← Back to Finora

Privacy policy

What we hold, and what we don't

Last updated 12 August 2026 · Applies to the Finora mobile app and this website

At a glance

1. Who is responsible

Finora (“we”, “us”) provides the Finora mobile application and this website. We are the data controller for the information described here.

Contact for any privacy question or request: sangeethfx@icloud.com.

Finora is currently in development and testing. It is being used by a small group of invited testers, and is not yet publicly released.

2. What we collect, and why

WhatWhy we need it
Email addressTo create your account, sign you in, and contact you about the service
PasswordTo sign you in. Stored only as an Argon2id hash — we cannot read or recover it
Display name (optional)To address you in the app
Your financial records — accounts, balances, transactions, categories, loans, the names you give people you lend to or borrow from, assets and their estimated valuesThis is the product. Without it there is nothing to show you
What you say or type to the assistantTo work out what entry you meant. See section 3
Technical logs — the time of a request, which endpoint, the response statusTo keep the service running and to investigate faults. We do not log the contents of requests, because those carry amounts, names and sentences

We do not collect your contacts, your location, your photos, your device advertising identifier, or your bank credentials. Finora does not connect to your bank.

3. Voice, speech and the AI

Your voice

When you speak to Finora, the speech is turned into text by your phone's own operating system — Apple's speech recognition on iOS, Google's on Android — not by us. Depending on your device, language and settings, that system may process the audio on the device or on Apple's or Google's servers. That processing is governed by Apple's and Google's privacy policies, not ours.

Finora never receives, stores or transmits the audio itself. We receive only the resulting text.

The AI that drafts your entries

To turn “lunch 2500 from cash” into a draft entry, we send the text of your message to a language model through OpenRouter, which routes it to a model provider (currently Google's Gemini). Along with your text we send the context the model needs to be useful: the names and types of your accounts, your categories, and any loans, so it can resolve “from cash” to the right account.

We do not send your email address, your name, or your password to the model. Message content is sent for the purpose of answering you and is not used by us to train any model. OpenRouter and the model providers apply their own retention policies to what passes through them.

The AI never records anything by itself. It can only propose an entry. Nothing is written to your records until you confirm it — this is enforced in the software, not by policy.

4. Our legal basis (GDPR)

Because our servers are in the European Union, EU data protection law applies to this processing. We rely on:

5. Where your data is kept

Your account and records are stored in a PostgreSQL database on a server we operate in Lauterbourg, France, hosted by Contabo GmbH. Backups are kept on the same server for 14 days and copied to secure storage controlled by us.

Sending a message to the assistant transfers that message text outside the EU, to OpenRouter and the model provider, which operate in the United States and elsewhere. If you would rather that did not happen, do not use the assistant — the rest of the app works without it.

6. Who else can see it

WhoWhat they receiveWhy
Contabo GmbH (Germany/France)Hosts the encrypted server holding your dataInfrastructure
OpenRouter, Inc. (USA)The text of assistant messages and your account/category namesRoutes your message to a model
Model provider (currently Google)The same message textGenerates the draft entry
Apple / GooglePossibly your speech audio, as described in section 3Speech recognition on your device

That is the complete list. There are no advertising networks, no analytics providers, no data brokers, and no other third parties. We have never sold personal data and will not.

7. How long we keep it

8. Your rights

You can ask us to:

Email sangeethfx@icloud.com and we will respond within 30 days. If you are in the EU or UK and are unhappy with our response, you may complain to your national data protection authority.

9. Deleting your account

In the app: Profile → Delete account. You will be asked for your password, because deletion cannot be undone.

This erases your ledger, accounts, transactions, loans, counterparties, assets, drafts and sessions. It is not a deactivation, and there is no hidden copy. Your email address becomes free to register again.

10. How we protect it

11. Children

Finora is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.

12. Changes to this policy

If we change how we handle your data, we will update this page and change the date at the top. For anything significant, we will also tell you in the app or by email before it takes effect.

13. Contact

Questions, requests, or complaints: sangeethfx@icloud.com.