Política de privacidad

Última actualización: 28 de septiembre de 2026

Jeff Banks es un panel personal de finanzas (P&L) que Jeffry ha creado para uso propio. Esta política explica qué datos trata la aplicación, de dónde salen, dónde se guardan y cómo ejercer tus derechos.

1. Qué es Jeff Banks

Una aplicación web privada para ver en un solo sitio los saldos, ingresos, gastos y el resultado (P&L) de las cuentas bancarias personales de Jeffry. No ofrece servicios a terceros, no tiene publicidad y es gratuita. Solo la cuenta de Google autorizada del titular puede iniciar sesión. Desde su web pública, cualquiera puede apuntarse a la lista de espera de la beta, que se explica más abajo.

2. Responsable y contacto

El responsable del tratamiento es Jeffry, titular y único usuario de Jeff Banks. Para cualquier consulta sobre privacidad o para ejercer tus derechos del RGPD, escribe a mrjeffersonx@gmail.com. No hay un delegado de protección de datos aparte: esa misma dirección es el contacto para cualquier asunto de protección de datos.

3. Datos que se tratan

  • Cuenta de Google: nombre, email y foto de perfil, obtenidos al iniciar sesión con Google (permisos openid, email y profile). Se usan solo para comprobar que quien entra es el titular.
  • Datos bancarios (Open Banking): identificadores y nombres de cuenta, saldos y movimientos (fecha, importe, divisa y concepto) de las cuentas que el titular autoriza.
  • Datos introducidos a mano: nombres de bancos, notas y movimientos importados desde ficheros CSV de extractos.
  • Lista de espera: el email que dejas en el formulario «Pedir acceso» de la web pública, con el idioma de la página y el plan que te interesa, si eliges uno.
  • Datos técnicos: el proveedor de hosting (Vercel) puede registrar datos estándar de cada petición, como la dirección IP y el navegador, para operar y proteger el servicio.

Los conceptos de los movimientos pueden incluir nombres de comercios o de personas que han enviado o recibido una transferencia. Se guardan tal como los facilita el banco y solo los ve el titular.

4. Open Banking con Enable Banking (solo lectura)

Para leer los datos de BBVA, Revolut y Santander, Jeff Banks usa el servicio de información sobre cuentas (AIS) de Enable Banking, conforme a la Directiva europea de servicios de pago (PSD2).

  • El acceso es de solo lectura: la aplicación puede consultar saldos y movimientos, pero no puede hacer pagos, transferencias ni cambios en las cuentas.
  • El titular autoriza cada banco directamente en la web o app de su banco, con la autenticación reforzada del propio banco. Jeff Banks nunca ve ni guarda las credenciales bancarias.
  • Cada autorización tiene fecha de caducidad y se puede revocar en cualquier momento. Una vez revocada o caducada, no se obtienen datos nuevos.

Enable Banking y cada banco tratan los datos según sus propias políticas de privacidad.

5. Lista de espera de la beta

La beta de Jeff Banks es por invitación. En la web pública, el formulario «Pedir acceso» te apunta a la lista de espera sin crear una cuenta.

  • Qué se guarda: tu email, el idioma de la página desde la que lo enviaste, el plan que te interesa si eliges uno, y la fecha de la solicitud. No se piden tu nombre ni datos bancarios.
  • Para qué: solo para escribirte, en tu idioma, cuando haya plaza en la beta. No se usa para boletines ni publicidad.
  • Base legal: tu consentimiento (art. 6.1.a RGPD), que das al marcar la casilla del formulario y puedes retirar cuando quieras.
  • Quién lo ve: solo el titular, desde el panel de administración de Jeff Banks. Se guarda en la misma base de datos Upstash Redis que el resto de la aplicación.
  • Cuánto tiempo: hasta que recibes la invitación o pides salir de la lista, lo que ocurra antes. Para salir, escribe a mrjeffersonx@gmail.com.
  • Tu invitación: al invitarte, tu email sale de la lista y queda solo en tu código de invitación, para que únicamente tu cuenta de Google pueda usarlo. Se borra del código en cuanto lo usas, caduca o se revoca.

Para frenar los envíos automáticos, la aplicación cuenta cuántas veces se usa el formulario desde cada conexión y con cada email. Esos contadores no guardan la dirección IP ni el email, solo una huella de cada uno (un hash calculado con una clave secreta), y se borran solos en 24 horas como máximo.

