Legal

Privacy Policy

Effective August 1, 2026 · Also read the Terms of Service

Finappses is bookkeeping software, which means you trust us with financial records. This policy explains exactly what we collect, why, who processes it, and how to get it out. The short version of the whole document: your books are yours, we don't run ads, and we don't sell data. Each section opens with a one-line summary; the full text is what's binding.

1Who we are

In shortFinappses is run by Chazbit LLC in Louisville, Kentucky. We're the data controller for your account.

Finappses is operated by Chazbit LLC, doing business as Finappses ("Finappses," "we," "us"), based in Louisville, Kentucky, USA. This policy covers the Finappses web application, its REST API, and the finappses.com website (together, the "Service"). For the personal information described here, we act as the data controller.

One distinction worth making early: if you use Finappses to invoice your customers, you are the controller of your customers' information (their names, emails, invoice details), and we process it on your behalf to provide the Service to you.

2What we collect

In shortYour email, the books you keep, what you import, and basic operational logs. Your card details never touch us.

Account information. Your email address. That's the account: Finappses uses passwordless magic-link sign-in, so we never collect or store a password.

Your books. The financial data you record or generate in the Service — chart of accounts, journal entries, invoices and customer details, budgets, reports, and any receipts or documents you attach.

Imported bank data. If you connect a bank through Plaid, we receive the transaction data needed for import and reconciliation (dates, amounts, descriptions, account identifiers). Your bank credentials go to Plaid, never to us. If you import via OFX/QBO or CSV instead, we receive only what's in the file you upload.

Purchase information. Payments are handled by LemonSqueezy, our merchant of record. We receive your license status, plan, and the email associated with the purchase — not your card number or billing details.

Operational data. Standard server logs (IP address, browser user-agent, timestamps, requested URLs) and API request logs, kept for security, debugging, and abuse prevention. The website and app use only the cookies necessary to operate — session and CSRF cookies. There are no advertising trackers and no third-party analytics scripts on the Service.

3How we use it

In shortTo run the product you signed up for — nothing cleverer than that.

We use the information above to:

operate the Service — store your ledger, generate your reports, send your invoices, and sync your bank feeds; sign you in, by emailing magic links to your address; deliver transactional email such as sign-in links, invoices you send, receipts, and important service notices; provide support when you write to us; secure the Service, including detecting abuse and investigating incidents; and understand aggregate usage (for example, which features are used) to improve the product.

Where the GDPR or similar law applies, our legal bases are performance of our contract with you (running the Service), legitimate interests (security, product improvement), and compliance with legal obligations. We'll ask for consent where the law requires it.

4What we don't do

In shortNo selling data. No ads. No mining your ledger.

We do not sell or rent your personal information or your financial records. We do not show ads and do not share your data with advertisers or data brokers. We do not read or analyze the contents of your books except as needed to operate the Service, to support you when you ask, or to investigate a specific security or integrity problem. Our business model is refreshingly boring: you pay for software, and that's the whole transaction.

5Service providers

In shortA short, deliberate list — each one sees only what its job requires.

We use a small set of providers to run Finappses. Each processes data only to provide its service to us:

ProviderRoleWhat it processes
DigitalOceanCloud hostingAll application data, hosted on servers we manage in the United States.
LemonSqueezyMerchant of recordCheckout, payment details, sales tax, license keys. Card data stays with them.
StripeInvoice paymentsYour customers' card payments, processed under your own Stripe account — funds never pass through Finappses.
PlaidBank connectionsYour bank credentials (held by Plaid, not us) and the transaction data you authorize for import.
MailgunEmail deliveryRecipient addresses and contents of transactional email — magic links, invoices, notices.

We don't add providers casually; if this list changes in a way that matters, we'll update this policy and note it per Section 11. Beyond these providers, we disclose information only if required by law or valid legal process, to protect the rights and safety of Finappses and its users, or as part of a business transfer such as a merger or acquisition — in which case this policy continues to apply to your data until you're told otherwise.

6Retention & deletion

In shortWe keep your books while you have an account. Delete the account and the data goes too, on a stated schedule.

Your ledger is kept for as long as your account exists — including after a trial ends or a subscription lapses, so your books are waiting if you come back, and remain exportable in the meantime.

When you delete your account (or ask us to), your application data is deleted from production systems within 30 days, and rotates out of encrypted backups within 90 days of that. We retain what we're legally required to keep — for example, records of purchases for tax and accounting purposes — and minimal operational logs, which age out on a rolling basis of at most 12 months. Bookkeeping advice from a bookkeeping company: export before you delete.

7Your rights

In shortAccess, export, correct, delete — mostly self-serve, all available by email.

Depending on where you live (GDPR in the EU/UK, CCPA/CPRA in California, and similar laws elsewhere), you may have rights to access, correct, export, delete, or restrict the processing of your personal information, and to object to certain processing. Finappses is built so most of these are self-serve: your data is visible and editable in the app, and full export is a standing feature, not a request form.

For anything you can't do in the app — including account deletion or a machine-readable copy of your account information — email support@finappses.com and we'll respond within the timeframe the applicable law requires (30 days or less). We don't discriminate against you for exercising privacy rights, and since we don't sell personal information, there's nothing to opt out of on that front. If you're in the EU/UK and believe we've fallen short, you can also lodge a complaint with your local supervisory authority — though we'd appreciate the chance to fix it first.

8Security

In shortEncrypted in transit, isolated per customer, no password database to breach.

All traffic to the Service is encrypted with TLS. Each customer's books live in an isolated per-tenant database rather than commingled tables — a structural boundary, not just a WHERE clause. Passwordless sign-in means there is no password database to steal; sign-in links are single-use and short-lived. We keep automatic encrypted backups, apply security patches promptly, and restrict production access.

No system is perfectly secure, and we won't pretend otherwise. If a breach affects your personal information, we'll notify you without undue delay, consistent with applicable law, and tell you plainly what happened and what we're doing about it. Security reports are welcome at security@finappses.com.

9Where data lives

In shortThe service is hosted in the United States.

The Service is hosted in the United States, and your information is processed there. If you use Finappses from outside the US, you're transferring your data to the US, where privacy laws may differ from your jurisdiction's. Where required — for example, for EU/UK personal data — we rely on appropriate safeguards such as standard contractual clauses with our providers.

10Children

In shortFinappses is for adults.

The Service is not directed to anyone under 18, and we don't knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we'll delete it.

11Changes

In shortMaterial changes come with an email, not a silent edit.

We may update this policy as the Service and the law evolve. For material changes, we'll email the address on your account before the change takes effect and update the effective date above. The current version always lives at this URL.

12Contact

In shortEmail us. A human reads it.

Privacy questions and requests: support@finappses.com. Security reports: security@finappses.com.

your data = your data ✓ · no hidden line items