Privacy Policy
Last updated 25 September 2026
Xfin is a personal finance app for iPhone. This policy explains what we collect, what we don't, and where your information actually lives. It describes how the app is built, not just what we intend.
Who we are
Xfin is operated by Xfin Technologies Inc. ("Xfin", "we", "us", "our"). Xfin Technologies Inc. is the data controller for the personal information described in this policy, except where this policy says otherwise. Most importantly, Plaid is an independent controller of the information it collects when you connect a bank.
Privacy enquiries: support@getxfin.com. A postal address for written correspondence will be published here before the app is released.
The short version
Your phone is where your money lives. Your accounts, transactions, budgets, goals and net worth history are stored in a database on your phone, and the app works from that copy. We do not sell your data, we do not share it for advertising, and we never see your bank login.
Cloud backup is on by default, and it is a real copy. With it on, a copy of the records you create in Xfin is stored on our server so you can restore after a reinstall and use more than one phone. That copy is protected by encryption in transit, encryption at rest and per-user database rules, but it is not encrypted with a key only you hold, so we could technically read it. You can turn it off in Settings, under Cloud backup and sync, and we would rather tell you that plainly than describe it as something it isn't. What backup covers, and what it does not, is set out below.
What is stored on your device
Xfin is offline-first. All of the following lives on your phone. Some of it is also copied to our server when cloud backup is on, which the next two sections spell out:
- Your accounts and their balances
- Your transactions, categories and any notes you add
- Budgets, spending limits and category focus settings
- Goals, contributions and progress
- Net worth snapshots
- Recurring bills and income you have set up or confirmed
- Your chat history with Fin
Chat history is the one item on that list that is never copied to our server, under any setting. It is also the one item the app deletes on its own: a conversation with no activity for 14 days is removed from your phone, unless you have starred it. Starred chats are kept until you delete them.
If you delete the app with backup off, this data is deleted with it and cannot be recovered by us or by you.
What we store on our servers
We use Supabase for accounts and for the parts of the app that need a server. Setting aside cloud backup, which has its own section below, this is what we hold:
| What | Why |
|---|---|
| Your profile: your name, your email or Apple sign-in identity, and the date of birth and country you give during setup | So you can sign in, and so Xfin can set itself up for where you live and your stage of life |
| Notification preferences, your device push token, and the UTC offset of your phone | To send you the alerts you asked for, and to send them during your waking hours rather than at 3am |
| The notification messages themselves, and which ones you have read or acted on | So the Fin inbox shows the same list on every device and does not repeat itself. These messages are written on your phone and can contain figures, for example an amount, a merchant or a category name. See Notifications below. |
| Bank connection records: the Plaid item reference, which institution it is, its status, and an access token | To refresh your transactions on request. The token is stored server-side and is never sent to your device. |
| Onboarding answers | To set the app up for your situation |
| Subscription status | So the app knows which plan you are on. Apple handles the billing itself. |
| Plaid usage records: which Plaid endpoint was called for one of your connections, for which connection, and when | To attribute what your connections cost us and to watch how often we sync. No financial content: no amounts, balances or merchant names. |
| Assistant usage counts: how many requests and tokens you have used this month, and what they cost us | To apply fair-use limits and prevent runaway cost. Never what you asked or what Fin answered. |
| Security audit records and rate-limit counters | To detect abuse of the account system. Each audit row holds the time, your account id, which endpoint was called, whether it succeeded, your IP address and your device's user-agent string, plus non-content detail such as how many messages a chat request carried. It also records consent decisions, so we can show when you agreed to something and to which version. |
| Deletion markers | A short record that a given item was deleted, so your other phones drop their copy too. It holds no content of its own. |
Transactions your bank sends through Plaid are not in that list, and are never stored on our server. When Xfin refreshes a connected account, our server passes the request through to Plaid and hands the result straight back to your device. Nothing is retained server-side on the way past.
Cloud backup and sync
Backup is on by default. You can turn it off at any time in Settings, under Cloud backup and sync. With it off, nothing in this section leaves your phone.
With it on, we store a copy of:
- Your accounts, including their names, icons, balances, credit limits, APR, minimum payments and which institution they belong to
- Transactions you create yourself, import from a statement, or ask Fin to log, including the amount, date, merchant, category, any notes you add and any merchant location the import supplied
- Your edits to transactions that came from your bank, meaning the category you moved one to, a merchant name you corrected, and any note
- Categories you create
- Your goals and contributions, including names, targets, dates, notes and progress
- Your settings and rules: manual bills and income, recurring rules, transaction and category rules, focus categories, items you have hidden or suppressed, and similar small preference records
We do not copy:
- Transactions fetched from your bank through Plaid. Each device re-fetches those from Plaid itself.
