FinWise← Back to home

Legal

Privacy Policy

FinWise keeps track of your expenses, income and budgets. That is financial data, so this page sets out exactly what we store, where it lives, who else sees it and how long we keep it.

Last updated: 2026-08-31

This policy describes what the application actually does today. It has not yet been reviewed by a lawyer, and the data protection impact assessment for the settlement features is still outstanding. For the features already available it is complete — please tell us about anything that looks wrong.

Data controller

The controller within the meaning of Art. 4(7) GDPR is:

Alex Fitterling
Wöhrder Kreuzgasse 8
90489 Nürnberg
Germany
info@sp33c.tech

What we process

We collect nothing speculatively. Everything below exists because you created an account and used the application.

  • Account: your email address and a pseudonymous user id (the Cognito "sub") for signing in. Access tokens last 5 minutes; id and refresh tokens last 24 hours.
  • Profile: if you fill it in — first and last name, postal address, country and date of birth, plus your tax and currency settings. These fields are optional and the application works without them.
  • Financial records: your expenses, income, fixed costs and budgets, each with an amount, date, category and your own description.
  • Receipts: photos and PDFs you upload, together with the file name, a checksum and the expense they belong to.
  • Server logs: the IP address, time, path and status code of each request, alongside your pseudonymous user id.
  • Cookies: one strictly necessary session cookie, plus your language and currency preferences.

No analytics, no tracking

FinWise runs no analytics, tracking or profiling services. There is no Google Analytics, there are no advertising pixels and there is no session recording. That is also why you see no cookie banner: the cookies we set are either strictly necessary or store a preference you chose yourself.

The fonts on these public pages are currently loaded from Google Fonts, which discloses your IP address to Google. We are working on serving them ourselves.

Legal bases

ProcessingLegal basis
Running your account, storing expenses and budgetsArt. 6(1)(b) GDPR — contract
Storing receipts and linking them to an expenseArt. 6(1)(b) GDPR — contract
AI reading of receipts and notesArt. 6(1)(b) GDPR — at your request
Server logs, operations and abuse preventionArt. 6(1)(f) GDPR — legitimate interest
Retaining completed settlementsArt. 6(1)(c) GDPR — legal obligation
Video recording during a settlementArt. 6(1)(a) GDPR — separate, withdrawable consent
Biometric face matchingArt. 9(2)(a) GDPR — explicit consent, with a non-biometric route always available

AI features and what they send

When you scan a receipt, have a note categorised or use any other AI feature, we send what that feature needs to OpenAI in the United States. The features do not work without that transfer.

Depending on the feature this includes: the full image or PDF of the receipt, your expense descriptions, budget figures, dietary preferences, a mood input and — for the voice feature — your microphone audio. The content is used to answer that one request and we do not store it beyond it.

A receipt can reveal more than it appears to: a pharmacy bill implies health data, a donation receipt implies religious or political belief. Art. 9 GDPR gives such data special protection. Only scan a receipt if you are comfortable with that transfer — you can always enter an expense by hand instead.

Recipients and sub-processors

We do not sell your data and we do not share it for advertising. We use the following providers:

ProviderPurposeLocation
Amazon Web ServicesSign-in, database, file storage, compute, logsFrankfurt (eu-central-1)
Amazon Web Services (CloudFront/WAF)Site delivery and attack protectionus-east-1, required by the service
OpenAIReceipt reading, categorisation, voice featureUnited States
Amazon SESSending system emailFrankfurt (eu-central-1)
Amazon ChimeVideo verification, only if you use itEU

Transfers outside the EU

The transfer to OpenAI and the operation of the CloudFront protection layer take place in the United States, on the basis of the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR. All other personal data is processed in Frankfurt.

Duplicate receipts

We store a checksum for every uploaded receipt so we can tell whether the same file has been recorded before — including when another account uploaded it. Only the checksum is compared: you never gain access to someone else's receipt, and nobody gains access to yours.

How long we keep things

There is currently no automatic deletion job for expenses, income and receipts — that data stays until you delete it or ask us to. This is deliberate: household data only becomes useful once it spans years.

DataPeriod
Expenses, income, budgets, receipts, profileuntil you ask for deletion or close your account
Completed settlements10 years (§ 147 AO, § 257 HGB)
Unsent settlement drafts30 days
Expired or cancelled settlements365 days
Previous versions of stored files90 days
Evidence preview images1 day
Server logs30 days

Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Where you have given consent, you can withdraw it at any time with effect for the future.

There is currently no button that deletes your account by itself. Write to info@sp33c.tech — we answer within 30 days and delete everything not subject to a statutory retention obligation. Anything we must keep, we will identify to you individually.

A completed settlement cannot be altered afterwards: it is the record of what both sides agreed, and rewriting it would destroy its value to both of you. A correction is appended instead, and both the original and the correction stay visible.

Automated decisions

In the settlement features, automated rules can block a request. When that happens we tell you the decision was automated, give you the reasons, and you can ask for a person to review it.

We do not disclose the underlying risk assessments themselves. Doing so would undermine the very abuse prevention they exist for; this is a restriction under Art. 23 GDPR. You still receive the outcome of any decision that affected you.

Settlements, video and identity checks

FinWise is gaining a feature that lets two people settle a shared expense between them. It is not switched on yet. If you use it, we additionally process: the settlement request with its amount and the expense behind it, the evidence you choose to share, a tamper-evident audit trail, the confirmations you give and — if you choose that route — a video verification.

Before the first request is made, we show both sides exactly what the other will see. Email address, phone number, postal address, bank details and all your other expenses are never disclosed.

The identity verification and payment providers have not been selected yet. Once they are, we will name them here before the feature goes live.

Right to complain to a supervisory authority

You may lodge a complaint with a data protection supervisory authority at any time under Art. 77 GDPR. Ours is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27, 91522 Ansbach, Germany
https://www.lda.bayern.de

The German version of this page is the legally authoritative one.

© 2026 FinWise · Alex Fitterling