Privacy policy
Effective July 22, 2026
What débutFin processes
débutFin processes account-profile information, connected-account metadata, balances, transactions, debts, bills, goals, scenarios, uploaded financial documents, extraction corrections, credit-score snapshots, and security and audit events needed to operate your account.
Why it is processed
The information is used to provide account access, synchronize supported institutions, stage and confirm document facts, calculate deterministic financial plans, prevent abuse, investigate failures, fulfill exports, and complete account deletion.
Processors
- Supabase provides authentication, PostgreSQL, and private object storage.
- Cloudflare provides DNS, TLS, Workers hosting, abuse controls, and operational logs.
- Plaid provides institution connection and supported financial data after your authorization.
- OpenAI processes an uploaded document only when automatic extraction is enabled; temporary processor files are deleted after the request and the original remains in private storage.
- Email provider delivers confirmation and recovery messages through Supabase Auth.
- Off-site object provider stores encrypted/private backup copies when backups are configured.
Data isolation and retention
User-owned database rows are protected by row-level security. Original documents are private. Routine deletion uses a recovery window before purge; backup retention and legal/security exceptions are documented in the operator runbook.
Your controls
You may correct imported facts, export your structured data and originals, revoke sessions, disconnect data sources, and request account deletion from Settings.
Security limits
No service can promise that loss or compromise is impossible. débutFin is designed to avoid preventable loss through encryption, least privilege, idempotent processing, backups, monitoring, and restore drills.