Finora Privacy Policy
Finora Privacy Policy
Your financial data stays on your device. We never upload, sell, or share it.
Last updated: August 20261. Introduction
Welcome to Finora — Your Money, Your Future. Finora is a personal finance manager for Android that helps you track income, expenses, and transfers; set budgets and savings goals; manage accounts; analyze spending patterns; and automate recurring transactions — all from one place.
This Privacy Policy explains exactly what information Finora accesses, why it accesses it, and the choices you have as a user. Finora is built as a local-first, offline-first app: every transaction, budget, goal, and account record is stored entirely on your device. We do not operate any servers that receive your financial data. By using Finora, you agree to the practices described in this policy.
2. Information We Access
All information Finora touches stays on your device. We do not collect or transmit your personal financial data to any server. Specifically:
- Transactions — income, expense, and transfer records you enter, including amounts, dates, categories, notes, and linked accounts, are stored only in Finora's private on-device database.
- Budgets & Goals — your budget limits, savings targets, goal names, and progress figures live entirely on-device.
- Accounts — account names, types, currencies, and balances you create in Finora are stored locally and never transmitted.
- Recurring rules — scheduled recurring transactions (frequency, amount, category) are kept in the on-device database and processed locally.
- Analytics & spending patterns — all charts, trend calculations, and financial recommendations are computed on-device using only your own local data.
- App preferences — settings such as theme, PIN, currency, and notification preferences are stored in Finora's private on-device storage.
- Encrypted backups — if you choose to create a backup, it is encrypted on-device with AES-256-GCM before being written to a location you select. Finora never uploads backups automatically.
- No account required — Finora does not ask you to sign up, log in, or provide an email address.
3. How We Use Information
Everything Finora accesses on your device is used solely to power the financial tools you choose to run:
- To record and categorize your income, expenses, and transfers.
- To track budgets and alert you when spending approaches or exceeds limits.
- To monitor savings goals and show you progress over time.
- To generate analytics — spending by category, monthly trends, cash-flow summaries — using only your local data.
- To schedule and auto-log recurring transactions based on rules you define.
- To remember your preferences across sessions and enforce your PIN lock if enabled.
- To create and restore encrypted backups at your explicit request.
Finora does not use your financial data for profiling, advertising targeting, or sale to third parties. The internet connection Finora requests is used only to display ads via Google AdMob (see Section 5) and to collect GDPR consent where required (see Section 6). Your financial data is never sent over the network.
4. Permissions Used
Finora requests only the permissions necessary to function as a finance manager and ad-supported app:
- READ_EXTERNAL_STORAGE / WRITE_EXTERNAL_STORAGE — Required to let you import and export backup files. Used only when you explicitly initiate a backup or restore.
- INTERNET & ACCESS_NETWORK_STATE — Used by Google AdMob to fetch and display ads, and by the UMP SDK to load the GDPR consent form for EEA/UK/Switzerland users. Your financial data is never transmitted.
- RECEIVE_BOOT_COMPLETED — Allows Finora to reschedule recurring transaction reminders after your device restarts.
- POST_NOTIFICATIONS — Required on Android 13+ to show budget alerts and recurring reminders. You can disable at any time in Android Settings.
Finora does not request access to your contacts, camera, microphone, location, call logs, or SMS messages.
5. Advertising — Google AdMob
Finora is free to use and is supported by ads served by Google AdMob. The app displays native ads (content-style ads inline on the Home screen) and rewarded ads (optional video ads tied to in-app actions).
Google AdMob may collect or use:
- Advertising ID — your device's resettable ad identifier. Reset or opt out anytime: Settings → Privacy → Ads.
- Approximate device information — device type, OS version, and language.
- IP address — used by Google for regional ad serving and fraud prevention.
- Ad interaction data — whether you viewed or clicked an ad, for performance measurement.
Finora itself does not receive, store, or process any ad-related data. It stays entirely within Google's systems.
To opt out of personalized ads: Android Settings → Privacy → Ads → Opt out of Ads Personalization. Finora continues to work normally with non-personalized ads instead.
6. GDPR & European Consent (EEA, UK, Switzerland)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, Finora complies with the General Data Protection Regulation (GDPR) and applicable national laws by using Google's User Messaging Platform (UMP) SDK to collect your consent before displaying personalized ads.
What happens when you first open Finora (EEA/UK/Switzerland only):
- A consent dialog is shown automatically, powered by Google's UMP SDK and compliant with IAB TCF 2.2 (Transparency & Consent Framework).
- You can choose to accept personalized ads, accept non-personalized ads only, or decline all ad tracking.
- Your consent choice is stored on-device and sent to Google. Finora does not receive or store your consent decision separately.
- Ads are only loaded after your consent is confirmed — never before.
Your consent rights under GDPR:
- Withdraw consent at any time — open Finora's Settings screen and tap "Manage Ad Consent (GDPR)" to review or change your choices.
- Right to access — Finora holds no personal data of its own; your financial data stays on your device.
- Right to erasure — clear all app data via Android Settings → Apps → Finora → Storage → Clear Data. This also resets your consent record.
- Right to object — withdraw ad consent at any time via the in-app Manage Consent button. This will not affect your ability to use Finora.
- Lawful basis — Finora's legal basis for processing ad-related data via Google AdMob is your freely given, specific, informed, and unambiguous consent (GDPR Art. 6(1)(a)).
For users outside the EEA/UK/Switzerland, no consent form is shown. AdMob initializes normally on first launch and may serve personalized ads based on your device's Advertising ID settings.
For questions about GDPR rights, contact us at privacy@finora.app — we will respond within 30 days.
