Plain-English Summary: FinCommand is a personal finance tool. Your personal financial data stays in your own browser and is only synced to your private account if you choose to sign in. Your data is never tracked, profiled, sold, or shared. It is not visible to other users, advertisers, or anyone else, and our team does not access, view, or analyze it. You own your data and can export or delete it at any time.
FinCommand ("we", "us", "our") is a personal finance platform operated as a private business. Our service is accessible at fincommand.net. For questions about this policy, contact us at hello@fincommand.net.
We are based in Canada and comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws. Where our users are located in the European Economic Area, we also comply with the General Data Protection Regulation (GDPR). For users in California, we comply with the California Consumer Privacy Act (CCPA).
When you create an account, we collect:
If you sign in with Google, we receive your email address and name from Google. We do not receive your Google password or phone number.
FinCommand processes personal financial data that you voluntarily enter, including:
This data is stored locally in your browser by default and only synced to your private account if you sign in. It is never tracked, viewed by our team, analyzed, sold, or shared with third parties, and it is not visible to any other user.
We collect a limited amount of anonymized usage data to keep the service working and understand which features are used. This data is never linked to the financial figures you enter:
We do not use session recording, heatmaps, or invasive analytics tools, and we never track your personal financial data.
When you use the Import Statement feature, you upload CSV or PDF files from your bank or credit card. These files are processed locally in your browser — the raw file content is never transmitted to our servers. Only the parsed transaction data (date, description, amount, category) is stored in your browser's localStorage and optionally synced to your account.
If you use the AI Advisor feature, the messages you send are passed to a third-party AI provider through FinCommand's secure server-side proxy. Your messages are never sent directly from your browser to the provider — they pass through FinCommand's infrastructure first, where your subscription is validated before the request is forwarded. Conversations are stored only in your browser. Please do not include sensitive personal information (such as your SIN, account numbers, or passwords) in AI conversations.
We use your data solely to provide and improve the FinCommand service:
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Providing the service | Account info, financial data you enter | Contract performance |
| Account authentication | Email, password hash, OAuth tokens | Contract performance |
| Cloud sync across devices | Financial data (encrypted in transit) | Consent (opt-in feature) |
| Sending account emails | Email address | Contract performance |
| Product improvement | Anonymized usage patterns | Legitimate interest |
| Security & fraud prevention | IP address, session data | Legitimate interest |
| Legal compliance | As required by law | Legal obligation |
We do not use your data for advertising, profiling, or any purpose not listed above. We do not sell your data to third parties.
By default, all your financial data is stored in your browser's localStorage — a private, sandboxed storage area on your own device. This data does not leave your device unless you sign in and choose to sync it, or you export a backup file. When you sign out, FinCommand wipes all of your personal financial data from the browser, so the next person to use the device cannot see it. A returning user's data is restored from their own private account on the next sign-in.
When you are signed into your FinCommand account, your financial data is synced to our cloud database provider so you can access it across devices. Your data is:
We implement the following security measures:
No method of electronic transmission or storage is 100% secure. While we take reasonable precautions, we cannot guarantee absolute security.
To operate FinCommand, we rely on a small number of trusted third-party providers for infrastructure and functionality. Each handles only the minimum information needed to perform its function, under its own privacy policy. These providers cover categories such as:
Your personal financial data is only ever shared with our authentication and cloud database provider, and only when you sign in and sync. Market data providers receive only the ticker symbols you look up — never your balances or personal information. The AI provider receives only the messages you choose to send to the AI Advisor. Your data is never sold, and never shared for advertising, profiling, or any other purpose.
A full list of the sub-processors we use is available on request — contact us at hello@fincommand.net.
If you choose to sign in with Google, you will be redirected to Google's authentication page. We receive the following information from Google after successful authentication:
We do not receive your Google password, phone number, contacts, calendar, or any other Google account data. The information received from Google is used solely to create and authenticate your FinCommand account.
By signing in with Google, you also agree to Google's Terms of Service and Privacy Policy. You can revoke FinCommand's access to your Google account at any time through your Google Account permissions settings.
FinCommand's use of Google user data is limited to the practices described in this privacy policy and complies with the Google API Services User Data Policy, including the Limited Use requirements.
The credentials used to access the third-party services that power features like real-time market data and the AI Advisor belong to FinCommand and are stored securely as server-side environment secrets. They are never exposed to your browser, and you never need to provide your own.
Some optional features let you provide your own API key for enhanced functionality. If you choose to do so:
You can delete any stored keys at any time from the Settings section of the app.
FinCommand uses browser localStorage (not traditional cookies) to store your data and preferences. localStorage is a standard browser feature that stores data on your device only — it is not transmitted with every request like cookies are.
We use the following types of browser storage:
| Type | Purpose | Can You Delete It? |
|---|---|---|
| localStorage (financial data) | Stores your budget, net worth, stock, and retirement data locally | Yes — via browser settings, the Export & Clear option in the app, or by signing out (which wipes all financial data from the browser) |
| localStorage (auth tokens) | Stores your login session tokens so you stay signed in | Yes — signing out clears these automatically |
| localStorage (preferences) | Stores your theme, UI settings, and module preferences | Yes — via browser settings |
| Infrastructure cookies | Security and performance (set by our hosting provider) | Yes — via browser settings |
We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies.
Local data: Financial data stored in your browser's localStorage persists until you clear your browser data, delete it from within the app, or sign out — signing out wipes all personal financial data from the browser. It is entirely under your control.
Cloud data: Financial data synced to your account is retained for as long as your account is active. If you delete your account, all associated cloud data is permanently deleted within 30 days.
Account data: Your email address and account information are retained for as long as your account is active. Upon account deletion, your personal information is removed from our systems within 30 days, except where retention is required by law.
Usage logs: Session logs (open timestamps) are retained for up to 12 months for product improvement purposes, then deleted.
Backup files: If you export a backup file, that file is downloaded entirely to your device. We do not retain a copy.
You have the following rights regarding your personal data:
You can export all your financial data at any time using the Export All Data feature in the Backup section. This downloads a complete JSON file of everything stored in your account.
You can edit or correct any data you have entered directly within the app at any time.
You can delete your account and all associated data by contacting us at hello@fincommand.net. We will process deletion requests within 30 days. You can also clear your local browser data at any time through your browser settings.
You can sign out at any time, which stops cloud sync. You can revoke Google OAuth access through your Google Account settings at any time without affecting your FinCommand account.
If you are located in the European Economic Area, you have additional rights under GDPR including the right to object to processing, the right to restriction, and the right to lodge a complaint with a supervisory authority. Contact us at hello@fincommand.net to exercise these rights.
California residents have the right to know what personal information is collected, the right to delete personal information, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at hello@fincommand.net.
Canadian users have the right to access their personal information and to challenge its accuracy. You may contact our privacy officer at hello@fincommand.net with any privacy-related inquiries or complaints.
FinCommand is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at hello@fincommand.net and we will promptly delete the information.
Users between 13 and 18 should use FinCommand only with parental or guardian consent.
We may update this Privacy Policy from time to time. When we make material changes, we will:
Your continued use of FinCommand after changes take effect constitutes acceptance of the updated policy. If you disagree with the changes, you may delete your account before they take effect.
Previous versions of this policy are available upon request by contacting hello@fincommand.net.
If you have any questions about this Privacy Policy, wish to exercise your data rights, or have a privacy concern, please contact us:
Email: hello@fincommand.net
Website: fincommand.net
We aim to respond to all privacy-related inquiries within 5 business days.