# Information We Collect
- Account information email, password hash, locale, subscription plan.
- Billing information handled by Stripe. We do not store card data.
- Usage data logins and feature use, measured with PostHog and internal logs.
- Trading and journal data entries you submit, used to compute the Discipline Score and mindset insights.
- Technical data IP, device and browser information, cookies, session identifiers.
# How We Use Your Data
- Provide access to accounts, dashboards, and reports.
- Compute the Discipline Score and bias insights.
- Process payments and manage subscriptions.
- Improve the product through aggregated analytics.
- Send service communications and weekly digests.
- Comply with legal obligations including GDPR.
# Lawful Bases for Processing
We rely on the following bases under Article six GDPR.
Purpose | Lawful basis |
---|---|
Account access and service delivery | Performance of a contract |
Payments and invoicing | Legal obligation and contract |
Product analytics via PostHog | Consent where required, otherwise legitimate interests with opt out |
Emails and operational notices | Legitimate interests service communications |
Marketing emails | Consent with unsubscribe link |
# Data Retention
- Subscription and invoice records kept up to six years for tax.
- Trading and journal data kept until you delete it or request erasure.
- Analytics data aggregated or anonymized after eighteen months.
# Third Party Processing
Processors operate under data processing agreements and appropriate safeguards. Regions reflect vendor offerings and your configuration.
Processor | Purpose | Data types | Region and safeguards |
---|---|---|---|
Supabase | Authentication and Postgres storage | Account and app data | EU region if configured. Standard Contractual Clauses if data leaves EEA. |
Stripe | Payments and subscriptions | Billing details and metadata | Global processing. Standard Contractual Clauses. |
PostHog | Product analytics | Pseudonymous usage events | EU hosting if available or SCCs otherwise. |
Cloudflare | CDN and object storage | Static assets and files | Global edge network with SCCs. |
Resend or SendGrid | Email delivery | Email and name | Global infrastructure with SCCs. |
# International Transfers
When data leaves the European Economic Area we rely on Standard Contractual Clauses or equivalent safeguards.
# Your Rights
- Access and rectification.
- Erasure and restriction.
- Portability.
- Objection and consent withdrawal.
To exercise your rights email hi@finaur.com with “Data Request” in the subject from your account email. We may request additional information to verify identity. We aim to respond within thirty days.
# Minors
Finaur is not intended for children under eighteen. If such data is discovered we delete it without delay.
# Security
- Encryption in transit and at rest.
- Role based access control and row level security.
- Signed URLs for file access.
- Monitoring and audit logs.
No system is perfectly secure. Use the service responsibly.
# Third Party Links
Linked sites have their own privacy terms. Review them before use.
# Business Transfers
If Finaur is acquired or merges with another entity your data may be transferred. You will be informed before any material change.
# Changes
Updates appear on this page with a new date. Significant changes are announced by email or in app.