Sub-processors
Sub-processors
> This list reflects the system as built and is **not** legal advice. Which entries are active > depends on how your operator has configured the instance — a minimal deployment sends your data to > no third party at all. Operators should confirm this list against their configuration and add the > processing region for each.
_Last updated: 2026-06-09 · Version 1.0.0_
A "sub-processor" is a third party that may process **your personal data** on our behalf. FinanceSight is designed so that **every external service is optional** — a minimal deployment sends your data to **no third party at all**.
| Sub-processor | Purpose | What is sent | Active when | | ------------------------------------------------------------ | ---------------------------- | ----------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------ | | **Your chosen LLM provider** (e.g. Anthropic, OpenAI) | AI analysis | Portfolio data you choose to analyse (anonymisable per run — see below) | You add an AI key and run an analysis. **Self-hosted Ollama is not a third party** — with Ollama, nothing leaves your instance | | **Email provider (SMTP)** | Transactional email + alerts | Your email address and notification content | The operator configures email and you enable it | | **Your browser's push service** (e.g. Google FCM for Chrome) | Browser notifications | Notification content + your push subscription endpoint and keys | You enable browser push. ⚠️ This service is determined by **your browser's subscription endpoint**, not chosen by the operator | | **Slack** | Alert delivery | Alert content, to a webhook you provide | You configure a Slack webhook | | **Google / Facebook / Authentik** | Optional sign-in | Your email and name from the chosen provider | You sign in with that provider (if enabled) | | **TrueLayer** | Open-banking import | Bank account metadata and transaction history you consent to import | You connect a bank (if enabled) |
AI analysis — what is sent
By default an analysis is sent **identified** (the `analysis_privacy` default). You can change this per run or as your default to **symbols-only** or **fully anonymous** in Settings → Privacy. With self-hosted **Ollama**, the analysis never leaves your instance and there is no sub-processor at all.
Market-data providers are **not** sub-processors
FMP, Twelve Data, Yahoo, Polygon, Frankfurter, FRED, SEC, the US Treasury, the Bank of England, SSGA and Marketaux receive **only ticker symbols and dates** — never your identity, your holdings, or any other personal data. They process no personal data and are therefore **not** sub-processors.
No analytics or error-tracking processor
FinanceSight uses **no third-party analytics, error-tracking, or tag-manager service** — no Google Analytics, no Sentry, no tag manager. Diagnostic error reports and performance metrics stay **first-party**, in the operator's own systems, and are covered in the [Privacy Policy](/legal/privacy).
Your controls
Most of these are opt-in per feature and can be turned off in **Settings** (Notifications, Privacy, Account). See the [Privacy Policy](/legal/privacy) for how to disable each, and the in-app **privacy hints** next to the fields that collect or transmit data.
Changes
When we add or change a sub-processor, this page and the in-app disclosures are updated. Material changes are notified in-app.
FinanceSight needs JavaScript to run. See /llms.txt for more.