Privacy Policy
Legal

Privacy Policy

Effective date: 1 May 2026 Last updated: 1 May 2026 Jurisdiction: Norway / EEA
Contents
  1. Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. Legal Basis
  5. Third-Party Services
  6. Data Retention
  7. Your Rights
  8. Security
  9. Children
  10. Changes to This Policy
  11. Contact Us
FINIO is a read-only personal finance application. We never initiate payments, hold funds, or have custody of your money. We access your bank transaction data solely to provide you with insights, budgeting tools, and savings opportunities.
01

Who We Are

FINIO ("we", "us", "our") is an AI-powered personal finance application. Our service helps users understand their spending, manage budgets, and identify savings opportunities by connecting to their bank accounts via open banking.

For the purposes of the General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (personopplysningsloven), FINIO is the data controller responsible for your personal data.

Contact: hello@getfinio.com

02

Data We Collect

We collect only the data necessary to deliver FINIO's core functionality. We do not collect data for advertising purposes.

Category Data Source
Identity Name (first name only, used to personalise the app) You, or retrieved via Tink open banking
Bank Transactions Transaction date, description (merchant name), amount, currency, category Your bank, via Tink by Visa (open banking)
Account Data Account type, institution name (read-only reference only) Your bank, via Tink by Visa
App Usage Budget limits you set, categories you customise, opportunities you dismiss Your interactions within FINIO
AI Conversations Messages you send to the FINIO AI Advisor (compressed transaction context included) Your interactions with the AI Advisor
Device Device type, OS version, app version (for crash reporting and compatibility) Automatically collected on app use

We do not collect: bank credentials or passwords (handled entirely by Tink), payment card numbers, national identity numbers, biometric data, or data from users under 18.

03

How We Use Your Data

Purpose Description
Core service delivery Displaying your transactions, calculating budgets, generating spending insights and savings opportunities
AI personalisation Sending compressed transaction summaries to our AI model to generate personalised financial advice and dashboard insights
Affiliate referrals Identifying relevant financial products (e.g. better loan rates, insurance) based on your spending patterns, and surfacing these as optional recommendations
Service improvement Improving transaction categorisation accuracy and AI response quality using aggregated, anonymised data
Security & fraud prevention Detecting anomalous access and protecting your account
Legal compliance Meeting our obligations under GDPR, PSD2, and Norwegian financial regulation
05

Third-Party Services

FINIO uses a small number of carefully selected third-party services to operate. Each is a data processor acting on our instructions.

Provider Role Data Shared Location
Tink by Visa Open banking / PSD2 data aggregation Bank connection consent; transactions retrieved on your behalf EU (Sweden)
Supabase Database and backend infrastructure Transactions, budget data, app preferences EU (Frankfurt, Germany)
Anthropic AI inference (Claude API) Compressed, anonymised transaction summaries for AI Advisor responses USA (data processed under SCCs)

We do not sell your data to any third party. We do not share your data with advertisers.

When data is transferred outside the EEA (specifically to Anthropic in the USA), we ensure appropriate safeguards are in place in accordance with Chapter V of the GDPR, including Standard Contractual Clauses (SCCs).

06

Data Retention

We retain your data only for as long as necessary to provide the service and meet legal obligations.

Data Type Retention Period
Transaction data For the duration of your account, plus 30 days after deletion
Budget limits and app preferences For the duration of your account
AI Advisor conversation history Not stored server-side — processed in real time only
Account data For the duration of your account, plus 30 days after deletion
Legal/compliance records Up to 5 years as required by applicable law

You can delete your account and all associated data at any time from the Profile & Settings screen in the app. Deletion is processed within 30 days.

07

Your Rights

Under GDPR, you have the following rights regarding your personal data. To exercise any of these rights, contact us at hello@getfinio.com. We will respond within 30 days.

Right of Access

Request a copy of all personal data we hold about you.

Right to Rectification

Request correction of inaccurate or incomplete data.

Right to Erasure

Request deletion of your data ("right to be forgotten").

Right to Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests, including affiliate recommendations.

Right to Withdraw Consent

Disconnect your bank account and withdraw open banking consent at any time.

Right to Restrict Processing

Request that we limit how we use your data in certain circumstances.

Right to Complain

Lodge a complaint with Datatilsynet, Norway's data protection authority, at datatilsynet.no.

08

Security

We take data security seriously. FINIO uses the following measures to protect your data:

All data is stored in Supabase's Frankfurt (EU) data centre with encryption at rest and in transit. Bank credentials are never stored by FINIO — authentication is handled entirely by Tink's secure OAuth flow. Access to our database is restricted to authorised systems only. We do not log or store raw bank credentials at any point.

While we take all reasonable steps to protect your data, no system is completely immune to risk. In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected users without undue delay.

09

Children

FINIO is not directed at or intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child under 18 has provided us with personal data, please contact us immediately and we will delete it.

10

Changes to This Policy

We may update this Privacy Policy from time to time as our service evolves or as legal requirements change. When we make material changes, we will notify you through the app and update the "Last updated" date at the top of this page.

Continued use of FINIO after changes take effect constitutes acceptance of the updated policy. If you disagree with any changes, you may delete your account at any time.

11

Contact Us

If you have any questions about this Privacy Policy or how we handle your data, please reach out.

FINIO

Email: hello@getfinio.com

Website: getfinio.com

For data protection matters, including exercising your GDPR rights, please use the subject line: "Data Privacy Request"