Privacy Policy
Last updated
Finly is a personal finance app. This page explains what it stores, who else sees it, and what you can do about it. It is written to be specific rather than reassuring — where something might surprise you, it is called out rather than smoothed over.
The short version
- Finly has no bank connection. Everything in your account is data you typed in.
- If you use the AI assistant, the relevant parts of your financial data are sent to an external AI provider to answer your question. This is the most important thing on this page.
- There is no advertising and no analytics or tracking software.
- You can export everything, and you can delete your account outright. Both work today.
What Finly stores
Data you provide:
- Account details — your email address, and a password stored only as a hash by our authentication provider.
- Financial data you enter — accounts, transactions, categories, budgets, goals, investments, businesses, debts and tags. Finly never retrieves this from a bank; it exists because you or the assistant entered it on your instruction.
- Assistant conversations— your messages and the assistant’s replies, so a conversation follows you between devices.
- Preferences — display currency, theme and similar settings.
Finly also records limited technical information about each assistant request for reliability monitoring: which provider answered, how long it took, whether it succeeded, and the first 200 charactersof your message. The assistant’s reply is never stored in those records, and neither are the arguments of any action it takes. These records are not readable by any user account, including yours.
Who else receives your data
Finly relies on the following processors. This list is exhaustive as of the date above.
| Processor | Role | What it receives |
|---|---|---|
| Supabase | Database, authentication, file storage | Everything listed above. This is where your account lives. |
| Vercel | Application hosting | Requests to the site, including IP address and standard server logs. |
| Groq | AI model provider | Assistant requests — see below. |
| Cerebras | AI model provider | Assistant requests — see below. |
| Google (Gemini) | AI model provider | Assistant requests — see below. |
| OpenRouter | AI model gateway | Assistant requests, which it forwards to a further model provider that it selects. Finly does not control that onward choice. |
Finly does not sell your data, does not share it for advertising, and has no affiliate or data-brokerage arrangements.
How the AI assistant uses your data
When you ask the assistant something, Finly sends the parts of your financial data needed to answer it — for example your recent transactions if you ask about spending — together with your message, to one of the AI providers listed above.
If a provider is unavailable or rate-limited, the same request is sent to the next provider in turn. A single question can therefore reach more than one provider before you get an answer. We have no way to predict which one will serve any given request.
Each provider handles data under its own terms, which Finly does not control. If you would rather no third party ever sees your financial data, do not use the assistant — the rest of Finly works without it.
The assistant can also take actions on your behalf, such as recording a transaction or deleting a budget. Destructive actions always require your explicit confirmation first.
Cookies
Finly sets only the cookies required to keep you signed in. There are no analytics cookies, no advertising cookies, and no third-party trackers, so there is nothing to consent to and no consent banner. If that changes, non-essential cookies will be blocked until you opt in, and this page will say so before they are used.
How long data is kept
Your data is kept for as long as your account exists. Finly does not expire or archive it on a schedule.
When you delete your account, your records are removed from the live database immediately — this is a real deletion, not a hidden flag. Reliability records described above have their link to your account cleared at the same time, leaving no association with you. Encrypted backups held by our database provider may retain copies for a short period before rotating out; those are not readable by Finly and are not used to restore deleted accounts.
Your data, and how to actually get it
These are working features, not requests you have to send to someone:
- Export everything. Settings → Privacy → Export. Produces a single JSON file containing every record Finly holds for you, across all areas of the app.
- Delete your account. Settings → Privacy → Delete account. You confirm by typing your email address. This permanently removes your account and every record attached to it — accounts, transactions, categories, budgets, goals, investments, businesses, debts and your entire chat history. It cannot be undone, and you are offered an export first.
- Delete only your chat history. Available from the assistant itself, if you want to clear conversations without touching the rest of your account.
- Correct your data. Every record is editable in the app.
For anything not covered by the above, contact privacy@<yourdomain> (placeholder — not yet live). Because Finly is in early access and that address is not yet live, please use the in-app export and deletion controls, which do not depend on anyone answering an email.
Age
Finly is for people aged 18 or over. It is not directed at children, and accounts are not knowingly created for anyone under 18. If you believe someone under 18 has an account, please get in touch and it will be removed.
Security
Every query is restricted to your own account at the database level, and that restriction is tested against a real database on every change rather than assumed. No security measure is absolute, and Finly is early-access software — please do not treat it as a system of record for anything you cannot afford to lose.
Changes
If this policy changes, the date at the top changes with it. Material changes to what is collected or who receives it will be surfaced in the app rather than only here.
See also the Terms of Service.