Privacy policy
Last updated 2 September 2026. Short on purpose; email us if anything is unclear.
Who is responsible
Redflake, Noord-Scharwoude, the Netherlands (KvK 83574018) is the data controller for the personal data processed through redflake.nl and the Redflake app. Privacy contact: joris@redflake.nl.
What we process
Account data: your name, email address and Google account identifier, used to sign you in. Bank data: account names, IBANs, balances and transactions (dates, amounts, counterparties, descriptions) from the banks you connect. Usage data: which AI tools were called, when, and by which connected client. Billing data: your subscription status. Card details are handled by Stripe and never reach our servers.
Where the bank data comes from
Bank data is retrieved under PSD2 through open-banking.io, which uses Enable Banking Oy, a licensed account information service provider (AISP). You give explicit consent at your bank; open-banking.io stores the data end-to-end encrypted and cannot read it, and only Redflake holds the key for your data. That consent is read-only, lasts at most 180 days and can be withdrawn at any time in the app, at open-banking.io or at your bank. See the privacy policies at open-banking.io and enablebanking.com.
Why we process it (purpose limitation)
Solely to show you your finances and to make them available to the AI assistants you connect and to the Redflake Agent, if you use it. We do not sell data, do not use it for advertising, do not build credit scores and do not share it with third parties beyond the processors listed below. PSD2 requires that account data is used only for the service you asked for; we hold ourselves to that.
AI assistants you connect
When you connect Claude, ChatGPT or another client to your Redflake MCP endpoint, the data those tools request is sent to that provider under their terms. You control which accounts are exposed, IBANs are masked by default and you can hide counterparty names. Every request is logged and visible to you. Revoking a client stops all access immediately.
Processors
Stripe (payments, EU), Google (sign-in), Vercel and our EU-region database provider (hosting), Resend (email) and Anthropic (the model behind the Redflake Agent, Pro plan only, with zero data retention). Each processes data on our instructions under a data processing agreement.
Retention
Bank data is kept while a connection is active. When you remove a connection you choose whether to keep or purge its history. When your subscription ends, all bank data is deleted within 30 days. When you delete your account, everything is deleted within 24 hours and our access key is revoked at open-banking.io.
Security
All traffic is encrypted in transit. IBANs and counterparty details are encrypted at rest with keys held in a managed key store. Access to production data is limited to the founder and audited.
Your rights
You can export your data (JSON and CSV) and delete your account from Settings at any time. You also have the right to access, rectification, restriction and objection under the GDPR, and to lodge a complaint with the Autoriteit Persoonsgegevens. Email joris@redflake.nl for anything the self-service tools do not cover.
Cookies
A session cookie to keep you signed in, and Google Analytics cookies on the public site to measure visits. No marketing cookies. Analytics data is not linked to your bank data.