How we handle your data
Effective May 15, 2026
FinaControl is a personal finance tool. We treat the data you enter — accounts, balances, transactions, categories — as private to you. This page explains what we collect, why, and the choices you have.
Information we collect
We collect only what's needed to run your account and the features you use:
- Account details you provide — name, email, password (stored hashed), and authentication factors like passkeys or one-time-code secrets.
- Financial data you enter — bank accounts, credit cards, transactions, categories, tax presets, and any notes attached to them.
- Technical data your browser sends — IP address, user agent, and minimal request logs used to keep the service running and secure.
How we use your information
We use your data to provide the product: to authenticate you, store and display your transactions, run projections, and deliver the features you ask for. We do not sell your data, and we do not use it to train third-party models.
Sharing
We don't share your personal data with third parties for marketing. We share data only with the infrastructure and analytics providers that operate the service — including the database and application hosting providers, our transactional email provider, and Google Analytics for aggregate usage measurement — and only to the extent needed for them to perform that service. We will disclose data when required to comply with a valid legal request.
Security
Passwords are stored hashed. Sessions are protected with industry-standard cookie protections. Optional second factors — TOTP and passkeys — are available in your settings and are recommended. No system is perfectly secure, but we follow common practice to reduce risk.
Data retention
We keep your data for as long as your account is active. You can delete your account at any time from settings; deleting your account removes your personal data and the financial records you've entered, subject to backups that expire on a rolling basis.
Your rights
You can access, export, correct, or delete your data from within the app. If you can't accomplish what you need from the settings screens, contact us and we'll help.
Cookies
We use cookies that are strictly necessary to keep you signed in and to protect form submissions against forgery. We also use Google Analytics cookies (see the Analytics section below) to measure aggregate usage. We don't use third-party advertising or cross-site tracking cookies.
Analytics
We use Google Analytics 4 to understand, in aggregate, how visitors find and use the product so we can improve it. Google Analytics sets cookies in your browser and collects usage data such as the pages you view, the approximate location derived from your (anonymized) IP address, your device and browser, and the referring site. We do not link your financial records to your analytics profile and we do not share analytics data with advertisers. Google processes this data on our behalf; see Google's privacy policy and how Google Analytics safeguards data for details.
Opting out of analytics
You can opt out of Google Analytics in three ways: (1) install the official Google Analytics opt-out browser add-on; (2) enable "Do Not Track" in your browser — when we receive a DNT signal we do not load the Google Analytics script at all; or (3) use a browser or extension that blocks third-party analytics. Opting out does not affect your ability to use FinaControl.
Changes to this policy
If we update this policy in a way that materially changes how we handle your data, we'll let you know in the app or by email before the change takes effect.
Contact
Questions about this policy or your data? Reach out to the address listed on the project's public repository and we'll respond.