Privacy policy
In short. FinTrack stores your email and the transactions you record so the app works. We do not sell your data, show ads, or build advertising profiles. Some of it is processed by named providers listed below. You can export your data, and delete your account, from inside the app.
Who we are
FinTrack is published by Mohammed Ibrahim Aejaz ("we", "us"). You can reach us at ibrahimaejaz@gmail.com. We are responsible for the personal data described in this policy.
What we collect
| Data | What it is | Why we use it | Required? |
|---|---|---|---|
| Email address | The address you sign up with. Your password is stored only as a one-way hash. | Creating your account, signing you in, and verifying it is you if you contact us. | Yes |
| Transaction records | The income and expense entries you record: item, amount, category, date, optional note, and whether it was added by typing, chat or voice. Also the chat messages you send, which are kept in an audit record alongside each change. | Showing your dashboard, list and analytics, letting you undo changes, and turning what you type or say into an entry. | Yes |
| Voice audio | A short recording, only while you are recording with the microphone button. It is sent to our server and passed straight to Deepgram to be turned into text. | Transcribing what you say so you can review the text before it is sent as a message. | No, optional |
| Crash diagnostics | If the app crashes: the error and stack trace, app version, Android version and device model. Never your messages, amounts or password. This is on by default and you can switch it off in Settings. | Finding and fixing crashes. | No, optional |
We do not collect:
- Advertising ID
- Precise or approximate location
- Contacts
- Photos, videos, files or documents
- Health or fitness data
- Payment card or bank account information
FinTrack does not connect to your bank, cards or any payment service. It only holds what you type or say yourself.
How we use it
We use your data only to provide FinTrack: to sign you in, to store and show your transactions, to turn your messages into entries, and to find and fix crashes. We do not sell your data, use it for advertising, or use it to profile you.
Who processes it for us
We use the providers below to run FinTrack. Each processes data on our behalf for the purpose shown, and only the data shown.
| Provider | What it does | What it receives |
|---|---|---|
| Groq | Turns the text of a chat message into a structured entry or query. | The text of your chat message, plus today's date and our category list. No account details and none of your stored transactions. |
| Deepgram | Speech-to-text for voice input. | The audio recording only. |
| Neon | Hosts the database. | Your email, password hash, transactions, audit records and sign-in sessions. |
| Render | Hosts the application server that the app talks to. | Everything the app sends to or receives from our server passes through it, including standard request logs such as IP address and timestamps. |
| Sentry | Crash reporting (optional, on by default, can be switched off). | Crash details described above. Never your messages, amounts or password. |
We also use Google (Gmail) to receive and send the emails you exchange with us when you contact support or request deletion.
These providers may process data in countries other than your own, including the United States. We do not otherwise disclose your data, except where the law requires it.
How long we keep it
- Email address: Until you delete your account.
- Transaction records: Entries until you delete them or your account (a deleted entry is kept as a hidden record so Undo and syncing work, and is removed with your account). Audit records, including your chat messages, are deleted automatically after 180 days.
- Voice audio: Not stored by us. The recording is discarded as soon as the text comes back, and we ask Deepgram not to use it to improve its models.
- Crash diagnostics: Kept by Sentry under its own retention period; crash reports are not linked to your account.
- Sign-in sessions: until you delete your account.
- Emails with us about support or deletion: for up to 12 months after we finish handling them.
Your rights and choices
- Access and export: Settings → Export my data downloads all your transactions as a CSV file.
- Correction: edit or delete any transaction in the app.
- Deletion: Settings → Delete account removes your account and data. If you cannot sign in, follow the steps on the delete-account page. We respond to requests within 30 calendar days.
- Crash reports: switch them off in Settings at any time; the app then sends nothing to Sentry.
- Microphone: optional. Voice input only works while you allow it, and you can revoke it in Android settings.
- Depending on where you live, you may have other rights, such as objecting to or restricting processing, or complaining to your data protection authority. Write to us and we will help.
Security
Data travels between the app and our server over encrypted HTTPS connections. Passwords are stored only as one-way hashes, and sign-in tokens are stored hashed. Our hosting providers encrypt stored data at rest. No system is perfectly secure, and we do not claim that your data is end-to-end encrypted: our server and the providers above process it in readable form in order to work.
Children
FinTrack is intended for adults. We do not knowingly collect data from anyone under 18. If you believe a child has given us data, contact us and we will delete it.
Changes to this policy
When we change this policy we update the version and effective date above and list the change below. For material changes we will also give notice in the app or by email before they take effect.
Version history
- 1.0 — 2026-09-20 — first published version.
Contact
Mohammed Ibrahim Aejaz · ibrahimaejaz@gmail.com