FinanceGadget
Independent · Kerava, Finland

Evidence-led privacy and security intelligence for financial software and AI tools.

FinanceGadget records what software can read, what it keeps, where the data goes, and who is accountable — from primary sources, with every figure dated and every gap marked unknown rather than filled in. Provider dossiers, tool audits, practical security guides, and calculators that show their working.

Every review opens with an audit record like this one →

Cursor

Free and Pro, individual · tested 10 Aug 2026
Input retention
No period stated. The privacy policy says data is retained 'only for as long as necessary to operate the Service effectively and to support legitimate business needs such as legal compliance, safety, dispute resolution, and enforcement of our agreements'. No figure is given for any data category.
Used for training
Committed against, with three named exceptions: 'We do not use Inputs or Suggestions to train our models, or permit third parties to use them for training, unless: (1) they are flagged for security review... (2) you explicitly report them to us... or (3) you've explicitly agreed to their use for such training purposes.'
Opt-out
Privacy Mode — 'When enabled, we will not train on your data.' Documented on the security page and available to free and Pro users. Not mentioned anywhere in the privacy policy read on this date.
Sub-processors
Not named in the privacy policy, which lists only categories: 'third-party hosting, cloud infrastructure, model, analytics, customer support, safety monitoring, communications, payment processing, compliance services, and IT providers'. A named list is published at trust.cursor.com/subprocessors for commercial accounts.
Proceed with caution

Anysphere commits not to train on inputs, with three named exceptions. But the privacy policy states no retention period at all, and Privacy Mode — the control users rely on — appears on the security page and not in the policy.

What this site covers

7 beats, chosen because nobody else covers them properly

Security & privacy teardowns

What each money app can read, how it authenticates, where your credentials end up, and who is legally accountable when something goes wrong.

Cross-border & remittance

The real cost of moving money out of the EU, including the exchange-rate spread that providers advertise as "no fees". Corridors most publishers ignore.

Open Banking in practice

Which apps genuinely connect to European banks under PSD2, how the consent flow actually behaves, and what happens when a token expires or is revoked.

Authentication & fraud

Second factors in banking apps, account-takeover and SIM-swap exposure, and the settings worth changing today.

AI tool security & privacy

What AI coding assistants and chatbots do with what you feed them: retention windows, training opt-outs, sub-processors, and how consumer terms differ from enterprise ones.

LLMs in regulated environments

Using AI tools under GDPR, ISO 27001 and PCI DSS. What the DPAs actually say, what a lawful basis looks like, and where teams get caught out.

Calculators & tools

Transfer-cost and fee comparison tools that show their working, so you can check the maths rather than trust it.

Provider dossiers

AI terms, retention and residency compared from primary records

Anthropic

What Anthropic commits to on training use, retention, residency and DPA terms, with a model inventory keyed to AI Act deadlines.

Training use
Consumer Claude.ai (Free/Pro/Max): yes, by default, unless the user opts out in account privacy settings. Commercial/API: no — Anthropic's Commercial Terms state it may not train models on customer content from the Services.
DPA
Yes, automatic for commercial tiers on accepting the Commercial Terms of Service — Anthropic states the DPA is accepted at the same time. Scoped explicitly to commercial products (Claude for Work, the API); not offered for individual Claude.ai Free/Pro use. A specific DPA effective date circulating in secondary sources was not confirmed on Anthropic's own page — see verification note.

Google

What Google commits to on training use, retention, residency and DPA terms, with a model inventory keyed to AI Act deadlines.

Training use
Consumer Gemini Apps, default ('Keep Activity' on): yes — Google states it uses activity 'to provide, develop, and improve its services (including training generative AI models).' Paid Gemini API / Vertex AI: no — Google states it does not use prompts or responses from paid use to improve its products. Free/unpaid Gemini API and AI Studio: yes — treated the same as consumer activity, used to improve Google's products.
DPA
Yes, for Google Cloud and the paid Gemini API, self-serve via clickthrough acceptance (reportedly through Cloud Console account settings). Not offered for the free consumer Gemini Apps product, which is governed by the Gemini Apps Privacy Notice instead.

Meta

What Meta commits to on training use, retention, residency and DPA terms, with a model inventory keyed to AI Act deadlines.

Training use
Meta AI: yes, by default — public posts and comments, plus interactions with Meta's AI features, are used to train, on a legitimate-interests legal basis for EU/UK users. EU training was paused in 2024 pending regulatory clarity and resumed the week of 14 April 2025. Meta Model API, paid tier: no — content from Paid Services is contractually excluded from training. Meta Model API, unpaid tier: yes — users are warned not to submit sensitive, confidential or personal information to it. Llama open-weight models: not applicable — Meta has no visibility into or processing role over self-hosted use.
DPA
Not applicable to the free consumer Meta AI product — no processor relationship exists. For the Model API's Paid Services, yes: governed by Meta's standard 'Meta Global Processor Terms,' incorporated by reference, which also states Meta will not use Paid Services content to train its models. The Unpaid Services carry no DPA protection. Not applicable to Llama open-weight downloads, which involve no processing relationship with Meta at all.

Mistral AI

What Mistral AI commits to on training use, retention, residency and DPA terms, with a model inventory keyed to AI Act deadlines.

Training use
Le Chat / Vibe (Free, Vibe Pro, Vibe Student): yes, by default, unless the user opts out — 'we do not use Your Data to train our...models except when you use Mistral AI Products under a free subscription, or are subscribed to Vibe Pro or Vibe Student, and you have not opted out of training.' La Plateforme (API): no by default for standard paid use; training does apply to free-tier API use and to explicitly opt-in 'Labs Models' unless zero data retention is active.
DPA
Yes, published and self-serve with no login gate, incorporated by reference into the Commercial Terms of Service. Applies to commercial/API customers acting as controllers; not clearly applicable to individual Le Chat / Vibe consumer use, where Mistral itself is the controller.

Moonshot AI (Kimi)

What Moonshot AI (Kimi) commits to on training use, retention, data residency and API terms, with a model inventory keyed to AI Act deadlines.

Training use
Consumer Kimi Chat (Web/App): yes, processed for service improvement by default. Moonshot API: no, off by default for paid commercial API calls per platform terms.
DPA
Unverified — standard GDPR Art. 28 DPA not published for self-serve consumer or API tiers

OpenAI

What OpenAI commits to on training use, retention, residency and DPA terms, with a model inventory keyed to AI Act deadlines.

Training use
Consumer ChatGPT (Free/Plus/Pro): yes, by default, via the 'Improve the model for everyone' setting. API, ChatGPT Business, Enterprise, Edu and Healthcare: no, off by default — OpenAI's Services Agreement states it will not use customer content to develop or improve its models unless the customer explicitly opts in.
DPA
Yes, self-serve for Business, Enterprise, API, and Edu/Healthcare (a separate Student Data Privacy Agreement variant applies to Edu/Teachers). Signed with OpenAI OpCo, LLC or OpenAI Ireland Ltd depending on customer location. Not applicable to individual consumer ChatGPT use.

Open the full provider table →

Latest

Recent articles

Browse every section →

Latest

Recent reviews

The standing caveat

This site does not rank things by how clever they are

It tells you how a piece of software behaves — what it reads, what it keeps, who can see it. Not which AI model scores highest on a benchmark someone else ran, and not what to do with your money. Nothing here is financial, investment, tax or legal advice, and I am not a licensed adviser.

Read how apps get tested · Who writes this