
Privacy Policy
The short version: your financial data is yours. Read-only access, encrypted, hosted in the EU, and never sold.
Last updated: October 3, 2026
On this page
Introduction
lait.finance ("we", "us", "our") is a personal finance and portfolio management platform operated by Mistinguett Capital Investments, S.L. (València, Spain) under the Lait brand. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our service at lait.finance.
Data Controller
The data controller responsible for your personal data is Mistinguett Capital Investments, S.L. (NIF B02670131, Avenida Primado Reig 187, 12º, puerta 64, 46020 València, España), contactable at privacy@lait.finance. As a European-based service, we comply with the General Data Protection Regulation (GDPR) and applicable Spanish data protection laws (LOPDGDD).
Data We Collect
We collect the following categories of personal data:
- Account data: Email address, name, and authentication credentials (managed by Clerk, our authentication provider).
- Financial data: Bank account balances, transaction history, portfolio holdings, and asset valuations — collected through read-only Open Banking connections (via Enable Banking), manual entries, and CSV imports.
- Usage data: Pages visited, features used, and interaction patterns to improve our service.
- Technical data: IP address, browser type, and device information for security and abuse prevention.
How We Collect Data
- Open Banking (PSD2): When you connect a bank account, we use Enable Banking as our licensed Account Information Service Provider (AISP). Connections are read-only — we can never initiate payments or move your money. You explicitly consent to each bank connection through your bank's own authorization flow.
- Manual input: Data you enter directly (trades, assets, savings accounts).
- CSV imports: Bank statement files you upload voluntarily.
- API integrations: Read-only connections to crypto exchanges using API keys you provide, and to wallets by their public address. To read them we ask that exchange with your key, and blockchain data services (Alchemy, Zerion, Helius, mempool.space) with the address; none of them receives your name or email.
Legal Basis for Processing
We process your data based on:
- Consent: You explicitly authorize each bank connection and data source.
- Contract: Processing necessary to provide the service you signed up for.
- Legitimate interest: Security monitoring, abuse prevention, and service improvement.
How We Use Your Data
Your financial data is used exclusively to:
- Aggregate and display your portfolio, net worth, and financial overview.
- Categorize transactions using AI-assisted classification (see section 7).
- Generate personalized insights and answer your questions through our AI advisor.
- Calculate performance metrics, allocation breakdowns, and historical trends.
We do not use your data for advertising or credit scoring. The one profile we build is the support prioritisation described in section 7: it orders our own to-do list and never changes what you can use or what you pay. You can object to it at any time by writing to privacy@lait.finance, and we stop.
AI Processing
Some features rely on third-party AI providers. We use them only when you trigger the feature, and we send the minimum data needed:
- Transaction categorization: we use OpenAI to classify transaction descriptions that our automatic rules cannot match. Rule-based matching runs first, so we send only the descriptions that fail it — not all your transactions.
- AI advisor (chat) & monthly insights: when you use the advisor or open AI insights, we send the relevant portfolio context to the AI provider you selected — OpenAI, Anthropic, or Google (for web-search-grounded answers). That context includes monthly totals from your cashflow (average income, average spending, savings rate and your top spending categories over the last full months) so the answer can be about your situation and not generic — aggregates only, never the individual transactions or who you paid.
- Budget note: when you write what is different this month while setting your budget and press "Estimate with this", that note (with identifiers removed), your category names, what you usually spend in each per month and this month's planned line go to OpenAI, which returns only which lines to move and why. Amounts are taken only from what you wrote. Nothing is saved until you save the budget, and the note itself is never stored.
- Asset valuation estimates & research briefs: when you request an estimate or research a ticker, the asset details or ticker are sent to Google.
- Reading an asset document: when you press "Read from the document" on a document (an insurance policy, an ITV report, an IBI receipt, an invoice, a warranty), that file is sent to Google and to no other AI provider. It may show your name, ID number or address; from a reading Lait keeps only the dates and amounts you confirm (renewal, next inspection, cadastral value, price paid, warranty end), never those identifiers. Nothing is read unless you ask. Details you type in yourself, such as a policy number or the insurer's phone, are kept as you enter them and never sent to an AI provider.
