Privacy policy
This policy explains what data Kingdom Finance collects, why, who it is shared with, and what you can demand about it. It covers both this website and the dashboard.
Last updated 25 August 2026.
1. Who handles your data
Kingdom Finance is the financial stewardship dashboard described on this website, operated by [legal entity name not yet set — see SUBMISSION.md] (ABN [ABN not yet set]), [registered address not yet set]. Account deletion is available inside the app under Settings. For anything else concerning this policy, including a copy of your data, write to contact@kingdomfinance.app.
2. What we collect
We collect only what the dashboard needs to work. We do not buy data from third parties and we do not build advertising profiles.
- Account data: name, e-mail address and the sign-in credentials for the product, held by a managed identity service.
- Financial data you enter: accounts, transactions, debts, commitments, goals, investments, categories and household settings.
- Banking data received with your consent: institution identity, accounts, balances and transactions, through an accredited Consumer Data Right gateway.
- Nothing is sold, rented or used for advertising or profiling. Your figures are read by the application and by the calculations it runs; the recipients outside that are Amazon Bedrock, under this product's own AWS account, and — only when you press “Categorize with AI” on the Cash Flow screen — Tavily, a search provider — see section 5 for exactly what each is asked and about which data.
- Minimal operational technical data, such as error and synchronisation logs, used to keep the service running.
3. What we never collect
Your internet banking credentials are typed on your own bank's site; they travel through neither this application nor the gateway, and are stored by neither. We have no transactional access: the integration is read-only.
4. Why we handle it
Every piece of data has a stated purpose, and none of them is advertising.
- Providing the service: showing balances, computing the score, projecting debts and goals, warning about due dates.
- Keeping the household safe: authenticating who signs in and preventing one household from reading another.
- Running the calculations the screens and simulators show you.
- Meeting legal obligations and responding to legitimate requests from authorities.
5. Who we share it with
We share data only with the providers needed to operate the product, and only as far as each one needs:
- The Consumer Data Right gateway: carries your consent to your bank and returns accounts, balances and transactions.
- Amazon Web Services: hosting, database, authentication and e-mail delivery.
- Amazon Bedrock, also Amazon Web Services: reads a bank statement file you choose to upload, and suggests a category for any transaction your own rules do not already recognise — whether it came from that file or from the accounts connected through your bank's Consumer Data Right consent. Your own rules are always tried first; the model sees only a transaction's date, amount and description and the categories your household has already defined. On the two automatic paths it is never given a category to invent; see the next entry for the one place it may.
- Tavily, a search provider — not Amazon, and not reached by anything automatic: only when you press “Categorize with AI” on the Cash Flow screen, and only for a transaction the model cannot place from its own knowledge. What it receives is a search query built from that one transaction's description, never an account number, a balance, or anything else this product holds. That same button is also the only place the model may propose a category your household does not have yet, drawn from nothing but the transaction in front of it — a proposal is written to your category list exactly as a category you added by hand would be, yours to rename or remove at any time.
- Nothing is sold, rented or handed over for advertising, and nothing is shared with data brokers.
6. Where data lives, and for how long
Data is stored on managed AWS infrastructure in the Australian region (ap-southeast-2), encrypted at rest and in transit. The one exception is a request to Amazon Bedrock — reading a bank statement file you choose to upload, or naming a transaction your own rules did not: neither the file nor the transaction is stored anywhere by Bedrock, each request exists only for its own length, and it may be answered from anywhere inside Amazon Bedrock's Asia-Pacific region (Sydney, Tokyo, Seoul, Osaka, Mumbai or Singapore) rather than Sydney alone. For a file you upload, what the model returns is shown to you for review before anything is written to your ledger. For a transaction that arrived through your bank's own connection, it is already on your ledger by the time the model is asked, so its suggestion is written directly and left in your review queue for you to confirm or correct — never marked as reviewed on the model's word alone. Either way, only the ledger itself is stored, and it is stored in ap-southeast-2. A search “Categorize with AI” runs is the second exception: Tavily is not asked to store anything, and this product does not control where it answers from the way it controls where Bedrock is asked to.
We keep a household's data for as long as the account exists. Once the account is deleted, the data is removed and the associated bank connections are ended, except for what the law requires us to retain and for operational backups, which expire on their normal retention cycle.
7. Your rights
You may request a copy of your data, correction of anything wrong, deletion of the entire household, and withdrawal of banking consent — the last one directly on the Accounts screen, without asking anybody.
For the rest, write to contact@kingdomfinance.app. We answer within the deadlines set by the Privacy Act 1988 (Cth) and, for banking data, the Consumer Data Right rules.
8. Cookies
This website uses no advertising cookies and no third-party tracking. The dashboard uses strictly necessary cookies to keep your session open and to remember which scope — personal or business — you were looking at.
9. Children
The product is not intended for people under 16 without the involvement of a responsible adult. A household may include children, but the account is created and administered by an adult.
10. Changes to this policy
When this policy changes materially, the date above is updated and the change is announced in the dashboard before it takes effect.