Finwise

Privacy Notice

Last updated: 12 August 2026

This notice explains what personal information Finwise collects when you use the service, why we collect it, who we share it with, and the choices you have. Finwise is operated by Lokesh M ("Finwise", "we", "us"), which acts as the data controller for the information described below.

1. Who we are

Finwise is a personal finance management application that lets you record and analyse your own financial data. Lokesh M decides how the personal information described in this notice is collected and used, and is therefore the controller of that information. You can reach us at any time at support@usefinwiseai.com.

2. Information you provide

We collect only what is needed to run your account and show you your data:

  • Account information — your email address, an optional display name, and authentication data such as a securely hashed password, email verification state and one-time sign-in codes.
  • Google sign-in information — if you choose to continue with Google, we receive your Google account email address, basic profile name and profile picture URL from Google so we can create or match your Finwise account. We do not receive your Google password and we do not access any other Google data.
  • Financial information you enter — accounts and opening balances, transactions and transfers, categories, budgets, bills, savings goals, investments and SIP plans, loans, credit cards, and the FIRE / personalisation preferences you set. Finwise does not connect to your bank; every record exists because you or an import you ran created it.
  • Uploaded files — receipt images or documents you attach to a transaction, plus their file name and size.
  • Support messages — anything you send us by email.

3. Technical information

When you use Finwise, our hosting and backend providers process standard technical data needed to serve and secure the application, including your IP address, browser and device type, request timestamps, sign-in events and error diagnostics. We use this to keep the service running, investigate faults and detect abuse. We do not run advertising or cross-site tracking, and we do not build advertising profiles.

4. How we use your information

  • Creating your account, signing you in and verifying your email address.
  • Storing your financial records and displaying your dashboard, reports, budgets, bills, goals, net worth, FIRE projections and rule-based insights.
  • Generating the in-app assistant answers and insights, which are produced by deterministic calculations over your own data.
  • Sending the notifications and reminders you enable in the app.
  • Providing customer support and responding to your requests.
  • Keeping accounts secure, preventing fraud and abuse, and diagnosing technical problems.
  • Handling your subscription purchase, renewal, invoicing and refunds through our payment provider.

5. Legal bases

Where the law requires us to identify a legal basis, we rely on: performance of our contract with you (providing the account and the features you use); our legitimate interests (securing the service, preventing abuse, improving reliability); your consent (optional notifications and optional marketing email, which you can withdraw at any time); and compliance with legal obligations (for example accounting and tax records kept by our payment provider).

6. How your data is stored and isolated

Your records are stored in a managed cloud database (Lovable Cloud, built on Supabase). Every table that holds user data has row-level security policies applied in the database itself, so a request authenticated as your account can only read or write rows belonging to that account. Uploaded receipts are stored in a private storage bucket with per-user access rules. Traffic between your browser and our infrastructure is served over HTTPS, and data at rest is encrypted by the infrastructure provider.

7. Service providers we share data with

  • Lovable Cloud / Supabase — authentication, database and file storage hosting. They process your account and financial records on our behalf as a processor.
  • Google — only if you choose Google sign-in, to authenticate you.
  • Paddle.com — our online reseller and Merchant of Record for all subscription purchases. Paddle handles checkout, payment processing, billing, invoicing, sales-tax compliance, subscription management and refunds. Payment card details are entered directly with Paddle and are never received or stored by Finwise. Paddle processes your billing information as an independent controller under its own terms and privacy notice.
  • Professional advisers and authorities — where we are legally required to disclose information, or need advice to protect our legal rights.

8. Cookies and local storage

Finwise uses browser storage for functional purposes only: a session cookie / local-storage entry to keep you signed in, a stored preference for light or dark theme and display currency, a short-lived marker used to complete Google sign-in redirects, and offline caching by the app's service worker so the interface loads reliably. Our payment provider may set cookies during checkout to operate the payment flow. We do not use advertising or cross-site tracking cookies. You can clear this storage in your browser at any time, which will sign you out.

9. International transfers

Our providers may process and store data on infrastructure located outside your country, including in the United States and the European Union. Where those transfers require safeguards, they are handled through the contractual terms our providers put in place with us and their own sub-processors.

10. Data retention

We keep your account and financial records for as long as your account exists, because the product's purpose is to show your history over time. Records you delete inside the app are removed from your workspace. When you delete your account, your personal and financial records are deleted from our systems within 30 days, except where we must retain limited information for legal, accounting or fraud-prevention reasons — for example, Paddle retains transaction and invoice records it is legally required to keep as Merchant of Record. Backups roll off on our provider's normal cycle.

11. Deleting your account and your data

You can delete individual accounts, transactions, budgets, bills, goals, investments, loans, credit cards and uploaded receipts at any time from within the app, and export your transactions to CSV before doing so. To delete your entire account, email us from your registered address at support@usefinwiseai.com with the subject "Delete my account". We will confirm and complete the deletion within 30 days. Deleting your account does not automatically cancel a paid subscription — cancel it first from Settings or via Paddle so you are not billed again.

12. Your rights

Depending on where you live, you may have the right to access a copy of your data, correct inaccurate data, delete your data, restrict or object to certain processing, receive your data in a portable format, and withdraw consent you previously gave. Most of these are available directly in the app through editing, export and deletion. For anything else, contact support@usefinwiseai.com. We aim to respond within 30 days. If you are unhappy with our response and your local law provides for it, you may complain to your data protection authority.

13. Security

We apply technical and organisational measures appropriate to a small service handling sensitive financial records: HTTPS in transit, encryption at rest by our infrastructure provider, database-enforced per-user isolation, private file storage, hashed passwords and short-lived refreshable sessions, restricted administrative access and monitored errors. No online service can promise absolute security, and we do not claim to be certified under any specific security or privacy standard.

14. Children

Finwise is not intended for children. You must be at least 16 years old, or the minimum age required in your country to enter a contract, to create an account. If we learn that we hold data about a child below that age, we will delete it.

15. Changes to this notice

We may update this notice as the product changes. The 'last updated' date above always reflects the current version. If a change materially affects how we use your information, we will notify you in the app or by email before it takes effect, and continued use after that point means you accept the updated notice.

16. Contact

Privacy questions: support@usefinwiseai.com. General support: support@usefinwiseai.com. Billing, invoices and refunds are handled by our Merchant of Record, Paddle, at paddle.net.