Legal
Privacy Policy
Last updated August 14, 2026
FinOS is a self-hosted personal finance system operated by a single individual ("we", "us") for a small set of people it tracks finances for ("you"). It runs on its own private server — not a shared, multi-tenant SaaS product — and this policy explains what data it collects, why, and what happens to it.
What we collect
To build your ledger, net worth, and bill tracking, FinOS collects:
- Bank SMS. If you install the FinOS Android app, transactional SMS from your monitored bank senders are forwarded to your account for parsing. Personal or non-bank SMS are never collected.
- Email statements (Gmail). If you connect Gmail, FinOS reads statement/notification emails and their attachments to extract transactions, and applies a Gmail label to messages it has processed (so it doesn't reprocess them). It never sends email, never deletes or trashes messages, and never reads or uses email unrelated to financial statements.
- Manually uploaded statements — PDF, CSV, or XLSX files from your bank or broker that you upload yourself.
- Investment & account data you connect directly — e.g. a CAS/portfolio session (MFCentral) or a broker connection (Groww) — to pull holdings and valuations.
- The financial data FinOS derives from the above: transactions, balances, categories, recurring subscriptions, bills, and investment holdings.
How your Gmail data is used
The Gmail connection requests the gmail.modify scope, which sounds broader than what we actually do with it. In practice FinOS only: reads messages and attachments to find bank/broker statements, and applies one of two labels — finos/processed or finos/error — so it knows what it has already ingested and never reprocesses the same message. It does not send mail on your behalf, does not delete or modify the content of any message, and never shares Gmail data with any third party or uses it for advertising. You can revoke access at any time from your Google Account's connected-apps settings or from FinOS's own Connections page.
How we use your data
Solely to compute and show your own dashboard — spend, net worth, bills, and recurring subscriptions. We don't run ads, sell data, or use it for anything beyond the product itself.
One exception worth naming specifically: when our category rules can't confidently categorize a transaction, FinOS sends the transaction's description text and your name to a third-party LLM API (Google Gemini or Anthropic, whichever is configured) to suggest a category. No account numbers, passwords, or Gmail content are included in that call — only the transaction line itself.
Where your data lives
Everything is stored in a Postgres database on a private VPS we control — not a third-party cloud data platform. OAuth tokens and other credentials are encrypted at rest before being written to the database. Every query is scoped to your own account; FinOS has no cross-account reporting or aggregation.
Analytics
FinOS uses Google Analytics to see basic usage — which pages get visited and how often — across the whole site, including pages you only reach after logging in. Google Analytics receives page paths and standard visitor/device metadata (browser, rough location from IP, referrer); it never receives your transactions, balances, account numbers, or anything else from your ledger. You can opt out of Google Analytics tracking across all sites using the Google Analytics Opt-out Browser Add-on.
Sharing
We do not sell your data, share it with advertisers, or use it to train third-party models. The only outbound calls are the LLM categorization fallback and analytics described above, and the connections you explicitly set up (Gmail, MFCentral, Groww) to pull your own data in.
Retention & deletion
Your data is retained for as long as your account is active. To request deletion of your account and all associated data, or to revoke a specific connection, email us at arun2007ind@gmail.com.
Children
FinOS is not directed at, or knowingly used by, children under 18.
Changes to this policy
If this policy changes, we'll update the date at the top of this page. Continued use of FinOS after a change means you accept the updated policy.
Contact
Questions about this policy or your data: arun2007ind@gmail.com.