Finch
FeaturesProductPrivacySupport
EN
EnglishEspañolPortuguês (Brasil)日本語한국어Bahasa MelayuBahasa IndonesiaTürkçe简体中文繁體中文
Download
Back to Finch

Finch

Privacy Policy

How Finch handles local financial records, optional AI and backup features, purchases, diagnostics and website visits.

Effective August 11, 2026

This policy is available in multiple languages. If a translation differs from the English version, the English version controls to the extent permitted by law.

On this page
1. Who we are and what this policy covers2. Your local financial data3. Data processed when you choose connected features4. Why we process information5. Service providers and disclosure6. Retention, deletion and choices7. Security8. International transfers and your rights9. Children10. Website, contact and changes

1. Who we are and what this policy covers

Finch is developed and operated by CHAORAN KANG, an independent developer. This policy covers the Finch mobile application for iOS and Android, this website, and support communications. For privacy questions, contact kcr0976@gmail.com.

2. Your local financial data

Finch is local-first. Ledgers, accounts, transactions, balances, budgets, reports, stock records, subscriptions, savings goals, loans, installments, item records, notes and locally selected images are primarily stored in an encrypted SQLCipher database and app storage on your device. Using the core bookkeeping features does not by itself upload that database to the developer.

  • You can edit or delete records in the app and export your data.
  • Clearing app data or uninstalling generally removes local Finch data, subject to operating-system or device backups.
  • You are responsible for keeping any export or backup you need before deletion or device replacement.

3. Data processed when you choose connected features

  • AI bookkeeping and imports: text, audio, selected images, spreadsheets and relevant account/category context are sent to the OpenAI-compatible provider selected by Finch's active configuration. The provider may be Finch's configured NO.1 service or OpenAI. Review results before saving and avoid including unnecessary sensitive information.
  • Camera, photos, microphone and speech: Finch accesses only the content you choose or capture for the requested feature. Biometric authentication is performed by the operating system; Finch does not receive your fingerprint or face template.
  • Google Drive or WebDAV backup: when enabled, the database and any image folders you choose are transferred to your own destination. Google sign-in information and authorization tokens are processed for Drive access. WebDAV server details and credentials are stored on your device.
  • Market and exchange data: currency codes, market identifiers or stock symbols may be sent to exchange-rate and end-of-day market-data services. Your full financial database is not sent for these requests.
  • Online icon library: Supabase may deliver public icon metadata and image assets. Core financial records are not uploaded to the icon library.
  • Purchases: Apple, Google and RevenueCat process purchase history, receipts or purchase tokens, an app-user identifier, device/app information and entitlement status.
  • App integrity, configuration and analytics: Firebase App Check, Remote Config, Authentication and Analytics may process installation identifiers, device/app information, IP-derived approximate location, app interactions and diagnostic or integrity signals.

4. Why we process information

  • To provide features you request and perform our agreement with you.
  • To protect the app, validate purchases, prevent abuse and maintain reliable operation.
  • To understand aggregate product use and improve Finch where permitted.
  • To answer support requests and comply with legal obligations.
  • Where consent is required, to process permission-gated content or optional features after you choose them. You can withdraw permission in system settings, though the related feature may stop working.

5. Service providers and disclosure

Finch does not sell personal information and does not use your financial records for cross-context behavioral advertising. Information is disclosed only as needed to the service you choose, to infrastructure and purchase providers, when you ask us to, or when legally required. Providers process data under their own terms and may operate in other countries.

  • Google / Firebase: app integrity, remote configuration, optional Google sign-in and Drive, authentication and analytics.
  • RevenueCat, Apple and Google Play: purchases, subscription status and entitlement delivery.
  • OpenAI-compatible providers: optional AI text, voice, image and spreadsheet processing.
  • Supabase: public icon delivery and supporting infrastructure.
  • Your chosen WebDAV host: optional backup storage.
  • Tsanghi and public currency-data services: stock and exchange-rate queries.
  • Vercel: website hosting, security and request logs.

6. Retention, deletion and choices

Finch does not host your financial database or cloud backups. Local data remains until you delete it, clear app storage or uninstall. User-controlled cloud backups remain until you remove them from your Google Drive or WebDAV. Support emails are kept only as reasonably needed to resolve the request. Provider-side identifiers, purchase records, analytics and AI content follow the provider's settings, retention rules and legal obligations.

  • Delete local records in Finch, clear app storage or uninstall the app.
  • Sign out of Google Drive, revoke Finch access in your Google account and delete your Finch backup files there.
  • Disable WebDAV backup and delete the remote Finch folder from your own server.
  • Revoke camera, photo, microphone, speech or biometric permissions in device settings.
  • Contact the relevant provider to exercise rights over provider-controlled identifiers, purchase records or AI content.

7. Security

Finch uses an encrypted local database, transport encryption where supported, platform permission controls, App Check and optional device authentication. No system is completely secure. Protect your device, backup credentials, AI keys and exported files, and do not send secrets in support messages.

8. International transfers and your rights

Service providers may process information outside your country, including in the United States and other locations where they operate. Depending on your location, you may have rights to access, correct, delete, restrict or object to processing, obtain a portable copy, withdraw consent, and complain to a data protection authority. California residents may request applicable access, correction and deletion rights; Finch does not sell or share personal information for cross-context behavioral advertising. Contact us to exercise a right. We may need limited information to verify the request.

9. Children

Finch is a general-audience personal finance tool and does not set a fixed minimum age beyond applicable law and the requirements of the app store or optional connected service you use. Core financial records stay on the device and are not collected by the developer merely because someone uses the app. A parent or guardian should supervise a minor's use of optional connected features and may contact us if they believe a child provided personal information through such a feature or a support request.

10. Website, contact and changes

This website does not run advertising trackers or product analytics and does not intentionally set marketing cookies. Vercel may process IP addresses, request metadata and security logs to deliver and protect the site. If you email us, we process your address, message and attachments to reply. We may update this policy as Finch changes; the effective date above identifies the current version.

Contact Finchkcr0976@gmail.com
Third-party privacy policiesGoogle / FirebaseRevenueCatSupabaseOpenAIAppleGoogleVercel
Finch

Thoughtful personal finance, without the clutter.

Privacy PolicyTerms of UseSupport
kcr0976@gmail.com© 2026 CHAORAN KANG. All rights reserved.