Skrudzas Privacy Policy
Last updated: July 16, 2026
Skrudzas ("the App") is a private, personal finance tracker developed and operated by AppAtlas ("we", "us", "our"). This Privacy Policy explains what data we access, how we use it, and how we protect it when you use Skrudzas — including transaction data imported through open banking (PSD2) and PayPal.
1. Information We Collect
Account information
- When you sign in via Authly ID we receive your email address and display name. We do not receive or store your bank credentials.
Financial data
- Transactions (date, amount, description, counterparty) andaccount metadata (account name, IBAN/account number, currency, balance) from accounts you explicitly connect.
- You may add this data three ways: uploading bank statement files (CSV), connecting a bank via open banking, or connecting PayPal.
- Categories, rules, recurring-payment definitions, and notes you create in the App.
2. How Bank & PayPal Access Works
- Open banking (PSD2): we connect to your bank throughEnable Banking, a licensed Account Information Service Provider (AISP). Access is read-only, limited to the accounts you explicitly authorize, and granted only after you complete strong customer authentication (SCA) directly with your bank. We never see or store your bank login.
- Consent is time-limited: under PSD2 your consent expires (about every 180 days) and access stops until you re-authorize. You can disconnect at any time in the App, and can also revoke access from your bank.
- PayPal: we read your transaction history via PayPal's Transaction Search API using credentials you authorize; we cannot move funds.
- We never initiate payments or transfers. Skrudzas only reads information.
3. How We Use Your Data
- To import, organize, and display your transactions and balances
- To automatically categorize transactions and detect transfers and recurring payments
- To generate personal budgeting analytics and insights
- To share a single household's finances between its members (when you opt in)
4. Third-Party Processors
- Enable Banking — provides the regulated connection to your bank. Their handling of data is governed by their own privacy policy.
- OpenAI — used only to suggest categories for transactions that rules don't match. Only the transaction description and amount are sent; never your identity, account numbers, or credentials.
We do not sell, rent, or share your financial data with anyone else, and we do not use it for advertising.
5. Data Storage and Security
- Your data is stored in our own encrypted PostgreSQL database — not on shared third-party ledgers
- All network communication uses HTTPS/TLS encryption
- Authentication uses Keycloak (Authly ID) with industry-standard OAuth2/PKCE and audience-validated tokens
- Open-banking access tokens and consents are stored encrypted and used only for background sync
6. Data Retention
- Imported transactions are retained while your account is active so you keep your history
- Disconnecting a bank or PayPal stops future syncing; previously imported transactions remain until you delete them
- You can delete individual transactions, a connection, or request full account deletion at any time
7. Your Rights
You have the right to:
- Access and export your data
- Delete your data or your account
- Withdraw consent for bank access at any time (in the App or at your bank)
- Rectify incorrect data (edit or recategorize transactions)
If you are in the EU/EEA, these rights are provided under the GDPR. AppAtlas is the data controller for Skrudzas.
8. Children's Privacy
Skrudzas is not intended for children under 13, and we do not knowingly collect data from children.
9. Changes to This Policy
We may update this policy from time to time. Changes will be posted here with an updated revision date.
10. Contact Us
For questions, data access, or deletion requests:
- Email: privacy@appatlas.eu
- Website: appatlas.eu