Legal · Privacy

Privacy policy

Last updated: September 23, 2026

Introduction

Centric ("we", "us") is a personal finance aggregation service operated by Luca Bottelli, based in Italy. This Privacy Policy explains what information we collect when you use Centric, why we collect it, how we protect it, and the rights you have under the EU General Data Protection Regulation (GDPR).

We designed Centric to handle the minimum amount of personal data required to deliver the service. We do not sell your data, we do not share it with advertisers, and we do not use it to train third-party models.

Data controller

The data controller responsible for your personal data is Luca Bottelli. You can reach us at [email protected] for any privacy-related question or request.

What we collect

  • Account data: email address, name, hashed password (Argon2), display preferences.
  • Financial data you enter or connect: account balances, transactions, categories, budgets, goals, and uploaded tax documents (busta paga, Modello 730, F24, invoices).
  • Open banking data: if you link a bank via our Plaid integration, we receive read-only account and transaction data on your behalf. Access tokens are encrypted at rest.
  • Operational metadata: IP address, user-agent, and timestamps for security-sensitive actions (login, password change, admin access). Retained for audit and fraud prevention.
  • Performance diagnostics (only if you turn them on): if you report that Centric is slow, you can share diagnostics from your support ticket for 15 minutes. We record page and request load times and basic device capabilities (CPU cores, memory, connection type, screen size) — never your financial data. Diagnostics are deleted after 14 days.

Why we use it

  • Providing the core service: aggregating, displaying, and analysing your finances.
  • Parsing documents you upload to extract structured income, tax, and expense data.
  • Securing your account, detecting abuse, and meeting our legal obligations.
  • Sending operational notifications you have opted into (e.g. budget alerts, tax reminders).

How we protect your data

  • Encryption in transit (TLS 1.2+) and at rest for sensitive fields and uploaded documents (Fernet: AES-128 in CBC mode with an HMAC-SHA256 integrity check).
  • Passwords hashed with Argon2; bank tokens and uploaded documents stored encrypted.
  • Strict per-user ownership checks on every backend mutation.
  • Two-factor authentication (TOTP) required for administrative access.
  • Auditable security event log for authentication-sensitive operations.

Who we share with

We share data only with the processors strictly required to run the service: Hetzner (our database and API servers, in Falkenstein, Germany), Vercel (the web app, served from Frankfurt), Resend (email, sent from the EU), Google (the Gemini model that reads the documents you upload, after we remove your codice fiscale, IBAN, address and contact details from the text it sees), and open banking aggregators (Plaid) when you choose to link a bank. Some of these providers may process data outside the EU; where they do, they are bound by data processing agreements and EU-adequate transfer safeguards (Standard Contractual Clauses). We never sell your data and never share it with advertisers.

How long we keep it

We retain your data for as long as your account is active. If you delete your account, all personal and financial records are permanently deleted within 30 days, except for the minimum records we are legally required to keep (e.g. billing invoices, kept up to 10 years under Italian tax law).

Beta Programme

If you participate in the Centric beta programme, we log additional information about how you use the app to help us understand usage and improve the product. This includes the pages you visit, actions you take (such as creating or editing records), client-side interaction events, page and request load times with basic device capabilities (performance diagnostics, deleted after 14 days), timestamps, and any feedback you submit through the in-app feedback tool.

The legal basis for this processing is your explicit consent, which we collect when you join the beta. You can withdraw at any time by leaving the beta programme (contact support). This activity data is tied to your account, included in your data export, and permanently deleted when you leave the beta or delete your account.

Your rights

Under GDPR you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Export your data in a portable format.
  • Erase your data ("right to be forgotten").
  • Object to or restrict certain processing.
  • Withdraw consent at any time, without affecting prior lawful processing.
  • Lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali).

To exercise any of these rights, email [email protected]. We respond within 30 days.

Cookies

We use a single first-party session cookie ( centric_session) to keep you logged in, and a CSRF token cookie to protect form submissions. We do not use third-party tracking or advertising cookies.

Changes to this policy

We may update this policy as the product evolves. Material changes will be communicated by email and surfaced inside the app before they take effect. The "last updated" date at the top of this page always reflects the current version.