- Your chat history with Fin.
- Your bank access token, which lives server-side only and is never part of a backup.
How it is protected, stated exactly. The copy travels over TLS and is encrypted at rest by our database provider. Every row is scoped to your account by row-level security, so no other user can read it. It is not encrypted with a key that only your phone holds, so we are technically capable of reading it. We do not, and it is not used for anything other than restoring your data to your devices. Deleting a record in the app deletes the server copy and records a deletion marker so your other phones drop it too.
Connecting a bank
Bank connections are handled by Plaid. When you connect an account, you enter your credentials into Plaid's own screen, not ours. We never see, receive or store your bank username or password.
Your bank may ask you to verify your identity more than once during this process. That is your bank's security step, not something Xfin controls or requests.
Plaid is an independent controller of the information it collects, not only our processor. As of its policy update on 16 April 2026, Plaid describes itself as connecting consumers to financial services directly and retains financial account connections and personal information in its own right. Its handling of your information is governed by its own policy, which you should read:
- Plaid End User Privacy Policy
- my.plaid.com. See the connections you have made through Plaid and disconnect them directly
By connecting an account you consent to Plaid collecting and processing your information as described in that policy. You can disconnect a bank at any time in Xfin under Settings, then Connected accounts, and independently at my.plaid.com.
One other thing goes to Plaid, and it has nothing to do with a bank connection. When you type a transaction in by hand or import one from a statement, Xfin can ask Plaid to recognise the merchant so the entry gets the right name, logo and category. That sends the description you typed, the amount, whether it is money in or out, and the currency. It does not send your name, your account or anything that identifies you, Plaid does not store the result for us, and this happens only for entries that did not come from a bank feed in the first place.
Fin, the assistant
Fin answers questions about your money. To do that, the question you type and a summary of the relevant figures are sent to our server and on to Anthropic, which generates the reply. The first time you use Fin the app asks for your permission, and that decision is recorded in our audit log. You can decline and keep using the rest of the app.
What the summary contains. It is built on your phone, and it is a summary rather than your raw history, but we would rather list it than let the word "summary" do work it should not:
- Totals and derived figures: income and spending for the period, your cash reserve, net worth, budget progress, goal progress and the health signals the app already shows you.
- Your last ten transactions, with the merchant, the category and the amount rounded to the nearest $5.
- Your accounts, with the display name you gave them replaced by a generic label such as checking or credit card, balances rounded to the nearest $50, and the name of the bank, so Fin can tell your Scotiabank card from your other one when you refer to it.
- Your goals, with their names replaced by generic labels, and their targets, dates and progress.
- Category names, spending patterns, your currency, today's date, and anything you have asked Fin to remember about you.
- Short internal record references, so Fin can point at the right row when it proposes an edit. They mean nothing outside your own database.
Account nicknames, goal names, exact balances and any notes you have written are not sent. Text that does go, such as a category you named yourself, is scanned first and anything that looks like a social insurance or social security number, an email address, a phone number or a card number is replaced before the request leaves your phone.
- If you attach a photo or a receipt to a chat, the image itself is sent.
- If your question needs current information, Fin can run a web search through Anthropic. The search text goes to Anthropic and its search provider. It is written by Fin from your question, and your figures are not part of it.
- Fin proposes. It cannot move money, and every write asks you to confirm it first.
- Conversations are stored on your device only, never on our server and never in a backup. One with no activity for 14 days is deleted automatically unless you star it.
Using Fin is your choice, and asking it a question is how you give permission. Nothing is sent to Anthropic unless you ask Fin something that needs your figures, or you hand us a PDF statement to read (below). Anthropic processes what it receives on our instructions, is not permitted to use it for its own purposes, and we grant no permission for it to be used to train models. Requests already made may sit in Anthropic's own operational logs under its retention policy, which we cannot shorten on your behalf. Deleting your account does not reach back into those logs.
Importing a statement
Importing is the one other place your figures leave the device, and it matters which file you hand us:
- A CSV never leaves. It is read on your phone, start to finish. No request is made.
- A PDF does. Your phone pulls the text out of it first, and that text is sent to our server and on to Anthropic to be turned into a list of transactions. If the PDF is a scan with no text in it, some banks issue those, the file itself is sent instead, so it can be read as an image.
