Privacy Policy
Actual Budget — personal instance · Effective 18 September 2026
1. Who is responsible
This instance of Actual Budget ("the Application") is a private, self-hosted personal finance application operated by Adrian Atanasov, an individual acting for purely personal, non-commercial purposes ("the Operator"). It is not a service offered to the public: it has exactly one user, the Operator.
Contact for any privacy matter: adrianstorm546@gmail.com
2. What data is processed
- Bank account information retrieved read-only through the Enable Banking PSD2 aggregation API, acting as the licensed account information service provider (AISP): account identifiers (IBAN), account name and currency, balances, and transaction records (booking/value date, amount, currency, counterparty name, remittance information).
- Budget data entered manually by the Operator: accounts, categories, rules, budgets, payees and notes.
- Credentials of the Application itself: the Enable Banking application ID and its RSA private key, used to sign API requests. These are stored on the Operator's own server and never shared.
No bank login credentials, passwords, card numbers or one-time codes are ever received or stored by the Application. Strong customer authentication always takes place on the website or app of the Operator's bank, or on Enable Banking's authorisation pages.
3. Why and on what legal basis
The data is processed to display the Operator's own balances and transactions in a personal budgeting tool, and to categorise them. The legal basis is the Operator's own consent, given explicitly for each bank account when linking it, under Article 6(1)(a) GDPR and the PSD2 access-to-account rules. Consent can be withdrawn at any time (see section 6).
4. Where data is stored and who receives it
- All retrieved data is stored on a private server operated by the Operator in his own home network, reachable only over encrypted TLS connections. Data is not sent to any cloud service, analytics provider, advertiser or third country.
- Read-only access to bank data is technically mediated by Enable Banking (Enable Banking Oy / Enable Banking AS), which acts as the licensed account information service provider and transmits requests to the Operator's bank. Enable Banking's own privacy notice applies to that processing.
- The Operator's bank processes the request under its PSD2 obligations.
No data is ever sold, rented, shared with other users, or used for profiling or advertising.
5. Retention
Transaction and balance data is kept for as long as it is useful for the Operator's own bookkeeping and history, and can be deleted by the Operator at any time from within the Application. Bank access sessions expire according to the validity period granted by the bank (typically up to 90 days) and must be re-authorised afterwards. Deleting data in the Application deletes it from the Operator's server; backups are rotated and overwritten.
6. Rights
As the sole data subject and the Operator, the individual concerned can at any time: access, correct, export or erase his data directly in the Application; revoke the bank consents in his bank's or Enable Banking's interface; or stop the Application entirely. Requests concerning data held by Enable Banking or by the bank should be addressed to those parties directly.
7. Security
- Access to the Application requires authentication and is served exclusively over HTTPS.
- API requests to Enable Banking are signed with a dedicated RSA key with RS256 JWTs and are valid for at most one hour.
- Bank access is read-only: the Application never initiates payments and holds no payment capability.
- The server is patched and backed up by the Operator.
8. Changes
This policy may be updated if the Application changes. The current version is always available at this address, with the effective date shown at the top.