Legal

Privacy Policy

Last updated: 2026-01-01

FinSight AI takes financial data seriously. This Privacy Policy explains what we collect, how it is used, and the controls available to you.

What we collect

  • Account data: email, name, password hash, and authentication metadata.
  • Workspace and financial records you create or import: accounts, categories, transactions, budgets, bills, goals, and debts.
  • Operational logs: IP address, user agent, timestamps for security audit purposes.

How we use it

  • To provide the dashboards, scores, and AI insights you ask for.
  • To send reminders you opt into (bills, digests, AI insights).
  • To detect and prevent abuse, fraud, and account takeover.
  • We do not sell your personal data.

How we protect it

  • Tenant isolation enforced at the query layer.
  • Sensitive fields encrypted at rest with key derivation.
  • Passwords hashed with bcrypt/argon2; tokens rotated.
  • Webhook signature verification for payment events.
  • Audit logs for sensitive actions.

Your controls

  • Export all your workspace data as JSON via the compliance API or settings.
  • Delete your account or a workspace at any time.
  • Opt out of optional emails and AI processing from notification preferences.

Subprocessors

We may use trusted infrastructure subprocessors (e.g., hosting, payment processing). A current list is available on request.