Legal
Privacy Policy
Last updated
Draft. This document is being finalised and is not yet in force. Sections marked “Placeholder” will be replaced with the final, reviewed text.
Your financial records are personal. This policy explains what FinMan collects, why, how it is protected, who it is shared with, and the choices and rights you have.
01Who we are
FinMan is operated by Aprillium, [Registered address]. For privacy questions or requests, email support@aprillium.com.
Placeholder: final legal text to follow
02Financial and personal data we collect
- Account details: your name, email address and password (stored only as a one-way hash), and optionally a username, picture, phone number, city and short bio.
- Financial records you add or import: accounts and balances, transactions, categories, bills and subscriptions, budgets, goals, investments, assets, loans, and insurance policies (we keep only the last four digits of a policy number).
- Files you upload: bank statements for import, and receipts or documents you attach.
- Location, only when you add it: a place or coordinates on a payment, or your device location when you press “Use my location”.
- Lending profile, if you create one: your handle, display name, city and repayment score are visible to other FinMan users; loan amounts are visible only to the people in that loan.
- Technical data: sign-in sessions, and your IP address for security and to limit repeated sign-in attempts.
- Page speed, only if you allow analytics: anonymous load-time measurements (Core Web Vitals) with the page pattern and device type, kept for 30 days.
Placeholder: final legal text to follow
03How we use it
To run FinMan for you: show your records and reports, send the reminders and emails you ask for, keep your account secure, and support you. We don't use your financial data for advertising, and we don't sell it.
Placeholder: final legal text to follow
04Encryption and security
- Connections to FinMan are encrypted with HTTPS (TLS).
- Passwords are hashed with Argon2id; we never store them in readable form.
- Sign-in tokens live in secure, httpOnly cookies that page scripts cannot read.
- Two-step sign-in secrets are stored encrypted, with single-use recovery codes.
- Each workspace is isolated, with owner, admin, member and viewer roles.
- Uploaded files are checked by their contents and served safely; repeated sign-in attempts are limited.
- Data is backed up daily, and backups are kept for a limited time.
Placeholder: final legal text to follow
06How long we keep data
We keep your records while your account is open. Sign-in sessions expire after 30 days, and daily backups are deleted after 14 days.
Placeholder: final legal text to follow
07Your rights (GDPR, CCPA and others)
You can see and correct your details on your profile, and export your transactions at any time. To ask for a copy of all your data, or for your account and data to be deleted, email support@aprillium.com.
Placeholder: final legal text to follow
08International transfers
Placeholder: final legal text to follow
09Children
Placeholder: final legal text to follow
10Changes and contact
If this policy changes, we'll update the date at the top and, for significant changes, tell you in the app or by email. Cookies are covered in the Cookie Policy. Questions: support@aprillium.com.