Privacy policy

This is everything FinanClear keeps about you, what it keeps it for, who it shares it with, and how to ask for it to be deleted. It's written to be read in one sitting, with no lawyer next to you.

In force since 26 August 2026Version 1.0

The short version

Five things

Nothing is sold

Your data is not sold, not rented, not handed over for advertising and does not train any model. There are no advertisers, no third-party trackers and no profiling.

Your bank is never touched

FinanClear never asks for your online banking credentials and connects to no financial institution. What's inside is what you wrote, by hand or by importing a CSV.

The money is your household's

The amounts, the entries, the balances and the notes are seen by the people in your household and by nobody else. Whoever runs the platform cannot see a single figure from any household.

Only the clock is measured

The only thing recorded about your use is when you opened the app and how long you stayed. Not which screen you looked at, not where you came from, not what device you used.

Take it with you, or delete it

You download the copy of everything that's yours yourself, whenever you want, from Settings: CSV spreadsheets that open without the app. Deleting all of it is still asked by email, answered within thirty calendar days at most, and free.

01

Who answers for your data

FinanClear is a household finance app operated from Asunción, Paraguay, and available at financlear.com. For the purposes of Paraguay's Law 7593/2025 on the Protection of Personal Data, FinanClear is the controller of the data described in this document. For the purposes of the European Union's General Data Protection Regulation (Regulation EU 2016/679, the «GDPR»), it is the controller; for Brazil's Lei Geral de Proteção de Dados (Law 13.709/2018, the «LGPD»), likewise.

This document covers the app, the public home page, and everything recorded from either of them. It does not cover what you do elsewhere: if you share a screenshot of your figures over WhatsApp, that screenshot is no longer governed by this text.

For anything in this document — asking for a copy, asking for deletion, making a complaint, or simply asking a question — the address is hola@financlear.com. A person answers, not a form, and it's the same address for all three.

02

What is kept

Seven things, and no more. Each one says what it's for, on what legal basis it's kept, and for how long. Hanging off a rule under each one is what the app deliberately does NOT keep: the half of the document that usually goes missing.

Your account

Your name, your email address, the fingerprint of your password, the colour you appear in inside the household, whether notifications are on, and when you signed up.

Not keptThe password itself. What is kept is a one-way cryptographic fingerprint: neither whoever runs the platform nor anyone with access to the database can read your password.

What for
So you can sign in, so the app knows who you are, and so every entry is attributed to whoever recorded it.
Legal basis
Performance of the service you asked for when you created the account.
How long
For as long as your account exists. Ask to close it and it is deleted whole, and everything hanging off it goes with it.

The household

The household's name, its eight-character invite code, the currency and format it chose, its time zone, and when it was created.

What for
Grouping the people who share the same money, and showing amounts and dates the way they read in your country.
Legal basis
Performance of the service.
How long
For as long as the household exists. Delete the household and all of its contents go with it, in cascade.

What you record

Entries with their amount, date, category, note and the person they're attributed to; cash accounts and their balances; cards with their bank, limit and closing days; loans and their instalments; fixed expenses; transfers between accounts; and the name and detail of every file you imported.

Not keptCard numbers, bank account numbers, online banking credentials or any financial credential. The app has nowhere to put them and never asks: of a card it keeps the name you gave it and its limit, not its number.

What for
So the app can do what it does: add up the month, tell you what's left, warn you what's due, and show all the people in your household the same thing.
Legal basis
Performance of the service, over data you recorded yourself.
How long
Until you delete it. Entries are deleted one by one from the ledger, and a whole import is undone in one go.

When you use the app

One row per stay: when you opened it, when the last heartbeat arrived, how many seconds it lasted, and how many heartbeats came in.

Not keptWhich screen you looked at, what you tapped, where you came from, what device you used, or from what address. Those four columns are enough to know whether the app gets used, and not enough to reconstruct anybody's day.

What for
Knowing whether this gets used and how much — the only question the project needs to be able to answer about itself.
Legal basis
The legitimate interest in knowing whether the service works, using the smallest amount of data that answers it.
How long
For as long as your account exists. It goes with it, automatically.

Phones with notifications on

If you turn notifications on, one row per device: the address your browser's push service issued, the two keys each message is encrypted with, a label to tell devices apart, and when the last message was sent.

Not keptYour phone number, your device model or its location. That address is issued by your browser and serves to deliver a notification, not to identify you.

