← Back to Home
Legal

Privacy Policy

Effective date: June 6, 2026  ·  Last updated: July 11, 2026  ·  Version: 1.1

Plain-English Summary: FinCommand is a personal finance tool. Your personal financial data stays in your own browser and is only synced to your private account if you choose to sign in. Your data is never tracked, profiled, sold, or shared. It is not visible to other users, advertisers, or anyone else, and our team does not access, view, or analyze it. You own your data and can export or delete it at any time.

Table of Contents
  1. Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. Data Storage & Security
  5. Third-Party Services
  6. Google OAuth
  7. API Keys
  8. Cookies & Local Storage
  9. Data Retention
  10. Your Rights
  11. Children's Privacy
  12. Changes to This Policy
  13. Contact Us

1. Who We Are

FinCommand ("we", "us", "our") is a personal finance platform operated as a private business. Our service is accessible at fincommand.net. For questions about this policy, contact us at hello@fincommand.net.

We are based in Canada and comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws. Where our users are located in the European Economic Area, we also comply with the General Data Protection Regulation (GDPR). For users in California, we comply with the California Consumer Privacy Act (CCPA).

2. Data We Collect

2.1 Account Information

When you create an account, we collect:

If you sign in with Google, we receive your email address and name from Google. We do not receive your Google password or phone number.

2.2 Financial Data You Enter

FinCommand processes personal financial data that you voluntarily enter, including:

This data is stored locally in your browser by default and only synced to your private account if you sign in. It is never tracked, viewed by our team, analyzed, sold, or shared with third parties, and it is not visible to any other user.

2.3 Usage Data

We collect a limited amount of anonymized usage data to keep the service working and understand which features are used. This data is never linked to the financial figures you enter:

We do not use session recording, heatmaps, or invasive analytics tools, and we never track your personal financial data.

2.4 Imported Bank Statements

When you use the Import Statement feature, you upload CSV or PDF files from your bank or credit card. These files are processed locally in your browser — the raw file content is never transmitted to our servers. Only the parsed transaction data (date, description, amount, category) is stored in your browser's localStorage and optionally synced to your account.

2.5 AI Advisor Conversations

If you use the AI Advisor feature, the messages you send are passed to a third-party AI provider through FinCommand's secure server-side proxy. Your messages are never sent directly from your browser to the provider — they pass through FinCommand's infrastructure first, where your subscription is validated before the request is forwarded. Conversations are stored only in your browser. Please do not include sensitive personal information (such as your SIN, account numbers, or passwords) in AI conversations.

3. How We Use Your Data

We use your data solely to provide and improve the FinCommand service:

PurposeData UsedLegal Basis
Providing the serviceAccount info, financial data you enterContract performance
Account authenticationEmail, password hash, OAuth tokensContract performance
Cloud sync across devicesFinancial data (encrypted in transit)Consent (opt-in feature)
Sending account emailsEmail addressContract performance
Product improvementAnonymized usage patternsLegitimate interest
Security & fraud preventionIP address, session dataLegitimate interest
Legal complianceAs required by lawLegal obligation

We do not use your data for advertising, profiling, or any purpose not listed above. We do not sell your data to third parties.

4. Data Storage & Security

4.1 Local Storage (Primary)

By default, all your financial data is stored in your browser's localStorage — a private, sandboxed storage area on your own device. This data does not leave your device unless you sign in and choose to sync it, or you export a backup file. When you sign out, FinCommand wipes all of your personal financial data from the browser, so the next person to use the device cannot see it. A returning user's data is restored from their own private account on the next sign-in.

4.2 Cloud Storage (Optional)

When you are signed into your FinCommand account, your financial data is synced to our cloud database provider so you can access it across devices. Your data is:

4.3 Security Measures

We implement the following security measures:

No method of electronic transmission or storage is 100% secure. While we take reasonable precautions, we cannot guarantee absolute security.

5. Third-Party Services

To operate FinCommand, we rely on a small number of trusted third-party providers for infrastructure and functionality. Each handles only the minimum information needed to perform its function, under its own privacy policy. These providers cover categories such as:

Your personal financial data is only ever shared with our authentication and cloud database provider, and only when you sign in and sync. Market data providers receive only the ticker symbols you look up — never your balances or personal information. The AI provider receives only the messages you choose to send to the AI Advisor. Your data is never sold, and never shared for advertising, profiling, or any other purpose.

