Privacy Policy
Last updated: 7 October 2026
This policy explains what personal data Finance App collects, why, and what you can do about it. Finance App is operated by Yellow Pipeline SRL (Romania), the controller of your personal data under the EU General Data Protection Regulation (GDPR). Questions and requests: office@yellow-pipeline.com.
Data we collect
- Account data: your name, email address and password. Passwords are stored only as a salted hash, never in plain text.
- Google sign-in: if you sign in with Google, we receive your name, email address, profile picture and Google account ID. We never see your Google password.
- Financial data you enter: accounts, balances, transactions, categories, budgets and any bank statements you import. We don't connect to your bank and can't move money.
- Technical data: for each signed-in session we store your IP address and browser user agent, and our servers keep standard request logs, to keep your account secure.
How we use it
- To provide the service: create your account, sign you in, and store and show your data (performance of a contract, Art. 6(1)(b) GDPR).
- To send emails the service needs, such as address verification (Art. 6(1)(b) GDPR). We don't send marketing emails.
- To keep the service secure and prevent abuse (legitimate interest, Art. 6(1)(f) GDPR).
We don't sell your data, show ads, or use your data for profiling or to train AI models.
Google user data
With Google sign-in we request only the basic openid, email and profile scopes. We use this data only to create and sign in to your account, and don't share it with anyone except the service providers listed below. We have no access to your Gmail, Drive, contacts or any other Google data. Finance App's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Who processes data for us
- Neon hosts the database, in the EU (Frankfurt, Germany).
- Our hosting provider runs the application servers, in the EU.
- Resend sends our transactional emails. Resend is based in the United States; transfers rely on the EU Standard Contractual Clauses.
- Google handles sign-in when you choose to sign in with Google.
How long we keep it
We keep your account and financial data for as long as your account exists. Sessions expire after 7 days of inactivity, and verification links expire shortly after they are sent. When you ask us to delete your account, we delete its data within 30 days.
Cookies and local storage
We use one strictly necessary cookie to keep you signed in. Your browser's local storage remembers your theme and your cookie banner choice. We don't use advertising or tracking cookies.
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to its processing, or to receive it in a portable format. Email office@yellow-pipeline.com and we'll reply within one month. You can also complain to the Romanian data protection authority, ANSPDCP, or the authority in your EU country.
Security
Data is encrypted in transit (HTTPS), passwords are hashed, and access to production systems is limited to the people who run the service.
Children
Finance App is not meant for anyone under 16.
Changes
If we change this policy, we'll update the date above, and tell you by email or in the app if the change is significant. See also our Terms of Service.