Privacy Policy
Last updated: June 30, 2026
Last updated: June 30, 2026
FinPulse AI ("we", "us", "our") is committed to protecting your personal and financial information. This Privacy Policy explains what data we collect, why we collect it, which third-party services process it on our behalf, and what rights you have over it. By using FinPulse AI, you agree to the practices described here.
1. What We Collect
- Account data — name, email address, country, and password (stored as a secure hash by Supabase Auth).
- Financial data — transaction records, amounts, dates, merchants, categories, and account balances you import or sync. This data is stored exclusively in your personal account and is never shared or sold.
- Bank connection data — if you connect a bank account via Plaid, we store only a Plaid access token (an opaque reference). We never see, store, or transmit your bank username, password, or card numbers.
- Uploaded files — CSV and PDF bank statements you upload for parsing. These are processed server-side and immediately discarded after parsing; they are not stored permanently.
- Usage data — feature usage counts (e.g., number of Pulse AI messages per day) for enforcing free-tier limits. No behavioural tracking or advertising profiles are built.
- Payment data — when you subscribe, payment is handled entirely by Stripe or Paystack. We store only the resulting subscription ID and customer reference — never card numbers, bank account details, or CVV codes.
- Support communications — messages you send through our in-app support system.
- Legal consent records — the version of these Terms and Privacy Policy you accepted and the timestamp of acceptance.
2. How We Use Your Data
- To provide the core service — displaying your transactions, budgets, goals, and spending insights.
- To power the Pulse AI coach — your transaction history is sent to an AI provider to generate personalised coaching responses. See Section 4 for details.
- To categorise transactions — transaction descriptions are sent to an AI provider for automatic categorisation.
- To generate your weekly email digest — a summary of your spending is composed and delivered via Resend.
- To manage your subscription — subscription status changes are communicated with Stripe or Paystack via webhooks.
- To respond to support requests and comply with legal obligations.
3. Data Storage & Security
All your data is stored in Supabase (PostgreSQL), hosted on infrastructure provided by Supabase Inc. (United States). Supabase is SOC 2 Type II certified.
- Row-Level Security (RLS) is enforced on every database table — your data is cryptographically scoped to your account and inaccessible to other users or unauthenticated requests.
- All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Uploaded files are stored temporarily in Supabase Storage in a private, access-controlled bucket.
- Plaid access tokens are stored server-side only, in a table with no user-facing RLS — they cannot be read by the browser or by your own account queries.
- Admin credentials use scrypt password hashing and are never stored in plaintext.
4. Third-Party Services
We use the following third-party services to operate FinPulse AI. Each acts as a data processor under contract and may process some of your data as described.
4a. Infrastructure & Hosting
- Supabase (supabase.com) — database, authentication, and file storage. Your account data and financial records reside here. Privacy policy: supabase.com/privacy
- Vercel (vercel.com) — application hosting and serverless functions. Request logs may be retained briefly for debugging. Privacy policy: vercel.com/legal/privacy-policy
4b. AI & Machine Learning
- Anthropic (Claude) — anthropic.com/privacy
- Google (Gemini) — policies.google.com/privacy
- OpenAI (GPT) — openai.com/privacy
- DeepSeek — deepseek.com/privacy
Only transaction descriptions, amounts, dates, and categories are included in AI requests. Your name, email, bank credentials, and payment details are never sent to any AI provider.
4c. Payments & Billing
- Stripe (stripe.com) — processes card payments for users in the UK, US, Europe, and other international markets. Stripe is PCI DSS Level 1 certified. We store only your Stripe Customer ID and Subscription ID. Privacy policy: stripe.com/privacy
- Paystack (paystack.com) — processes card and Mobile Money payments for users in Ghana, Nigeria, Kenya, and other African markets. We store only your Paystack subscription code and email token reference. Privacy policy: paystack.com/privacy
Raw card numbers, bank account numbers, CVV codes, and Mobile Money PINs are never handled by FinPulse AI. They go directly to Stripe or Paystack via their secure hosted payment forms.
4d. Bank Account Linking
- Plaid (plaid.com) — powers bank account connection for Pro and Ultimate subscribers. Plaid handles your bank login credentials directly in their own secure interface — FinPulse never sees your banking username or password. We receive only a Plaid access token, which we use to fetch transaction data on your behalf. Privacy policy: plaid.com/legal/#privacy-policy
4e. Email
- Resend (resend.com) — sends transactional emails (weekly digest, password reset, legal update notices). Your email address is shared with Resend solely for delivery. Privacy policy: resend.com/legal/privacy-policy
5. Data Retention
- Your account and all associated financial data are retained for as long as your account is active.
- If you delete your account, all your data (transactions, budgets, goals, insights, coaching sessions, attachments) is permanently deleted within 30 days.
- Anonymised, aggregated usage statistics (with no personal identifiers) may be retained indefinitely for product improvement.
- Webhook event records (used to prevent duplicate billing events) are retained for 90 days then purged.
6. Your Rights
Depending on your country, you may have the following rights regarding your personal data:
- Access — request a copy of all data we hold about you.
- Correction — request we correct inaccurate data.
- Deletion — request we delete your account and all associated data.
- Portability — request your transaction data in a machine-readable format (CSV export is available in-app).
- Objection — object to any processing you believe is not justified.
To exercise any of these rights, email us at privacy@finpulseinc.com. We will respond within 30 days.
7. International Data Transfers
FinPulse serves users in Ghana, Nigeria, Kenya, the United Kingdom, the United States, and other countries. Your data may be processed by our third-party providers in the United States and other jurisdictions. Where required, we rely on standard contractual clauses or equivalent legal mechanisms for cross-border data transfers.
8. Children's Privacy
FinPulse is not directed at children under 18. We do not knowingly collect personal information from minors. If you believe a minor has created an account, please contact us and we will promptly delete it.
9. Changes to This Policy
We may update this Privacy Policy when we add new features or services. Material changes will be communicated in-app and by email, and we will ask for your renewed consent where required. The "Last updated" date at the top of this page reflects the most recent revision.
10. Contact
Questions or concerns about your privacy? Contact us at privacy@finpulseinc.com.