A full list of the sub-processors we use is available on request — contact us at hello@fincommand.net.

6. Google OAuth (Sign in with Google)

If you choose to sign in with Google, you will be redirected to Google's authentication page. We receive the following information from Google after successful authentication:

We do not receive your Google password, phone number, contacts, calendar, or any other Google account data. The information received from Google is used solely to create and authenticate your FinCommand account.

By signing in with Google, you also agree to Google's Terms of Service and Privacy Policy. You can revoke FinCommand's access to your Google account at any time through your Google Account permissions settings.

FinCommand's use of Google user data is limited to the practices described in this privacy policy and complies with the Google API Services User Data Policy, including the Limited Use requirements.

7. API Keys & Service Credentials

FinCommand-Managed Credentials (Server-Side)

The credentials used to access the third-party services that power features like real-time market data and the AI Advisor belong to FinCommand and are stored securely as server-side environment secrets. They are never exposed to your browser, and you never need to provide your own.

Optional User-Provided Keys

Some optional features let you provide your own API key for enhanced functionality. If you choose to do so:

You can delete any stored keys at any time from the Settings section of the app.

8. Cookies & Local Storage

FinCommand uses browser localStorage (not traditional cookies) to store your data and preferences. localStorage is a standard browser feature that stores data on your device only — it is not transmitted with every request like cookies are.

We use the following types of browser storage:

TypePurposeCan You Delete It?
localStorage (financial data)Stores your budget, net worth, stock, and retirement data locallyYes — via browser settings, the Export & Clear option in the app, or by signing out (which wipes all financial data from the browser)
localStorage (auth tokens)Stores your login session tokens so you stay signed inYes — signing out clears these automatically
localStorage (preferences)Stores your theme, UI settings, and module preferencesYes — via browser settings
Infrastructure cookiesSecurity and performance (set by our hosting provider)Yes — via browser settings

We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies.

9. Data Retention

Local data: Financial data stored in your browser's localStorage persists until you clear your browser data, delete it from within the app, or sign out — signing out wipes all personal financial data from the browser. It is entirely under your control.

Cloud data: Financial data synced to your account is retained for as long as your account is active. If you delete your account, all associated cloud data is permanently deleted within 30 days.

Account data: Your email address and account information are retained for as long as your account is active. Upon account deletion, your personal information is removed from our systems within 30 days, except where retention is required by law.

Usage logs: Session logs (open timestamps) are retained for up to 12 months for product improvement purposes, then deleted.

Backup files: If you export a backup file, that file is downloaded entirely to your device. We do not retain a copy.

10. Your Rights

You have the following rights regarding your personal data:

Access & Portability

You can export all your financial data at any time using the Export All Data feature in the Backup section. This downloads a complete JSON file of everything stored in your account.

Correction

You can edit or correct any data you have entered directly within the app at any time.

Deletion

You can delete your account and all associated data by contacting us at hello@fincommand.net. We will process deletion requests within 30 days. You can also clear your local browser data at any time through your browser settings.

Withdrawal of Consent

You can sign out at any time, which stops cloud sync. You can revoke Google OAuth access through your Google Account settings at any time without affecting your FinCommand account.

GDPR Rights (EEA Users)

If you are located in the European Economic Area, you have additional rights under GDPR including the right to object to processing, the right to restriction, and the right to lodge a complaint with a supervisory authority. Contact us at hello@fincommand.net to exercise these rights.

CCPA Rights (California Users)

California residents have the right to know what personal information is collected, the right to delete personal information, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at hello@fincommand.net.

PIPEDA Rights (Canadian Users)

Canadian users have the right to access their personal information and to challenge its accuracy. You may contact our privacy officer at hello@fincommand.net with any privacy-related inquiries or complaints.

11. Children's Privacy

FinCommand is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at hello@fincommand.net and we will promptly delete the information.

Users between 13 and 18 should use FinCommand only with parental or guardian consent.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

Your continued use of FinCommand after changes take effect constitutes acceptance of the updated policy. If you disagree with the changes, you may delete your account before they take effect.

Previous versions of this policy are available upon request by contacting hello@fincommand.net.

13. Contact Us

Privacy Questions & Requests

If you have any questions about this Privacy Policy, wish to exercise your data rights, or have a privacy concern, please contact us:

Email: hello@fincommand.net

Website: fincommand.net

We aim to respond to all privacy-related inquiries within 5 business days.