Pluto is a private, non-commercial personal finance application. It is operated by a single private individual, for their own exclusive use, on hardware they own and control. There are no other users, no customers, and no public sign-up.
This policy describes how personal and financial data is handled within the application. It is published to satisfy the transparency requirements of third-party service providers used by the application.
The application is operated by a private individual acting outside of any professional or commercial activity. For any question regarding this policy or the data handled by the application, use the contact address in section 9.
The application processes:
No data belonging to any other person is processed. No marketing, tracking, profiling or analytics data is collected. The application contains no advertising, no third-party trackers and no cookies for tracking purposes.
Data is processed for the sole purpose of allowing the operator to view and manage an overview of their own finances. The legal basis is the operator's own explicit consent, given separately to each data source at the time of connection.
Bank account information is retrieved through Enable Banking Oy, an Account Information Service Provider (AISP) authorised under PSD2 and supervised by the Finnish Financial Supervisory Authority (FIN-FSA).
Enable Banking's own privacy terms apply to their role in this process and are available on their website.
All data is stored locally in a database file on hardware owned and physically controlled by the operator. Data is not uploaded to any cloud service, not shared with third parties, and not used for any purpose beyond the operator's own consultation. Data is retained for as long as the operator finds it useful and can be deleted at any time.
No third party has access to the stored data. Data is not sold, rented, shared, licensed or otherwise disclosed. The application is not publicly reachable and is accessible only over a private network controlled by the operator.
Access to the application is restricted to a private network. Credentials and cryptographic keys used to communicate with external services are stored with restricted file permissions and are never included in source control or shared. Connections to external services use TLS.
As the only data subject is also the operator of the application, all rights under the GDPR (access, rectification, erasure, portability, objection) are exercised directly and immediately through the application itself.
For any enquiry relating to this policy, including data protection matters, contact:
nextfindvault@gmail.com
This policy may be updated to reflect changes in how the application works. The date at the top of this page indicates the latest revision.