shared space and by selecting the accounts you expose there.
- Managing subscriptions and the free trial — legal basis: performance of the contract.
- Account information messages (reminders about the end of the free trial and its consequences, confirmation of a referral benefit) — legal basis: performance of the contract. These are not marketing communications and therefore cannot be switched off while the contract is running.
- Follow-up after a trial ends (a single message, one week after the end date) — legal basis: legitimate interest in offering a similar service to someone already registered. You may object at any time, using the unsubscribe link in the message or by writing to us; the objection takes effect immediately and does not affect the contractual messages above.
- Referrals — legal basis: performance of the contract. When a code is used, we record the link between the referring and referred accounts, the date, and the status of the benefits granted. The referrer only ever sees aggregate counters: neither the identity, nor the email address, nor the activity of the people they referred is disclosed to them.
- Notifications of new transactions — legal basis: your consent, given at operating-system level and withdrawable at any time.
- Security, fraud prevention and legal obligations — legal basis: legitimate interest and legal obligation.
We carry out no advertising profiling and no automated decision-making producing legal effects concerning you. Your data is never used to train a machine-learning model.
4. Bank aggregation through Powens (PSD2) and consent
Connecting to your accounts relies on the Payment Services Directive (PSD2) framework and is carried out through Powens, an account information service provider (AISP) authorised by the French Prudential Supervision and Resolution Authority (ACPR). Tefin makes this feature available as an agent of Powens; access is strictly read-only (account information service), with no payment initiation capability whatsoever.
You authenticate directly with your bank through the secure Powens interface (strong customer authentication — SCA). At no point does Tefin see, receive or store your banking credentials. Under PSD2, your consent may require periodic re-authentication (typically every 90 to 180 days depending on your bank).
You may disconnect a bank and withdraw your consent at any time from the application: the corresponding connection is then deleted at Powens and the associated access revoked. Transactions already imported remain in your space until you delete them — it is your history, and erasing it must remain your decision (see §7).
5. Tokenisation, encryption and storage
To protect your financial information, we apply the following principles:
- Read-only tokenisation: your banking credentials never pass through Tefin. After your strong authentication, Powens issues a technical access token that replaces them and only permits reading your data. That token is encrypted in our database and is never exposed to the application installed on your device.
- Application-level encryption: beyond our host’s disk encryption (AES-256 at rest), all sensitive data — financial model, IBAN, account names and balances, access tokens, API secrets and household data — is encrypted at application level. The encryption key is held by our server functions and is never stored in the database.
- Location: the database, server functions and backups are hosted in Frankfurt, Germany (region eu-central-1), therefore within the European Union.
- Restricted access: reading and writing encrypted data goes exclusively through secured server functions. The client application has no direct access to banking tables; it reads your accounts through a dedicated server function that decrypts only what is necessary.
- Per-user isolation: every record is partitioned (Row Level Security) so that you can only access your own data.
- No third-party calls from your device: external elements shown in the application — institution logos, asset prices, inflation rates — are fetched by our own servers and then relayed. No request leaving your device therefore reveals to a third party where you bank.
6. Processors and recipients
We never sell your data and never disclose it to advertisers. We use the following processors, all bound by contractual confidentiality and security obligations:
- Powens (France) — PSD2 bank aggregation (ACPR-authorised AISP); receives your authentication and provides read-only account data.
- Supabase — database, authentication and server functions, hosted in Frankfurt (European Union).
- Vercel (United States) — hosting and delivery of the website. Public pages are static and process no personal data; application requests transit through this delivery network before reaching our server functions.
- Stripe — collection of subscriptions purchased on the web.
- Resend — delivery of the emails we send you directly (trial end reminders, referral benefit confirmations, support). Only your email address and the message content are passed to it; no banking or wealth data appears in them. Authentication emails (signup confirmation, password reset) are still sent by Supabase.
- RevenueCat, Apple and Google — mobile app distribution and in-app purchase management.
- Expo, together with Apple and Google for final delivery — sending push notifications, if you have accepted them.
- Tally — collecting your feedback, only if you open the feedback form from the application. This component is loaded within the application only: the public pages of the website call no third-party service.
- Cryptocurrency platforms — only if you connect one. Access goes through Powens, exactly as for a bank, and remains read-only.
Market and inflation data used for projections (asset prices, the harmonised index of consumer prices published by the European Central Bank) come from third-party sources with no transmission of your personal data: our servers request a price or an index, never a profile.
Where data is transferred outside the European Union — which concerns website hosting and the payment and mobile distribution providers — such transfers are covered by appropriate safeguards, in particular the European Commission’s standard contractual clauses.
7. Data retention
Your data is retained for as long as your account exists. We do not purge your transaction history over time: retaining it is a feature of the Service, and erasing it must remain your decision.
- End of subscription: automatic synchronisation stops and bank connections are disabled, but your transactions, accounts and categories are kept and remain viewable.
- Disconnecting a bank: the connection is deleted at Powens and access revoked. Transactions already imported remain in your space until you delete them.
- Deleting an item: a deletion marker is kept for up to 180 days, long enough for the deletion to propagate to your other devices, and then disappears.
- Account deletion: your personal data is erased from our systems and bank connections are revoked, subject to retention periods imposed by law (in particular accounting obligations relating to subscription invoices).
- Technical logs: kept for a limited period for security and diagnostic purposes, then deleted.
8. Cookies and local storage
The public website and the application set no analytics, advertising or tracking cookies. We use neither Google Analytics, nor advertising pixels, nor any ad network. That is why you are shown no consent banner: it would have nothing to ask you.
The application uses your browser’s or device’s local storage for three things strictly necessary to its operation: keeping your session open, remembering your theme preference, and holding a copy of your data for offline consultation. This information stays on your device and is cleared when you sign out or clear the site’s data.
You can check this yourself: on the public pages of the website, your browser’s “Network” tab shows no request to any domain other than ours.
9. Security
We implement appropriate technical and organisational measures: tokenisation and encryption of sensitive data (see §5), per-user data isolation (Row Level Security), encrypted communications (HTTPS/TLS with HSTS), strict security headers and restricted access to server functions. No banking credential ever passes through or is stored by Tefin.
Two additional protections are available for you to enable: two-factor authentication on your account, with recovery codes, and the app lock on mobile using a passcode, fingerprint or face recognition.
Security researchers are invited to report any vulnerability following the policy published at /.well-known/security.txt: a good-faith report will not result in any legal action.
10. Your rights
Under the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability of your data, as well as the right to withdraw your consent at any time. You can exercise these rights directly from the application (editing your information, disconnecting a bank, deleting your account) or by writing to contact@tefin.fr. We respond within one month.
You also have the right to lodge a complaint with the French data protection authority, the CNIL (www.cnil.fr), or with the supervisory authority of your country of residence. For any question about PSD2 access to your accounts, you may also contact Powens in its capacity as an authorised AISP, and your bank.
11. Disclaimer
12. Changes
We may update this policy. Any substantial change will be notified in the application. The date of the last update appears at the top of this page.
Tefin