What for
Being able to let you know when someone else in the household records an expense, or when something falls due.
Legal basis
Your consent, given through the browser permission and withdrawable whenever you like.
How long
Until you turn notifications off, uninstall the app or change devices. Turning them off deletes the row.

Support actions

If you ever ask for help and your account has to be touched, what was done, who did it, whom it was done to, when, and the reason written out by hand are all recorded. You also get a notification on your phone.

Not keptAnything from inside your household. A support action reaches the door of the account and does not open it: there is no «view as you».

What for
So that no intervention on somebody else's account can be left without a trace or without an explanation.
Legal basis
The legitimate interest in traceability, and the duty to account for what is done with other people's data.
How long
Kept. It is the record that makes support auditable, and a record that deletes itself proves nothing.

Visits to the home page

For each visit to financlear.com: a salted hash of the address you came from, the approximate country and city, the route you asked for, the site you came from, the campaign parameter if there was one, whether it was a phone or a computer, and the string your browser announces.

Not keptYour IP address. It is never stored: what is stored is a truncated sha256(salt + address), which is enough to count distinct people and not enough to recover anybody's address.

What for
Counting how many people arrive, from where and by what route, to know whether the app is any use to anyone.
Legal basis
The legitimate interest in measuring your own site's audience, without identifying anyone and with a one-click way out.
How long
They don't expire on their own: they're the history that explains why one day had a hundred visits. Since they contain no address of yours, they can't be tied back to you.

None of this is topped up by a third party: the app buys no lists, cross-references your data with no other database, and infers nothing you didn't write.

03

What for, and on what basis

Every row in the table above carries its legal basis beside it, which is the short way of saying on what right it is kept. Three are used: performance of the service you asked for, your consent — for notifications — and legitimate interest, which appears in exactly two places, the usage clock and the visit count, both minimised until they stopped being able to identify anyone.

What there isn't: no automated decisions that affect you, no profiling, no credit scoring, no advertising, no sale or transfer of data to anyone, and nothing you record trains any artificial intelligence model. If any of that changed, this document would change first.

The consent you gave for notifications is withdrawn from Settings, in one tap, and withdrawing it leaves you out of nothing else.

  1. Law 7593/2025 on the Protection of Personal Data in the Republic of Paraguay, enacted on 27 November 2025. It sets out the legal bases — among them performance of a contract, consent and legitimate interest —, the principles of purpose, minimisation, accuracy, storage limitation and security, and the rights of access, rectification, erasure, objection and portability, with a response deadline of thirty calendar days. Its penalty regime and the National Data Protection Agency finish coming into force in November 2027; FinanClear was written to comply with it from now.
  2. The Constitution of the Republic of Paraguay, articles 33 — the right to privacy — and 135, which recognises habeas data: you may go to court for access to the data held about you and for it to be updated, corrected or destroyed.
  3. Regulation (EU) 2016/679, the GDPR, and its UK equivalent. It applies if you are in the European Economic Area or the United Kingdom, and from it come the article 6 bases, the article 13 and 14 duty to inform, and the article 15 to 22 rights.
  4. Brazil's Law 13.709/2018, the LGPD. It applies if you are in Brazil: its article 7 legal bases and article 18 rights are equivalent to the above, and the competent authority is the ANPD.
  5. For readers in California and other United States states with consumer privacy laws: FinanClear does not sell or share personal information, in any of the senses those laws give those two words, and never has.

04

Who it's shared with, and where it lives

Four, and only for what each row says. The first three don't receive your data to use on their own account: they process it on FinanClear's instructions, to provide the service each one provides and nothing else. The fourth is different, which is why it's set apart: it's your own Google Drive, it only exists if you connect it, and there FinanClear instructs nobody — it hands your copy to you.

Railway

What it does
Hosts the application and the database.
What it touches
Everything the app keeps, to the extent that it lives on a server and in a database that Railway operates.
Where
United States

ipwho.is and api.country.is

What it does
Tell the app which country a visit to the home page came from, when the edge hasn't said so already.
What it touches
That visit's IP address, on its own and with nothing beside it. No data from any account is ever sent to them.
Where
Outside Paraguay

Your browser's push service

What it does
Delivers notifications to the device. It belongs to whoever made your browser or your system: Google, Apple, Mozilla or Microsoft.
What it touches
The delivery address it issued itself, and the encrypted notification. The content travels encrypted with keys held only by your device and FinanClear.
Where
Depends on the browser

