Privacy policy
Last updated: September 2026. Draft: this privacy policy will be reviewed by a lawyer before the official launch.
- 1. Controller
Escher Consulting GmbH, Höhenweg 2c, 44265 Dortmund, Germany. Email: hello@banking-mcp.com.
Contact us at this address with questions about data protection or to exercise your rights.
- 2. Overview
BankingMCP connects your bank accounts to the AI assistants you choose. We only process the data this service needs. We use no advertising or analytics tools, no tracking and no marketing cookies. Fonts are served from our own server, not from Google.
- 3. Hosting
The website, app and database run on servers of Hetzner Online GmbH in Germany (data centers in Nuremberg or Falkenstein). Hetzner processes data only on our behalf under a data processing agreement (Art. 28 GDPR).
When you visit the website, the server processes technically necessary connection data such as your IP address. To prevent abuse (e.g. mass sign-in attempts), we briefly count requests per IP address in memory; these counters are not stored permanently. We keep no access logs. App error messages may contain an internal user id and are stored temporarily for troubleshooting.
The database is backed up every night, encrypted. Backups are deleted after 14 days.
Legal basis: Art. 6(1)(b) GDPR (providing the service) and Art. 6(1)(f) GDPR (legitimate interest in secure, reliable operation).
- 4. Your account and sign-in
For your account we store your email address, language, sign-up date and the end of your free trial. You sign in with a 6-digit code we send by email. Codes are stored only as a cryptographic hash and expire after 10 minutes.
After signing in we store a session (only as a hash of the session key). It ends after 7 days without use, after 30 days at the latest, or when you sign out.
Legal basis: Art. 6(1)(b) GDPR.
- 5. Cookies
We only use strictly necessary cookies: a session cookie that keeps you signed in (up to 30 days), a cookie for a sign-in or email change in progress (up to 1 hour) and a cookie that remembers your language (1 year).
These cookies are strictly necessary to use the service and therefore need no consent (Section 25(2) no. 2 TDDDG).
- 6. Sending emails (Brevo)
We send sign-in codes and other service emails through Brevo (Sendinblue SAS, Paris, France). Brevo receives your email address and the email's content and processes them as our processor within the EU. The connection to Brevo is encrypted.
Legal basis: Art. 6(1)(b) GDPR.
- 7. Bank data (finAPI)
The connection to your bank is made by finAPI GmbH (Munich, Germany), an account information service supervised by BaFin. You enter your bank credentials only in finAPI's form; BankingMCP never sees them.
For every BankingMCP account we create a separate user at finAPI. Its password is stored encrypted (AES-256-GCM).
We store your connected banks and, per account, its name, IBAN, type, currency and the balance from the last update. We don't store transactions: they are fetched from finAPI for each request of your assistant and only passed on to that assistant.
Legal basis: Art. 6(1)(b) GDPR. When you disconnect a bank or delete your account, the data is deleted with us and at finAPI.
- 8. AI assistants
Every assistant you add gets its own secret MCP address. We store the name you give it, when it was last used and the address (encrypted).
When you connect an assistant such as Claude (Anthropic), ChatGPT (OpenAI), Le Chat (Mistral AI) or Cursor, that provider receives the account data and transactions the assistant requests to answer your questions. You initiate this transfer yourself; from then on, the privacy policy of that provider applies, who acts as an independent controller and may process data outside the EU. Please check its settings, for example whether your chats are used for training.
You can deactivate or remove any assistant at any time. Legal basis: Art. 6(1)(b) GDPR.
- 9. Payments (Stripe)
Subscriptions are handled by Stripe Payments Europe, Ltd. (Dublin, Ireland). You enter payment details directly at Stripe; we don't store them. We only receive a customer and subscription id, the subscription status and the end of the billing period from Stripe.
Stripe may also process data in the United States, based on the EU-U.S. Data Privacy Framework and the EU Standard Contractual Clauses.
Legal basis: Art. 6(1)(b) GDPR, and Art. 6(1)(c) GDPR for statutory retention of invoices.
- 10. Internal notifications
For important account events (e.g. sign-up, sign-in, bank connected, subscription started, account deleted) we receive a short internal email with your email address, user id and the event. It helps us troubleshoot and support the service. It never contains sign-in codes, bank or transaction data.
These emails are sent through Brevo and received in our mailbox at Google (Google Ireland Limited, Dublin, Ireland). Google may also process data in the United States, based on the EU-U.S. Data Privacy Framework and the EU Standard Contractual Clauses.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in reliable operation).
- 11. Contacting us by email
When you write to us, we process your message and email address to answer your request (Art. 6(1)(b) or (f) GDPR) and delete them once they are no longer needed.
- 12. Retention
We keep your data as long as your account exists. When you delete your account, we immediately remove your account data, sessions, assistants and bank data, disconnect your banks at finAPI and cancel your subscription at Stripe. The data disappears from our encrypted database backups within 14 days.
Data we must keep by law (e.g. invoices for up to 10 years) is restricted and not used otherwise until that period ends.
- 13. Security
All connections are encrypted with TLS. Session keys, sign-in codes and MCP addresses are stored only hashed or encrypted. Sign-in and request attempts are limited to prevent abuse.
- 14. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). Where we process data based on legitimate interests, you can object (Art. 21). You can change your email address and delete your account yourself in your account settings.
You can also lodge a complaint with a data protection supervisory authority. Ours is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW) in Düsseldorf.