Privacy Policy
Version 1.4 · Effective from 25 August 2026
This policy explains what personal data the FinLad app and the finlad.site website process, for what purpose, on what legal basis and for how long they are kept. The data controller is FOP Itsekson Oleksii Volodymyrovych.
It is written to be read. If any part seems unclear, write to us through the contact form on the site and we will make the wording plainer.
1. Who processes your data
Controller: FOP Itsekson Oleksii Volodymyrovych, Ukraine. You can reach us through the contact form at finlad.site — that is the main channel for any question about this policy or your rights.
Processing follows the General Data Protection Regulation (GDPR, EU 2016/679) and the Law of Ukraine "On Personal Data Protection" No. 2297-VI.
2. What data we process
| Category | What exactly | Where it comes from |
|---|---|---|
| Account data | Google or Apple identifier, email address, interface language | From you when signing in with Google or Apple |
| Financial records | Transactions, accounts, categories, budgets, goals, utility services and readings, assets, investments | You create them in the app or import them |
| Bank access | Monobank access token (stored encrypted), imported statements | You add the token yourself; you upload the statement yourself |
| Receipt and document images | The photo you take for recognition | Device camera, by your action |
| Technical data | Session and device records, server request logs, crash reports | Generated automatically as you use the app |
| Sign-in log | The date and time of every sign-in, sign-up, failed attempt and sign-out, the sign-in method, the IP address and the kind of app the request came from | Generated automatically when you sign in |
| Messages | Message text, plus name and email if you provide them, and any screenshots you attach (up to three images) | The contact form on the site |
What we do not collect: an advertising identifier, your behaviour in other apps, contacts, precise location, or any payment details — payment runs only through the app stores (Google Play, and the App Store on iOS) and we never receive your card numbers.
An account can be created without telling us anything about yourself. The primary way to sign up is a single tap: the app creates a passkey on your device, and what we store is a random account id, a public key, a generated short name such as "FL-7F3A-K2M9", and your tier. No address, no name, no phone number is asked for or received. We will also state the limit of that anonymity plainly: every sign-in to any account goes into the sign-in log together with an IP address (see the row above) — so that you can find out about a sign-in that was not yours, and we can recognise guessing. That address does not name you, but the law treats it as personal data, so we do not hide it inside the general line about technical logs, and we delete it after 90 days. The "Account data" row above applies to people who chose to sign in with Google or, on iOS, with Apple: there we receive the identifier and the address from that account. Apple also lets you hide your real address — we then receive an @privaterelay.appleid.com alias and never see yours. That is your choice rather than a condition of use — and you can make it later, or never.
If you give us an email address yourself — in a message through the contact form, for instance — we have no way to verify it, so we do not use it as a way to sign in or to restore access, and we never merge two accounts by it. It stays what you made it: a way to reach you about that message.
3. Why, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Providing the service itself: storing your financial records, computing budgets and statistics, syncing between your devices | Performance of a contract (Art. 6(1)(b) GDPR) — the Terms of Use you accept at the start |
| Connecting a bank and receiving your transactions automatically | Your explicit consent (Art. 6(1)(a)) — you add the token yourself and can revoke it at any time |
| Receipt recognition and category suggestions using AI | Your consent — the feature is triggered by your action and can be fully disabled with one switch in settings |
| Security, crash diagnostics, abuse prevention | Legitimate interest (Art. 6(1)(f)) — so the service works and does not lose your data |
| Replying to your message | Legitimate interest, and your act of providing the address |
| Anonymous website visit statistics | Legitimate interest — aggregated statistics, no cookies, no profiling |
4. Who we share data with
We do not sell your data and we do not pass it to advertising networks. It reaches only the providers the service cannot run without, and only to the extent their function requires:
| Recipient | What it receives | Why |
|---|---|---|
| Hetzner Online GmbH (Germany) | All server data — it is physically stored on their hardware; also technical request data for finlad.site | Hosting the server, the database and the website itself in the EU |
| Google LLC (Gemini API, USA) | Only the receipt, meter or bill image you sent for recognition, or the line you typed / the description from a statement. No amounts, balances, account names or your identifier | Image recognition, category suggestions and parsing a typed line |
| Anthropic PBC (USA) | The same, on the same terms — but only when the primary provider did not answer | Backup provider, so recognition does not disappear during an outage |
| Google LLC / Google Ireland Ltd | Google sign-in data; data about a purchase you made | Account sign-in, payment via Google Play |
| Apple Inc. / Apple Distribution International Ltd (Ireland) | Apple sign-in data — the identifier and an address that may be an @privaterelay.appleid.com alias; data about a purchase you made | Account sign-in on iOS, payment via the App Store |
| Functional Software, Inc. (Sentry), EU region | Crash reports: error type, stack trace, request route. Request bodies, authorization headers and images are stripped before sending | Fixing errors |
| JSC Universal Bank (Monobank) | Requests carrying your token to fetch your own transactions | Only if you connected the bank |
| Umami Software, Inc. | Anonymous page-view data: page, referrer, device type. No cookies and no identifier that could recognize you | Website visit statistics |
Transfers outside the EU concern only the AI features (Google and Anthropic, USA) and Google or Apple sign-in, and take place under the standard contractual clauses of those providers; for users in the EU, the Apple party holding that data is its Irish company. Both model providers are used on their paid tiers, whose terms forbid training models on what is sent. If you switch AI off in settings, no transfer to them happens at all.
5. Where data is stored
The server and database are located in the European Union (Germany). Server backups are encrypted before they are written anywhere they will stay, and are stored in the EU as well; the key that opens them is kept apart from the server, so a copy that falls into the wrong hands along with the server stays unreadable. Receipt images are not retained on the server after recognition — they are processed in transit, and whatever you choose to keep stays in your app.