That is a whole statement rather than a summary, so we will not dress it up: a PDF import shares more than asking Fin a question does. It happens only when you pick a file and only for that file, we do not keep a copy after the import finishes, and Anthropic may not use it for its own purposes or to train models on it. If you would rather nothing left the device at all, export your statement as CSV instead, or add the account by hand.
Fin is not a financial advisor and does not give investment advice.
The protection third parties must give your data
Where we share your information with a third party, we require by contract that they protect it to the same standard this policy sets, and that they use it only for the purpose we engaged them for. That applies to Supabase, Anthropic, Resend, Sentry and PostHog, each of which acts as our processor on our written instructions and none of which may use your data for their own purposes.
Two are not our processors, and we will not pretend otherwise. Plaid is an independent controller and handles your information under its own policy, which we cannot bind. Apple is likewise an independent controller for Sign in with Apple and App Store billing. Where those two are concerned, their protections are theirs, and the links in this policy take you to them.
We hold no parent, subsidiary or affiliated company that gets access to your data, because there isn't one. We do not sell your data or share it for advertising, and we have no advertising or data-broker relationships to disclose.
How your data is protected
Data in transit is encrypted with TLS, and there is no unencrypted endpoint. Data at rest on our server is encrypted by our database provider, and every row that belongs to you is scoped to your account by row-level security, so one account cannot read another's even if our application code is wrong. Secrets held on your phone sit in the iOS Keychain rather than in plain preferences. Access to production systems is limited to those who need it for a specific task, and administrative access is logged. Your bank access token is stored server-side only and is never transmitted to your device.
We do not offer end-to-end encryption, and we do not claim it. Cloud backup is encrypted in transit and at rest, not with a key that only you hold.
Diagnostics and analytics
We use Sentry for crash reports. When the app crashes or hits an unexpected error, Sentry receives the error type and message, the stack trace, the app version and build number, your iOS version and device model, a short trail of recent app events, and your account id when you are signed in. We have turned off Sentry's option to attach personal detail by default, and we do not enable Sentry's session replay, performance tracing or screen recording of any kind. Crash reports carry technical detail and internal record references, not your transactions, balances or account names.
You can turn crash reporting off in Settings. Turning it off shuts down both the JavaScript and the native crash handler, so nothing further is uploaded, and it takes effect immediately without restarting the app.
We use PostHog (PostHog, Inc.) to understand which features are used: that a setup step was completed, that a goal was created, that an option was tapped. An event carries the name of what happened and simple labels, such as which screen it happened on.
An event never carries a dollar amount, an account number, a transaction note, a merchant name, or anything you typed into a search. That is not a rule we apply by hand. Every event passes one filter on the way out: an event whose name contains a figure is dropped whole, and a property is dropped by its key or by the shape of its value. A test fails our build if that filter is weakened, because an amount inside an analytics event is the kind of mistake that looks wrong on no screen.
Three things are switched off in PostHog, and they are worth naming because the defaults are on. Session recording, so there is no video of your screen. Automatic error capture, because crashes belong to Sentry and one fact should have one owner. Location lookup, because a city is not needed to count a tap. We do not use PostHog for advertising and we do not sell this data. Your ledger stays on your phone and in our own database; it is not sent to PostHog.
Crash reports and usage analytics share one switch: Settings, Crash reports, Send crash reports. Turning it off stops both immediately, with no restart, and PostHog is not started at all until the app has read that setting.
The app also ships Google's Firebase Analytics library from an earlier build. It is not configured, so it sends nothing and Google receives nothing. If that ever changes we will say so here first.
Notifications
If you allow notifications, we store your device push token, your notification preferences and your phone's UTC offset, so we can deliver alerts and deliver them at a sensible hour. Delivery to your phone is handled by Apple.
The messages themselves are written on your phone by the app, then stored on our server so the Fin inbox reads the same on every device and the same alert is not sent twice. Some of them contain figures, because that is what makes them useful: a message may name an amount, a merchant, a category or an account. If you would rather that did not sit on our server, turning a notification category off stops those messages being created. You can turn any category off in Settings, or all of them in iOS Settings.
