Skip to content
FCFocused Capitalist
What it doesPricingTrustHelpManifestoLog in
Log inRegister

Privacy Policy

Expense Hunter and Focused Capitalist

Version 2. Effective 18 August 2026. Replaces the policy of 18 August 2025.

The short version

  • Expense Hunter and Focused Capitalist run on one platform with one user account. This policy covers both, and says so wherever the two differ.
  • We store what you type: your account details, your transactions, your positions and their dated values. Nothing arrives from your bank. There are no bank connections, no account aggregation and no credentials to hand over.
  • Free-text fields (titles, descriptions, notes, names of lenders, counterparties and accounts) are encrypted in the database with keys that are themselves encrypted. Amounts, dates and quantities are stored as numbers so that the Service can calculate with them.
  • Your data goes to an AI provider only if you switch AI features on, and only the pieces those features need. Connected AI tools (MCP) read your data only after you authorise them, and only within the scope you grant.
  • We do not sell personal data and there is no advertising. Our servers are in the European Union.
  • You can export everything from your account settings and delete the account yourself. Deletion is immediate.

1. Who is responsible

The controller for the personal data described here is:

Recherche Ventures e.U.
Owner: DI Marc Fenz
Alfred-Coßmann-Gasse 14/2
8054 Graz, Austria
Email: hello@expensehunter.com (Expense Hunter) · info@focusedcapitalist.com (Focused Capitalist)
Company registry number FN 659947k, Landesgericht für Zivilrechtssachen Graz

Either address reaches the same person for privacy questions. This policy is written under the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).

2. What this policy covers

It covers the Expense Hunter apps for iOS and Android, the Expense Hunter web app (app.expensehunter.com), the Focused Capitalist web app (app.focusedcapitalist.com), the MCP endpoint (mcp.focusedcapitalist.com), and the websites expensehunter.com and focusedcapitalist.com. Both products are served by one backend and one database, and one account signs you into both. Which product you registered with is recorded, and the same rules apply either way.

3. What we process, why, and on what basis

We process only what the Service needs. Unless stated otherwise, the legal basis is the performance of our contract with you (Art. 6(1)(b) GDPR). Where we rely on legitimate interest (Art. 6(1)(f)) or on your consent (Art. 6(1)(a)), the section says so.

A. Account and identity

Data: a user ID, username, email address, and optionally your first name, last name and company; a password hash (bcrypt) if you use a password; whether and when your email was confirmed; language and display preferences (week start, date, time and number format); your AI-processing consent flag; the product you signed up with; your role (user or, for us, administrator).

If you sign in with Google or Apple we store only the provider name and the provider's user identifier for you. We do not store the provider's tokens. Your email and name from the provider are used once, to fill in the account. A social identity is attached to an existing account automatically only where the provider has verified the email address and is authoritative for its domain; otherwise you link it yourself after signing in.

Username, email, names and company are stored in one encrypted record; username and email additionally have keyed hashes so that we can look them up without decrypting.

Purpose: creating and securing your account, signing you in, contacting you about the Service (confirmation, password reset, security notices), support.

B. Expense Hunter data

Data: ledgers (title, default currency, time zone); transactions (title, description and notes; date; type; amount and currency; converted amount; exchange rate; who paid and who created it); categories, tags and budgets; expense splits between participants; recurring-transaction templates; bank-account records that you type yourself (institution, account name, account number, routing code, notes, balance); details attached to statement imports (booking text, counterparty name and account, your own name and account, last four card digits, external transaction and merchant IDs); import jobs (original filename and column mapping); sharing (who has access to which ledger, category or tag, at which permission level, and pending invitations, which always name an existing user by ID and never an email address).

Encrypted fields: ledger titles; transaction titles, descriptions and notes; tag names; recurring templates; bank-account name, number, routing code and notes; statement-import booking text, counterparty and own name and account. Category names, amounts, dates, currencies and exchange rates are stored in the clear so that the Service can search, sum and convert.

