Your data, clearly explained
Privacy Policy
This policy explains the information FinanceOS processes, why it is needed, the providers that help us operate, and the choices available to you.
Effective and last updated: 20 August 2026
FinanceOS is designed as a private financial workspace. We do not sell or rent your personal or financial information, use it for third-party advertising, or use your content to train general-purpose AI models.
1. Who we are and the scope of this policy
This Privacy Policy applies to FinanceOS websites, dashboards, application programming interfaces, emails, and related services (collectively, the “Service”). In this policy, “FinanceOS,” “we,” “us,” and “our” refer to the operator of the Service. This policy does not govern a third party’s independent website, product, or privacy practices.
2. Information we collect
We collect information you or an authorized workspace member provides, information created through use of the Service, and limited technical information needed to operate it. Depending on the features used, this may include:
- Identity and account data: name, email address, profile image, authentication identifiers, workspace membership, invitations, and assigned Admin, Client, or Accounts role.
- Financial records: bank and credit-card account details, transactions, balances, holdings, stock or mutual-fund identifiers, precious-metal records, private-equity interests, budgets, goals, loans, other liabilities, and related notes or classifications.
- Property, vehicle, and insurance data: asset descriptions, ownership and purchase details, valuations, registration or policy information, loan details, tax information, maintenance records, and photographs.
- Documents and files: bank and card statements, consolidated account statements, invoices, receipts, GST certificates, tax records, loan schedules, insurance or vehicle documents, property documents, investment evidence, PDFs, spreadsheets, images, and information extracted from those files.
- Tax and business data: filing periods, PAN or GSTIN when supplied, legal and trade names, registration and contact details, document requests, comments, and invoice data used to identify possible GST matches.
- Collaboration and communications: workspace invitations, comments, support requests, notification preferences, email-delivery details, and information you send when reporting a problem or exercising a privacy right.
- AI-processing records: the feature used, processing status, provider and model, timestamps, confidence or review information, and generated results.
- Usage and technical data: page or route visited, timestamp, referrer, approximate location derived from a request, browser, operating system, device type, IP address in security or server logs, session and security events, and diagnostic information.
Please provide only information you are authorized to use and that is reasonably needed for your financial workspace.
3. Where information comes from
Information may come directly from you; from an administrator, accountant, client, or other authorized workspace member; from files you choose to upload; from your use of the Service; or from the service and market-data providers described below. FinanceOS does not connect to or retrieve information from your bank, broker, Gmail, Google Drive, contacts, or calendar.
4. How and why we use information
We use information for the following purposes:
- authenticate users, maintain sessions, provision accounts, and enforce workspace permissions;
- store, display, organize, calculate, reconcile, search, and export the financial records you choose to maintain;
- process documents, extract or classify records, match invoices, refresh public market data, and generate user-requested financial insights;
- support collaboration, deliver invitations, notifications, and requested exports, and remember essential preferences;
- provide support, monitor reliability, troubleshoot errors, understand aggregate usage, and improve the Service;
- detect misuse, prevent fraud, maintain security, establish or defend legal claims, and protect users and the Service; and
- comply with applicable law and enforce our Terms & Conditions.
Where applicable law requires consent, you may withdraw it by stopping the relevant optional feature or contacting us. Withdrawal does not affect processing already completed and may prevent us from providing the feature that requires the information. We may also process information as necessary to provide the Service you request, comply with law, or pursue legitimate interests such as security and reliability where those grounds are recognized.
5. Google sign-in data
When you choose Google sign-in, FinanceOS requests only the standard openid, email, and profile permissions. Google provides your account identifier, name, email address, and profile image. FinanceOS and Clerk use this information to authenticate you, create or locate your FinanceOS account, display your account identity, maintain secure sessions, and apply the correct workspace permissions.
FinanceOS does not request or receive access to Gmail, Google Drive files, contacts, calendars, payment information, or other Google service content. We do not sell Google user data, use it for advertising, or use it to train general-purpose AI models.
Revoking FinanceOS access in your Google Account stops future Google authorization but does not automatically delete information already stored in FinanceOS. You may request deletion as described below, subject to applicable retention requirements.
6. AI-assisted processing
When you invoke an AI-assisted feature, the content needed for that task may be sent to OpenAI through its API. Depending on the feature, this can include a statement, invoice, investment statement, tax or GST document, loan schedule, property or vehicle document, image, selected workspace fields, and your instructions. FinanceOS receives the generated result and related processing metadata so it can present the result for review.
