Skip to content
Madeyyat

Privacy Policy

Last updated: 14 August 2026

Madeyyat is a personal-finance application operated as a private service in the Netherlands. Access is by invitation only. This policy explains what data the service handles and why, in plain language, because that is also how the app works.

What we store

  • Account identity: the email address and name from your Google sign-in. Your Google password never touches the app; if you set an optional app password, only a scrambled version of it (a bcrypt hash) is stored, never the password itself.
  • Financial data you provide: bank statements you upload, transactions synced from banks you explicitly connect, and figures you enter (income, assets, budgets).
  • Your settings and decisions: categories you confirm, rules you create, preferences.
  • Monthly money check-ins you record: the score inputs, results, confidence, method version, and recording time needed to preserve an honest history. Opening the app alone never records one.

Bank connections

Optional bank sync uses PSD2 open-banking through Enable Banking Oy (a licensed account-information service provider in the EU). Connections are read-only by law: the service can retrieve balances and transactions and can never move money or see your bank credentials. You approve access in your own bank's app, and you can revoke it there at any time. Consents expire automatically and must be re-approved. Connected accounts refresh when you open the app and once a day in the background. When you are using the app, those requests include your IP address and browser name, so your bank knows you asked for the update yourself.

Where data lives

All data is stored in a Postgres database hosted in the European Union (Frankfurt, Germany). Every record is isolated per user: one user's data is structurally inaccessible to another. Amounts are stored exactly, as integer cents.

AI features

The built-in AI assistant answers questions about your own data. To do that, relevant figures (totals, transactions you ask about) are sent to Anthropic's API for processing and are not used to train their models. AI features are optional and read-only: they can see your numbers, never change them.

What we don't do

  • No selling or sharing of your data with advertisers. There are no ads and no trackers.
  • No analytics beyond server logs needed to keep the service running.
  • No cookies except the session cookie that keeps you signed in.

Your rights

Under the GDPR you can request a copy of your data or its complete deletion at any time. Settings offers exports for setup, transactions, and recorded financial-health history; disconnecting a bank stops its sync immediately. For deletion or any privacy question, contact the operator: ahmedmkhashaba@gmail.com.