Purpose: the core features: recording, categorising, budgeting, converting currencies, sharing.

Voice entry is transcribed on your device by the operating system's speech engine. Only the resulting transaction reaches our servers. Where on-device recognition is unavailable, the operating system may fall back to Apple's or Google's speech service under their terms.

Please keep records neutral. The Service is built for financial records. Do not enter data that reveals health, ethnic origin, political opinions, religious beliefs, trade-union membership, sexual orientation or criminal history, whether about you or anyone else. Write "medical bill", not a diagnosis; "loan to a friend", not a name and a reason. Our Terms of Service prohibit entering such data.

C. Focused Capitalist data

Data: portfolios, sheets and sections (name, description, order, reporting currency, default capital-gains tax rate); positions (name and description; asset or liability; instrument or currency; liquidity class; ownership share; capital-gains tax rate; visibility dates); liability details (type, such as mortgage or student loan; lender name; terms; interest rate; minimum payment; maturity date); snapshots, the dated series (quantity, unit price, gross value, acquisition value, after-tax value, value in your reporting currency, exchange rate, ownership share, notes, source, price provenance); pending inputs (a quantity awaiting a price); aliases you give to positions; write batches recorded when the web app or a connected tool changes your data (what changed, when, from which origin, and the previous values so that you can undo); the pairing configuration between one of your portfolios and one of your Expense Hunter ledgers (which ledger, which scope of transactions); custom instruments you define (name, symbol, metadata).

Encrypted fields: portfolio, sheet, section and position names and descriptions; snapshot and pending-input notes; aliases; lender names and terms; the raw text of statement and series imports. Quantities, prices, values, dates, rates and tax rates are stored in the clear so that the Service can value, convert and chart them. Custom-instrument names and symbols are stored in the clear because they behave like reference data.

Not personal data: the instrument catalogue and market prices (stocks, funds, ETFs, crypto, metals, exchange rates) are shared reference data with no link to any user. Requests to price providers carry only instrument identifiers, currency codes and dates, never your identity, quantities or values.

Runway and attribution are calculated when you open the page from your snapshots and, if you paired a ledger, from that ledger's transactions. Nothing about them is stored. The pairing is keyed to the person who set it up: someone else who could see the same portfolio would not see your ledger.

Purpose: keeping the logbook, valuing positions, converting to one currency, showing the series and its changes, undoing changes made through connected tools.

D. AI processing (only with your consent)

Three features send data to an external AI model. Each is off until you switch on external AI processing in your account settings (Art. 6(1)(a) GDPR). You can switch it off again at any time; earlier processing remains lawful.

  • Expense Hunter transaction categorisation: sends the transaction title and description (up to 300 characters), amount, currency and direction, plus your category names with a few example descriptions per category. Not sent: date, notes, bank account, counterparty, your identity. A local rule-based pass runs first and often decides without any external call.
  • Expense Hunter CSV mapping: sends the header row and up to ten sample rows of the file you are importing.
  • Focused Capitalist statement import: sends the statement text you paste, so that holdings can be recognised. The pasted text and the parsed rows are stored encrypted for at most 24 hours and then deleted.

The provider is OpenRouter, Inc. (USA), which routes the request to the model we configure (currently a Google Gemini model). For Expense Hunter we keep an encrypted copy of the prompt and the response for quality control; it is encrypted to a key held offline, so the running system cannot read it. For Focused Capitalist we log only token counts. Usage counts per feature are kept to enforce fair-use limits.

E. Connected tools and API access (MCP)

You can connect AI assistants and developer tools (for example Claude, ChatGPT, Claude Code or Codex) to your own data through our MCP server. Each connection is authorised by you in your browser (OAuth 2.1 with mandatory consent), scoped to reading Expense Hunter data, reading Focused Capitalist data, or reading and writing Focused Capitalist data, and can be revoked at any time in your account settings. Idle connections expire after 90 days.