- Advisor reply check: to keep the advisor's answers informational rather than personalised investment advice, we may send the text of its reply — which can repeat figures from your portfolio — to TypeSafe, which returns only a probability that the reply reads as a recommendation. When that probability is very high, we show a note under the reply saying it is general information, not a recommendation. Identifiers (IBANs, emails, phone numbers) are removed first, and we keep only that number.
- Question routing: to know what the advisor is asked about (the topic of each question, so we can see which areas to improve), or to find the page you are looking for when you type a phrase into the search palette (⌘K), we may send that text (with identifiers removed) to TypeSafe, which returns only which topic it is about, how likely it is to need in-depth reasoning, or which of the app's own actions it matches. Off unless we switch it on.
- Category review: after a transaction is categorised, we may send its description (with identifiers removed), its amount and the proposed category to TypeSafe, which returns only a probability that the category fits. Low-probability rows are marked for your review; nothing is changed without you. Off unless we switch it on.
- Bug report triage: when you send us a bug report or a suggestion, its text (with identifiers removed) and the page it came from may go to TypeSafe, which returns only an area, a severity and whether it reads as a suggestion, so we fix what hurts first. Your name and email never leave.
- Support prioritisation: to decide whom to help first, aggregated facts about your account — plan, how many sources are connected, sessions per week, net-worth band, how you found us — may go to TypeSafe, which returns only a category and a probability. Never your email, your name or a transaction. This never changes what you can use or what you pay; it orders our own to-do list.
- No training, ever: every AI provider is used under its API terms, under which the data we send is not used to train models. Your data is not the product, now or ever.
- News headline translation: public market-news headlines are translated via Google.
Where a selected provider is unavailable, a request may fall back to another of the providers named above. Transaction categorization does not produce fully automated decisions that affect your legal or material rights — you can manually correct any AI-assigned category at any time, and your corrections improve future accuracy for your account only.
Data Storage & Security
- Infrastructure: Your data is stored in a Neon Postgres database in the EU (Frankfurt). The application is served by Vercel: static content from the edge location nearest to you, and the server functions that process requests run in the EU (Frankfurt), next to the database, under Vercel's Data Processing Agreement.
- Encryption: Data is encrypted at rest (AES-256) and in transit (TLS 1.3).
- API credentials: Exchange API keys are encrypted before storage and are never exposed in API responses.
- Access control: Each user can only access their own data. Admin access is restricted to the platform operator.
- Read-only access: All bank and exchange connections use read-only permissions. We cannot move, transfer, or modify your funds.
Sub-processors
We share data only with the following third-party processors, each strictly necessary to provide the service:
- Clerk (authentication) — processes your email, name, and login data.
- Enable Banking (Open Banking / PSD2) — facilitates read-only bank connections; processes balances and transactions.
- SnapTrade (brokerage connections) — facilitates read-only connections to your brokerage accounts; processes holdings and balances.
- Neon (database) — hosts your financial data in the EU.
- Vercel (hosting & infrastructure) — serves the application and, via Vercel Analytics and Speed Insights, processes anonymized usage and performance metrics; via Vercel Blob (EU, Paris) it stores the photos you attach to your assets and, in a private store that opens only through your signed-in session, their documents.
- OpenAI — processes transaction descriptions for categorization, and portfolio context when you use the AI advisor.
- Anthropic — processes portfolio context when you use the AI advisor.
- TypeSafe — receives the text of the advisor's replies to check they stay informational and, when switched on, your questions and palette searches (for routing), transaction descriptions with their proposed category (for review), bug reports (for triage) and aggregated account facts (for support prioritisation) — all with identifiers removed; returns only categories and probabilities.
- Google — processes transaction descriptions for categorization, ticker/asset details for research and valuation estimates, the asset documents you ask it to read, news headlines for translation, and queries for web-search-grounded AI answers.
- Sentry — receives application error reports and diagnostic data for debugging and stability (we configure it not to send default personal-data fields).