What we never do
- Sell your personal or financial information
- Share it with advertisers or data brokers
- Give your financial data to anyone to train AI models on
- Store your bank credentials
- Move money, or initiate any payment or transfer
How long we keep things, and when they go
| What | How long |
|---|---|
| Everything on your device | Until you delete it or delete the app. We cannot reach it and cannot recover it. |
| Your chat history with Fin | 14 days after the last message in that conversation, then deleted from your phone automatically. Starred chats are kept until you delete them. |
| Your profile and server-side records | For as long as your account exists |
| Bank access tokens | Until you disconnect that bank, or delete your account. Revoked with Plaid at the same time. |
| Your cloud backup | Until you delete the record in the app, or delete your account. Turning backup off stops any further copying; the copy already stored is removed when you delete your account. |
| Notification messages and read state | For as long as your account exists. Deleted with your account. |
| Security and audit records | 90 days, on a rolling daily clean-up, for abuse investigation. This is the one server record that outlives account deletion. |
| Rate-limit counters | Minutes. They exist only for the length of their window. |
| Crash reports (Sentry) | 90 days |
When you delete your account (Settings, then Delete account, inside the app) your bank connections are revoked with Plaid first, then every server-side record listed above is deleted, including your cloud backup, your notification history, your onboarding answers, your usage counts and your profile. Data on your device goes when you delete the app.
Two things do not go with it, and you should know about both. Security audit records are kept for up to 90 days after deletion, so we can still investigate abuse of the account system; they hold your account id, IP address and which endpoints were called, not your financial data. And crash reports already sent to Sentry are not reached by the in-app deletion; email support@getxfin.com and we will remove them. Requests already processed by Anthropic sit under its own retention policy, as the Fin section above explains.
You do not need to email us to be forgotten, and you do not need to explain why. If you would rather we did it, or want written confirmation once it is done, write to support@getxfin.com and we will respond within 30 days.
Your choices
- Delete your account. Settings, then Delete account. This removes your server-side records and revokes bank connections. Data on your device goes when you delete the app.
- Export your data. Settings, then Data export. It returns everything we hold on the server for you, as a file.
- Disconnect a bank without deleting anything else.
- Turn cloud backup off and keep your data on the phone only.
- Turn crash reporting off.
- Decline Fin and keep using the rest of the app.
Withdrawing consent
Anything you consented to, you can take back, from inside the app, without asking us:
| What you consented to | How to withdraw it |
|---|---|
| Connecting a bank through Plaid | Settings → Connected accounts → disconnect. Also independently at my.plaid.com. Withdrawing here stops Xfin fetching; Plaid's own retention is governed by its policy. |
| Sending a summary to Fin | Stop using Fin. Nothing is sent unless you ask it something. |
| Crash reporting | Settings → Crash reports → turn off. This stops uploads immediately, native crash handler included. |
| Notifications | Settings → turn off any category, or all of them in iOS Settings. Turning a category off also stops those messages being written to our server. |
| Cloud backup | Settings → Cloud backup and sync → turn off. Nothing further is copied. To remove the copy already stored, delete the records in the app or delete your account. |
| Having an account at all | Settings → Delete account. This is available inside the app and does not require contacting us. |
None of these are behind a paywall, and turning any of them off does not disable functionality you have paid for.
If you are in Canada
Under PIPEDA you may ask what personal information we hold, ask us to correct it, and withdraw consent. You may complain to the Office of the Privacy Commissioner of Canada.
If you are in the United States
Residents of California, Colorado, Connecticut, Virginia and other states with comparable laws may request access, correction, deletion and portability, and may appeal a refusal. We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done so. There is therefore no "Do Not Sell or Share My Personal Information" process to operate, but you may still contact us to confirm this in writing.
We will not discriminate against you for exercising any of these rights.
If you are in the UK or EEA
You have the rights of access, rectification, erasure, restriction, portability and objection under the UK GDPR and GDPR, and may complain to your supervisory authority. Our lawful bases are performance of our contract with you (running the app), your consent (bank connections, notifications, optional analytics), and our legitimate interests (security and abuse prevention).
Making a request
Email support@getxfin.com. We will respond within 30 days. Most requests are faster to satisfy yourself: export and account deletion are both in Settings.
Where your data is processed
Our providers operate in Canada and the United States, so information stored on our servers may be processed outside the country you live in and may be subject to lawful access requests there. Where required, transfers rely on standard contractual clauses or an equivalent safeguard.
This website
getxfin.com sets no cookies, runs no advertising or tracking scripts, and does not profile visitors. Our host keeps standard server logs, including IP addresses, for security and reliability.
Data breaches
If a breach affects your personal information and creates a real risk of significant harm, we will notify you and the relevant regulator as the law requires, without undue delay.
Children
Xfin is not intended for anyone under 13, and we do not knowingly collect their information.
Changes
If this policy changes in a way that affects how your information is handled, we will tell you in the app rather than only updating this page.
Contact
Questions, requests or complaints: support@getxfin.com.
The data controller is Xfin Technologies Inc. A postal address for written correspondence will be published here before the app is released.