Legal
Privacy Policy
Last updated: 2026-01-01
FinSight AI takes financial data seriously. This Privacy Policy explains what we collect, how it is used, and the controls available to you.
What we collect
- Account data: email, name, password hash, and authentication metadata.
- Workspace and financial records you create or import: accounts, categories, transactions, budgets, bills, goals, and debts.
- Operational logs: IP address, user agent, timestamps for security audit purposes.
How we use it
- To provide the dashboards, scores, and AI insights you ask for.
- To send reminders you opt into (bills, digests, AI insights).
- To detect and prevent abuse, fraud, and account takeover.
- We do not sell your personal data.
How we protect it
- Tenant isolation enforced at the query layer.
- Sensitive fields encrypted at rest with key derivation.
- Passwords hashed with bcrypt/argon2; tokens rotated.
- Webhook signature verification for payment events.
- Audit logs for sensitive actions.
Your controls
- Export all your workspace data as JSON via the compliance API or settings.
- Delete your account or a workspace at any time.
- Opt out of optional emails and AI processing from notification preferences.
Subprocessors
We may use trusted infrastructure subprocessors (e.g., hosting, payment processing). A current list is available on request.