Your Google Drive, if you connect it

What it does
Keeps the backup you ask for, in your own Google account and in a folder the app creates. It isn't on by default: it doesn't exist until you connect it from Settings, and it stops when you disconnect it.
What it touches
The backup file, which holds everything in the household. Google receives it the way it receives any file of yours: it sits in YOUR account and under YOUR terms with Google, not under FinanClear's. The app asks for the smallest permission there is — it can only touch the files it creates itself — and for your email address, so it can show you which account it ended up connected to.
Where
Google, wherever your account lives

Since the app is hosted outside Paraguay, keeping your data is an international transfer. Law 7593/2025, the GDPR and the LGPD all allow it where there are adequate safeguards: here those safeguards are the contract with the provider, end-to-end encryption in transit, and the fact that no third party receives the data for purposes of its own. If the infrastructure ever moves, this document says so first.

Typefaces are served from the app's own domain, not from Google: opening the home page makes no request to any third-party server. There is no Google Analytics, no social network pixels, no heatmaps and no measurement script of any kind: visits are counted on the server while the page is being built, which is why the home page needs no cookie banner.

There can also be a demand from the law: if a court orders it, what the order says has to be handed over. In that case the minimum the order asks for is handed over and — unless the order itself forbids it — whoever it concerns is told.

05

How long it's kept

The general rule is in the table above, row by row, and fits in one line: what is yours lives as long as you want it to, and leaves with you.

When a household is deleted, everything hanging off it — entries, cash accounts, cards, debts, fixed expenses, transfers, categories, imports and usage stays — goes in the same operation, with no stray copies left behind. When a person is deleted, the same happens to what is theirs.

There is one exception, written in on purpose: a person who leaves the household is archived rather than deleted, so that the entries they recorded don't end up without an author and the household doesn't lose its history. If you ask for erasure of your personal data, your name and your email are deleted all the same and the entries are left with nobody assigned; the only way for them to disappear too is to delete the whole household, and that decision belongs to the household, not to the app.

The support action log is not deleted either: it is the trace that makes power over somebody else's account auditable. It keeps who, to whom, when and why — never what is inside the household.

06

Your rights, and how to use them

The same ones Law 7593/2025, the GDPR and the LGPD give you. Below, each one with what it actually takes to exercise it today: half is settled inside the app without asking anyone's permission, and the other half by email.

Access
Inside the app you see everything held about you, live and without asking. And if you also want a copy as a file, you download it yourself from Settings → Backup, without asking anyone.
Rectification
You fix it yourself: your name and email from My account, and any mis-recorded entry from the ledger.
Erasure
Entries are deleted one by one, and a whole import in one go. To delete your account or the entire household, write in and it's done.
Objection
Notifications are turned off in Settings. The home page visit count is turned off for your browser with the link at the end of this document.
Portability
Take your data in an open format: Settings → Backup downloads a ZIP with one CSV spreadsheet per thing, the same format the app imports from. If you prefer, the app can leave that same copy in your Google Drive.
Restriction
You can ask for processing to stop while it's being argued whether something is accurate or appropriate. For as long as that lasts, the data is kept and not used.
Withdrawing consent
What you gave with a permission you take back just as easily, and taking it back neither affects what was done while it stood nor leaves you out of the rest of the app.

All of this is free and answered within thirty calendar days of the request arriving, which is the deadline Law 7593/2025 sets. If a request is complicated and will take longer, you'll be told before the deadline runs out, not after. The only thing asked in return is being able to check it's you: writing from the email address you sign in with is normally enough.

If any of this isn't honoured, you can complain. In Paraguay, to the National Data Protection Agency created by Law 7593/2025 once it is up and running; until then, the route is the habeas data of article 135 of the Constitution, brought before the ordinary courts.

If you are in the European Union or the United Kingdom, to your country's supervisory authority. If you are in Brazil, to the Autoridade Nacional de Proteção de Dados. Going to them doesn't oblige you to write to us first, though it's almost always faster.

07

Cookies

Two, both strictly technical, none for measurement and none from third parties. That's why there is no banner: there is nothing to consent to, because nothing that needs consent is left behind.

financlear_session

What for
Keeps you inside the app from one visit to the next. It is signed, it holds no data about you beyond your identifier, and it stops being valid on its own when you change your password.
How long
180 days

financlear_noan

What for
The one you asked for: it tells the server this browser doesn't count in the visit figures. It is the opposite of a measurement cookie.
How long
One year

The app installed on your phone also keeps a few things on your side so it can open — its own code and its icons — and that goes when you uninstall it. To stop this browser counting in the visit figures, tap here once.

