Privacy Policy
Privacy Policy
> The factual descriptions below reflect the system as built. This is **not** legal advice. > Operators should confirm the descriptions against their own configuration and add > jurisdiction-specific detail (data-controller identity, deploy region, lawful bases) before > relying on this notice for a public deployment.
_Last updated: 2026-06-09 · Version 1.0.0_
What we collect, and where it goes
**What we store.** Your account (a username; an email _only if you choose to give one_), the financial data you enter (accounts, transactions, portfolios, trades, plans, goals), and a record of security events on your account. Your data stays in **our database on the server you (or your operator) control**.
**Guests (trying the app without an account).** A guest session lets you use the app before you register. For each guest we store a **salted, one-way hash of your IP address** (`ip_hash = SHA-256(ip + salt)`) and your **browser user-agent string**. We keep these solely to run an **abuse-prevention throttle** (a limit on how many new guest sessions one network address can start in an hour). The IP is never stored in the clear, and this data is removed when the idle guest session is reaped (see [Retention](#how-long-we-keep-it)). We disclose it here because we hold it about visitors who have not registered.
**Trial accounts (a username, and an *optional* email address).** Where the operator has switched this on, you can create an account with **only a username and a password** — you keep your work without handing an address to an instance you have no reason to trust yet, and by default we store none. You **may** add one, at sign-up or later from Settings → Security & Access, and we ask you to use a **test address**: a trial account is for trying the app out, and everything in it should be test data. Adding an address does not change what kind of account it is — the deletion window below is exactly the same with one and without. Read what follows before you use one, because a trial account is not a smaller version of an ordinary account:
• **Whether anything can be recovered depends on that address.** With **no address** there is no password reset and no verification, and nobody can give the account back to you: **if you forget the password, the account and everything in it is gone.** With an address on it, verified the ordinary way, a forgotten password can be reset exactly as on any other account. - **You cannot link a Google / Facebook / Authentik sign-in to a trial account.** That is refused because the terms this kind of account rests on — test data, and deletion on a timer — cannot be passed on to the provider: the link is a record held by somebody else, saying that identity is this account, and it outlives the account on a system we do not control. - **It is deleted after 90 days without a sign-in** (`TRIAL_ACCOUNT_IDLE_DAYS`) — see [Retention](#how-long-we-keep-it) for exactly what that means. - **A bank cannot be connected to it**, because real bank data must not land in an account that expires. Everything else works as it does on a full account, email ingestion included. - **Export works throughout**, from Settings → Privacy. Use it before you stop using the account: nothing is recoverable afterwards.
**What's optional — and how to turn it off.**
• **AI analysis.** Off until you add your own AI provider key. When you run an analysis, your portfolio data is sent to **your chosen AI provider**. By **default** an analysis is sent **identified**; you can switch it to **symbols-only** or **fully anonymous** per run or as your default in Settings → Privacy, or never use it at all. If you use **self-hosted Ollama**, nothing leaves your instance. - **Market data.** To show live prices we ask market-data providers about _ticker symbols and dates_ — never who you are or what you hold. Market-data providers receive **no personal data** and are not sub-processors. - **Bank connection.** Optional. If you connect a bank (via TrueLayer), we import your accounts and transactions. Disconnect any time to stop. - **Notifications.** Email, browser push, and Slack alerts are each opt-in and individually configurable in Settings → Notifications. - **Sign-in with Google/Facebook/Authentik.** Optional; password sign-in always works.
See the full list of third parties in the [Sub-processors](/legal/sub-processors) page.
**Product and diagnostic events (first-party).** To keep the app healthy and improve it, we record **first-party** client events — batched error reports, performance metrics, and key in-app UX events — through our own `/api/clientlog` endpoint into **our own database**. An event carries a **hashed** session token, your user-agent, the page URL, and a small context blob (all size-capped server-side); it is linked to your account where you are signed in. **There is no third-party analytics, error-tracking, or tag manager** — nothing is sent to Google Analytics, Sentry, or any similar service. **Turn this off in Settings → Privacy** (`telemetry_opt_out`) — when off, your browser stops sending these events and our server stops recording them.
**Logs.** Operational and security-audit logs **redact personal fields** — your email address, username and display name are **not written to logs or the audit trail**. Where a log or audit line needs to identify who acted, it records your **user id** (and, for social sign-in, the provider and its subject identifier) instead of your address. For events that happen **before an account exists** (sign-up, invitations, credential shares), we log a **salted hash** of the address so related lines can be correlated **without storing the address itself**.
Lawful basis
We process your account and financial data to **provide the service you asked for** (contract), and we rely on your **consent** for optional processing such as AI analysis and first-party product events. The guest abuse-prevention throttle (hashed IP + user-agent) rests on our **legitimate interest** in keeping the service available and free of abuse. You can withdraw consent at any time using the in-app controls described above.
How long we keep it
Your data is kept until you remove it. You can **export** or **delete** your account from **Settings → Account**. When you delete, **you choose the timing**: an **immediate** deletion (irreversible, confirmed before it runs) or a **scheduled** deletion with a **grace period** (currently 90 days, `DELETE_GRACE_DAYS`) that you can **cancel** at any time until it runs. Both choices remove exactly the same data — the difference is only _when_. After deletion, the forensic security-event log is retained but **anonymised** — your user reference is cleared and any surviving email is **removed entirely** (set to null, not replaced with a hash), so nothing that could identify you remains. Guest sessions are removed automatically after **30 days** of inactivity (`REAP_ANON_IDLE_DAYS`).
**Trial accounts** (a username, and an optional email address) are deleted **90 days after the last sign-in** (`TRIAL_ACCOUNT_IDLE_DAYS`), and signing in starts that period again — an account you are still using is never removed, only an abandoned one. The erasure runs through the **same deletion path** as a deletion you ask for yourself: it is a real erasure, not an archive, and it removes exactly what an account deletion removes. There is **no grace period and no way to recover the account afterwards** — an address on the account, if you added one, resets a forgotten password but cannot bring back an account that has been deleted, and no other channel is offered in its place. You are told inside the app **14 days** beforehand (`TRIAL_ACCOUNT_WARN_DAYS`), your export stays available until the moment it runs, and the expiry date is shown in the app throughout — not only when you sign up.
**Backups.** Routine database backups are taken for disaster recovery and **retain a copy of your data for a period after deletion**. Backups are rotated on the operator's retention schedule and are not used to restore individually deleted accounts. _(Operators: state your backup retention period here.)_
Who can see it
Only you, and anyone you explicitly share a household or account with (you control their role, and can revoke access at any time). Administrators of your instance can manage the shared market-data catalogue and system health — **they cannot see your accounts, portfolios, or planning data.**
Your rights
Depending on your jurisdiction (e.g. UK GDPR / EU GDPR), you have rights to access, port, correct, and erase your personal data, and to object to or restrict certain processing. The in-app **export** and **delete** tools cover access, portability, and erasure directly; for anything else, contact the operator of your instance.
Self-hosting
FinanceSight can run entirely on infrastructure you control, with no third-party services required. See the project documentation for the minimal-footprint deployment.
Contact
For privacy questions or to exercise a right that isn't covered by the in-app tools, contact the operator of your instance. _(Operators: insert your data-controller contact and, where required, your Data Protection Officer here.)_
FinanceSight needs JavaScript to run. See /llms.txt for more.