What we store: the client's self-declared name and version, the scopes you granted, hashed tokens (never the tokens themselves), and, per tool call, the tool name, outcome and duration. We do not record what a tool asked or what it returned. This telemetry is kept for 13 months and used, in aggregate, to operate and size the service (Art. 6(1)(f)); an administrator can see it only per client type, not per call content.

What leaves: whatever a connected tool reads within its scope goes to that tool's operator and is then governed by their privacy policy. Reading transactions, positions or net worth through a tool is a transfer you instruct. We do not vet or endorse individual clients; any MCP client can register with our server, and none gains privileges by doing so.

F. Security, technical and usage data

Activity log: for security-relevant actions (sign-in and failed sign-in, sign-out, password and email changes, sharing changes, exports, deletion, connected-tool authorisation and revocation, and similar) we record the action, its outcome, the time, your user ID, the product and platform you used, a request ID, your browser or app identifier (user agent) and your IP address. The IP address is stored encrypted, with a keyed hash for lookup; a failed sign-in records a hash of the username, not the username. We use this log to protect accounts, investigate abuse and answer your questions about your account (Art. 6(1)(f)). Entries are retained for as long as they are needed for the security of the Service and for the establishment, exercise or defence of legal claims. The log is not deleted when you delete your account, because it also documents that the deletion happened and who requested it; it then contains no readable identity beyond your former user ID.

Aggregate statistics such as sign-ins per day or daily active users are computed from that log and contain no IP addresses or user agents.

Sessions: we store your refresh tokens with their expiry and rotation state, so that "sign out everywhere" works. Access tokens live 15 minutes; refresh tokens up to 30 days in the web apps and up to one year in the mobile apps.

Rate limiting: to slow down brute-force and abuse, sign-in, registration and a few public endpoints are limited per IP address; the IP is held only transiently in memory for the limit window.

App analytics (Expense Hunter): the apps send us usage events (for example which screen or feature was used) with your user ID, a per-installation identifier, device model, operating system and app version, a keyed hash of your IP address, and event details. We use them to understand which features are used and to fix problems (Art. 6(1)(f)). Some interactions in the Expense Hunter app (selecting a ledger, category or currency) and the onboarding goals you pick are recorded together with the time, device information and the IP address of the request.

Habit tracking (Expense Hunter): streak and habit records for the tracking feature, stamped to expire after two years.

Firebase (Expense Hunter mobile app only): the iOS and Android app use Google Firebase Crashlytics and Google Analytics for Firebase to report crashes and anonymised usage patterns; your user ID is set at sign-in so that a crash can be matched to a report you send us. Firebase is not used in the Focused Capitalist web app, in the Expense Hunter web app or on the websites.

Website and web-app analytics: expensehunter.com, focusedcapitalist.com and the Expense Hunter web app use Matomo, an analytics tool that we run ourselves on our own server (allure.thefuture.at). Page views and your IP address are processed there and go to no third party (Art. 6(1)(f)). Matomo may set a first-party cookie to recognise a returning browser; see section 4.

Server logs: our application logs carry request IDs, not IP addresses, and rotate after 14 days.

G. Email

We send three kinds of email:

  • Transactional and security email (email confirmation, password reset, and notices when your password, email address or sign-in methods change or when all sessions are signed out). These cannot be switched off while you have an account. Security notices state the event and its time; they contain no IP address, device or location.
  • Onboarding and re-engagement email in the first weeks after registration and if the account goes quiet (Art. 6(1)(f), our interest in helping new users get value from the Service). Every such email has an unsubscribe link and a one-click unsubscribe header. Unsubscribing is per category, is permanent, and applies to your whole account, so it covers both products.
  • Announcements about the Service, with the same unsubscribe.

What we log: for each send, your user ID, the email type, language, campaign, status and time. We do not store the recipient address, the subject or the body in that log, and we do not track opens or clicks. The log is kept for 12 months. Email is sent through Amazon Simple Email Service in the EU (Frankfurt) from addresses at expensehunter.com and focusedcapitalist.com. If you reply, your reply lands in an ordinary mailbox that we read; it is not stored in the product.

