Privacy notice
Your financial life is not an advertising profile.
This notice explains what débutFin receives, why it is needed, where it goes, how long it remains, and the controls available to you.
Effective July 30, 2026 · Last updated July 30, 2026
Information you choose to provide
We process account identity information, manual financial records, planning inputs, preferences, messages sent to the advisor, and files you deliberately upload. If bank connectivity is available and you authorize Plaid Link, we receive the account, balance, transaction, liability, and investment data included in the consent you select. We do not receive or store your bank username or password.
Information created by the service
débutFin creates derived facts, calculations, coverage and conflict states, scenario snapshots, review items, action proposals, synchronization status, audit receipts, and security logs. Derived values retain their source and as-of boundaries. The service does not treat an unknown value as zero merely to complete a chart.
How information is used
- Operate the workspace and the features you request.
- Authenticate sessions, prevent abuse, isolate accounts, and investigate failures.
- Reconcile evidence, run deterministic calculations, and explain results.
- Provide support, exports, deletion, and legally required notices.
- Improve reliability using route-level diagnostics that exclude financial values and raw questions.
We do not sell or rent personal information, and this release does not use financial data for third-party advertising.
Service providers and transfers
Cloudflare provides application delivery, security, and—only when expressly enabled—model inference. Supabase provides authentication, database, and private object storage. Resend may deliver transactional account email. Plaid is used only when bank connectivity is enabled and you start its consent flow. Each provider processes information to perform its contracted service; their own notices also apply to their direct interfaces.
Artificial intelligence boundary
The advisor is disabled unless the deployment reports it as configured. When enabled, the service builds an intent-limited context packet instead of sending an uncontrolled database dump. Deterministic tools—not a language model—produce material financial calculations. Conversation history remains private to the authenticated owner and may be exported or deleted. Advisor output is educational information, not a guarantee or a substitute for a qualified professional.
Security and retention
Controls include encrypted transport, managed encryption at rest, row-level database isolation, private storage, server-only provider credentials, bounded access, and audited destructive operations. No system can promise absolute security. Account deletion uses a seven-day recovery window and then removes registered records, private files, and the sign-in identity through a verified workflow. Encrypted recovery copies age out under the documented backup-retention procedure.
Your choices
You can correct or remove supported records, hide financial values on screen, disconnect eligible integrations, download an account archive, reset financial numbers and files without deleting the sign-in, or schedule complete account deletion. You may also contact us to request access, correction, deletion, or help exercising an applicable privacy right.
Children, changes, and contact
The service is intended for adults and is not directed to children under 18. Material changes will be dated here and, when appropriate, surfaced in the product. Questions or requests may be sent to contact@debutfin.com.