Privacy Policy
Last updated: 2026-10-04
1. Who we are
Finclir ("we", "us") is a personal and household wealth-tracking web app available at finclir.com. This policy explains what personal data we handle, why, and the choices you have.
2. Data we collect
Account data: your email address, name, and a bcrypt-hashed password (or your Google account identifier and email if you sign in with Google).
Financial data you provide or connect: holdings, properties, mortgages and loans, pension and insurance records, transactions, tax details, and documents you upload (statements, contracts, tax forms). If you connect Open Banking through Financy, we also store the account and transaction data it returns, and your Financy credentials, encrypted with AES-256-GCM.
Usage and technical data: sign-in sessions, AI-assistant conversation history, AI usage counters, and basic server logs (such as IP address and request metadata) used to keep the service secure and working.
Billing data: if you subscribe, payment is handled by Stripe. We store your plan and subscription status, not your card number.
3. How we use it
To provide the app: show your net worth, run reports, import and read your documents, sync your accounts, and power the AI assistant. To secure the service and prevent abuse. To manage your subscription and send service messages. To comply with law. We do not sell your personal data and do not use your financial data for advertising.
4. Service providers who process data for us
Vercel (hosting and private file storage), a managed PostgreSQL database provider (storage), Anthropic (AI features: when you use the assistant or import a document, the relevant text or file content is sent to Anthropic to generate the result), Financy (Open Banking connectivity, only if you connect it), Google (sign-in, only if you use it), and Stripe (payments). Each receives only what it needs for its function. Some of these providers process data outside Israel, including in the United States and the European Union.
5. How we protect it
Connections use HTTPS. Bank credentials are encrypted at rest (AES-256-GCM) and decrypted only on the server to run a sync. Passwords are hashed with bcrypt. Each account's data is isolated server-side and every request is checked against the signed-in session. Uploaded documents are stored privately and served only after an ownership check. No system is perfectly secure, and we do not claim formal security certifications; see the Security page in the app for details.
6. Retention and deletion
We keep your data while your account is active. You can ask us to delete your account and all data in it at any time by writing to the contact address below; we will act on verified requests within a reasonable time. Some limited records (such as billing records) may be kept where the law requires.
7. Your rights
You may request access to the personal data we hold about you, correction of inaccurate data, and deletion. You can disconnect Open Banking and delete individual records or documents inside the app at any time. Where applicable law (for example Israel's Protection of Privacy Law or the GDPR) grants further rights, we honor them.
8. Cookies and local storage
We use a strictly necessary session cookie to keep you signed in, and your browser's local storage to remember display preferences (language, theme, privacy mode). We do not use advertising or third-party tracking cookies.
9. Children
Finclir is for adults (18+). Household profiles may list children as family members for planning, entered by the adult account holder. We do not knowingly offer accounts to minors.
10. Changes and contact
We may update this policy and will change the date above when we do; for material changes we will notify you in the app or by email. Questions or requests: support@finclir.com.