Your bank. Your rules.
We ask you for access to sensitive things. It's only fair you know exactly what we do with it — in plain language.
Read-only, always
The connection to your bank is made through certified open banking (PSD2) and lets us read balances and transactions — and nothing else. We don't initiate payments, we don't move money. Technically, we can't.
We never see your credentials
Authentication happens on your bank's own site or app. Your banking passwords never pass through MoneyLights — we neither see them nor store them.
The data is yours
We use your data to serve you, and no one else. We don't sell it, we don't share it for advertising, and the AI doesn't train models with it.
The bank connection, from the inside
The integration is handled through Yapily, one of Europe's leading open banking partners, under the European PSD2 directive.
Consent is explicit: you're the one who grants it, at your bank. It's renewed periodically and can be revoked at any time — at the bank or in MoneyLights.
Transactions sync automatically throughout the day. And you can connect and disconnect banks whenever you like.
Your data
Encrypted
In transit and at rest, hosted on the Microsoft Azure cloud.
GDPR
Processed under the General Data Protection Regulation. To exercise your rights, just write to us.
AI with limits
The AI agent reads your data only to answer you. It is never used to train AI models.
Protected document email
Only members of your organisation can send documents to your MoneyLights address — emails from strangers are rejected.
Your account
Sessions under control
You see every device with an active session and can end them remotely, one by one.
Payments via Stripe
Your card details never pass through MoneyLights — the payment is processed by Stripe, a global leader in online payments.
Leave whenever you like
No lock-in. Cancel whenever you like and, if you ask, we'll delete your data.
Straight questions, straight answers.
Still have a question? Talk to the people who build the product.
Write to us