7. Backup & Data Export
Finora gives you full control over your data through its built-in backup and restore system:
- Encrypted backups — All backups are protected with AES-256-GCM encryption with 100,000 PBKDF2 iterations before leaving the app. You set and keep the passphrase; Finora never stores or transmits it.
- You choose where to save — Finora writes the encrypted backup to the location you select via Android's standard Share/Save dialog. Finora has no involvement after handoff.
- Restore is local — restoring reads and decrypts entirely on-device. No server involved.
- CSV / data export — exported files go to the location you pick. Finora does not cache a copy.
8. Third-Party Services & Libraries
Finora uses the following libraries and services. Except for Google AdMob and UMP SDK, all are fully on-device:
- Google AdMob — native & rewarded ad serving. Requires internet; governed by Google's Privacy Policy. See Section 5.
- Google UMP SDK (User Messaging Platform) — collects GDPR/EEA consent before AdMob initializes. Governed by Google's Privacy Policy. See Section 6.
- Jetpack Compose — Android UI toolkit (Apache 2.0). No data transmitted.
- Room Database — local on-device database for transactions, accounts, budgets, goals (Apache 2.0). No data transmitted.
- AndroidX DataStore — local settings storage (Apache 2.0). No data transmitted.
- Moshi — JSON serialization for backup encoding (Apache 2.0). No data transmitted.
- Vico Charts — on-device chart rendering. No data transmitted.
- WorkManager — on-device recurring reminder scheduling (Apache 2.0). No data transmitted.
Finora does not include Firebase Analytics, Crashlytics, or any tracking SDK beyond AdMob + UMP. If this changes, this policy will be updated and your consent sought first.
9. Data Retention & Deletion
Because Finora stores all data locally, you are in full control of how long data is kept. Finora imposes no retention period.
- Transactions, accounts, budgets & goals — retained indefinitely until you delete them or clear app data.
- App preferences & settings — retained until you clear data or uninstall.
- Encrypted backup files — retained at the location you saved them until you manually delete them.
- Ad consent record (EEA/UK/CH) — stored on-device by the UMP SDK. Reset by clearing app data or tapping "Manage Ad Consent" in Settings.
- Ad-related data (AdMob) — managed by Google under their own retention policy. Reset via Settings → Privacy → Ads → Reset Advertising ID.
How to delete your data:
- Individual records — swipe or long-press any transaction, account, budget, or goal and choose Delete.
- All app data — Android Settings → Apps → Finora → Storage → Clear Data. This also resets your GDPR consent record.
- Uninstall — removes the app and its private database. Externally saved backups remain in your chosen location.
10. Data Security
All financial processing in Finora happens on-device, protected by:
- Android app sandboxing — Finora's database and preferences are in private internal storage, inaccessible to other apps.
- Device storage encryption — Android 6.0+ encrypts device storage by default.
- Optional in-app PIN lock — enable a PIN or biometric lock inside Finora for extra access control.
- AES-256-GCM backup encryption — all backups are encrypted before being written anywhere, with 100,000 PBKDF2 iterations.
The only outbound network traffic Finora initiates is the AdMob SDK (ads) and UMP SDK (consent form for EEA users). Your financial data is never part of those requests.
11. Children's Privacy
Finora is intended for general users aged 13 and above. It is not designed or marketed to children under 13.
Finora contains ads served by Google AdMob and uses the UMP SDK for EEA consent. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has used Finora, please contact us via Section 15 — we will take appropriate action promptly.
12. Your Rights
Because Finora stores your data only on your own device, most rights are exercised directly:
- Access — every transaction, account, budget, goal, and setting is visible inside the app at all times.
- Deletion — delete records from within Finora, or go to Android Settings → Apps → Finora → Storage → Clear Data.
- Portability — export your data as an encrypted backup or CSV file at any time.
- Withdraw ad consent (EEA/UK/CH) — tap "Manage Ad Consent (GDPR)" in Finora's Settings screen at any time.
- Opt out of personalized ads — Android Settings → Privacy → Ads → Opt out of Ads Personalization.
- Reset Advertising ID — Android Settings → Privacy → Ads → Reset Advertising ID.
EU, UK, and California users may have additional rights under GDPR, UK GDPR, or CCPA. Contact us at privacy@finora.app — we respond within 30 days.
13. Google Play Data Safety Section
Finora's Data Safety section on the Google Play Store provides a standardized summary consistent with this Privacy Policy.
- Data collected by Finora — none; all financial data stays on your device.
- Data collected by Google (AdMob + UMP) — Advertising ID, device info, IP address, ad interaction data, and consent signal (EEA only). Governed by Google's Privacy Policy.
- Data shared — no financial or personal data from Finora is shared with any third party.
- Security practices — data encrypted at rest (device + AES-256-GCM backups) and in transit (AdMob/UMP communications).
- Data deletion — users can delete all data at any time as described in Section 9.
If there is any inconsistency between this Privacy Policy and the Play Store Data Safety section, this Privacy Policy governs.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will:
- Update the "Last updated" date at the top of this page.
- Notify users via an in-app notice on the next launch if changes are material.
- Seek your explicit consent before any change involving new types of data collection.
Continued use of Finora after a policy update constitutes acceptance of the revised policy.
15. Developer Information & Contact
If you have questions or concerns about this Privacy Policy or how Finora handles your data, please reach out:
- Developer: Khushlal
- Publisher / Company: Vidora NG
- App Name: Finora — Your Money, Your Future
- Package ID: com.finora.yourfinora
- Privacy inquiries: privacy@finora.app
- General support: support@finora.app
We respond to all privacy inquiries within 48 hours. GDPR/CCPA data requests within 30 days as required by applicable law.
Comments
Post a Comment