Data Usage Policy
Last updated 8 August 2026
The privacy policy covers your rights. This page is the plainer companion to it: for each kind of data, where it physically sits and what touches it.
Where each thing lives
| Data | Where it lives | Leaves your device? |
|---|---|---|
| Transactions | Your phone | No, except as an anonymised summary when you ask Fin a question |
| Account balances | Your phone | Same as above |
| Budgets, goals, limits | Your phone | No |
| Net worth history | Your phone | No |
| Chat history with Fin | Your phone | No |
| Name, email, sign-in | Our server (Supabase) | Yes, that is where it lives |
| Bank access token | Our server only | Never sent to your device |
| Notification settings, push token and history | Our server | Yes |
| Subscription status | Our server | Yes, that is where it lives |
| Assistant usage counts | Our server | A count only, never what you asked |
| Security and audit logs | Our server | Yes, that is where they live |
| Encrypted backup, if enabled | Our server, encrypted | Only if you turn it on |
When data leaves your device
Refreshing a connected bank
Your device asks our server, our server asks Plaid, and the result comes straight back to your device. Our server is a pass-through for this. It does not keep a copy of your transactions.
Asking Fin a question
Your question and a summary of the relevant figures are sent to our server and on to Anthropic. The summary is aggregates and totals, not your raw transaction list, and identifiers are removed before it leaves your device.
Fin only reads your financial picture when the question needs it. Asking it to log a coffee, or saying hello, does not send a summary at all.
Crash reports
If the app crashes, a report goes to Sentry with the technical details of the crash. It does not contain your financial data. You can turn this off in Settings.
Usage analytics
Firebase Analytics records events like "opened the goals screen". It records that something happened, not what your numbers are.
What we never send anywhere
- Your bank username or password. We never receive them at any point.
- Your raw transaction history.
- Anything at all to advertisers or data brokers.
How long things are kept
- On your device: until you delete the app or the data.
- Server records: for as long as your account exists.
- After you delete your account: server records are removed and bank connections revoked. Backups are purged within 30 days.
- Security and audit logs: kept up to 12 months for abuse investigation.
Who we share with, and why
| Who | What for | Their role |
|---|---|---|
| Plaid | Connecting to your bank and fetching transactions | Independent controller. Plaid collects and uses the information it gathers in its own right, under its own privacy policy — not merely on our instructions. |
| Apple | Sign in with Apple, push notification delivery, and subscription billing | Not our processor. Apple is an independent controller for Sign in with Apple and for App Store billing, and handles that information under its own policy. For push notifications it carries the message to your device. |
| Supabase | Accounts, authentication and the server-side records listed above | Processor acting on our instructions |
| Anthropic | Generating Fin's replies, from the summary described above | Processor acting on our instructions |
| Sentry | Crash reports | Processor acting on our instructions |
| Google (Firebase) | Usage analytics | Processor acting on our instructions |
The vendors marked as processors handle data only on our instructions and are not permitted to use it for their own purposes.
Plaid and Apple are different, and it is worth being clear about it. Neither is acting solely on our instructions. When you connect a bank through Plaid, Plaid collects your information as a controller in its own right and decides how it uses it; you can review and disconnect those connections directly at my.plaid.com. When you use Sign in with Apple or buy a subscription, Apple is likewise handling that information on its own terms, not ours. The privacy policy says the same thing, and this table is the shorter version of it.
Controls you have
- Disconnect a bank without deleting your account
- Turn encrypted backup on or off
- Turn crash reporting off
- Turn any notification category off
- Export everything
- Delete your account entirely
All of these are in Settings.