Privacy Policy
Effective Date: September 2026 • Product of OSM Digital
1. Core Architectural Privacy Commitments
FinBrain is designed on the principle that your financial records belong exclusively to you. Unlike traditional financial aggregation services that monetize transaction telemetry, sell market trends to advertisers, or train third-party foundational AI models on raw banking feeds, FinBrain provides an isolated computing environment.
- No Global AI Model Training: Your raw bank descriptions, account names, transaction amounts, and uploaded statement contents are never used to train public or shared machine learning models.
- Isolated Tenant Boundaries: PostgreSQL Row-Level Security (RLS) ensures that every financial record is bound deterministically to your authenticated user ID. Cross-tenant data leakage is prevented at the database engine level.
- Zero-Proxy Binary Pipeline: Document files uploaded via private Cloudflare R2 presigned URLs transfer directly from your browser to encrypted storage, bypassing intermediate application server memory.
2. Categories of Information We Process
We process only the minimum necessary data to construct and maintain your deterministic financial ledger:
Account & Authentication
Email address, hashed authentication credentials, and optional OAuth identity tokens (managed securely by Supabase Auth).
Uploaded Financial Documents
User-provided bank statements, CSV spreadsheets, and statement metadata for parsing and categorization.
Normalized Ledger Records
Transaction dates, integer cent amounts, sanitized merchant descriptions, categorization tags, and user budget rules.
Operational Telemetry
PII-redacted error logs, performance metrics, and security audit timestamps to ensure platform stability.
3. Authorized Sub-Processors & Infrastructure
FinBrain relies on enterprise-grade infrastructure providers to execute core ledger capabilities:
| Sub-Processor | Purpose | Location |
|---|---|---|
| Supabase | PostgreSQL Database, Authentication, Row-Level Security | AWS (Enterprise Cloud) |
| Cloudflare | Direct encrypted object storage (R2) & Edge routing | Global Edge Network |
| Groq | LLM classification & categorization (Scrubbed text only) | United States |
| Vercel | Application hosting, serverless compute, and CDN | Global Edge Network |
4. AI Intelligence & Third-Party Provider Boundaries
When FinBrain generates merchant classifications or category suggestions, it transmits only normalized, scrubbed text candidates through our secure AI adapter. Sensitive authentication tokens, complete document binary bodies, unredacted account numbers, and unrelated historical transactions are strictly filtered out before dispatch.
5. Data Retention, Portability & Deletion
You maintain complete sovereignty over your data. You may export your normalized transactions to sanitized CSV at any time. Upon account deletion through your profile settings or a verified data request, all associated ledger records, imports, and R2 document objects are permanently purged.
To submit a formal inquiry or request data erasure, visit our Data Subject Requests page or email us at support@osmdigital.in.