6. Para qué se usan

Los datos bancarios, únicamente para mostrar al titular sus saldos, ingresos, gastos y P&L por periodos; el email de la lista de espera, solo para invitarte a la beta. La base legal es el consentimiento (art. 6.1.a RGPD): el del titular, que da al iniciar sesión y al autorizar cada banco, y el tuyo al apuntarte a la lista.

  • No se venden, alquilan ni ceden datos a nadie.
  • No se usan para publicidad, perfiles comerciales, puntuaciones de crédito ni para entrenar modelos de IA.
  • No hay cookies de analítica ni de publicidad.

7. Dónde se guardan

  • Base de datos: los bancos, los movimientos y la lista de espera se guardan en una base de datos Upstash Redis vinculada al proyecto de Vercel. Solo la aplicación accede a ella, con credenciales privadas que no están en el código fuente.
  • Sesión: el nombre, email y foto de Google no se guardan en la base de datos; van en una cookie de sesión cifrada y HTTP-only que caduca a los 7 días o al cerrar sesión.
  • Hosting: la aplicación se ejecuta en Vercel y todo el tráfico va cifrado por HTTPS.
  • Copias locales: el titular puede ejecutar una herramienta de sincronización en su propio ordenador que guarda allí copias de los datos descargados.

Vercel y Upstash son empresas con sede en Estados Unidos y pueden tratar datos fuera del Espacio Económico Europeo, según sus propios acuerdos de tratamiento de datos.

8. Con quién se comparten

Solo con los proveedores necesarios para que la aplicación funcione, cada uno para su función:

  • Google: inicio de sesión. Las fuentes tipográficas se sirven desde la propia aplicación.
  • Enable Banking y los bancos conectados (BBVA, Revolut, Santander): acceso a los datos de las cuentas.
  • Vercel: hosting de la aplicación.
  • Upstash: base de datos.

Fuera de estos casos, los datos solo se comunicarían si lo exigiera una ley o una autoridad competente.

9. Cuánto tiempo se conservan

Mientras el titular use la aplicación. Al eliminar un banco en Jeff Banks se borran también sus movimientos, y el titular puede borrar la base de datos completa en cualquier momento. La cookie de sesión caduca a los 7 días o al cerrar sesión. Cada solicitud de la lista de espera se conserva hasta que se envía la invitación o pides salir de la lista; el email de una invitación, hasta que se usa, caduca o se revoca; y los contadores contra envíos automáticos, 24 horas como máximo.

10. Tus derechos (RGPD)

Puedes ejercer los derechos de acceso, rectificación, supresión, limitación, portabilidad y oposición, y retirar tu consentimiento en cualquier momento, escribiendo a mrjeffersonx@gmail.com. Si crees que tus datos no se han tratado correctamente, puedes reclamar ante la Agencia Española de Protección de Datos (aepd.es).

11. Seguridad

  • Acceso restringido a una lista cerrada de cuentas de Google verificadas (actualmente, solo la del titular).
  • Inicio de sesión con OAuth y PKCE, y cookies de sesión cifradas y HTTP-only.
  • Tráfico cifrado por HTTPS y secretos (claves y tokens) fuera del repositorio de código.
  • Límites de envíos por conexión, por email y en total en el formulario de la lista de espera.

12. Cambios en esta política

Si la política cambia, se actualizará esta página y su fecha de última actualización. Consulta también los términos del servicio.

Privacy Policy

Last updated: September 28, 2026

Jeff Banks is a personal finance (P&L) dashboard that Jeffry built for his own use. This policy explains what data the app processes, where it comes from, where it is stored and how to exercise your rights.

1. What Jeff Banks is

A private web app that shows, in one place, the balances, income, expenses and profit and loss (P&L) of Jeffry's personal bank accounts. It does not offer services to anyone else, has no ads and is free. Only the owner's authorized Google account can sign in. On its public website, anyone can join the beta waiting list, explained below.

2. Controller and contact

The data controller is Jeffry, the owner and only user of Jeff Banks. For any privacy question or to exercise your GDPR rights, email mrjeffersonx@gmail.com. There is no separate data protection officer: that same address is the contact for any data protection matter.

3. Data processed

  • Google account: name, email and profile picture, obtained through Google sign-in (openid, email and profile scopes). Used only to check that the person signing in is the owner.
  • Bank data (Open Banking): account identifiers and names, balances and transactions (date, amount, currency and description) for the accounts the owner authorizes.
  • Manually entered data: bank names, notes and transactions imported from bank statement CSV files.
  • Waiting list: the email you leave in the "Request access" form on the public website, with the page's language and the plan you are interested in, if you pick one.
  • Technical data: the hosting provider (Vercel) may log standard request data, such as IP address and browser, to operate and protect the service.

