Privacy Policy
Privacy Policy
Effective date: January 1, 2026 · Last updated: September 27, 2026
fin0.cloud ("fin0", "we", "us", "our") is a personal finance calendar application that helps you track spending and understand whether your daily spending is on track. This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to the fin0 mobile apps (iOS, Android) and the fin0 web app at app.fin0.cloud.
fin0 is operated by Denis Pishchukhin, operating as fin0.cloud (NIF: Z2646978M), based in Getxo, Bizkaia, Spain. You can contact us at privacy@fin0.cloud.
1. Information We Collect
1.1 Account information
- Email address and, if you sign in with Google, your name and Google account identifier — collected via Firebase Authentication.
- A unique internal user ID used to associate your data with your account.
1.2 Financial data you provide
fin0 does not connect to your bank account. All financial data is entered manually by you. This includes:
- Transactions (amount, date, category, description you provide)
- Budget categories and monthly budget limits
- Currency selection and, where applicable, exchange-rate conversions
This data is used solely to calculate your daily spending corridor status (Green / Yellow / Red) and your account balance history.
1.3 Payment information
If you subscribe to fin0 Pro, payment is processed by Stripe. We do not receive or store your card number or other full payment credentials — Stripe shares with us only your subscription status, plan, and billing history needed to manage your account.
1.4 Device and notification data
- A push-notification token (via Firebase Cloud Messaging) if you enable notifications, used only to deliver corridor-status alerts to your device.
- Basic technical data such as app version and platform, for debugging and stability purposes.
1.5 Google Calendar integration (optional)
If you choose to connect Google Calendar, fin0 requests limited access (via the calendar.app.created scope) to a separate calendar created by fin0 in your Google account, used only to push your daily corridor status as calendar events. fin0 cannot see, read, or modify any of your other existing calendars or events. We store the OAuth token needed to maintain this connection on our servers for as long as the integration stays enabled; you can disconnect it at any time in the app, which revokes our access.
1.6 Information we do not collect
- We do not access your contacts, photos, SMS, or call logs.
- We do not use advertising SDKs or sell data to advertisers.
- We do not and will not access your bank accounts or payment cards directly — fin0 has no open-banking or bank-sync integration.
Some optional features (e.g. syncing corridor status to Google Calendar) may request additional, narrowly-scoped permissions at the time they are introduced. Any such feature will only access the specific data needed for it, with your explicit consent, and this policy will be updated accordingly before the feature is enabled for you.
2. How We Use Your Information
- To provide core functionality: calculating your spending corridor, balances, and budget tracking.
- To authenticate you and keep your account secure.
- To process subscription payments and manage billing.
- To send you transactional emails (e.g. account verification, receipts) via our email provider, Resend.
- To send optional push notifications about your corridor status, if enabled.
- To maintain, debug, and improve the reliability of the service.
We do not use your financial data to train third-party AI models, and we do not sell your personal data.
3. Third-Party Services
We rely on the following processors to operate fin0. Each only receives the minimum data needed to perform its function:
| Service | Purpose | Data shared |
|---|---|---|
| Google Firebase (Google LLC) | Authentication, push notifications | Email, name, auth tokens, device notification token |
| Google Cloud Platform | Hosting, infrastructure | All application data, encrypted at rest and in transit |
| Stripe, Inc. | Subscription billing | Email, subscription/plan status, billing history |
| Resend | Transactional email delivery | Email address, email content |
| Frankfurter.app | Currency exchange rates | No personal data — public exchange-rate lookups only |
| Google Calendar API | Optional: syncing corridor status as calendar events, if you enable it | OAuth token; access limited to a fin0-created calendar only |
4. Data Retention
We retain your account and financial data for as long as your account is active. If you request deletion of your account, your personal data and transaction history are permanently deleted from our production systems within 90 days of your request, except where retention is required by law (e.g. billing records for tax compliance).
5. Data Security
- All data is transmitted over TLS (HTTPS).
- Authentication is handled by Firebase; passwords are never stored or seen by fin0 directly.
- Financial data is stored in an access-controlled PostgreSQL database on Google Cloud Platform infrastructure.
6. Your Rights
If you are in the EU/EEA or another jurisdiction with data protection laws (e.g. GDPR), you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Export your data (available in-app for Pro subscribers, or on request)
- Withdraw consent for optional features (e.g. push notifications) at any time via device or app settings
To exercise any of these rights, including deleting your account, contact us at support@fin0.cloud or use our account deletion request page. We will process deletion requests within 90 days.
7. International Data Transfers
Our infrastructure runs on Google Cloud Platform. Data may be processed in data centers located outside your country of residence, including in the European Union. Where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses.
8. Children's Privacy
fin0 is not directed at children under 16 and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified in-app or by email. Continued use of fin0 after changes take effect constitutes acceptance of the revised policy.
10. Contact Us
Questions about this policy or your data can be sent to privacy@fin0.cloud.