Privacy Policy
How Finula handles your account, household finances and optional AI features.
1. Who is responsible
Finula is operated by Peter Šinál, the controller of personal data processed to provide Finula. Contact: peter.sinal2002@gmail.com. Correspondence address: Zápotočná 416/14, 028 01 Trstená, Slovensko.
This policy covers the Finula mobile app and its support pages. Brumshake's other services are not covered by this policy.
2. Data we process
- Account: your Firebase user identifier, email address, display name, sign-in provider and verification status. Apple or Google provide the information you authorise during sign-in. Password authentication is handled by Firebase Authentication, not stored as a readable password by Finula.
- Financial records: income, expenses, dates, merchants, categories, notes, recurring costs, budgets, savings goals and contributions. Receipt records may include item names, quantities, prices, discounts, the original currency and currency-conversion information.
- Households: membership, invitations, permissions and shared financial records. Other members may access shared data within their permissions.
- Optional AI: chat messages and replies, relevant financial context, receipt photos submitted for recognition, selected expense details submitted for savings suggestions, and accepted savings plans.
- Subscriptions: app-store purchase and entitlement identifiers, product, status and renewal information. Apple or Google handle payments. Finula does not receive your full payment-card details.
- Technical information: app and operating-system version, error reports, request/security information, App Check attestation, language preference, notification settings and a push token if you enable notifications. Support emails contain the information you send us.
- Consent: whether you granted or withdrew permission for each AI purpose, the notice version, time and language.
Do not upload passwords, full card details, government identifiers or unnecessary sensitive information. Receipt photos and free-text messages may contain personal information beyond the fields Finula needs; review them before submitting.
3. Purposes and legal bases
- We process account information and financial records to provide the service you request, including synchronisation, budgeting, goals and authorised household sharing (performance of our contract).
- We process subscription information to provide purchased features and verify access (performance of our contract), and retain records where required by applicable accounting or other law (legal obligation).
- We process proportionate technical and security information to prevent abuse, investigate failures and keep the service reliable (legitimate interests). You may object on grounds relating to your situation.
- Sending your data to OpenAI for an optional AI purpose requires your explicit consent for that purpose. You can refuse without losing ordinary budgeting, goals and manual expense entry.
- We respond to support requests to assist you and administer the service (contract or legitimate interests, depending on the request).
We do not sell personal data. Finula's financial suggestions do not make lending, credit or other legally significant decisions about you.
4. Optional AI and OpenAI
Finula uses the OpenAI API, not a public ChatGPT conversation. Before first use, a separate unchecked checkbox explains each purpose and asks for permission:
- AI chat: your message, part of previous conversation history and financial context such as income, fixed costs, spending summaries and goals.
- Receipt recognition: the receipt image to recognise the merchant, date, currency, items and prices, including other information visible in the image.
- AI optimisation: selected spending summaries, relevant item and merchant names, prices and goal information for savings suggestions. We preprocess expense data rather than sending all raw receipt photos for this purpose.
In a household, relevant context may include shared finances you are authorised to access. Your permission belongs to your own account; another member's permission does not grant yours. Only share other people's information when you have the necessary authority and have informed them.
By default, OpenAI does not use API inputs and outputs to train its models. We request responses with storage disabled; this does not guarantee zero retention. OpenAI may retain abuse-monitoring data, normally for up to 30 days, with exceptions described in its policies. See OpenAI's API data controls and OpenAI's privacy policy.
Withdraw an AI permission in Profile → Data and privacy → AI consents. New use of that feature will require fresh permission. Withdrawal does not undo completed processing or recall a request already sent. AI results can be inaccurate: verify amounts, categories, currency conversions and suggestions before acting.
5. Service providers and sharing
We use Google Firebase for authentication, database, storage, backend functions and application attestation; OpenAI for the optional AI purposes above; RevenueCat for subscription verification; Apple App Store or Google Play for billing; Expo for push notifications; and Sentry for crash/error diagnostics. These services receive the information needed for their role. Apple and Google also process sign-in and purchase information under their own policies.
We disclose information to household members only through the sharing you enable and the permissions assigned. We may disclose information when required by law or necessary to protect the service or establish, exercise or defend legal claims.
Diagnostic and security reports may contain identifiers, device details and information associated with an error; they are not a promise of anonymous processing. Support attachments should not contain unnecessary financial or sensitive information.
6. International processing
Our current main Firebase backend functions are hosted in Europe, but this does not mean all processing by every provider stays in the European Economic Area. Providers may process information in other countries, including the United States. Applicable transfers must use a valid legal mechanism, such as an adequacy decision or standard contractual clauses and any necessary supplementary safeguards. Contact us for information about the safeguards applicable to your data.
7. Retention and deletion
Your account and financial records are kept while you use the service, until you delete individual records where supported or request account deletion. AI conversations and saved plans form part of your account data. Consent decisions are kept to operate and document your choices. Security logs, backups, subscription and support records may persist for the period needed for security, recovery, legal obligations or legal claims; they are not all erased instantly with the live account.
Use Profile → Data and privacy → Delete account to request deletion through the app. A household founder may first need to remove members or resolve the household; a member may need to leave it. Contact support if that prevents deletion. The deletion process removes your account and associated app records; shared records may have consequences for other household members.
Deleting an account does not cancel an Apple or Google subscription. Cancel it separately in the relevant store. Store billing records are subject to the store's retention obligations. Provider-held data and backups may follow their own deletion schedules.
8. Your choices and rights
You can edit supported account/financial fields, manage household permissions, disable notifications, withdraw AI permissions and export your data in Profile → Data and privacy.
Where the GDPR applies, you may request access, correction, erasure, restriction and portability, object to processing based on legitimate interests and withdraw consent without affecting prior lawful processing. These rights are subject to the conditions in applicable law. Email the controller above; we may need to verify your identity securely. You may complain to your local data-protection authority, including the Slovak Office for Personal Data Protection.
9. Children and household use
Finula is not designed primarily for children. An adult setting up a household must ensure that each member's participation and any processing of a child's data meet applicable consent and parental-authorisation requirements. Household permission controls alone are not age verification or a substitute for parental consent. Please contact us if you believe a child's data was submitted without appropriate authority.
10. Security, website and changes
We use authentication, access controls, encrypted transport and app attestation to protect the service, but no system is completely secure. Keep your device and sign-in credentials safe. These legal pages do not embed advertising or third-party analytics; the hosting provider may process ordinary server access logs.
We update this notice when practices change and identify its date/version. A material change to an AI disclosure requires a new in-app permission rather than silently reusing the previous version. For privacy or support questions, use the contact above or our support page.