Skip to content

Privacy Policy

Version 1.4 · Effective from 25 August 2026

This policy explains what personal data the FinLad app and the finlad.site website process, for what purpose, on what legal basis and for how long they are kept. The data controller is FOP Itsekson Oleksii Volodymyrovych.

It is written to be read. If any part seems unclear, write to us through the contact form on the site and we will make the wording plainer.

1. Who processes your data

Controller: FOP Itsekson Oleksii Volodymyrovych, Ukraine. You can reach us through the contact form at finlad.site — that is the main channel for any question about this policy or your rights.

Processing follows the General Data Protection Regulation (GDPR, EU 2016/679) and the Law of Ukraine "On Personal Data Protection" No. 2297-VI.

2. What data we process

CategoryWhat exactlyWhere it comes from
Account dataGoogle or Apple identifier, email address, interface languageFrom you when signing in with Google or Apple
Financial recordsTransactions, accounts, categories, budgets, goals, utility services and readings, assets, investmentsYou create them in the app or import them
Bank accessMonobank access token (stored encrypted), imported statementsYou add the token yourself; you upload the statement yourself
Receipt and document imagesThe photo you take for recognitionDevice camera, by your action
Technical dataSession and device records, server request logs, crash reportsGenerated automatically as you use the app
Sign-in logThe date and time of every sign-in, sign-up, failed attempt and sign-out, the sign-in method, the IP address and the kind of app the request came fromGenerated automatically when you sign in
MessagesMessage text, plus name and email if you provide them, and any screenshots you attach (up to three images)The contact form on the site

What we do not collect: an advertising identifier, your behaviour in other apps, contacts, precise location, or any payment details — payment runs only through the app stores (Google Play, and the App Store on iOS) and we never receive your card numbers.

An account can be created without telling us anything about yourself. The primary way to sign up is a single tap: the app creates a passkey on your device, and what we store is a random account id, a public key, a generated short name such as "FL-7F3A-K2M9", and your tier. No address, no name, no phone number is asked for or received. We will also state the limit of that anonymity plainly: every sign-in to any account goes into the sign-in log together with an IP address (see the row above) — so that you can find out about a sign-in that was not yours, and we can recognise guessing. That address does not name you, but the law treats it as personal data, so we do not hide it inside the general line about technical logs, and we delete it after 90 days. The "Account data" row above applies to people who chose to sign in with Google or, on iOS, with Apple: there we receive the identifier and the address from that account. Apple also lets you hide your real address — we then receive an @privaterelay.appleid.com alias and never see yours. That is your choice rather than a condition of use — and you can make it later, or never.

If you give us an email address yourself — in a message through the contact form, for instance — we have no way to verify it, so we do not use it as a way to sign in or to restore access, and we never merge two accounts by it. It stays what you made it: a way to reach you about that message.

3. Why, and on what legal basis

PurposeLegal basis
Providing the service itself: storing your financial records, computing budgets and statistics, syncing between your devicesPerformance of a contract (Art. 6(1)(b) GDPR) — the Terms of Use you accept at the start
Connecting a bank and receiving your transactions automaticallyYour explicit consent (Art. 6(1)(a)) — you add the token yourself and can revoke it at any time
Receipt recognition and category suggestions using AIYour consent — the feature is triggered by your action and can be fully disabled with one switch in settings
Security, crash diagnostics, abuse preventionLegitimate interest (Art. 6(1)(f)) — so the service works and does not lose your data
Replying to your messageLegitimate interest, and your act of providing the address
Anonymous website visit statisticsLegitimate interest — aggregated statistics, no cookies, no profiling

4. Who we share data with

We do not sell your data and we do not pass it to advertising networks. It reaches only the providers the service cannot run without, and only to the extent their function requires:

RecipientWhat it receivesWhy
Hetzner Online GmbH (Germany)All server data — it is physically stored on their hardware; also technical request data for finlad.siteHosting the server, the database and the website itself in the EU
Google LLC (Gemini API, USA)Only the receipt, meter or bill image you sent for recognition, or the line you typed / the description from a statement. No amounts, balances, account names or your identifierImage recognition, category suggestions and parsing a typed line
Anthropic PBC (USA)The same, on the same terms — but only when the primary provider did not answerBackup provider, so recognition does not disappear during an outage
Google LLC / Google Ireland LtdGoogle sign-in data; data about a purchase you madeAccount sign-in, payment via Google Play
Apple Inc. / Apple Distribution International Ltd (Ireland)Apple sign-in data — the identifier and an address that may be an @privaterelay.appleid.com alias; data about a purchase you madeAccount sign-in on iOS, payment via the App Store
Functional Software, Inc. (Sentry), EU regionCrash reports: error type, stack trace, request route. Request bodies, authorization headers and images are stripped before sendingFixing errors
JSC Universal Bank (Monobank)Requests carrying your token to fetch your own transactionsOnly if you connected the bank
Umami Software, Inc.Anonymous page-view data: page, referrer, device type. No cookies and no identifier that could recognize youWebsite visit statistics

Transfers outside the EU concern only the AI features (Google and Anthropic, USA) and Google or Apple sign-in, and take place under the standard contractual clauses of those providers; for users in the EU, the Apple party holding that data is its Irish company. Both model providers are used on their paid tiers, whose terms forbid training models on what is sent. If you switch AI off in settings, no transfer to them happens at all.

5. Where data is stored

The server and database are located in the European Union (Germany). Server backups are encrypted before they are written anywhere they will stay, and are stored in the EU as well; the key that opens them is kept apart from the server, so a copy that falls into the wrong hands along with the server stays unreadable. Receipt images are not retained on the server after recognition — they are processed in transit, and whatever you choose to keep stays in your app.

