This Privacy Policy explains what data FinOS collects, how it's used, and how it's protected.
1. What We Collect
Account data: name, email, and a securely hashed password (scrypt, salted — we never store or see your plaintext password). Portfolio data: the holdings, transactions, watchlist items, goals, alerts, and journal/review entries you enter. Usage data: which features you use, for reliability and product improvement.
2. How We Use It
Your portfolio data drives the analytics, health scores, and recommendations shown to you — this computation happens on our servers and is never sold or shared with third parties for advertising. Row-Level Security is enforced at the database level so your data is only ever queryable in the context of your own authenticated session.
3. Third-Party Data Providers
To fetch live prices, fundamentals, and news, FinOS queries market-data providers (Yahoo Finance, Finnhub) by ticker symbol. These lookups do not include your personal account information — only the ticker being priced.
4. AI Provider
Daily-brief narration and AI-paired trade reviews are generated by a third-party AI model (Google Gemini). To produce this narration, a summary of the relevant portfolio numbers or company metrics — not your raw account credentials — is included in the prompt sent to that provider. Disable AI-narrated features at any time by not using the "Generate" actions that trigger them.
5. Data Storage
Data is stored in a Postgres database (either a local embedded instance for self-hosted use, or a hosted Supabase project with Row-Level Security enabled) protected by per-user access policies enforced at the database layer, not just the application layer.
6. Data Retention & Deletion
You may request deletion of your account and all associated data at any time from the Profile page or by contacting us. Deleted data is removed from primary storage; backups age out on their normal retention schedule.
7. Cookies
FinOS uses a single session cookie to keep you signed in. It is not used for cross-site tracking or advertising.
8. Children's Privacy
The Service is not directed at, and should not be used by, anyone under the age of 18.
9. Changes
This policy may be updated as the product evolves. Material changes will be reflected here with an updated date.
10. Contact
Questions about this policy or a data-deletion request can be sent to the address on your account's registered contact method.
This document is a general template describing the system's actual current data flows, and has not been reviewed by legal counsel. It is not a substitute for professional legal advice on data -protection law (e.g. GDPR, India's DPDP Act) in the jurisdictions you operate in.