Privacy Policy
Last updated: July 6, 2026
At Finanzya, your financial data is yours. This policy lays out exactly what we collect, why, the legal basis for it, who processes it, how it's protected, and the control you keep over it — in line with UK and EU data protection law.
Overview
Your privacy matters to us. This Privacy Policy explains what personal data Finanzya collects, why we collect it, the legal basis we rely on, who processes it on our behalf, how long we keep it, and the rights you have. We are committed to handling your data responsibly and transparently, in line with the UK GDPR and the EU GDPR.
Who We Are (Data Controller)
Finanzya is operated by Guillaume Corneloup, a sole trader based in England, United Kingdom ("Finanzya", "we", "us", "our"). For the purposes of the UK GDPR and, where it applies to customers in the European Economic Area, the EU GDPR, we are the "data controller" responsible for your personal data. If you have any questions about this policy or how your data is handled, you can reach us at contact@finanzya.app.
Personal Data We Collect & Why
Email address: Used to create and secure your account, sign you in, and send essential service messages (security, account, and billing). Legal basis: performance of our contract with you.
Name (if provided): If you sign up with Google, we receive the name on your Google account so we can personalise the app. You are not required to give us a name otherwise. Legal basis: performance of our contract with you; your consent when you choose Google sign-in.
Authentication information (Google login): If you sign in with Google, we receive a Google account identifier and basic profile info (email, name) to authenticate you. We never receive or store your Google password. Legal basis: performance of our contract with you and your consent to use Google sign-in.
Financial accounts: The accounts you add (name, type, balances, currency, and — for liabilities — loan terms). Used to display and organise your finances. We never ask for or store your bank login credentials. Legal basis: performance of our contract with you.
Transactions: Income and expense records you enter manually or import via CSV. Used to track spending, produce analytics, and power projections. Legal basis: performance of our contract with you.
Budgets: Budget categories and planned amounts you set. Used to compare your spending against your plan. Legal basis: performance of our contract with you.
Categories: The categories and category groups you create or customise to classify transactions. Used to organise and analyse your finances. Legal basis: performance of our contract with you.
Goals: Saving pots, retirement and FIRE targets, and forecasting modules you configure. Used to model your goals and projections. Legal basis: performance of our contract with you.
App preferences: Settings such as your language, theme, and display preferences. Used to remember how you like the app to work. Legal basis: our legitimate interest in providing a functioning, personalised app.
Technical & log data: Our hosting providers keep standard server logs (such as IP addresses and request timestamps) for security, debugging, and reliability. We do not use third-party analytics or cross-site tracking. Legal basis: our legitimate interest in keeping the service secure and reliable.
We only collect what we need to run the service. For each type of data below, we set out why we collect it and the legal basis we rely on.
Legal Basis for Processing
Under the UK GDPR and EU GDPR we must have a lawful basis to process your personal data. We rely on:
- Performance of a contract — to provide the Finanzya service you sign up for (your account and all the financial data features above).
- Consent — where you actively choose an optional feature, such as signing in with Google, or opt in to any non-essential communications. You can withdraw consent at any time.
- Legitimate interests — to keep the service secure, reliable, and working (e.g. server logs and remembering your app preferences), balanced against your rights.
- Legal obligation — to meet legal, tax, and accounting requirements, such as retaining billing and payment records.
Data We Do Not Collect
We do not collect your national insurance / social security number or any government-issued identification. The app does not set advertising or third-party tracking cookies (see Cookies & Local Storage), and we never sell, share, or provide your data to data brokers or advertisers.
How We Use Your Data
We use your data to:
- Provide and maintain the Finanzya service
- Process your financial calculations, analytics, and projections
- Send essential account-related communications (security, service, and billing)
- Keep the service secure and diagnose problems
- Respond to your support and privacy requests
We do not use your financial data for advertising, profiling for marketing, or any purpose other than providing the service to you.
Third-Party Services (Sub-Processors)
Supabase: Our backend: authentication, database (where your account and financial data are stored), and edge functions.
Vercel: Hosting and content delivery for the Finanzya web app and marketing site.
Resend: Delivers our transactional emails (sign-up confirmation, password reset, email change, and similar account emails).
Google (OAuth): Only if you choose "Sign in with Google", to authenticate you. Governed by Google’s own privacy policy.
Stripe: Processes payments for paid subscriptions. Stripe handles your card details directly — we never see or store your full card number. Stripe acts as an independent controller for the payment data it collects, under its own privacy policy.
Analytics: We currently do not use any third-party analytics or advertising provider. If this ever changes, we will update this policy and, where required, ask for your consent first.
We use a small number of trusted providers to run the service. They process data only on our instructions and only as needed to provide their service. We do not share your financial data with third parties for marketing or analytics.
Where Your Data Is Stored & Security
Your account and financial data are stored on secure servers located in the United Kingdom (London), managed by our backend provider Supabase. Data is encrypted in transit and at rest. Passwords are hashed and never stored in plain text. We apply industry-standard measures and per-user access controls (row-level security) so each account can only access its own data.
International Data Transfers
Your primary data store is in the UK. Some of our providers (for example email delivery and, in future, payments) may process limited data outside the UK/EEA. Where that happens, we rely on appropriate safeguards — such as UK International Data Transfer Agreements / Addenda or the EU Standard Contractual Clauses — so your data receives an equivalent level of protection wherever it is processed.
Data Retention
We retain your data for as long as your account is active so you can keep using the service. If you delete your account, we delete your associated personal data within 30 days, except where we must keep certain records (for example, billing and tax records we are required by law to retain). Exported CSV files are generated on demand and are not stored on our servers.
Your Rights
Under the UK GDPR and EU GDPR, you have the right to:
- Access — get a copy of the personal data we hold about you
- Rectification — correct inaccurate or incomplete data (much of it you can edit directly in the app)
- Erasure — request deletion of your account and associated data ("right to be forgotten")
- Portability — export your data at any time via CSV
- Restriction & objection — ask us to limit or stop certain processing
- Withdraw consent — for anything based on consent (e.g. Google sign-in), at any time
To exercise any of these rights, contact us at contact@finanzya.app. We will respond within one month, as required by law.
Complaints
If you are unhappy with how we handle your data, please contact us first at contact@finanzya.app so we can put it right. You also have the right to lodge a complaint with a supervisory authority. In the UK this is the Information Commissioner’s Office (ICO) at ico.org.uk. If you are in the EEA, you can complain to your local data protection authority.
Children's Privacy
Finanzya is not intended for use by children under 16 years of age. We do not knowingly collect personal data from children.
Changes to This Policy
We may update this Privacy Policy from time to time. The date at the top shows when it was last updated. When we make significant changes, we will notify you by email or through a notice in the application. Continuing to use Finanzya after an update takes effect means you accept the revised policy.
Contact
If you have questions about this Privacy Policy, want to exercise your rights, or wish to make a privacy request, reach out at contact@finanzya.app.