Privacy Policy
Privacy Notice
Privacy Policy – Finance Tracker App
Last updated: 2. January 2026
This Privacy Notice explains how personal data is processed in connection with the Finance Tracker application and the associated website.
The project is a non-commercial diploma thesis developed at HTL Rennweg and is intended solely for educational and demonstration purposes.
1. Data Controller
Project: Finance Tracker (Diploma Thesis)
Responsible Entity:
- Project Team “Finance Tracker”
- Lorenz Schmidt
- Email: Lorenz.schmidt@htl.rennweg.at
2. Nature of the Project
- The Finance Tracker app is not a commercial product and does not provide financial, investment, or banking advice.
- The app allows users to view and analyze their own financial data (e.g. expenses, balances, savings) for informational and statistical purposes only.
3. Data We Process
With the user’s explicit consent, the following categories of personal data may be processed:
- Account balances
- Transaction data (amounts, dates, descriptions)
- Categories of income and expenses
- Account and bank-related metadata
No login credentials, passwords, PINs, or TANs are processed or stored by the project team.
4. Source of the Data & Third-Party Provider
Bank account data is accessed exclusively via the third-party open banking provider TrueLayer.
Authentication and data access occur directly between the user and their bank via TrueLayer.
The project team does not receive or store banking credentials at any time.
For more information, please refer to TrueLayer’s own privacy policy.
5. Purpose of Data Processing
Personal data is processed solely for the following purposes:
- Displaying personal financial overviews
- Generating statistics (e.g. expenses, income, savings)
- Visualizing financial trends for the user
The data is not modified, not shared, and not used for automated decision-making.
6. Storage of Data
- Financial data is stored exclusively locally on the user’s device,
- or temporarily processed on a server as described in the app or documentation.
- The project team and the school have no access to users’ financial data.
7. Legal Basis
The processing of personal data is based on:
Article 6(1)(a) GDPR – Explicit user consent
Consent can be withdrawn at any time by disconnecting bank accounts or uninstalling the app.
8. Data Retention
- The user actively uses the app, or
- The data is retained locally on the user’s device.
When the app is uninstalled, all locally stored data is deleted.
9. User Rights
Under the GDPR, users have the right to:
- Access their personal data
- Rectify inaccurate data
- Request deletion of data
- Restrict processing
- Data portability
- Withdraw consent at any time
10. Data Security
Appropriate technical and organizational measures are implemented to protect data against unauthorized access, loss, or misuse.
However, as this is an educational project, no guarantee of uninterrupted availability or absolute security can be provided.
11. Changes to This Privacy Notice
This Privacy Notice may be updated as part of the ongoing development of the diploma thesis.
The current version will always be available on the website.
12. Contact
Lorenz Schmidt
Rennweg 89b, 1030 Vienna