
Trust & security
How Lait protects your money and your data, in plain language. No jargon, no certifications we do not hold, no fine print that contradicts this page.
Last reviewed: September 27, 2026
On this page
- 01How we protect you
- 02Read-only Open Banking (PSD2)
- 03Encryption & credentials
- 04Authentication & access
- 05Where your data lives
- 06Who touches your data
- 07Optional AI, minimum context
- 08We never sell your data
- 09We tell you when a sync breaks
- 10Export and delete, no tickets
- 11Report a vulnerability
- 12Questions
How we protect you
Read-only by design
Bank and broker connections are read-only under PSD2. We can never move, transfer or spend your money.
Encrypted at rest and in transit
AES-256 at rest, TLS 1.3 in transit. Exchange API keys get a second layer of AES-256-GCM before they touch the database.
Your data, only yours
Sign-in is handled by Clerk. Every request is scoped to your account; there is no shared view.
Database in the EU
Your financial data lives in Frankfurt (Neon Postgres). Where each processor runs is listed below, not hidden.
We never sell your data
No advertisers, no data brokers, no credit scoring. Ever.
Export or delete everything
From Settings you can export all your data (JSON or CSV) or erase your account and every row we hold.
Read-only Open Banking (PSD2)
When you connect a bank, Lait uses Enable Banking, a licensed Account Information Service Provider (AISP) under PSD2. The connection is read-only by law and by design: we see balances and transactions to build your dashboard, and we can never initiate a payment or move funds.
You authorize every connection on your own bank's login and consent screen. We never see or store your banking password. Lait caps each consent at 90 days; it never renews without you, and revoking it from Settings withdraws the consent at the bank side too, not just in our database.
Broker connections through SnapTrade follow the same rule: read-only, authorized by you, revocable.
Direct bank connections are rolling out gradually. Until they reach your account, bank data comes in through the statements you upload (CSV or Excel), which give Lait no access to your bank at all.
Encryption & credentials
Data is encrypted at rest with AES-256 and in transit with TLS 1.3. Exchange API keys you add are encrypted a second time at the application layer (AES-256-GCM, with a key that lives only in the server environment) and are never returned by any API response. Wherever the exchange allows it, we ask for read-only keys, so even a leaked key could not move your assets.
Authentication & access
Sign-in is managed by Clerk, a dedicated authentication provider; Lait never handles your password. Every request is scoped to your account: there is no shared view and no way to reach another user's data through the API. Administrative access is restricted to the platform operator, for support and maintenance only.
Where your data lives
Your database is Neon Postgres in Frankfurt (EU). The application runs on Vercel: pages are served from the edge location nearest to you, and the server functions that process your requests run in Frankfurt (EU), next to the database. Some processors in the table are US companies (sign-in, email, error reports, payments, AI models); each of those transfers is covered by the EU Standard Contractual Clauses in our Data Processing Agreements. We list them plainly instead of claiming "100% EU".
As a European service we operate under the GDPR: you can access, correct, export or delete your data at any time. To exercise any right, write to privacy@lait.finance.
Who touches your data
Every third party that processes any of your data, what it sees and where it runs. The same list as our Privacy Policy, in one table.
| Provider | Purpose | What it sees | Where |
|---|---|---|---|
Enable BankingRegulated AISP · rolling out | Bank connections under PSD2 | Balances and transactions | EU |
SnapTrade | Read-only brokerage connections | Holdings and balances | Canada, and the US per its policy |
Clerk | Sign-in and sessions | Email, name, login data | US |
Neon | Database | Your financial data | EU · Frankfurt |
Vercel | Hosting, server functions, attached files, cookieless analytics | App traffic and the files you attach | Edge worldwide · functions in EU · Frankfurt |
Upstash | Short-lived cache | Market quotes, short-lived copies of your data (expire within 40 days, most in minutes), IP counters against abuse (2 minutes) | EU · Frankfurt |
Stripeoptional | Payments for Premium | Email, name and billing details. Your card goes to Stripe, never to Lait | EU · Ireland, US |
Resend | Account, support and summary emails | Email and name; what a summary contains, only if you turn summaries on | US |
Sentry | Error reports | Diagnostics when an error happens, no session recording, no personal-data fields by default | EU · Frankfurt |
Cloudflare | Domain and email forwarding | The emails you send to our addresses, in transit | US |
OpenAIoptional | Transaction categorization, advisor, budget note | Transaction descriptions, portfolio context and the note you write for your budget, without IBANs, emails or phone numbers | US |
Anthropicoptional | Advisor (Claude) | Portfolio context, without IBANs, emails or phone numbers | US |
