Xfin

Data Usage Policy

Last updated 18 August 2026

The privacy policy covers your rights. This page is the plainer companion to it: for each kind of data, where it physically sits and what touches it.

Where each thing lives

DataWhere it livesLeaves your device?
Transactions from your bank, through PlaidYour phoneNever copied to our server, even with backup on. Each phone re-fetches them from Plaid. A rounded summary of the last ten goes to Anthropic when you ask Fin a question.
Transactions you type, import or ask Fin to logYour phone, and our server when backup is onYes, with backup on. Also in the Fin summary as above.
Your edits to bank transactions (category, corrected merchant, notes)Your phone, and our server when backup is onYes, with backup on
Account balances, names and institutionsYour phone, and our server when backup is onYes, with backup on. The bank name and a rounded balance also go in the Fin summary; the name you gave the account does not.
Budgets, goals, limits, contributionsYour phone, and our server when backup is onYes, with backup on. Goal names are replaced with generic labels in the Fin summary.
Net worth historyYour phoneNo. Only the current total appears in the Fin summary.
Chat history with FinYour phone onlyNo, and it is not in any backup. Deleted after 14 days of no activity unless starred.
Name, email or Apple sign-in, date of birth, countryOur server (Supabase)Yes, that is where it lives
Bank access tokenOur server onlyNever sent to your device
Notification settings, push token, phone UTC offsetOur serverYes
Notification messages and read stateOur serverYes. Written on your phone, so a message can name an amount, merchant or category.
Subscription statusOur serverYes, that is where it lives
Assistant usage countsOur serverA count and a cost only, never what you asked
Security and audit logsOur serverYes, that is where they live. They hold your account id, IP address, device user-agent and which endpoint was called.

When data leaves your device

Cloud backup, which is on by default

This is the big one, so it goes first. With cloud backup on, the records you create in Xfin are copied to our server as you make them: your accounts and their balances, the transactions you enter or import, your edits to bank transactions, your categories, your goals and contributions, and your rules and preferences. It exists so a reinstall or a new phone does not lose your work.

It travels over TLS and is encrypted at rest, and row-level security scopes every row to your account. It is not encrypted with a key only you hold, so we are technically capable of reading it. Turn it off in Settings, under Cloud backup and sync, and nothing further is copied.

Refreshing a connected bank

Your device asks our server, our server asks Plaid, and the result comes straight back to your device. Our server is a pass-through for this. It does not keep a copy of your transactions, and neither does cloud backup.

Recognising a merchant you typed in

When you enter a transaction by hand or import one, Xfin can ask Plaid to identify the merchant so the entry gets a proper name, logo and category. That sends the description you typed, the amount, whether it is money in or out, and the currency. Nothing that identifies you goes with it, and Plaid keeps nothing for us. Transactions that already came from your bank never go through this.

Importing a statement

A CSV is read on your phone and nothing is sent. A PDF is different: the text your phone extracts from it goes to our server and on to Anthropic to be turned into a transaction list, and a scanned PDF with no text layer is sent as the file itself. That is the whole statement, not a summary. It happens only for the file you picked, and no copy is kept once the import finishes.

Asking Fin a question

Your question and a summary of the relevant figures are sent to our server and on to Anthropic. It is mostly aggregates and totals rather than your raw transaction list, but "summary" is a vague word, so here is what is in it: your period income and spending, cash reserve, net worth, budget and goal progress, your last ten transactions with merchant, category and an amount rounded to the nearest $5, your accounts with balances rounded to the nearest $50 and the bank they belong to, your goals, your categories, your currency and anything you have asked Fin to remember.

Account nicknames and goal names are replaced with generic labels, exact balances are rounded off, and your notes are not sent at all. Text that does go is scanned first, and anything shaped like a social insurance or social security number, an email address, a phone number or a card number is replaced before it leaves your phone.

Two extras worth naming. If you attach a photo to a chat, the image is sent. If your question needs current information, Fin can run a web search through Anthropic, and the search text goes to Anthropic and its search provider.

Fin only reads your financial picture when the question needs it. Asking it to log a coffee, or saying hello, does not send a summary at all. The conversation itself stays on your phone.

Crash reports

If the app crashes or hits an unexpected error, a report goes to Sentry: the error and its stack trace, the app version and build, your iOS version and device model, a trail of recent app events, and your account id when you are signed in. It does not contain your transactions, balances or account names. You can turn this off in Settings, and turning it off stops the native crash handler too.

Usage analytics

We use PostHog to see which features get used: a setup step finished, a goal created, an option tapped. An event carries what happened and a simple label like the screen it happened on.

No dollar amount, account number, transaction note, merchant name or search text is ever part of an event. One filter on the way out enforces it, and a test fails our build if that filter is weakened. Session recording, automatic error capture and location lookup are all switched off, though PostHog turns them on by default.

It shares the crash-reporting switch in Settings. Turning that off stops both at once, and PostHog never starts until the app has read the setting. The Firebase Analytics library is still in the app from an earlier build, unconfigured, sending nothing.

What we never send anywhere

How long things are kept

Who we share with, and why

WhoWhat forTheir role
Plaid Connecting to your bank, fetching transactions, and recognising merchants on entries you typed in yourself Independent controller. Plaid collects and uses the information it gathers in its own right, under its own privacy policy. Not merely on our instructions.
Apple Sign in with Apple, push notification delivery, and subscription billing Not our processor. Apple is an independent controller for Sign in with Apple and for App Store billing, and handles that information under its own policy. For push notifications it carries the message to your device.
Supabase Accounts, authentication and the server-side records listed above Processor acting on our instructions
Anthropic Generating Fin's replies from the summary described above, running a web search when a question needs one, and reading a PDF statement you choose to import Processor acting on our instructions
Resend Sending the one confirmation email when you join the waitlist on our website Processor acting on our instructions
PostHog Which features are used. Never amounts, account numbers, notes or search text Processor acting on our instructions
Sentry Crash reports Processor acting on our instructions

The vendors marked as processors handle data only on our instructions and are not permitted to use it for their own purposes.

Plaid and Apple are different, and it is worth being clear about it. Neither is acting solely on our instructions. When you connect a bank through Plaid, Plaid collects your information as a controller in its own right and decides how it uses it; you can review and disconnect those connections directly at my.plaid.com. When you use Sign in with Apple or buy a subscription, Apple is likewise handling that information on its own terms, not ours. The privacy policy says the same thing, and this table is the shorter version of it.

Controls you have

All of these are in Settings.

Questions

support@getxfin.com