Privacy Policy
Summary
- We keep only what the app needs to work: your account and the entries that you type in.
- The app does not connect to your bank and never asks for a bank password.
- We do not sell your data, do not show ads and do not use tracking tools.
- The servers are in the USA (DigitalOcean). The AI features send Groq (USA) only what is needed to generate the answer, without your name or e-mail.
- You can ask to access, correct, copy or delete your data at any time.
- 1. Who is responsible
- 2. What data we process
- 3. Why we use it and on what legal basis
- 4. Artificial intelligence
- 5. Who we share it with
- 6. International transfer
- 7. Storage in the browser
- 8. How long we keep it
- 9. Security
- 10. Your rights
- 11. Minors
- 12. Changes to this policy
- 13. Contact and data protection officer
1. Who is responsible for your data
Financial Control, available at fincontrol.digital, is run by Angelo Pelisson (CPF 072.917.819-65), who acts as the controller of the personal data processed in the service, under Brazilian Law No. 13,709/2018 (the General Personal Data Protection Law, “LGPD”).
This policy applies to the website, the web app (/app) and the mobile versions of the app. It is part of the Terms of Use.
2. What data we process
Account data
- Name and e-mail given at sign-up.
- Password, stored only as a cryptographic hash (not even we can read it).
- Language, currency and country chosen in the preferences.
- Account creation date, e-mail confirmation, and the date and version in which you accepted these terms.
Financial data you enter
Categories, fixed expenses, installment purchases, transactions, income, budgets, accounts and cards (only name, type, bank and color; never a card number or password) and goals. This data is typed in by you; the app does not collect it from banks or other sources.
Technical data
- IP address, date and time of requests and pages visited, logged by the hosting infrastructure and used for security (for example, to limit login attempts).
- Messages you write to the AI assistant, while the conversation is open (see section 4).
We do not process sensitive personal data (art. 5, II, of the LGPD) and ask you not to include it in entry descriptions or messages to the assistant.
3. Why we use it and on what legal basis
| Purpose | Data | Legal basis (LGPD) |
|---|---|---|
| Create and maintain your account, authenticate access | Account | Performance of a contract (art. 7, V) |
| Show dashboards, reports, budgets and goals | Financial | Performance of a contract (art. 7, V) |
| Send service e-mails (account verification, security) | Name and e-mail | Performance of a contract (art. 7, V) |
| Generate AI summaries and answers, when you use those features | See section 4 | Performance of a contract (art. 7, V) |
| Prevent fraud and abuse, limit attempts, investigate incidents | Technical | Legitimate interest (art. 7, IX) |
| Keep acceptance records and meet legal obligations | Account and technical | Legal obligation (art. 7, II) and regular exercise of rights (art. 7, VI) |
We do not use your data for advertising, do not build profiles for third parties and do not make automated decisions that affect your rights.
4. Artificial intelligence
Two features use a language model hosted by Groq, Inc. (USA). They are only triggered when you use them.
- Report summary: the app computes the analysis on our server and sends the model only the already computed facts for the period (totals, changes, category and goal names). Your name, e-mail and individual entries are not sent.
- Assistant: the model receives the message you write and the previous messages in the same conversation, plus the app language. The assistant has no access to your entries. The conversation stays on screen only; we do not keep it on our servers and it disappears when you close or reload the page.
The content is sent only to generate the answer. AI answers may contain errors and are not financial, investment or tax advice.
5. Who we share it with
We do not sell or rent personal data. It is accessed only by the processors below, hired to make the service work and who process the data according to our instructions:
| Company | Role | Location |
|---|---|---|
| DigitalOcean, LLC | Hosting of the app and the database (PostgreSQL) | New York, USA |
| Groq, Inc. | AI model (section 4) | USA |
| Resend (Plus Five Five, Inc.) | Sending the service e-mails | USA |
| GoDaddy | Contact mailbox and backup e-mail sending | USA |
| GitHub, Inc. | Stores the daily database backups, encrypted before they leave our server (GitHub cannot read them), for 30 days | USA |
| Google Fonts and unpkg | Fonts and icons loaded by the browser (they receive your IP, not your account data) | USA |
We may also share data when required by law, by a court order or an order from a competent authority, or to defend rights in legal proceedings.
6. International transfer
Because the processors above are in the United States, your data is transferred outside Brazil. This transfer is necessary to provide the service you signed up for and follows art. 33 of the LGPD, with processors that adopt contractual and technical data protection safeguards.
7. Storage in the browser
We do not use advertising or analytics cookies. We use only what the service needs to work:
- Session cookie (
fc_refresh): keeps you signed in for up to 30 days. It is httpOnly (page scripts cannot read it), is only sent to the app’s sign-in routes and is replaced on every use; - Local storage (
localStorage): a copy of the basic account data (name, e-mail, language, currency) and your language and light/dark theme preferences; - Infrastructure technical cookie (
__cf_bm): set by the Cloudflare network, used by DigitalOcean, to tell people from bots. It lasts 30 minutes.
When you sign out, the session is ended on the server and the session cookie and account data are deleted from the browser. Changing your password ends the sessions on other devices.
8. How long we keep it
- Account and financial data: for as long as your account exists. When you delete the account, the data is erased from the main database immediately. We make one encrypted backup a day, which is deleted automatically after 30 days; so, within 30 days, your data also ceases to exist in the backups. Backups are only opened to restore the service after a failure or to test that restoring works.
- Unconfirmed accounts: the verification link is valid for 24 hours; accounts that are never confirmed may be removed.
- Technical logs: for as long as needed for security and, where applicable, for the 6-month period of art. 15 of the Brazilian Civil Rights Framework for the Internet (Law No. 12,965/2014).
- Record of acceptance of the terms: may be kept after the account is deleted, for as long as needed for the regular exercise of rights.
9. Security
We use an encrypted connection (HTTPS) for all traffic, passwords stored as a hash, data isolation by account (each entry can only be read by the account that created it), e-mail confirmation, limits on login and sign-up attempts, and encrypted daily backups. No system is completely immune to failures; if a security incident with relevant risk occurs, we will notify you and Brazil’s National Data Protection Authority (ANPD), as required by art. 48 of the LGPD.
10. Your rights
Under art. 18 of the LGPD, you may, at any time and free of charge:
- confirm whether we process your data and access it;
- correct incomplete, inaccurate or outdated data (name, language and currency can be changed in the app’s Preferences);
- ask for anonymization, blocking or deletion of unnecessary data or data processed in breach of the law;
- receive a copy of your data in a structured format (portability) — in the app, under Preferences › My data › Download my data (JSON file);
- delete your account and all your data — in the app, under Preferences › My data › Delete my account, immediately;
- know who we share your data with (section 5);
- withdraw consent, when processing is based on consent;
- file a complaint with the ANPD (gov.br/anpd).
For the other rights, or if you cannot access your account, write to [email protected] from the registered e-mail. We reply within 15 days. We may ask you to confirm your identity to protect your account.
11. Minors
Financial Control is intended for people over 18. We do not knowingly collect data from children and adolescents; if you know of such a case, tell us so the account can be removed.
12. Changes to this policy
We may update this policy to reflect changes in the service or the law. The version in effect is always on this page, with the date at the top. Relevant changes will be announced by e-mail or in the app before they take effect and, when necessary, we will ask for a new acceptance.
13. Contact and data protection officer
The officer in charge of personal data processing (art. 41 of the LGPD) can be reached by e-mail at [email protected].