Privacy Policy
Effective and last updated: 28 September 2026
FINNEX is a personal-finance tracker. This policy explains what data the app handles, why it is used, where it is stored and the choices you have. We designed FINNEX to keep financial data private. We do not sell your data or use it for advertising.
Questions may be sent to support@finnex-app.com. FINNEX is operated from the United Arab Emirates.
1. Information we handle
Account information
Your email address is used to create your account, authenticate you and enable optional cloud sync. Authentication is provided by Supabase.
Financial information you enter
This may include accounts, balances, liabilities, recurring income and commitments, transactions, budgets, assets and stock watchlists. For credit cards, FINNEX may store the credit limit, APR and balance you enter. We never request or store full card numbers, CVV codes or card expiry dates.
Family accounts (version 1.0.6)
When you create or join a household, Supabase stores its shared financial records, membership roles, display names, invitation details and change history. Household members can view the shared workspace; owners and editors can update shared financial records. Owners manage invitations, membership and recovery. Joining does not automatically share your personal accounts or transaction history. Invitation codes should only be shared with their intended recipient.
Receipt photos
If you use Scan Receipt, the selected image is sent through our backend to Google Cloud Vision to extract amount, merchant and date. Extracted fields are returned for your confirmation. Our server does not retain the image after processing.
Bank notifications and pasted messages
Android auto-capture reads incoming bank transaction notifications only after you grant notification-access permission. Parsing happens on your device. Raw notification content is not uploaded. The same applies to manually pasted bank messages. This feature is optional and off by default.
AI insights
If you request an AI brief, FINNEX sends aggregated totals, ratios and category sums to Google Gemini through our backend. Raw transactions, merchant names, account numbers and your identity are not included.
Subscriptions
Apple or Google processes subscription payments. RevenueCat manages entitlement status. We receive subscription state but not payment-card details.
2. How information is used
- Provide financial tracking, optional sync, receipt scanning, auto-capture and insights.
- Authenticate users and protect accounts.
- Manage subscriptions and trials.
- Respond to support requests.
We do not use your information for third-party advertising or sell it.
3. Service providers
| Provider | Purpose | Information |
|---|---|---|
| Supabase | Authentication, optional personal cloud sync and shared households | Email, entered financial data, household membership, invitations and change history |
| Google Cloud Vision | Optional receipt extraction | Receipt image submitted by you |
| Google Gemini | Optional AI guidance | Aggregated metrics only |
| RevenueCat | Subscription management | Anonymous app-user identifier and status |
| Apple / Google | Store payment processing | Handled directly by the store |
4. Security
Data is encrypted in transit and at rest where cloud services are used. Row-level security restricts personal cloud records to their account and shared household records to authorized members according to their role. App PIN and biometric credentials use the operating system’s secure keystore. Personal backup files are protected with encryption and a password you choose. Household exports are separate, unencrypted files shared by an owner; keep them private.
5. Retention and deletion
Personal cloud data is retained while your account exists. You can delete your account and personal cloud data inside FINNEX from Profile. Shared household records and their history belong to the household workspace and can remain available to its other members after a member leaves or deletes their account. A last owner must assign another owner or delete the household before deleting their account. Removing a member cannot erase copies they previously exported. You may also request deletion by emailing support@finnex-app.com.
6. Your choices and rights
Depending on your jurisdiction, you may request access, correction, export or deletion of personal data and withdraw consent for optional processing. Most controls are available directly in the app.
7. Children
FINNEX is not directed to children and is not intended for anyone below the age required to consent to data processing in their country.
8. Changes
We may update this policy as FINNEX evolves. The updated date will change and material updates may be communicated in the app.