Privacy Policy →

Fino — Account & Data Deletion

App: Fino | Android package: com.fino.android | iOS bundle ID: com.fino.iosApp
Last updated: 28 September 2026

This page explains how to request deletion of your Fino account and associated data, what gets deleted, what may be retained, and how long it takes. For details on what data Fino collects and how it is used, see the Privacy Policy.

1. How to request account deletion

In the app: open Fino → the Settings tab → scroll to Delete Account at the bottom.

You will be taken through four steps:

This usually completes within seconds and does not require any manual processing. If something fails midway, the app tells you why and lets you retry. Deletion runs step by step, and anything already deleted before the failure is not restored; but your sign-in account is only deleted in the very last step, so after a failure the account still exists and you can retry, and a retry deletes whatever is left.

No device at hand? If you have already uninstalled the app or cannot sign in, you can instead email liokhgf@gmail.com (suggested subject: Fino Account Deletion Request), stating the email address you registered with and the platform you use. The developer will first verify your identity — confirming the request comes from the same email address registered to the account, and asking for more information if needed — before performing the deletion, so that nobody else can delete your data on your behalf. This is a fallback alongside the in-app entry point, not the required route.

2. Data that will be deleted

Once deletion runs, the following cloud data tied to your account (Firebase Auth uid) is deleted:

For clarity: receipt images captured or selected for AI receipt scanning, along with OCR text recognition and AI inference, are processed entirely on your device and are not uploaded to the cloud. There is therefore no cloud copy of those images or of the inference to delete. The one exception is a receipt photo you chose to save on the confirmation screen — it becomes a transaction photo, falls under “Transaction photos in Cloud Storage” above, and is deleted with them. To clear the cached receipt images from the device, uninstall the app.

One more exception: the item names and amounts parsed from recognition (not the receipt's full recognised text, the store name, or the voice-entry transcript) are written to the app activity log on your phone as a summary. If you have ever sent a problem report, the log at that time went to the developer with the report and is retained as described in the “problem reports” row of section 3.

⚠️ One distinction to keep in mind: the recognition results you confirm and save (item names, amounts) become fields of a transaction, and transactions do sync to the cloud once you are signed in. That text is therefore part of the transaction data listed above and is removed together with your account.

3. Data that may be retained or cannot be fully deleted

To preserve the integrity of other users' shared bookkeeping records, to keep the record of problem reports being handled, and to comply with legal requirements, the following may remain after your account is deleted:

DataWhy it is retainedWhat we do about it
Shared-ledger content you shared with other members (entries, splits, item names, entry notes, photos on entries, repayment records) These records also belong to the other members of the same ledger and form their joint accounting history; deleting them outright would break their settlement balances. The entries stay in that ledger. We clear your display name and avatar from that ledger's member record, so other members will see “Deleted user” where your name used to be; entries, splits and repayments still carry your internal account identifier (uid), because that is the field that determines whose money is whose — removing it would break the other members' balances outright. The item names and entry notes you typed are kept as-is (they are the ledger's content, which the other members still need to reconcile their accounts), and photos you attached to shared entries are kept too and remain visible to other members, so avoid putting personal information you would not want left behind into shared-ledger free-text fields or photos.
Shared-ledger activity history (including previous and new values of changes) This history is append-only by design — the server-side rules explicitly forbid any update or deletion — so members can trace changes and resolve disputes. Entries are retained exactly as written; we can neither edit nor delete them (the developer is bound by the same rules; only an out-of-band admin operation could alter them, and we do not do that). The history itself records only the actor's internal account identifier (uid), the field name and the before/after values — not your display name or email.
Problem reports you sent (title, description, conversation, screenshots, diagnostic information, app activity log and crash records) They are the developer's record of handling a problem and are “anonymised and kept”, as with shared ledgers: deleting them would remove the basis for problems already being worked on or fixed. Reports are kept, but we clear the link between each report and your account, the push token stored on it, and the internal account identifier (uid) in every message and in the diagnostic information; from then on the developer sees only “account deleted” and no further notifications are sent to you. Report content, screenshots and the remaining diagnostic information are kept as-is with no automatic deletion period; app activity log and crash-record files are not rewritten one by one and are deleted automatically 90 days after upload. The log may contain item names and amounts parsed from receipt recognition, but not the receipt's full recognised text, the store name, the voice-entry transcript, or your internal account identifier. If you want a report erased completely, email us with its title and roughly when you sent it, and the developer will action it within 30 days of receiving the request.
Automatically sent crash reports (Firebase Crashlytics) Crash reports are not linked to your Fino account (we set no user ID), so they cannot be found and deleted by account. Kept by Google: according to Firebase's official documentation, crash stack traces and associated identifiers are kept for 90 days before removal from live and backup systems begins. Deleting your account does not affect them. If you do not want any more sent, turn off “Send crash reports” in Settings; turning it off also deletes crash reports on the phone that have not been sent yet.
The minimum records required by law or for abuse / fraud prevention In limited cases (for example a lawful request from an authority, or handling abuse) retaining certain records is legally necessary. Only what is necessary is kept, it is not used for any other purpose, and it is deleted once no longer needed.

If you administer any shared ledgers, the first step of the in-app deletion flow asks you to name a member to take over, or to delete the ledger along with your account — you cannot continue without deciding, so that no ledger is left without an owner. If you would rather leave some ledgers yourself first, you can do that from each ledger's settings page.

4. Timeline and retention period

Deleting some of your data without deleting your account

You don’t have to delete your whole account to remove data that has been synced to the cloud:

None of the above deletes your account — you can keep using Fino.

5. If you only want to delete local data on your device

If you do not want to delete your account and only want the data on this device gone, uninstall Fino — that clears everything Fino-related from the device, including any downloaded AI model files, the app activity log and crash records.

About problem reports: reports sent while not signed in can only be found through the report numbers remembered on that phone. After you uninstall, you can no longer see them in the app, but the reports themselves are still kept on the developer's side (to have them deleted, email us as described under “Problem reports” above). Reports sent while signed in are linked to your account, so you see them again when you sign back in.

One exception: on Android, translation language packs live in Google Play services' shared storage rather than in Fino's own sandbox, so uninstalling Fino does not remove them (other apps may be using the same packs). To clear them, delete them under Settings → “Translation language packs” in Fino before you uninstall.

The app does offer a “reset data” option inside the change main currency wizard, but it only clears historical transactions as part of switching currency — it is not a full reset.

Important: clearing local data is not the same as deleting your account. As long as your account still exists, signing in again with it syncs your cloud transactions, categories, budgets and photos back onto the device. To actually delete cloud data, follow section 1, “How to request account deletion”, in the app.

6. Contact

For any question about data deletion, email liokhgf@gmail.com. Fino is built and maintained by an individual developer, who will reply as soon as possible.