Privacy
Last updated 31 July 2026
Pachal holds records of your money. This page states exactly what is stored, where it lives, and every outside service the app talks to. It describes what the software actually does — not an intention.
Where your data lives
There are two vaults, and you choose which one at first run.
- Local vault (desktop app). Everything — positions, plans, statements, transactions — is stored in an SQLite database inside your operating system's application-data directory on your own machine. It is never uploaded. If you lose the machine without a backup, the data is gone; there is no copy on our side to restore.
- Cloud vault (web app). Your records are stored in our Supabase database, encrypted in transit and at rest, and separated per user by row-level security: a query authenticated as you can only ever return your own rows.
The demo profile contains sample data only. Nothing you do in it is written anywhere.
What we do not do
- No analytics, no tracking pixels, no session recording, no advertising identifiers.
- No third-party scripts on the app. Fonts are served from our own domain.
- We do not sell, rent or share your financial data with anyone.
- We never connect to your bank. Statements enter the app only as files you choose to upload. There is no open-banking link and no stored bank credentials.
Every outside service the app contacts
The complete list. Market and calendar requests carry the instrument or date being looked up — never your holdings, your amounts or your identity.
Prices, exchange rates and market data
- Yahoo Finance — quotes and price history
- CoinGecko, Binance — crypto prices
- Frankfurter, exchangerate.host — foreign-exchange rates
- TEFAS (Türkiye Elektronik Fon Alım Satım Platformu) — Turkish fund prices
- Twelve Data — fallback quotes when a primary source fails
Calendar, markets and news
- Polymarket — read-only implied probabilities. No wallet, no account, no trading.
- Faireconomy — economic release calendar
- BBC, Anadolu Agency — news headlines
Artificial intelligence (opt-in only)
Two features can send data to Anthropic, and neither runs unless you turn it on:
- Bulletins. A short market summary written against your portfolio. Instrument symbols and weights are sent; account numbers and identity are not.
- Categorising transactions. Only merchant names are sent — no amounts, no dates, no account numbers, no identity. Long digit sequences are masked before sending. The screen shows you the exact payload before it leaves, and nothing is applied until you approve it.
On the desktop app your Anthropic API key is stored in the macOS Keychain — never in the database and never in logs.
Accounts and hosting
- Supabase — authentication and, for the cloud vault, storage. Sign-in with Google is optional; if you use it, Google receives the sign-in request.
- Vercel — serves the application and the serverless data endpoints.
Bank connections (only if you connect a bank)
Connecting a bank account is optional and off until you start it yourself. Nothing below happens if you only upload statements or type your records in.
- Enable Banking (Enable Banking Oy, Finland) — licensed access to European banks under PSD2. You authorise the connection on your own bank's login page; Pachal never sees your banking credentials. Your account details, balances and transactions travel from the bank through Enable Banking to your vault.
- Plaid — the same role for banks in the United States.
The consent you give at the bank has an expiry date and a scope, both shown to you before you approve it. You can end a connection at any time from Cash flow → Connect bank, and revoke it at your bank as well. Transactions already pulled stay in your vault until you delete them; removing the connection does not delete them for you.
What we collect about you personally
Your email address, so you can sign in and reset your password. That is all. There is no profiling, no behavioural data, and no marketing list you are added to by signing up.
Your rights
Under the GDPR (EU) and KVKK (Türkiye) you may request access to your data, correction, deletion, or a portable export. The app can already export everything you hold as JSON and CSV from Settings, and deleting your account deletes your rows. For anything else, write to the address in the imprint.
Changes
If this policy changes in a way that affects what leaves your device, you will be told inside the app before it takes effect — not by a silently updated page.