Privacy Policy
Effective date: August 7, 2026 · Last updated: August 7, 2026
FinSight ("we", "us", or "our") is a personal finance platform that connects to your bank accounts to help you understand your spending, track budgets, and get AI-powered financial insights. This Privacy Policy explains what information we collect, how we use it, who we share it with, and your rights regarding your data.
By creating an account or using FinSight, you agree to this Privacy Policy. If you do not agree, do not use the service.
1. Information We Collect
1.1 Account information
When you sign up, we collect your name and email address through our authentication provider, Clerk. If you sign in via Google or GitHub, we receive the profile data those providers share (name, email, profile picture).
1.2 Financial data from Plaid
When you connect a bank account, FinSight uses Plaid — a regulated, bank-level financial data aggregator — to access:
- Account names, types, and current balances
- Transaction history (date, amount, merchant name, category)
- Account and routing numbers (read-only; we never initiate payments)
We store a Plaid access token (not your bank credentials) to periodically refresh transaction data. This token is encrypted with AES-256-GCM before being written to our database. Your bank login credentials are entered directly in Plaid's interface and are never transmitted to or stored by FinSight.
1.3 Data you create in the app
Budgets, financial goals, goal amounts, notes, and other settings you configure in FinSight are stored in our database and associated with your account.
1.4 AI chat messages
If you use the AI Assistant, we store the messages you send and the responses you receive so your conversation history persists across sessions. These messages, along with a summary of your account balances, budgets, and goals, are sent to Anthropic to generate a response. We do not use your chat messages to train AI models.
1.5 Usage data
We collect product analytics — pages visited, features used, session duration — via PostHog to understand how users interact with the product and to improve it. This data is anonymized and does not include your financial transaction details.
1.6 Payment information
Subscription payments are processed by Stripe. We receive a Stripe customer ID and subscription status. Your card number, CVV, and billing address go directly to Stripe and are never transmitted to or stored by FinSight.
2. How We Use Your Information
- Provide the service — sync your bank data, calculate spending summaries, evaluate budgets, and track progress toward your goals.
- AI-powered insights — your transaction data is sent to Anthropic (the company behind Claude) to generate financial summaries, budget advice, and the AI chat assistant. Anthropic's API does not train models on your data by default; see Anthropic's privacy policy for details.
- Email notifications — budget alerts, weekly spending digests, and account updates are sent via Resend using the email address on your account.
- Security and fraud prevention — rate limiting, anomaly detection, and log analysis to protect your account.
- Product improvement — aggregated, anonymized analytics help us decide which features to build next.
3. Third-Party Service Providers
We share your information with these processors only to the extent necessary to operate the service:
| Vendor | Purpose | Data shared |
|---|---|---|
| Clerk | Authentication & user management | Name, email, session tokens |
| Plaid | Bank account connectivity | Bank credentials (via Plaid's UI only), access tokens |
| Stripe | Subscription billing | Email, subscription tier |
| Anthropic | AI financial insights | Transaction summaries, account totals, chat messages |
| OpenAI | Reserved for a future knowledge-base search feature | Not currently active — no user data is sent to OpenAI today |
| PostHog | Product analytics | Page views, feature usage (anonymized) |
| Resend | Transactional email | Email address, notification content |
| Neon (AWS) | Database hosting | All stored user data (encrypted at rest) |
| Vercel | Application hosting | Request logs, IP addresses |
| Upstash | Rate limiting & caching | User IDs, rate-limit counters |
We do not sell your personal information to third parties. We do not share your data with advertisers.
4. Data Security
- Encryption in transit — all traffic is served over HTTPS with TLS 1.2 or higher. All API calls to Plaid, Stripe, Anthropic, and other third parties use HTTPS.
- Encryption at rest — Plaid access tokens are encrypted with AES-256-GCM before being stored. The Neon database is hosted on AWS, which encrypts storage volumes at rest by default.
- Access control — all dashboard routes require authentication (Clerk JWT). Admin routes include a server-side role check on every request. API endpoints are rate-limited.
- No credential storage — we never store your bank username, password, or security questions. Bank authentication happens inside Plaid's interface.
No system is 100% secure. If you discover a security vulnerability, please report it to info@finsight.it.com.
5. Data Retention
We retain your data for as long as your account is active. When you delete your account, we will delete your personal information, financial data, and Plaid connections within 30 days, except where we are required to retain it by law (e.g., billing records for tax purposes).
Disconnecting a bank account within the app revokes FinSight's Plaid access token for that institution and removes the stored transactions from that account.
6. Your Rights
Depending on where you live, you may have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate data.
- Deletion — request deletion of your account and associated data.
- Opt-out of analytics — PostHog respects the
Do Not Trackbrowser signal. You can also contact us to opt out. - Data portability — request an export of your financial data in a machine-readable format.
To exercise these rights, email info@finsight.it.com. We will respond within 30 days.
7. California Residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
- Right to Know — you may request disclosure of the categories and specific pieces of personal information we have collected about you.
- Right to Delete — you may request deletion of personal information we have collected from you.
- Right to Opt-Out of Sale — we do not sell your personal information. You do not need to opt out.
- Right to Non-Discrimination — exercising your privacy rights will not result in different pricing or service levels.
8. Children's Privacy
FinSight is intended for users 18 years of age or older. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided personal information, we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in the app at least 7 days before the change takes effect. Continued use of FinSight after the effective date constitutes acceptance of the updated policy.
10. Contact Us
Questions about this Privacy Policy? Contact us at: info@finsight.it.com