Privacy Policy
This policy explains what data Finx collects, why, who processes it, how to review or delete it, and which providers help operate the service. Finx is offered only to individuals residing in the United States for supported US financial accounts.
Data stored on your device
Most lock configuration stays on your device. The following data is stored locally:
- Budget and lock configuration: your budgets, rules, lock pool / app and category selections, emergency overrides, and sync timestamps.
- Screen Time selections: the apps and categories you choose to lock. Apple's Screen Time (Family Controls) framework keeps these as opaque tokens; we never see the names of the apps you select.
- Financial cache: if you use Finx Plus bank automation, the app stores linked-account metadata, transaction records, sync status, and category corrections returned from the backend so budgets can be evaluated locally.
- Subscription state: StoreKit entitlement status and product identifiers used to show Plus access.
- Basic diagnostics: on-device counters of in-app events and the name of the most recent uncaught crash, used only to show you diagnostics inside the app. This stays on your device and is not sent to us or any third party.
Data we collect on our servers
- Account identifiers (Sign in with Apple): the Apple user identifier and, if you choose to share it, your name and email. Used to create and authenticate your Finx account.
- Legal assent records: the Terms and Privacy Policy versions and document hashes accepted during account creation, plus app, build, screen version, action, and timestamp.
- Subscription data (Apple): transaction and entitlement status for Finx Plus, validated with Apple. Used to unlock paid features. Payment is handled by Apple; we do not receive your card details.
- Financial data (Plaid), Finx Plus only: if you link a bank account, Plaid provides item and institution identifiers, account metadata, account mask/last-four where available, account currency metadata used to confirm supported USD accounts, transaction records, merchant names, amounts, dates, categories, pending status, and sync status. Finx does not persist numeric account balance values. This data is used to update budgets automatically and trigger locks. Finx never receives your bank login credentials.
- Support requests: if you contact support, we collect your email address, message content, and any screenshots or attachments you send.
- Request and security logs: IP-derived rate-limit keys, timestamps, request identifiers, authentication and account-action audit records, webhook processing records, and limited device or user-agent information provided by hosting, auth, or support systems.
- Security audit records: minimal records of sensitive account actions (such as account deletion), used for abuse prevention and legal/security purposes. These do not contain your transactions or app-selection details.
Data we do not collect
Finx does not receive your bank credentials, does not receive your Apple payment-card details, does not sell or rent personal data, does not use Plaid data for advertising, and does not track you across apps or websites. We do not collect precise location data.
How we use data
- To operate budgets and the app-locking feature.
- To authenticate you and maintain your session.
- To validate and manage your Finx Plus subscription.
- To sync transactions and update budget state (Plus).
- To process account deletion, Plaid disconnection, legal assent, and security-sensitive account operations.
- To respond to support, data access, correction, export, and deletion requests.
We do not sell your data, do not use it for advertising, and do not track you across other apps or websites.
Processors and providers
- Supabase — backend hosting, database, and authentication.
- Plaid — financial account linking and transaction data (Finx Plus only). See Plaid's end-user privacy policy at plaid.com/legal. Plaid may process data under its own privacy policy and is not governed solely by Finx's instructions.
- Apple — Sign in with Apple, Screen Time / Family Controls, and subscription payments.
Data sharing
We do not sell your data. We share data only with the processors above as needed to provide the service, and as required by law.
Retention and deletion
You can delete your account from within the app (Profile → Delete Account). Deletion removes your Finx account, deletes your subscription record and account data from our backend, and disconnects linked Plaid items. If a Plaid item cannot be disconnected at the moment of deletion, our backend retries automatically until the disconnection succeeds. We revoke server access immediately.
After deletion, a minimal security audit record of the deletion (without transactions or app-selection details) may be retained for abuse prevention, dispute resolution, legal, and security purposes. If a Plaid disconnection has to be retried, the retry tombstone is retained only while needed to revoke the external item and then removed with the stored token reference. Hosting, security, and support logs may remain in backups or provider systems only for as long as needed for the purpose they were collected for — security monitoring, abuse prevention, dispute resolution, or compliance with legal obligations — or as required by a legal hold, after which they are deleted or expire under the applicable provider retention schedule. Deleting your Finx account does not cancel an Apple subscription; manage that in your Apple subscription settings.
You can withdraw consent at any time by unlinking a bank account in the app, or by deleting your account entirely.
Access, export, and correction requests
You can request a copy of account data stored on our servers, ask us to correct it, or ask privacy questions by emailing support@getfinx.app. We may need to verify that the request comes from the Finx account holder before returning or changing data.
Server-side exports can include account identifiers, subscription entitlement metadata, linked Plaid account metadata, security records, and provider disconnection status where available. Screen Time selections, stored transaction records, and most budget configuration live on your device and can be reviewed in the app. We aim to respond within 30 days unless a different period is required by applicable law.
US state privacy rights
Depending on where you live, state privacy laws may give you rights to access, correct, delete, or export personal information, and to opt out of the sale of personal data, sharing for targeted advertising, or certain profiling. Finx does not sell personal data, does not share it for targeted advertising, and does not use it for profiling that produces legal or similarly significant effects, so there is no such activity to opt out of. We honor access, correction, export, and deletion requests for all users regardless of the state you live in, through the process described above, and we will not discriminate against you for exercising privacy rights. If we decline a request, you may appeal by replying to our response and we will review the appeal.
Security
Finx uses HTTPS/TLS in transit, stores Plaid access tokens and Sign in with Apple revocation tokens in backend vault storage, limits direct table access with row-level security, and keeps financial access tokens off your device. No system can be guaranteed perfectly secure.
Do Not Track and cross-context tracking
Finx does not track users across third-party apps or websites for advertising, so browser Do Not Track signals do not change how Finx operates.
Geography and international processing
Finx is scoped to United States residents and supported US financial accounts for v1. Our providers may process or store operational data in the United States or other countries where they maintain infrastructure.
Changes to this policy
We update the "Last updated" date when this policy changes. For material changes that affect data use, user rights, payment-related data, or dispute processes, we will provide notice through the app, email, or another reasonable method before the change takes effect where required.
Children's privacy
Finx is intended for adults 18 and older and is not directed to minors. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.
Contact
Privacy questions: support@getfinx.app