H. Subscriptions and payments

Paid tiers are purchased through the Apple App Store or Google Play (Expense Hunter today), with RevenueCat as our subscription backend. We receive and store: the store, the product identifier, the entitlement (Expense Hunter Pro or Focused Capitalist Pro), status, period type (normal, trial, introductory), period start and end, auto-renew flag, and the store's transaction identifiers. We never receive your card or bank details, and we do not store the price you paid. The raw notifications from RevenueCat are kept for 90 days for troubleshooting; a reduced billing record is kept for as long as accounting law requires. Purchases are also subject to Apple's, Google's and RevenueCat's privacy policies.

I. Support and feedback

If you write to us or use the in-app feedback form we process your message, your user ID if you were signed in, and technical context (app and operating system version, and for the feedback form the IP address of the request) to answer you and to improve the Service (Art. 6(1)(f)). Feedback records are kept in anonymised form (without your user ID) after account deletion.

J. Websites

The websites are static pages. Besides Matomo (section 3F), they load nothing from anyone else: the typefaces are served from our own servers, so no third party sees your IP address. The runway calculator on focusedcapitalist.com runs entirely in your browser; the figures you type there never leave it.

4. Cookies and local storage

  • Sign-in cookies (web apps): HttpOnly, Secure cookies carry your session and refresh tokens. Strictly necessary; no consent required.
  • Preferences (web apps): your browser's local storage remembers display choices such as a selected period or view. Nothing in it identifies you to us.
  • Analytics (websites and Expense Hunter web app): our self-hosted Matomo may set first-party cookies to recognise a returning browser. They are used only for our own statistics and are never shared.

We use no advertising or cross-site tracking cookies.

5. How we protect your data

  • Encryption in transit: all connections use TLS. Our mobile apps additionally accept only certificates issued under the public root certificates we pin.
  • Encryption at rest: free-text fields are encrypted with AES-256-GCM. Each ledger and each portfolio has its own data key; the data keys are themselves encrypted by a master key that never leaves a separate secrets vault (HashiCorp Vault), so a copy of the database alone does not reveal them. When your account is deleted, the keys of your ledgers and portfolios are destroyed with the data.
  • Credentials: passwords are hashed with bcrypt; confirmation, reset and API tokens are stored only as hashes.
  • Least visibility: our administration console can see account and activity data for support, but it has no view of Expense Hunter transactions and no view of Focused Capitalist positions, values or net worth.
  • Backups: a nightly encrypted backup (public-key encryption; the private key is kept offline, never on the server) is stored on object storage with an EU data-location setting and a 30-day immutability lock. Backups are retained for 60 days. Restores are scripted and rehearsed.
  • Isolation: the application, its database and its secrets vault run on a server we control in the European Union; the application itself is not directly reachable from the internet, all traffic passes through one TLS-terminating proxy.

No system is perfectly secure. If a breach affects your data we will notify the supervisory authority and, where required, you, as the GDPR prescribes.

6. Retention and deletion

While your account exists

We keep the data in section 3 for as long as your account exists, subject to the shorter periods stated there (AI import text 24 hours; email log 12 months; MCP telemetry 13 months; RevenueCat raw notifications 90 days; write-batch details 180 days; prepared exports 7 days).

When you delete your account

You can delete your account from the settings of either app after re-authenticating. Deletion runs immediately, in one step, and cannot be undone. There is no grace period, so export first.

