Legal
Privacy Policy
This policy covers Mission Control, a personal desktop application I built and use myself. It explains what account data the application handles, where that data is stored, and who can see it.
Last updated 25 July 2026
Who this is
Mission Control is written and operated by Belal Zaky, an individual based in London, United Kingdom. It is not a company, a product, or a service offered to anyone else. Questions about this policy go to hello@belalzaky.uk.
Who uses the application
I am the only user. There are no accounts, no sign-up, and no way for another person to put their data into it. The only financial records it holds are ones I have exported from my own bank and opened on my own computer. If that ever changes, this policy will be rewritten before it changes, not after.
What data is handled
The application has no connection to any bank. It cannot log in to an account, request data from one, or reach a bank's systems in any way. Data arrives only when I download a CSV statement from my own online banking and open that file in the application myself. From those files it reads the date, amount, description and running balance of each transaction, and the account it belongs to.
There is no payment capability of any kind. The application cannot move money, initiate transfers, or alter anything at a bank, because it has no route to a bank at all.
Where the data is stored
Imported transactions are written to a local database file on my own computer. Nothing is uploaded to a server, synced to cloud storage, or backed up off-device. There is no hosted component to this application — no website, no API, no remote database operated by me or by anyone else.
That data folder is excluded from version control, so no financial record can be published with the source code if the code is ever made public.
Who the data is shared with
Nobody. It is not sold, not shared, not sent to advertisers, and not used to train anything. The application contains no analytics, no telemetry, and no third-party trackers. No processor, intermediary or service provider is involved in the flow, because the flow is a file moving from my downloads folder into an application on the same machine.
Retention and deletion
Transaction data stays in the local database until I delete it. The application includes a function that erases the entire local store in one action, and deleting its data folder has the same effect. Because nothing is stored remotely, deletion is final — there is no copy elsewhere to be removed.
Rights
I am the sole data subject and the sole operator, so the usual rights of access, correction, portability and erasure are exercised directly: the data is on my machine, in an open format, and I can read, export or destroy it at will. Rights against my bank are exercised through the bank's own processes.
Changes
If what the application does with data changes materially, this page is updated and the date at the top changes with it. An earlier version of this policy described access to bank data through a licensed account information provider; that route was never used and has been removed from the application entirely.
Contact
Belal Zaky — hello@belalzaky.uk