Privacy.
What KrabyFlow keeps about you, why, for how long, who else sees it, and what you can do about it.
Version of 24 September 2026
Who is responsible
KrabyFlow is operated by PentaLab SRL, which decides what is done with the data described here (the controller, in the words of the GDPR). Write to contact@thepentalab.com for anything about your data.
- Company. PentaLab SRL, a Belgian private limited company.
- Registered office. Avenue Georges Henri 196, 1200 Woluwe-Saint-Lambert (Brussels), Belgium.
- Enterprise number. 1037.930.979. VAT. BE1037.930.979.
- Contact. contact@thepentalab.com.
What we keep and why
Your account
Your email address, a hash of your password (a password is never stored as you typed it), the version of these texts you accepted and when. Signing in creates a session, kept in a cookie on your device and in a table on our side with the address your browser connected from, the name your browser gives itself, and when it was last used, so that you can see and end your sessions under Settings.
What you enter
The portfolios, holdings, targets, transactions, accounts, loans, properties, watchlists, budgets and settings you type in. KrabyFlow never connects to your bank or broker and holds no login of theirs.
What the app derives
A daily record of your net worth, so the overview can draw it over time, and the reports the pages show. These are computed from what you entered and from market prices.
Who invited you
If you created your account through someone’s referral link or code, we keep which account that was, so your discount and their reward can be worked out. They see a shortened form of your email address, the plan you are on and when you joined; never your portfolio or anything in it.
Which pages you open
A count of how many times you opened each page of the app on each day. It tells us which pages are used and which can be made simpler or removed. It is a number per page and day: not what the page showed, not the time, and nothing leaves our servers.
Messages you send us
A message from the contact page is stored with your name, your email address, the address your browser connected from and the name your browser gives itself, so that we can answer it and notice abuse of the form.
What our staff do
Every action taken in the admin area on an account (a plan granted, an account suspended, an account looked at) is written to an audit log with the email of the person who acted, the email of the account concerned and the address the action came from. When we look at your portfolio, only to fix a problem you asked us to look at, we see your account as you see it, we cannot change anything in it, and each time is recorded in that log.
Technical records
The web server in front of the app keeps an access log: the address a request came from, the page asked for, the time and the name the browser gives itself. It is used to look into failures and attacks. The app also counts requests per address and per account, in memory and for an hour at most, to slow down anyone sending too many, and remembers in memory when each account last made a request, so that we can see how many people are online; that memory is gone when the server restarts.
Legal basis
- Contract. Your account, sessions, what you enter and what the app derives from it, the referral that brought you in, and the Claude connection when you make one: we need them to provide the service you signed up for.
- Legal obligation. Billing records, which accounting and tax law require to be kept. Stripe keeps them, as the seller of the plans (see below).
- Legitimate interest. Rate limiting, the access log and other abuse prevention, page counts, the admin audit log, and contact messages: keeping the service safe and working, improving it, and being able to show who did what in the admin area. You may object to any of these by writing to us; we then stop unless we have a compelling reason that outweighs yours, such as an attack in progress.
How long we keep it
- Your account and what you enter. As long as the account exists. Deleting it under Settings removes it at once.
- Sessions. 30 days after the session was last used, or until you sign out or end it under Settings.
- Password reset requests. One hour, with the address the request came from.
- Email confirmation links. One day.
- Page counts. One year, per account, page and day.
- Contact messages. Until we have handled them, then 12 months, in case the conversation continues. They go sooner if you delete your account.
- Admin audit log. 2 years. When an account is deleted its rows stay, with its email address replaced by a number.
- Web server access log. 14 days.
- Backups. A copy of the whole database is made every night and each copy is kept 30 days. A deleted account can therefore survive in a backup for up to 30 days, where nobody uses it; a backup is only ever read to restore the service after a failure.
- Billing records. At Stripe, for as long as the law requires Stripe to keep them.
When you delete your account, everything that names you goes with it: your data, your sessions, your contact messages, your Claude connection, your password reset and confirmation links, and the referral line that shows who invited you. What stays is anonymous: a credit the person who invited you earned from your payments, and the audit log rows about your account, which from then on name it by a number only.
Who else receives it
- OVH SAS, France. Hosts the servers the service and its database run on, inside the European Union.
- Google Workspace. Sends the emails the service sends you: address confirmation, password reset and notifications. Google may process mail outside the European Union, under Google’s EU transfer terms.
- Stripe. Sells the paid plans and takes the payment. It receives your email address, the plan, your name and billing address, and the payment details you enter on Stripe’s own pages, and it keeps the billing records. Stripe processes data in the United States under its EU transfer terms and is responsible for that data under its own privacy policy. KrabyFlow never sees your card number.
- Anthropic, PBC, United States, only if you connect Claude. It reads the figures it asks for in the conversations where you use it, through a connection you can end at any time under Settings. You send it there yourself, and what Claude does with a conversation is governed by Anthropic’s policy.
- KrabyData, PentaLab SRL’s own market data service, running on the same server. It receives the symbols and ISINs of the instruments you hold or watch, to return prices, fund contents and identifiers; never who you are.
- Market data providers. Prices, exchange rates and company figures are fetched using the instrument’s symbol only. Your identity is never part of these requests.
We do not sell, rent or share your data with anyone else.
What we do not do
- No advertising and no analytics service. Nothing on the site or in the app reports to a third party what you look at.
- Two cookies, both needed to run the service: the session cookie that keeps you signed in, and a small cookie that remembers which account last signed in on this browser, kept 400 days, so that we can notice an account that invites itself. Neither tracks you anywhere else.
Your rights
You can see, export and correct everything you entered from the app itself, and delete the account yourself. You also have the right to:
- Access a copy of the data we hold about you, including what the app does not show, such as your sessions and page counts.
- Correct what is wrong.
- Erase it, by deleting the account or by asking us.
- Restrict what we do with it while a question about it is settled.
- Take it elsewhere (portability): the export under Settings gives what you entered in a file another tool can read.
- Object to what we do on the basis of legitimate interest, listed above.
Write to contact@thepentalab.com; we answer within one month. You can also complain to the Belgian Data Protection Authority (Autorité de protection des données, dataprotectionauthority.be), or to the authority of the country where you live.
Changes
When this text changes in a way that matters, its version date changes and signed-in accounts are asked in the app to accept the new version.