On the free tier sync is off by design: your financial records stay on your device only and never reach the server at all. The same is available on the paid tier — sync can be switched off in settings at any time, and the app then works locally: new records stay on the device.
6. How long we keep it
- Account data and financial records — for as long as your account exists. After a deletion request they are kept for a further 7 days so you can change your mind, and are then deleted for good.
- Backups — 14 daily, 8 weekly and 6 monthly. Data you deleted ages out of backups as they rotate, which takes roughly six months.
- Server request logs — a limited technical period needed for diagnostics.
- The sign-in log — 90 days, after which entries are deleted automatically. Deleting your account deletes its log with it.
- Crash reports — per Sentry’s retention periods.
- Contact form messages, together with any screenshots attached to them — until the conversation is finished, plus a reasonable period after. Screenshots are deleted with the message they belong to, never separately.
7. Your rights
You have the right of access, rectification, erasure, restriction of processing, objection, and data portability. Here is how to exercise them:
- Rectification — directly in the app: every record is yours to edit.
- Erasure — the "Delete account and all data" button in settings. This device’s copy is wiped at once and for good, every session ends, and the bank connection is disconnected. The data on the server is deleted after 7 days: throughout that time you can sign in and cancel the deletion — or finish it straight away without waiting. What comes back is the server copy; if your plan has no sync there is none, so there would be nothing to bring back. Once the window has passed we deliberately keep no shadow copy, so data cannot be restored. If you no longer have the app, send a request at finlad.site/delete-account and we will carry it out within 30 days.
- Access and portability — in the app: More → Data → Export data. Transactions download as a CSV sheet, and everything as a JSON file in a machine-readable format. Receipt photos are listed in the JSON but not embedded; if you need the images themselves, or a copy in another shape, send a request through the contact form.
- Withdrawing consent — switch AI off in settings or disconnect the bank; this does not affect the lawfulness of processing before withdrawal.
You also have the right to lodge a complaint with a supervisory authority: in Ukraine, the Ukrainian Parliament Commissioner for Human Rights; in the EU, the authority where you live.
8. How the AI works and what it sees
The app calls an external model in exactly three cases: when you send a photo of a receipt, a meter or a bill for recognition; when a transaction description could not be categorized by its own rules; and when a line you typed by hand could not be parsed on the device itself.
- Amounts, dates, balances, your account names and your identifier are never sent.
- A description recognized as naming a person rather than a merchant (a card-to-card transfer, for example) is not sent at all and is left for manual categorization.
- The model’s answer is immediately turned into a local rule, so the same merchant is recognized next time without any outbound call.
- The model providers — Google (Gemini) and, when it is unavailable, Anthropic — are used on their paid tiers: under those terms, what is sent is not used to train the models.
- One switch in settings disables every AI feature. The app remains fully functional afterwards.
9. Cookies and website statistics
This site uses no cookies and shows no consent banner, because it has nothing to ask you about: visit statistics are collected anonymously, without cookies and without identifiers that could recognize you or follow you across other sites.
The only thing stored in your browser is the theme you chose (light or dark). That is a technical setting in local storage and it is never sent anywhere.
10. Children
The service is not intended for people under 16 and we do not knowingly collect their data. If you believe a child has created an account, write to us and we will delete it.
11. Security
- Connections to the server are HTTPS only.
- Bank tokens and two-factor authentication secrets are stored encrypted.
- Sign-in runs through Google, and on iOS through Apple as well, optionally with a passkey; inside the app you can enable a PIN or biometrics.
- Two-factor authentication (2FA) can be enabled in settings: signing in then needs a one-time code from an authenticator app in addition to your Google or Apple account.
- Crash reports are stripped of request bodies, authorization headers and images before they leave the device or the server.
There are no passwords in this service at all — we do not create them, accept them or store them. There are three ways in: a passkey on your device, Google or Apple sign-in if you chose it, and a recovery code. The app shows the recovery code once, right after sign-up; the server keeps only a one-way hash of it, so the code itself cannot be recovered from what we hold, and the number of attempts to enter it is limited. The code is shown once — at the moment it is created — and never again: no device keeps a readable copy of it. From the settings you can only generate a new one, which retires the old one, or remove the code if Google or Apple is linked to the account; once it is removed that provider can no longer be unlinked, so a way in always remains. The other side of that design we state plainly: if both the passkey and the recovery code are lost, nobody can restore access to the account — including us. That is exactly why the app has a backup that depends on no server.
Images — receipt photos, meter photos, utility bills and asset documents — can be encrypted end to end: the app has a «Photo encryption» switch, and once it is on, new images are encrypted on your device under a key that belongs to your account, and they reach the server already encrypted: what is stored there is the ciphertext, the file type and the size. The server never holds the key in usable form, so neither we as the operator of the service nor anyone with access to the server or the database can look at those images.
The key reaches your other devices in one of two ways: by pairing with a device that is already set up (the key is shown on your own screen and never travels the network), or with a recovery code the app shows once when you turn encryption on. A copy of the key encrypted under that code may be kept on the server — without the code it does not open. The other side of that design we state plainly: if you lose every device and the recovery code, nobody can bring those images back, ourselves included.
What the encryption does not cover: when you send a photo for recognition, the frame passes through our server to the external model (section 8) — it is not stored there, but at that moment it is not encrypted under your key.
12. Changes to this policy
If the policy changes we will update the version number and date on this page. Material changes — ones that widen processing or add a recipient — will be announced in the app before they take effect.