TypeSafeoptional | Advisor reply check, routing, category review, bug triage, support prioritisation | The text of the advisor's replies (which can repeat figures from your portfolio) and, when switched on, your question or palette search, transaction descriptions with their proposed category, bug reports and aggregated account facts — without IBANs, emails, names or phone numbers; it returns only categories and probabilities | US |
Googleoptional | Categorization, research, valuations, translation, reading documents you ask it to | Transaction descriptions, tickers, headlines, the asset documents you ask it to read | US |
- Enable BankingRegulated AISP · rolling outEU
Bank connections under PSD2
Sees: Balances and transactions
- SnapTradeCanada, and the US per its policy
Read-only brokerage connections
Sees: Holdings and balances
- ClerkUS
Sign-in and sessions
Sees: Email, name, login data
- NeonEU · Frankfurt
Database
Sees: Your financial data
- VercelEdge worldwide · functions in EU · Frankfurt
Hosting, server functions, attached files, cookieless analytics
Sees: App traffic and the files you attach
- UpstashEU · Frankfurt
Short-lived cache
Sees: Market quotes, short-lived copies of your data (expire within 40 days, most in minutes), IP counters against abuse (2 minutes)
- StripeoptionalEU · Ireland, US
Payments for Premium
Sees: Email, name and billing details. Your card goes to Stripe, never to Lait
- ResendUS
Account, support and summary emails
Sees: Email and name; what a summary contains, only if you turn summaries on
- SentryEU · Frankfurt
Error reports
Sees: Diagnostics when an error happens, no session recording, no personal-data fields by default
- CloudflareUS
Domain and email forwarding
Sees: The emails you send to our addresses, in transit
- OpenAIoptionalUS
Transaction categorization, advisor, budget note
Sees: Transaction descriptions, portfolio context and the note you write for your budget, without IBANs, emails or phone numbers
- AnthropicoptionalUS
Advisor (Claude)
Sees: Portfolio context, without IBANs, emails or phone numbers
- TypeSafeoptionalUS
Advisor reply check, routing, category review, bug triage, support prioritisation
Sees: The text of the advisor's replies (which can repeat figures from your portfolio) and, when switched on, your question or palette search, transaction descriptions with their proposed category, bug reports and aggregated account facts — without IBANs, emails, names or phone numbers; it returns only categories and probabilities
- GoogleoptionalUS
Categorization, research, valuations, translation, reading documents you ask it to
Sees: Transaction descriptions, tickers, headlines, the asset documents you ask it to read
US providers are covered by the EU-US Data Privacy Framework or the EU Standard Contractual Clauses in each Data Processing Agreement. Canada holds an EU adequacy decision; SnapTrade says it may also process data in the US. Optional providers only see anything if you use that feature: AI if you use AI, Stripe if you subscribe.
Optional AI, minimum context
AI features are optional; Lait works completely without them. When you use one, we send only the minimum context the answer needs, and never your credentials. Before any transaction leaves for a model, we strip IBANs, emails, phone numbers and account numbers. We use these providers to answer you and for the checks our Privacy Policy lists, never for advertising. And nothing you share trains a model: every provider is used under its API terms, where inputs are not used for training. Your data is not the product, now or ever.
We never sell your data
Your financial data is used only to build your portfolio, categorize your transactions and power the features you asked for. We do not use it for advertising or credit scoring, and we do not sell, rent or share it with advertisers or data brokers. The one profile we build is the support prioritisation our Privacy Policy describes: it never changes what you can use or pay, and you can object to it. The processors in the table are the complete list; reading a wallet or an exchange also means asking that service, with the public address or read-only key you gave us.
We tell you when a sync breaks
When a source stops syncing (an exchange key revoked, a wallet provider down, a bank consent about to lapse), we show the real error instead of letting your numbers go stale in silence. Sources are checked when you open the app, at most every six hours, and connected banks three times a day in the background, so you always know whether what you see is current.
Revolut · sync failed
Consent invalid · 401 Unauthorized
The exact alert you would see.
Export and delete, no tickets
From Settings you can export everything you have in Lait as JSON or CSV, and delete your account. Deletion erases every row we hold about you, withdraws your bank consents at the bank side, removes any photos or documents you attached, and closes your sign-in account. No email, no waiting.
Report a vulnerability
Found something? Write to security@lait.finance and a real person reads it. We do not run a bug bounty and we are not SOC 2 or ISO 27001 certified; we are a small team and will not pretend otherwise. What we will do is answer, fix, and credit you if you want. Our contact is also published at /.well-known/security.txt (RFC 9116).
Questions
Security questions, data requests, or you just want to dig deeper? Write to a real person.
Lait is operated by Mistinguett Capital Investments, S.L. (València, Spain).