  • Deleted outright: your credentials, sessions, social sign-in links, invitations, email preferences, connected-tool authorisations and tokens, pairing configuration, prepared exports, and every ledger and portfolio of which you are the sole owner, together with their contents and their encryption keys.
  • Anonymised and kept: your account record itself (identity fields overwritten with placeholders, so that references stay consistent), feedback, app analytics events, Expense Hunter AI usage records, and category names you created. Custom instruments you defined are detached from you and remain as reference data.
  • Kept with a stated reason: the activity log (section 3F), the email log for its remaining 12 months, and a reduced subscription record for as long as accounting law requires (in Austria generally 7 years).
  • Shared ledgers (Expense Hunter): data you contributed to a ledger that others still use stays in that ledger for them; your association with it is anonymised. Delete individual entries first if you want them gone.
  • Backups: deleted data can persist in encrypted backups for up to 60 days and is then gone.

Deleting your account does not revoke the authorisation you gave Google or Apple; you can do that in your Google or Apple account.

7. Your rights

  • Access and portability: request a complete export from your account settings at any time. It is a ZIP with a manifest and one file per kind of data (profile, account records, Expense Hunter ledgers, Focused Capitalist portfolios including write batches, connected tools), in JSON and CSV. One export per 24 hours; the file is encrypted at rest and available for 7 days.
  • Rectification: edit your data in the apps, or ask us.
  • Erasure: delete your account yourself, or ask us.
  • Restriction and objection: you can object to processing based on legitimate interest, including analytics and re-engagement email (use the unsubscribe link, or write to us).
  • Withdraw consent: switch external AI processing off in your settings at any time.
  • Complaint: you can lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, dsb.gv.at) or with the authority in your country of residence.

Write to hello@expensehunter.com or info@focusedcapitalist.com. We answer within one month.

8. Who receives data

We do not sell personal data and there is no advertising. We share data only with the processors below, under data-processing agreements, or when the law requires it, or when you instruct it (section 3E).

RecipientPurposeDataLocation
netcup GmbH, Karlsruhe (DE)Hosting of the application, database and secrets vaultAll data described above, on our own serversEU
Amazon Web Services EMEA SARLSending email (SES); unsealing our secrets vault (KMS)Email addresses and message content; KMS sees no user dataEU (Frankfurt)
Cloudflare, Inc.Backup storage (R2)Encrypted backup bundles only; Cloudflare cannot read themEU jurisdiction setting; US company
OpenRouter, Inc.AI features, only with your consent (section 3D)Transaction text, CSV samples, pasted statementsUSA; models may run with Google or other model providers
Google LLC / Google IrelandSign in with Google (verified locally; nothing sent); Firebase in the Expense Hunter appCrash and usage data with your user ID (Firebase)USA / EU
Apple Inc.Sign in with Apple (verified locally; nothing sent); App Store purchasesPurchase data under Apple's policyUSA
RevenueCat, Inc.Subscription managementApp user ID, store transaction and entitlement data; no email, no cardUSA
Market data providers (EODHD, Frankfurter/ECB, CoinGecko and others)Prices and exchange rates for the instrument catalogueInstrument identifiers and dates only; no user datavarious
Tools you connect (MCP clients)Reading or writing your data on your instructionWhatever the granted scope allowsdepends on the tool

Matomo analytics run on our own infrastructure and involve no third party.

9. International transfers

Your data is stored and processed in the European Union. Where a processor is in the United States (OpenRouter, Google, Apple, RevenueCat, Cloudflare), transfers rest on the EU-US Data Privacy Framework where the company is certified and otherwise on the EU Standard Contractual Clauses. AI processing that sends your content to the United States happens only with your explicit consent (Art. 49(1)(a) GDPR in addition to the safeguards above), and you can withdraw it at any time.

10. Children, automated decisions, changes

The Service is for adults (18+); we do not knowingly process data of children. We make no decisions with legal or similarly significant effect by automated means; AI categorisation only proposes a category that you can change. We may update this policy; material changes are announced by email or in the apps before they take effect, and the current version is always at this address.

11. Contact

Recherche Ventures e.U.
Alfred-Coßmann-Gasse 14/2, 8054 Graz, Austria
hello@expensehunter.com · info@focusedcapitalist.com

Focused CapitalistTwo products, one story · Expense Hunter + Focused Capitalist
TrustPrivacyTermsImprint
© 2026