Authoritative Privacy Standard

Privacy Policy

Effective Date: September 2026 • Product of OSM Digital

1. Core Architectural Privacy Commitments

FinBrain is designed on the principle that your financial records belong exclusively to you. Unlike traditional financial aggregation services that monetize transaction telemetry, sell market trends to advertisers, or train third-party foundational AI models on raw banking feeds, FinBrain provides an isolated computing environment.

  • No Global AI Model Training: Your raw bank descriptions, account names, transaction amounts, and uploaded statement contents are never used to train public or shared machine learning models.
  • Isolated Tenant Boundaries: PostgreSQL Row-Level Security (RLS) ensures that every financial record is bound deterministically to your authenticated user ID. Cross-tenant data leakage is prevented at the database engine level.
  • Zero-Proxy Binary Pipeline: Document files uploaded via private Cloudflare R2 presigned URLs transfer directly from your browser to encrypted storage, bypassing intermediate application server memory.

2. Categories of Information We Process

We process only the minimum necessary data to construct and maintain your deterministic financial ledger:

Account & Authentication

Email address, hashed authentication credentials, and optional OAuth identity tokens (managed securely by Supabase Auth).

Uploaded Financial Documents

User-provided bank statements, CSV spreadsheets, and statement metadata for parsing and categorization.

Normalized Ledger Records

Transaction dates, integer cent amounts, sanitized merchant descriptions, categorization tags, and user budget rules.

Operational Telemetry

PII-redacted error logs, performance metrics, and security audit timestamps to ensure platform stability.

3. Authorized Sub-Processors & Infrastructure

FinBrain relies on enterprise-grade infrastructure providers to execute core ledger capabilities:

Sub-ProcessorPurposeLocation
SupabasePostgreSQL Database, Authentication, Row-Level SecurityAWS (Enterprise Cloud)
CloudflareDirect encrypted object storage (R2) & Edge routingGlobal Edge Network
GroqLLM classification & categorization (Scrubbed text only)United States
VercelApplication hosting, serverless compute, and CDNGlobal Edge Network

4. AI Intelligence & Third-Party Provider Boundaries

When FinBrain generates merchant classifications or category suggestions, it transmits only normalized, scrubbed text candidates through our secure AI adapter. Sensitive authentication tokens, complete document binary bodies, unredacted account numbers, and unrelated historical transactions are strictly filtered out before dispatch.

5. Data Retention, Portability & Deletion

You maintain complete sovereignty over your data. You may export your normalized transactions to sanitized CSV at any time. Upon account deletion through your profile settings or a verified data request, all associated ledger records, imports, and R2 document objects are permanently purged.

To submit a formal inquiry or request data erasure, visit our Data Subject Requests page or email us at support@osmdigital.in.