Privacy Policy
Last updated 8 August 2026
Xfin is a personal finance app for iPhone. This policy explains what we collect, what we don't, and where your information actually lives. It describes how the app is built, not just what we intend.
Who we are
Xfin is operated by Xfin Technologies Inc. ("Xfin", "we", "us", "our"). Xfin Technologies Inc. is the data controller for the personal information described in this policy, except where this policy says otherwise — most importantly Plaid, which is an independent controller of the information it collects when you connect a bank.
Privacy enquiries: support@getxfin.com. A postal address for written correspondence will be published here before the app is released.
The short version
Your financial records stay on your device. Your accounts, transactions, budgets, goals and net worth history are stored in a database on your phone. They are not stored on our servers. We do not sell your data, we do not share it for advertising, and we never see your bank login.
What is stored on your device
Xfin is offline-first. The following lives only on your phone unless you turn on encrypted backup:
- Your accounts and their balances
- Your transactions, categories and any notes you add
- Budgets, spending limits and category focus settings
- Goals, contributions and progress
- Net worth snapshots
- Recurring bills and income you have set up or confirmed
- Your chat history with Fin
If you delete the app, this data is deleted with it. If you have not enabled backup, it cannot be recovered by us or by you.
What we store on our servers
We use Supabase for accounts and for the parts of the app that need a server. What we hold there is deliberately limited:
| What | Why |
|---|---|
| Your profile (name, email, sign-in identity) | So you can sign in and so your settings follow you |
| Notification preferences, your device push token, and delivery records | To send you the alerts you asked for, and not send them twice |
| Bank connection records (an institution reference and an access token) | To refresh your transactions on request. The token is stored server-side and is never sent to your device. |
| Onboarding answers | To set the app up for your situation |
| An encrypted backup blob, if you enable it | So you can restore after reinstalling or changing phone |
| Subscription status | So the app knows which plan you are on. Apple handles the billing itself. |
| Assistant usage counts | To apply fair-use limits and prevent abuse |
| Security audit records and rate-limit counters | To detect abuse of the account system |
Your transactions and balances are not in that list. When Xfin fetches data from your bank, our server passes the request through to Plaid and hands the result straight back to your device. It is not retained server-side.
Connecting a bank
Bank connections are handled by Plaid. When you connect an account, you enter your credentials into Plaid's own screen, not ours. We never see, receive or store your bank username or password.
Your bank may ask you to verify your identity more than once during this process. That is your bank's security step, not something Xfin controls or requests.
Plaid is an independent controller of the information it collects, not only our processor. As of its policy update on 16 April 2026, Plaid describes itself as connecting consumers to financial services directly and retains financial account connections and personal information in its own right. Its handling of your information is governed by its own policy, which you should read:
- Plaid End User Privacy Policy
- my.plaid.com — see the connections you have made through Plaid and disconnect them directly
By connecting an account you consent to Plaid collecting and processing your information as described in that policy. You can disconnect a bank at any time in Xfin under Settings, then Connected accounts, and independently at my.plaid.com.
Fin, the assistant
Fin answers questions about your money. To do that, the question you type and a summary of the relevant figures are sent to our server and on to Anthropic, which generates the reply.
- We send a summary, not your raw transaction history.
- Identifiers are stripped before the request leaves your device.
- Fin proposes. It cannot move money, and every write asks you to confirm it first.
- Conversations are stored on your device so you can look back at them.
Using Fin is your choice, and asking it a question is how you give permission. Nothing is sent to Anthropic unless you ask Fin something that needs your figures. If you never open Fin, no summary of your money ever leaves your device. Anthropic processes that summary on our instructions and is not permitted to use it for its own purposes or to train models on it.
Fin is not a financial advisor and does not give investment advice.
The protection third parties must give your data
Where we share your information with a third party, we require by contract that they protect it to the same standard this policy sets, and that they use it only for the purpose we engaged them for. That applies to Supabase, Anthropic, Sentry and Google (Firebase), each of which acts as our processor on our written instructions and none of which may use your data for their own purposes.
Two are not our processors, and we will not pretend otherwise. Plaid is an independent controller and handles your information under its own policy, which we cannot bind. Apple is likewise an independent controller for Sign in with Apple and App Store billing. Where those two are concerned, their protections are theirs, and the links in this policy take you to them.
We hold no parent, subsidiary or affiliated company that gets access to your data, because there isn't one. We do not sell your data or share it for advertising, and we have no advertising or data-broker relationships to disclose.
How your data is protected
Data in transit is encrypted with TLS. Data at rest on our server is encrypted, and the encrypted backup blob is encrypted with a key derived on your device, so we cannot read it. Access to production systems is limited to those who need it for a specific task, and administrative access is logged. Your bank access token is stored server-side only and is never transmitted to your device.