OpenAI states that API inputs and outputs are not used to train its models by default. You can learn more in OpenAI’s business data privacy information. FinanceOS does not use AI output by itself to file a return, transfer money, execute a trade, approve credit or insurance, or make another binding decision for you.
AI output can be incomplete or incorrect. FinanceOS may record provenance and flag low-confidence results, but you should review the source and generated result before accepting, exporting, filing, paying, claiming a tax benefit, or otherwise relying on it.
7. Market and reference data
FinanceOS may send a public identifier such as a stock ticker, ISIN, mutual-fund scheme code, or currency pair to Yahoo Finance or MFapi.in to retrieve public prices, net asset values, exchange rates, and instrument details. It may also request a public company logo from Logo.dev. We do not intentionally send these providers your uploaded documents, account balances, transaction history, or identity data for these lookups. Their returned data can be delayed, incomplete, or inaccurate.
8. Service providers and other disclosures
We disclose information only as needed to operate the Service, follow your instructions, protect legal rights, or comply with law. Current provider categories include:
- Clerk and Google for authentication, account identity, workspace membership, invitations, roles, and session security.
- Supabase for hosted database infrastructure used to store application and workspace records.
- Vercel for application hosting, server execution, private Vercel Blob file storage, operational logs, and privacy-focused Web Analytics.
- PostHog for product analytics and frontend and backend error monitoring. Signed-in analytics profiles include the FinanceOS authentication identifier, email address, and name so usage and errors can be traced to the affected user.
- OpenAI for AI-assisted document, extraction, classification, and insight features you invoke.
- Resend for transactional email, including invitations, notifications, and financial exports or attachments you request to be emailed.
- Yahoo Finance, MFapi.in, and Logo.dev for public market, instrument, currency, and company-logo data.
Providers process information under their own contractual, privacy, security, and retention commitments. We may also disclose information when required by law or valid legal process; to investigate abuse or a security incident; to protect a person’s safety, rights, or property; or as part of a merger, financing, reorganization, sale, or transfer of the Service, subject to applicable law.
9. International processing
FinanceOS and its providers may process or store information in India and other countries. Those countries may have different data-protection laws. We will take the steps required by applicable law and comply with applicable restrictions on cross-border processing.
10. Storage and retention
We retain account, workspace, document, and generated information while the relevant account or workspace is active and for as long as reasonably needed to provide the Service. Different periods may apply to temporary processing files, operational logs, security records, provider records, backups, disputes, and information that must be retained by law. When information is no longer needed, we delete or de-identify it where reasonably practicable. Deletion from backups and provider systems may take additional time.
Workspace owners and authorized users can delete many records in the Service. For account or workspace deletion, contact us. We may ask you to verify your identity and authority before acting on a request.
11. Security
We use administrative, technical, and organizational safeguards intended to protect information, including authenticated access, role-based workspace controls, private file storage, protected download paths, file validation, and security logging. No online service or storage system can be guaranteed to be completely secure. You are responsible for protecting your Google account, devices, exported files, and access credentials and for promptly reporting suspected unauthorized access.
12. Your rights and choices
Depending on applicable law, you may request a summary of or access to your personal information; correction, completion, updating, or deletion; withdrawal of consent; restriction of or objection to certain processing; and grievance redressal. You may also have a right to nominate another person to exercise specified rights on your behalf. Some requests may be limited where processing or retention is required for security, fraud prevention, legal compliance, establishment or defence of claims, or the rights of others.
To make a request, email us from the address associated with your FinanceOS account and identify the account or workspace concerned. We may request additional information to verify your identity, authority, and the scope of the request. If you are dissatisfied with our response, you may contact the competent data-protection authority where applicable.
13. Client and shared workspace data
Workspace owners and administrators control invitations, roles, and access to shared workspace information. Authorized accountants and other invited users may view and work with financial, document, and tax data in that workspace. If another person or organization invited you to FinanceOS, they may be responsible for deciding why and how that workspace data is processed. Direct workspace-specific requests to the workspace owner or contact us for assistance.
15. Children
The Service is intended for adults and business users and is not directed to anyone under 18. Do not create an account for or upload personal information about a child unless you have a lawful basis and any permission required by applicable law. If you believe a child has provided information without appropriate authorization, contact us so we can review and address it.
16. Changes to this policy
We may update this policy to reflect changes to the Service, providers, risk, or law. We will update the effective date above and provide additional notice or request consent where required.
17. Contact and grievances
For privacy questions, requests, complaints, or security concerns, contact abhilash0505@gmail.com. Please do not include bank statements, passwords, full card or account numbers, or other sensitive documents in an ordinary email.