On the free tier sync is off by design: your financial records stay on your device only and never reach the server at all. The same is available on the paid tier — sync can be switched off in settings at any time, and the app then works locally: new records stay on the device.

6. How long we keep it

  • Account data and financial records — for as long as your account exists. After a deletion request they are kept for a further 7 days so you can change your mind, and are then deleted for good.
  • Backups — 14 daily, 8 weekly and 6 monthly. Data you deleted ages out of backups as they rotate, which takes roughly six months.
  • Server request logs — a limited technical period needed for diagnostics.
  • The sign-in log — 90 days, after which entries are deleted automatically. Deleting your account deletes its log with it.
  • Crash reports — per Sentry’s retention periods.
  • Contact form messages, together with any screenshots attached to them — until the conversation is finished, plus a reasonable period after. Screenshots are deleted with the message they belong to, never separately.

7. Your rights

You have the right of access, rectification, erasure, restriction of processing, objection, and data portability. Here is how to exercise them:

  • Rectification — directly in the app: every record is yours to edit.
  • Erasure — the "Delete account and all data" button in settings. This device’s copy is wiped at once and for good, every session ends, and the bank connection is disconnected. The data on the server is deleted after 7 days: throughout that time you can sign in and cancel the deletion — or finish it straight away without waiting. What comes back is the server copy; if your plan has no sync there is none, so there would be nothing to bring back. Once the window has passed we deliberately keep no shadow copy, so data cannot be restored. If you no longer have the app, send a request at finlad.site/delete-account and we will carry it out within 30 days.
  • Access and portability — in the app: More → Data → Export data. Transactions download as a CSV sheet, and everything as a JSON file in a machine-readable format. Receipt photos are listed in the JSON but not embedded; if you need the images themselves, or a copy in another shape, send a request through the contact form.
  • Withdrawing consent — switch AI off in settings or disconnect the bank; this does not affect the lawfulness of processing before withdrawal.

You also have the right to lodge a complaint with a supervisory authority: in Ukraine, the Ukrainian Parliament Commissioner for Human Rights; in the EU, the authority where you live.

8. How the AI works and what it sees

The app calls an external model in exactly three cases: when you send a photo of a receipt, a meter or a bill for recognition; when a transaction description could not be categorized by its own rules; and when a line you typed by hand could not be parsed on the device itself.

  • Amounts, dates, balances, your account names and your identifier are never sent.
  • A description recognized as naming a person rather than a merchant (a card-to-card transfer, for example) is not sent at all and is left for manual categorization.
  • The model’s answer is immediately turned into a local rule, so the same merchant is recognized next time without any outbound call.
  • The model providers — Google (Gemini) and, when it is unavailable, Anthropic — are used on their paid tiers: under those terms, what is sent is not used to train the models.
  • One switch in settings disables every AI feature. The app remains fully functional afterwards.

9. Cookies and website statistics

This site uses no cookies and shows no consent banner, because it has nothing to ask you about: visit statistics are collected anonymously, without cookies and without identifiers that could recognize you or follow you across other sites.

The only thing stored in your browser is the theme you chose (light or dark). That is a technical setting in local storage and it is never sent anywhere.

10. Children

The service is not intended for people under 16 and we do not knowingly collect their data. If you believe a child has created an account, write to us and we will delete it.

11. Security

  • Connections to the server are HTTPS only.
  • Bank tokens and two-factor authentication secrets are stored encrypted.
  • Sign-in runs through Google, and on iOS through Apple as well, optionally with a passkey; inside the app you can enable a PIN or biometrics.
  • Two-factor authentication (2FA) can be enabled in settings: signing in then needs a one-time code from an authenticator app in addition to your Google or Apple account.
  • Crash reports are stripped of request bodies, authorization headers and images before they leave the device or the server.

There are no passwords in this service at all — we do not create them, accept them or store them. There are three ways in: a passkey on your device, Google or Apple sign-in if you chose it, and a recovery code. The app shows the recovery code once, right after sign-up; the server keeps only a one-way hash of it, so the code itself cannot be recovered from what we hold, and the number of attempts to enter it is limited. The code is shown once — at the moment it is created — and never again: no device keeps a readable copy of it. From the settings you can only generate a new one, which retires the old one, or remove the code if Google or Apple is linked to the account; once it is removed that provider can no longer be unlinked, so a way in always remains. The other side of that design we state plainly: if both the passkey and the recovery code are lost, nobody can restore access to the account — including us. That is exactly why the app has a backup that depends on no server.

Images — receipt photos, meter photos, utility bills and asset documents — can be encrypted end to end: the app has a «Photo encryption» switch, and once it is on, new images are encrypted on your device under a key that belongs to your account, and they reach the server already encrypted: what is stored there is the ciphertext, the file type and the size. The server never holds the key in usable form, so neither we as the operator of the service nor anyone with access to the server or the database can look at those images.

The key reaches your other devices in one of two ways: by pairing with a device that is already set up (the key is shown on your own screen and never travels the network), or with a recovery code the app shows once when you turn encryption on. A copy of the key encrypted under that code may be kept on the server — without the code it does not open. The other side of that design we state plainly: if you lose every device and the recovery code, nobody can bring those images back, ourselves included.

What the encryption does not cover: when you send a photo for recognition, the frame passes through our server to the external model (section 8) — it is not stored there, but at that moment it is not encrypted under your key.

12. Changes to this policy

If the policy changes we will update the version number and date on this page. Material changes — ones that widen processing or add a recipient — will be announced in the app before they take effect.