08

How it's looked after

Everything travels encrypted: the app is served over HTTPS and there isn't one screen that opens without it. Passwords are stored as a one-way cryptographic fingerprint, so neither the team nor anyone with database access can read them. The session is signed with a server key and expires on its own; changing your password immediately invalidates every session opened with the old one, on every device.

Every screen that shows money comes in through the same door, which first checks which household you belong to and only then queries. There is no way to ask for another household's entries by changing a number in the address: the query comes out already scoped to your household. Sign-in attempts, and attempts to reset somebody else's password, are rate-limited so they can't be tried in series.

What can't be promised, written down too: the data is not end-to-end encrypted, so technically it exists in the clear in the database the hosting provider operates. No system is unbreakable. If there is ever a breach that could affect you, whoever needs to know and you will be told within seventy-two hours of it becoming known — the deadline set by Law 7593/2025 and by the GDPR.

And one warning that isn't technical: the household is a space of trust and it is designed as one. Inside there is no hierarchy — anyone in the household sees, edits and deletes exactly what you do — and, using their own password, any of them can reset another household member's. Only add people you'd share a wallet with.

09

Children and sensitive data

FinanClear is not aimed at minors and is not designed for a minor to open an account. If you are under eighteen, create your account only with the permission of a parent or guardian. If we learn of a minor's account opened without that permission, it is deleted.

A household may name the children of the house — the school fee, the club membership — and that's fine: it's the name of an expense. Law 7593/2025 protects children's and adolescents' data with particular severity, so the app asks for what a prudent notebook would ask for: in the notes, put what's needed to understand the expense and nothing more.

The same goes for sensitive data. An entry's note is a free-text field and can end up saying things the law treats separately: a medical appointment, a medicine, a donation to a church, a party membership fee. The app doesn't ask for them, doesn't look for them and doesn't use them for anything; but if you write them there, they are stored like the rest of the text and your household sees them. The advice is simple: write «pharmacy», not the diagnosis.

10

The admin panel: what it sees and what it doesn't

The platform has an admin panel, and what it can see is limited in writing and in code. It sees how many households there are, how many people, when each was created, when the app was opened and for how long it was used, and how many times something was recorded.

It does not see a single amount. Not an entry, not a balance, not a card limit, not a debt balance, not a note, not a category, not the name of an account or a bank, from any household. Entries are counted, never read. Nor is there a «view as you»: support reaches the door of the account and does not go in.

That limit is not a loose promise: it is written into the code, at the head of the module that produces the metrics, with the list of what it may read and the list of what it may not. One extra query there is not a better metric — it is this policy broken.

And when support does have to touch something — reset a password, grant or remove access — it is logged with its reason and a notification goes to the affected person's phone. Power without a trace cannot be promised in any privacy policy, so here there isn't any.

11

The home page: counted, not tracked

Visits to financlear.com are counted on the server, while the page is being built. There is no line of measurement JavaScript, so there is no extra request from your phone, nothing for a blocker to cut, and no cookie left behind to count you.

Of your IP address a salted hash is kept and never the address itself: enough to know that two visits came from the same person, not enough to know who that person is or where they came from. The approximate country and city come from it, and for that — and only that — the address is asked of one of the two providers in the table above, at that moment, without being stored.

What's done with it is counting: how many people arrived, from which countries, by what route and on what device. No profile is built, nobody is followed across sites, and there is nothing to sell.

If you'd still rather not be counted, turn the count off in this browser. A cookie stays behind saying exactly that, and you can turn it back on whenever you like.

12

Beta, changes and effective date

FinanClear is free while the beta lasts, and the beta is under construction: things keep being added and some screens will change. That changes nothing this document says, but it's worth saying: it is young software and, although there are backups, FinanClear shouldn't be the only place where a figure you can't afford to lose exists.

When what the app keeps changes, this text changes first and the code second, never the other way round. If the change is substantive — a new piece of data, a new purpose, a new third party — it is announced in the app before it takes effect, and if your consent is needed, you'll be asked for it.

This document is in force from the date shown above. It was written in Spanish, and the Portuguese and English versions are translations so that it can be understood: if they ever say different things, the Spanish one governs.