fincy

Privacy policy

Effective September 14, 2026

fincy is a private household ledger. This page describes what the app stores and how optional Gmail access is used. It is written for the people who actually use this instance, and so Google can review the Gmail scopes we request.

What we store

Your sign-in email, password hash, and the financial records you enter (accounts, transactions, budgets, documents you import). If you connect Gmail, we also store OAuth tokens and PDF attachments that match the document streams you configure.

Gmail

Connecting Gmail is optional. We request gmail.readonly so a background job can search mail you already received. We only pull messages that match a stream you created (for example a sender address), and we only keep PDF attachments from those messages. We do not read, store, or send the rest of your mailbox. We do not modify or delete mail.

You can disconnect Gmail in Settings → Documents. That deletes the stored tokens. Already-imported documents stay until you remove the stream or the files.

Processors

PDFs are stored on Vercel Blob. Text is extracted with Azure Document Intelligence and classified with OpenAI so we can show vendor, amount, tax year, and account labels. Ledger data lives in Neon Postgres. The app is hosted on Vercel. These vendors process data to provide the feature you turned on. We do not sell data or use it for advertising.

Google Limited Use

Gmail data is used only to provide fincy’s document inbox: find matching messages, store the PDF, and extract fields you can review. We do not transfer Gmail data to other parties except the processors above, and only to run that feature. We do not use Gmail data to train general AI models, serve ads, or let humans read your mail except when you ask us to debug a problem you reported.

Contact

This instance is private (sign-up is allow-listed). Use the email on your Account page, or the operator of fincy.ca.