Legal
Privacy Policy
FinWise keeps track of your expenses, income and budgets. That is financial data, so this page sets out exactly what we store, where it lives, who else sees it and how long we keep it.
Last updated: 2026-08-31
This policy describes what the application actually does today. It has not yet been reviewed by a lawyer, and the data protection impact assessment for the settlement features is still outstanding. For the features already available it is complete — please tell us about anything that looks wrong.
Data controller
The controller within the meaning of Art. 4(7) GDPR is:
Alex FitterlingWöhrder Kreuzgasse 8
90489 Nürnberg
Germany
info@sp33c.tech
What we process
We collect nothing speculatively. Everything below exists because you created an account and used the application.
- Account: your email address and a pseudonymous user id (the Cognito "sub") for signing in. Access tokens last 5 minutes; id and refresh tokens last 24 hours.
- Profile: if you fill it in — first and last name, postal address, country and date of birth, plus your tax and currency settings. These fields are optional and the application works without them.
- Financial records: your expenses, income, fixed costs and budgets, each with an amount, date, category and your own description.
- Receipts: photos and PDFs you upload, together with the file name, a checksum and the expense they belong to.
- Server logs: the IP address, time, path and status code of each request, alongside your pseudonymous user id.
- Cookies: one strictly necessary session cookie, plus your language and currency preferences.
No analytics, no tracking
FinWise runs no analytics, tracking or profiling services. There is no Google Analytics, there are no advertising pixels and there is no session recording. That is also why you see no cookie banner: the cookies we set are either strictly necessary or store a preference you chose yourself.
The fonts on these public pages are currently loaded from Google Fonts, which discloses your IP address to Google. We are working on serving them ourselves.
Legal bases
| Processing | Legal basis |
|---|---|
| Running your account, storing expenses and budgets | Art. 6(1)(b) GDPR — contract |
| Storing receipts and linking them to an expense | Art. 6(1)(b) GDPR — contract |
| AI reading of receipts and notes | Art. 6(1)(b) GDPR — at your request |
| Server logs, operations and abuse prevention | Art. 6(1)(f) GDPR — legitimate interest |
| Retaining completed settlements | Art. 6(1)(c) GDPR — legal obligation |
| Video recording during a settlement | Art. 6(1)(a) GDPR — separate, withdrawable consent |
| Biometric face matching | Art. 9(2)(a) GDPR — explicit consent, with a non-biometric route always available |
AI features and what they send
When you scan a receipt, have a note categorised or use any other AI feature, we send what that feature needs to OpenAI in the United States. The features do not work without that transfer.
Depending on the feature this includes: the full image or PDF of the receipt, your expense descriptions, budget figures, dietary preferences, a mood input and — for the voice feature — your microphone audio. The content is used to answer that one request and we do not store it beyond it.
A receipt can reveal more than it appears to: a pharmacy bill implies health data, a donation receipt implies religious or political belief. Art. 9 GDPR gives such data special protection. Only scan a receipt if you are comfortable with that transfer — you can always enter an expense by hand instead.
Recipients and sub-processors
We do not sell your data and we do not share it for advertising. We use the following providers:
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Sign-in, database, file storage, compute, logs | Frankfurt (eu-central-1) |
| Amazon Web Services (CloudFront/WAF) | Site delivery and attack protection | us-east-1, required by the service |
| OpenAI | Receipt reading, categorisation, voice feature | United States |
| Amazon SES | Sending system email | Frankfurt (eu-central-1) |
| Amazon Chime | Video verification, only if you use it | EU |
Transfers outside the EU
The transfer to OpenAI and the operation of the CloudFront protection layer take place in the United States, on the basis of the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR. All other personal data is processed in Frankfurt.
Duplicate receipts
We store a checksum for every uploaded receipt so we can tell whether the same file has been recorded before — including when another account uploaded it. Only the checksum is compared: you never gain access to someone else's receipt, and nobody gains access to yours.
How long we keep things
There is currently no automatic deletion job for expenses, income and receipts — that data stays until you delete it or ask us to. This is deliberate: household data only becomes useful once it spans years.
| Data | Period |
|---|---|
| Expenses, income, budgets, receipts, profile | until you ask for deletion or close your account |
| Completed settlements | 10 years (§ 147 AO, § 257 HGB) |
| Unsent settlement drafts | 30 days |
| Expired or cancelled settlements | 365 days |
| Previous versions of stored files | 90 days |
| Evidence preview images | 1 day |
| Server logs | 30 days |
Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Where you have given consent, you can withdraw it at any time with effect for the future.
There is currently no button that deletes your account by itself. Write to info@sp33c.tech — we answer within 30 days and delete everything not subject to a statutory retention obligation. Anything we must keep, we will identify to you individually.
A completed settlement cannot be altered afterwards: it is the record of what both sides agreed, and rewriting it would destroy its value to both of you. A correction is appended instead, and both the original and the correction stay visible.
Automated decisions
In the settlement features, automated rules can block a request. When that happens we tell you the decision was automated, give you the reasons, and you can ask for a person to review it.
We do not disclose the underlying risk assessments themselves. Doing so would undermine the very abuse prevention they exist for; this is a restriction under Art. 23 GDPR. You still receive the outcome of any decision that affected you.
Settlements, video and identity checks
FinWise is gaining a feature that lets two people settle a shared expense between them. It is not switched on yet. If you use it, we additionally process: the settlement request with its amount and the expense behind it, the evidence you choose to share, a tamper-evident audit trail, the confirmations you give and — if you choose that route — a video verification.
Before the first request is made, we show both sides exactly what the other will see. Email address, phone number, postal address, bank details and all your other expenses are never disclosed.
The identity verification and payment providers have not been selected yet. Once they are, we will name them here before the feature goes live.
Right to complain to a supervisory authority
You may lodge a complaint with a data protection supervisory authority at any time under Art. 77 GDPR. Ours is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)Promenade 27, 91522 Ansbach, Germany
https://www.lda.bayern.de
The German version of this page is the legally authoritative one.
© 2026 FinWise · Alex Fitterling