Finitum respects your privacy.
Finitum does not access your email account or your bank. It only processes the emails you explicitly forward to your personal Finitum address, for the sole purpose of extracting financial transaction information from bank notification emails. You control what is forwarded and can stop at any time by removing the forwarding rule.
No raw email content is permanently stored. Only extracted transaction data (amount, merchant, date, category) is saved to provide financial analytics.
Google sign-in is optional and used for authentication only. Finitum does not request access to Gmail or to any email content.
Data Retention and Deletion
Forwarded emails are processed in real time and are not stored beyond the immediate processing session. Only the derived transaction data (amount, merchant, date, category) is retained in your account for as long as your account remains active.
You may request deletion of all your data at any time by contacting [email protected]. Upon receiving a deletion request, all stored transaction data and associated account information will be permanently deleted within 30 days. You may also delete your account directly within the application, which will immediately remove all stored data.
Tokens granted by Google for sign-in are stored securely and are revoked and deleted when you disconnect your Google account or delete your Finitum account.
Finitum does not sell, share, or use user data for advertising purposes.
Authentication is handled securely using JWT tokens, with optional Google OAuth2 sign-in. Sensitive credentials and tokens are stored securely.
Finitum is open-source software (MIT license); you can inspect exactly how your data is handled, or self-host your own instance, at github.com/richardhapb/finitum.
If you have questions about this policy, contact: [email protected]