Data Usage Policy
Last updated 18 August 2026
The privacy policy covers your rights. This page is the plainer companion to it: for each kind of data, where it physically sits and what touches it.
Where each thing lives
| Data | Where it lives | Leaves your device? |
|---|---|---|
| Transactions from your bank, through Plaid | Your phone | Never copied to our server, even with backup on. Each phone re-fetches them from Plaid. A rounded summary of the last ten goes to Anthropic when you ask Fin a question. |
| Transactions you type, import or ask Fin to log | Your phone, and our server when backup is on | Yes, with backup on. Also in the Fin summary as above. |
| Your edits to bank transactions (category, corrected merchant, notes) | Your phone, and our server when backup is on | Yes, with backup on |
| Account balances, names and institutions | Your phone, and our server when backup is on | Yes, with backup on. The bank name and a rounded balance also go in the Fin summary; the name you gave the account does not. |
| Budgets, goals, limits, contributions | Your phone, and our server when backup is on | Yes, with backup on. Goal names are replaced with generic labels in the Fin summary. |
| Net worth history | Your phone | No. Only the current total appears in the Fin summary. |
| Chat history with Fin | Your phone only | No, and it is not in any backup. Deleted after 14 days of no activity unless starred. |
| Name, email or Apple sign-in, date of birth, country | Our server (Supabase) | Yes, that is where it lives |
| Bank access token | Our server only | Never sent to your device |
| Notification settings, push token, phone UTC offset | Our server | Yes |
| Notification messages and read state | Our server | Yes. Written on your phone, so a message can name an amount, merchant or category. |
| Subscription status | Our server | Yes, that is where it lives |
| Assistant usage counts | Our server | A count and a cost only, never what you asked |
| Security and audit logs | Our server | Yes, that is where they live. They hold your account id, IP address, device user-agent and which endpoint was called. |
When data leaves your device
Cloud backup, which is on by default
This is the big one, so it goes first. With cloud backup on, the records you create in Xfin are copied to our server as you make them: your accounts and their balances, the transactions you enter or import, your edits to bank transactions, your categories, your goals and contributions, and your rules and preferences. It exists so a reinstall or a new phone does not lose your work.
It travels over TLS and is encrypted at rest, and row-level security scopes every row to your account. It is not encrypted with a key only you hold, so we are technically capable of reading it. Turn it off in Settings, under Cloud backup and sync, and nothing further is copied.
Refreshing a connected bank
Your device asks our server, our server asks Plaid, and the result comes straight back to your device. Our server is a pass-through for this. It does not keep a copy of your transactions, and neither does cloud backup.
Recognising a merchant you typed in
When you enter a transaction by hand or import one, Xfin can ask Plaid to identify the merchant so the entry gets a proper name, logo and category. That sends the description you typed, the amount, whether it is money in or out, and the currency. Nothing that identifies you goes with it, and Plaid keeps nothing for us. Transactions that already came from your bank never go through this.
Importing a statement
A CSV is read on your phone and nothing is sent. A PDF is different: the text your phone extracts from it goes to our server and on to Anthropic to be turned into a transaction list, and a scanned PDF with no text layer is sent as the file itself. That is the whole statement, not a summary. It happens only for the file you picked, and no copy is kept once the import finishes.
Asking Fin a question
Your question and a summary of the relevant figures are sent to our server and on to Anthropic. It is mostly aggregates and totals rather than your raw transaction list, but "summary" is a vague word, so here is what is in it: your period income and spending, cash reserve, net worth, budget and goal progress, your last ten transactions with merchant, category and an amount rounded to the nearest $5, your accounts with balances rounded to the nearest $50 and the bank they belong to, your goals, your categories, your currency and anything you have asked Fin to remember.
Account nicknames and goal names are replaced with generic labels, exact balances are rounded off, and your notes are not sent at all. Text that does go is scanned first, and anything shaped like a social insurance or social security number, an email address, a phone number or a card number is replaced before it leaves your phone.
Two extras worth naming. If you attach a photo to a chat, the image is sent. If your question needs current information, Fin can run a web search through Anthropic, and the search text goes to Anthropic and its search provider.
Fin only reads your financial picture when the question needs it. Asking it to log a coffee, or saying hello, does not send a summary at all. The conversation itself stays on your phone.
Crash reports
If the app crashes or hits an unexpected error, a report goes to Sentry: the error and its stack trace, the app version and build, your iOS version and device model, a trail of recent app events, and your account id when you are signed in. It does not contain your transactions, balances or account names. You can turn this off in Settings, and turning it off stops the native crash handler too.
Usage analytics
We use PostHog to see which features get used: a setup step finished, a goal created, an option tapped. An event carries what happened and a simple label like the screen it happened on.
No dollar amount, account number, transaction note, merchant name or search text is ever part of an event. One filter on the way out enforces it, and a test fails our build if that filter is weakened. Session recording, automatic error capture and location lookup are all switched off, though PostHog turns them on by default.
It shares the crash-reporting switch in Settings. Turning that off stops both at once, and PostHog never starts until the app has read the setting. The Firebase Analytics library is still in the app from an earlier build, unconfigured, sending nothing.
What we never send anywhere
- Your bank username or password. We never receive them at any point.
- Your raw bank transaction history, to anyone other than the summary described above.
- Your chat history with Fin, to any server, including our own.
- Anything at all to advertisers or data brokers.
How long things are kept
- On your device: until you delete the app or the data.
- Chat history: deleted from your phone 14 days after the last message, unless you starred it.
- Server records, backup included: for as long as your account exists.
- After you delete your account: bank connections are revoked with Plaid, then every server record is removed, backup included. Crash reports already sent to Sentry are removed on request by email.
- Security and audit logs: 90 days, cleaned up daily. These are the one server record that survives account deletion, so we can still investigate abuse.
Who we share with, and why
| Who | What for | Their role |
|---|---|---|
| Plaid | Connecting to your bank, fetching transactions, and recognising merchants on entries you typed in yourself | Independent controller. Plaid collects and uses the information it gathers in its own right, under its own privacy policy. Not merely on our instructions. |
| Apple | Sign in with Apple, push notification delivery, and subscription billing | Not our processor. Apple is an independent controller for Sign in with Apple and for App Store billing, and handles that information under its own policy. For push notifications it carries the message to your device. |
| Supabase | Accounts, authentication and the server-side records listed above | Processor acting on our instructions |
| Anthropic | Generating Fin's replies from the summary described above, running a web search when a question needs one, and reading a PDF statement you choose to import | Processor acting on our instructions |
| Resend | Sending the one confirmation email when you join the waitlist on our website | Processor acting on our instructions |
| PostHog | Which features are used. Never amounts, account numbers, notes or search text | Processor acting on our instructions |
| Sentry | Crash reports | Processor acting on our instructions |
The vendors marked as processors handle data only on our instructions and are not permitted to use it for their own purposes.
Plaid and Apple are different, and it is worth being clear about it. Neither is acting solely on our instructions. When you connect a bank through Plaid, Plaid collects your information as a controller in its own right and decides how it uses it; you can review and disconnect those connections directly at my.plaid.com. When you use Sign in with Apple or buy a subscription, Apple is likewise handling that information on its own terms, not ours. The privacy policy says the same thing, and this table is the shorter version of it.
Controls you have
- Disconnect a bank without deleting your account
- Turn cloud backup off, so your data stays on the phone
- Turn crash reporting off
- Decline Fin and keep the rest of the app
- Turn any notification category off
- Export everything
- Delete your account entirely
All of these are in Settings.