Diagnostics and analytics
We use Sentry for crash reports and Firebase Analytics for basic usage counts, such as which screens are opened. These tell us the app crashed or that a screen was used. They do not carry your transactions, balances or account names. Crash reporting can be turned off in Settings.
Notifications
If you allow notifications, we store a device push token so we can deliver them. You can turn any category off in Settings, or all of them in iOS Settings.
What we never do
- Sell your personal or financial information
- Share it with advertisers or data brokers
- Use your financial data to train AI models
- Store your bank credentials
- Move money, or initiate any payment or transfer
How long we keep things, and when they go
| What | How long |
|---|---|
| Everything on your device | Until you delete it or delete the app. We cannot reach it and cannot recover it. |
| Your profile and server-side records | For as long as your account exists |
| Bank access tokens | Until you disconnect that bank, or delete your account. Revoked with Plaid at the same time. |
| Encrypted backup blob | Until you turn backup off or delete your account |
| Notification delivery records | Rolling 90 days |
| Security and audit records | Up to 12 months, for abuse investigation |
| Crash reports (Sentry) | 90 days |
| Usage analytics (Firebase) | 14 months, in aggregate |
When you delete your account — Settings, then Delete account, inside the app — your server-side records are deleted and your bank connections are revoked with Plaid. Copies in encrypted backups are purged within 30 days. Data on your device goes when you delete the app. We keep only what a law obliges us to keep, and nothing else.
You do not need to email us to be forgotten, and you do not need to explain why. If you would rather we did it, or want written confirmation once it is done, write to support@getxfin.com and we will respond within 30 days.
Your choices
- Delete your account. Settings, then Delete account. This removes your server-side records and revokes bank connections. Data on your device goes when you delete the app.
- Export your data. Settings, then Data export.
- Disconnect a bank without deleting anything else.
- Turn off backup, analytics or crash reporting individually.
Withdrawing consent
Anything you consented to, you can take back, from inside the app, without asking us:
| What you consented to | How to withdraw it |
|---|---|
| Connecting a bank through Plaid | Settings → Connected accounts → disconnect. Also independently at my.plaid.com. Withdrawing here stops Xfin fetching; Plaid's own retention is governed by its policy. |
| Sending a summary to Fin | Stop using Fin. Nothing is sent unless you ask it something. |
| Crash reporting | Settings → turn off crash reporting |
| Usage analytics | Settings → turn off analytics |
| Notifications | Settings → turn off any category, or all of them in iOS Settings |
| Encrypted backup | Settings → turn backup off. The stored blob is deleted. |
| Having an account at all | Settings → Delete account. This is available inside the app and does not require contacting us. |
None of these are behind a paywall, and turning any of them off does not disable functionality you have paid for.
If you are in Canada
Under PIPEDA you may ask what personal information we hold, ask us to correct it, and withdraw consent. You may complain to the Office of the Privacy Commissioner of Canada.
If you are in the United States
Residents of California, Colorado, Connecticut, Virginia and other states with comparable laws may request access, correction, deletion and portability, and may appeal a refusal. We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done so. There is therefore no "Do Not Sell or Share My Personal Information" process to operate, but you may still contact us to confirm this in writing.
We will not discriminate against you for exercising any of these rights.
If you are in the UK or EEA
You have the rights of access, rectification, erasure, restriction, portability and objection under the UK GDPR and GDPR, and may complain to your supervisory authority. Our lawful bases are performance of our contract with you (running the app), your consent (bank connections, notifications, optional analytics) and our legitimate interests (security and abuse prevention).
Making a request
Email support@getxfin.com. We will respond within 30 days. Most requests are faster to satisfy yourself: export and account deletion are both in Settings.
Where your data is processed
Our providers operate in Canada and the United States, so information stored on our servers may be processed outside the country you live in and may be subject to lawful access requests there. Where required, transfers rely on standard contractual clauses or an equivalent safeguard.
This website
getxfin.com sets no cookies, runs no advertising or tracking scripts, and does not profile visitors. Our host keeps standard server logs, including IP addresses, for security and reliability.
Data breaches
If a breach affects your personal information and creates a real risk of significant harm, we will notify you and the relevant regulator as the law requires, without undue delay.
Children
Xfin is not intended for anyone under 13, and we do not knowingly collect their information.
Changes
If this policy changes in a way that affects how your information is handled, we will tell you in the app rather than only updating this page.
Contact
Questions, requests or complaints: support@getxfin.com.
The data controller is Xfin Technologies Inc. A postal address for written correspondence will be published here before the app is released.