Transaction descriptions may include the names of merchants or of people who sent or received a transfer. They are stored as provided by the bank and are only visible to the owner.

4. Open Banking through Enable Banking (read-only)

To read data from BBVA, Revolut and Santander, Jeff Banks uses the account information service (AIS) of Enable Banking, under the EU Payment Services Directive (PSD2).

  • Access is read-only: the app can view balances and transactions, but it cannot make payments, transfers or any change to the accounts.
  • The owner authorizes each bank directly on the bank's own website or app, using the bank's strong customer authentication. Jeff Banks never sees or stores bank credentials.
  • Each authorization has an expiry date and can be revoked at any time. Once revoked or expired, no new data is fetched.

Enable Banking and each bank process data under their own privacy policies.

5. Beta waiting list

The Jeff Banks beta is invite-only. On the public website, the "Request access" form puts you on the waiting list without creating an account.

  • What is kept: your email, the language of the page you sent it from, the plan you are interested in if you pick one, and the date of the request. Neither your name nor any bank data is asked for.
  • What for: only to write to you, in your language, when there is a place in the beta. It is not used for newsletters or advertising.
  • Legal basis: your consent (Art. 6(1)(a) GDPR), given by ticking the form's box, which you can withdraw at any time.
  • Who sees it: only the owner, in the Jeff Banks admin console. It is stored in the same Upstash Redis database as the rest of the app.
  • How long: until you receive the invitation or ask to be taken off the list, whichever comes first. To leave it, email mrjeffersonx@gmail.com.
  • Your invitation: when you are invited, your email leaves the list and stays only on your invitation code, so that only your Google account can use it. It is removed from the code as soon as you use it, it expires or it is revoked.

To curb automated submissions, the app counts how often the form is sent from each connection and with each email. Those counters keep neither the IP address nor the email, only a fingerprint of each (a hash computed with a secret key), and delete themselves within 24 hours.

6. How the data is used

Bank data, only to show the owner his balances, income, expenses and P&L over time; the waiting list email, only to invite you to the beta. The legal basis is consent (Art. 6(1)(a) GDPR): the owner's, given when signing in and when authorizing each bank, and yours when you join the list.

  • Data is never sold, rented or shared with anyone for their own purposes.
  • It is not used for advertising, marketing profiles, credit scoring or training AI models.
  • There are no analytics or advertising cookies.

7. Where the data is stored

  • Database: banks, transactions and the waiting list are stored in an Upstash Redis database linked to the Vercel project. Only the app accesses it, using private credentials that are not in the source code.
  • Session: the Google name, email and picture are not stored in the database; they live in an encrypted, HTTP-only session cookie that expires after 7 days or on sign-out.
  • Hosting: the app runs on Vercel and all traffic is encrypted over HTTPS.
  • Local copies: the owner may run a sync tool on his own computer that keeps copies of the downloaded data there.

Vercel and Upstash are US-based companies and may process data outside the European Economic Area, under their own data processing agreements.

8. Who the data is shared with

Only the providers the app needs to work, each for its own role:

  • Google: sign-in. Fonts are served by the app itself.
  • Enable Banking and the connected banks (BBVA, Revolut, Santander): access to account data.
  • Vercel: app hosting.
  • Upstash: database.

Beyond these, data would only be disclosed if required by law or by a competent authority.

9. How long the data is kept

For as long as the owner uses the app. Deleting a bank in Jeff Banks also deletes its transactions, and the owner can delete the whole database at any time. The session cookie expires after 7 days or on sign-out. Each waiting list request is kept until the invitation is sent or you ask to be taken off the list; the email on an invitation until it is used, expires or is revoked; and the counters against automated submissions for 24 hours at most.

10. Your rights (GDPR)

You can exercise your rights of access, rectification, erasure, restriction, portability and objection, and withdraw your consent at any time, by emailing mrjeffersonx@gmail.com. If you believe your data has not been handled properly, you can lodge a complaint with the Spanish Data Protection Agency (aepd.es).

11. Security

  • Access restricted to a closed list of verified Google accounts (currently only the owner's).
  • Sign-in with OAuth and PKCE, and encrypted, HTTP-only session cookies.
  • Traffic encrypted over HTTPS, and secrets (keys and tokens) kept out of the code repository.
  • Submission limits per connection, per email and overall on the waiting list form.

12. Changes to this policy

If this policy changes, this page and its last updated date will be updated. See also the terms of service.