Trust & Compliance

Senast uppdaterad: 1 augusti 2026

This page is maintained by Åkraberg ("we", "us", "our") to answer common security and privacy questions about Aega ("the Service"). It describes the controls and practices that are visible in the Service today. It is not an independent certification, audit report or legal opinion.

1. Who operates the Service

Controller / operator: Åkraberg, 780612-2433, Sweden.
Privacy contact: privacy@aega.se
General support: support@aega.se

2. Platform and hosting context

Aega is built on the Lovable platform and uses Lovable Cloud for backend infrastructure (database, authentication, storage and server functions). Lovable provides the underlying platform capabilities; Åkraberg configures the Service, writes the data-access rules, and decides what data is collected and how long it is kept. You can read more about Lovable's platform security in Lovable's own documentation.

3. Access and authentication

  • Accounts are personal and password-protected. Passwords are hashed by the auth provider.
  • You can sign in with email/password or with a supported social provider (e.g. Google). We never see your social-provider password.
  • Data is isolated by household. Row-Level Security in the database ensures a household can only read and write its own rows.
  • Household owners can invite other users by email. Invited users join the household only after accepting an invitation.
  • Site-wide administrator access is restricted and requires either a deployer-configured setup secret or proof of being the first account created in the installation.

4. Data we collect and why

We collect only the data needed to run the Service:

  • Account data: email address, display name, authentication data. Needed to create and secure your account.
  • Household data: transactions, categories, budgets, receipts, projects, properties, appliances, tasks, shopping lists, net-worth records and settings. This is the data you enter to use the Service.
  • Bank data (optional): when you connect a bank via Enable Banking Oy, we receive account holder name, IBAN/account number, balance and transaction list. This only happens with your explicit PSD2 consent and you can revoke it at any time.
  • AI data (optional): when you use AI features, relevant text or images may be sent to the AI provider you or your administrator configured. Built-in AI goes through Lovable AI Gateway.
  • Technical data: IP address, browser type and device type may be logged by the hosting platform for security and diagnostics.

5. Subprocessors

We use the following subprocessors to operate the Service:

  • Lovable — hosting, deployment and AI gateway infrastructure.
  • Supabase — database, authentication and file storage. Data is hosted in the EU region.
  • Enable Banking Oy — licensed PSD2 AISP (Finnish Financial Supervisory Authority) for bank account aggregation in the EU.
  • Optional AI providers — only when you or your administrator configure a custom AI provider (OpenAI, Google, Ollama, etc.).

We do not sell personal data and we do not use it for advertising. Data is shared only with the subprocessors above and with other members of your household when you explicitly share it.

6. Cookies and storage

We use only strictly necessary authentication tokens and local storage to keep you signed in and remember your UI preferences (theme, sidebar state). We do not use advertising or third-party tracking cookies. The auth provider may issue session cookies as part of sign-in; these are necessary for the Service to work.

7. Retention and deletion

  • Account data: kept while your account is active, then removed within 30 days.
  • Bank transactions: kept until you remove the bank connection or delete the data yourself.
  • Backups: rotated and overwritten within 30 days.
  • Data required by law (for example accounting records): kept for the period required by applicable law.

You can download a full backup of your household data in Settings → Backup. You can delete your account permanently in Settings → Danger Zone. Deleting your account removes your auth record and cascades to your profile and household data.

8. Security measures

  • TLS encryption for data in transit.
  • Row-Level Security and household-scoped access controls in the database.
  • Encrypted storage of sensitive values such as bank session keys and API keys.
  • Least-privilege server functions; admin operations require service-role authorization.
  • SSRF guards on outbound AI and backup destinations.
  • Audit logging of data changes.

No system is 100 % secure. You are responsible for keeping your password confidential and for using a strong, unique password.

9. Your privacy rights

9.1 GDPR (EU/EEA) and UK GDPR

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your data ("right to be forgotten").
  • Restrict or object to certain processing.
  • Receive your data in a portable format.
  • Withdraw consent at any time (for example for bank aggregation or AI features).
  • Lodge a complaint with your local supervisory authority.

Most rights can be exercised directly in the app (Settings → Backup, Settings → Danger Zone, or by disconnecting bank/AI integrations). You can also email privacy@aega.se.

9.2 CCPA / CPRA (California, USA)

California residents have the right to:

  • Know what personal information we collect and how we use it.
  • Request deletion of personal information.
  • Correct inaccurate personal information.
  • Request a copy of personal information in a portable format.
  • Opt out of the "sale" or "sharing" of personal information.

We do not sell or share personal information for cross-context behavioural advertising. If you would like to exercise your California privacy rights, email privacy@aega.se.

10. International transfers

Your data is primarily stored on servers in the EU. If data is transferred outside the EEA/UK, we rely on adequacy decisions or standard contractual clauses (SCCs) approved by the European Commission or UK authorities.

11. Data Processing Agreement

We process personal data only on documented instructions from you, as far as those instructions are compatible with the Service. If you need a signed Data Processing Agreement for your own records, contact us at privacy@aega.se.

12. Incident and vulnerability reporting

If you discover a security issue or experience a suspected data breach, please contact us immediately at privacy@aega.se. We will investigate and, where required, notify affected users and regulators without undue delay.

13. Changes to this page

We update this page as the Service changes. The "Last updated" date at the top of the page shows the latest revision. Significant changes will be communicated in the app.