- Resend — processes your email address and name to deliver account, security, and support emails. If you turn on the weekly summary or the monthly report in Settings, it also carries what those emails contain: your portfolio value and its split by asset class, your largest price moves, your weekly spending by category and, for the monthly report, the PDF report. Both are off unless you turn them on, and each email has a link to turn it off.
- Upstash — keeps, in the EU (Frankfurt), market quotes and short-lived copies of your data so the app stays fast (they expire on their own, within 40 days at most and most within minutes), and counters by IP address to stop abuse (2 minutes).
- Stripe (payments) — processes your email, name and billing details when you subscribe to Premium, and the payment itself. Your card details go to Stripe directly; Lait never sees or stores them. Only if you subscribe.
- Cloudflare (domain and email) — resolves our domain and forwards the emails you send to our addresses, including privacy@lait.finance, to the mailbox where we read them.
OpenAI, Anthropic, TypeSafe, Google, Clerk, Resend, Stripe and Cloudflare process data in the United States; Neon, Vercel, Upstash and Sentry keep it in the EU (Frankfurt or Paris) but are US companies too. Those transfers rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the EU Standard Contractual Clauses in its data processing terms. SnapTrade processes brokerage-connection data in Canada, which the EU recognizes as providing an adequate level of data protection, and says it may also process it in the United States. Our record of processing lists each provider's terms, location and retention.
We do not sell, rent, or share your personal data with advertisers, data brokers, or any other third parties.
Data Retention
- Account and financial data: kept while your account exists. You can delete individual records at any time. Deleting your account erases it at once: first what the providers hold (your bank consent at Enable Banking, your user at SnapTrade, your subscription at Stripe), then everything in our database and file storage.
- Usage and cost records: AI cost records are unlinked from you after 90 days, except those paid with Lait Rewards credit, which make up your credit balance; usage events, sessions and AI usage counters are deleted after 13 months, except the record that you completed sign-up; operational error records after 90 days; bug reports after 2 years; a CSV file you choose to share to improve the importer after 12 months. A daily job applies these periods.
- Waitlist: the waitlist entry is deleted after 2 years. The contact record of someone who never opened an account has no automatic period yet and is reviewed by hand; ask us and we delete it.
- Short-lived copies: copies of your data kept on our servers to make the app fast expire on their own, within 40 days at most and most within minutes; counters by IP address last 2 minutes.
- Bank connections: a bank consent lasts up to 90 days and is never renewed without your explicit re-authorization. When you disconnect a bank or a broker, we withdraw the access at Enable Banking or SnapTrade and delete the IBAN and identifiers, keeping only a minimal record while your account exists.
- Providers and backups: our database keeps a restore history for a limited window (hours to days), after which erased data is gone for good; server and error logs, AI providers and email expire what they received on their own schedules, listed in our record of processing.
- Billing records: charges already made stay at Stripe and in our accounts for as long as tax and accounting law requires.
Your Rights (GDPR)
Under the GDPR, you have the right to:
- Access: Request a copy of all personal data we hold about you.
- Rectification: Correct any inaccurate data.
- Erasure: Request deletion of your data ("right to be forgotten").
- Portability: Receive your data in a structured, machine-readable format.
- Restriction: Limit how we process your data.
- Objection: Object to processing based on legitimate interest.
- Withdraw consent: Revoke any bank connection or data permission at any time through Settings.
- Lodge a complaint: File a complaint with your data protection supervisory authority — in Spain, the Agencia Española de Protección de Datos (AEPD, aepd.es) — if you believe we have not respected your rights.
To exercise these rights, contact us at privacy@lait.finance, or use the data export and account-deletion tools in Settings. We will respond within 30 days.
Children
lait.finance is not intended for users under 18 years of age. We do not knowingly collect data from minors.
Changes to This Policy
We may update this Privacy Policy from time to time. Significant changes will be communicated via email or in-app notification. The "Last updated" date at the top reflects the most recent revision.
Contact
For any questions about this Privacy Policy or your personal data, contact us at privacy@lait.finance.