Account & Data Deletion →

Fino Privacy Policy

Last updated: 1 October 2026

The short version: Fino's AI receipt scanning runs entirely on your device, and receipt images are not uploaded to any server unless you choose to save one on the confirmation screen. Fino contains no advertising SDKs and no analytics SDKs, and we do not sell your data; when the app crashes it reports the crash automatically through Google's Firebase Crashlytics, which you can turn off in Settings. Your bookkeeping data syncs to your own cloud space only after you sign in, so you can use it across devices. Separately, only when you choose to send a problem report does the app send diagnostic information, its activity log and crash records to the developer along with it.

1. Who we are

Fino is a personal bookkeeping app for Android (package com.fino.android) and iOS (bundle ID com.fino.iosApp). Fino is built and operated by a single independent developer, not a company.

For any privacy question, a data deletion request, or to ask what data we hold about you, email liokhgf@gmail.com. Please use this address for all privacy and data requests; the developer reads it personally. General questions and feature suggestions can also be sent from inside the app via Feedback & suggestions in the Settings tab (see “Problem reports” in section 2).

2. What data we collect

Below is the split between what leaves your device and what stays on your device. This is the complete list; there is no "and other data" catch-all.

1. Data that leaves your device (bookkeeping data syncs only after you sign in)

Fino's cloud backend is Google Firebase. If you never sign in, none of your bookkeeping data is ever synced. Even without signing in, however, the app still makes seven kinds of network request: downloading on-device AI models (huggingface.co), downloading translation language packs (on Android, from Google), fetching exchange rates (tw.rter.info), device integrity verification (Firebase App Check), registering this device for push notifications when the app launches (Firebase Cloud Messaging and Firebase Installations), automatic crash reports after the app crashes (Firebase Crashlytics, which you can turn off in Settings; see “Crash reports” in the table below), and the technical information Google's SDKs report automatically (see “Device and app technical information” in the table below). None of these seven send your bookkeeping content. The only case in which content you wrote is uploaded without signing in is when you choose to send a problem report (see the three “Problem reports” rows in the table below).

DataSpecificallyStored in
Account identity Your Firebase Auth user ID (uid), email address, avatar URL, display name, and which sign-in provider you used (Google or Apple). These are held by Firebase Auth; in addition, your email is stored in plain text in your Firestore user document (that document holds only your email, primary currency, creation time and last-updated time). Your display name and avatar URL are written into a ledger's member record only if you use shared ledgers. Firebase Authentication; your cloud space
Transaction records (all fields) Amount, original currency, exchange rate, income/expense type, category, date, note text, group name (when several entries from one purchase are folded into one row: the name you typed or the store name on the receipt), account, travel-mode flag, source flag, plus the technical fields that tie records together (attached-photo ID, whether the entry uses its group's photo, receipt/voice group ID, recurring-rule ID, line index, source ledger name, created and updated timestamps).
About the note text: if you typed the entry by hand, the note is what you typed. If the entry came from AI receipt scanning or voice entry, the note is the recognised item name or the transcribed text. In other words: the audio is never uploaded, and neither is the receipt image unless you choose to save it, but the text you confirm and save does sync to the cloud with the transaction.
Your cloud space (Firestore)
Settings and rules Your categories with their budget amounts (a budget is a field on a category), recurring-transaction rules, and quick-entry templates (three collections), plus your primary currency setting (stored on the user document). Your cloud space (Firestore)
Photos you attach to a transaction Photos you deliberately attach while editing a transaction, and receipt photos you choose to save on the AI receipt confirmation screen (all the entries recognised from one receipt share that single photo; the cloud keeps one copy). Photos you attach to entries in a shared ledger are the same kind of photo (see “Shared ledgers”; members of that ledger can see them). They are compressed to WebP before upload (roughly 224KB each, 5MB max per photo). These photos are uploaded to the cloud so they are still there when you switch devices. Cloud file storage (Cloud Storage); only you can read photos on your personal transactions, while members of a shared ledger can also read photos on that ledger's entries
Shared ledger content See the "Shared ledgers" section below. This only exists if you create or join a ledger yourself. That shared ledger's cloud space (Firestore)
Your personal shared-ledger side data The list of ledgers you belong to (ledger name, appearance tag, your role, join time), plus the private personal category you assign to a shared line item and the exchange-rate snapshot taken at that time. These live in your own space and other members of the ledger cannot read them. Your cloud space (Firestore)
Push notification token The Firebase Cloud Messaging (FCM) token issued to this device. The app registers with Google and obtains it as soon as it launches (which also creates a Firebase installation ID, and on iPhone links the push identifier Apple issues); this step does not require you to sign in. Only once you sign in is the token written to your own cloud space, so the server knows which device to notify. When you send a problem report, the token is also stored on that report (whether or not you are signed in) so the developer's reply can notify you. Notification content may include a member's name, an amount, a ledger name, or the opening text of the developer's reply. Your cloud space; the problem-report cloud space; Google FCM; on iOS, delivered onward via Apple APNs
Problem reports (only when you choose to send one) What you send from Feedback & suggestions in the Settings tab: the type (problem or suggestion), title, description, up to 3 screenshots (compressed to WebP before upload, 5MB max each), and the messages you and the developer exchange afterwards. The report also records the platform, app version, OS version, device model, language, whether you were signed in, and this device's push token (see “Push notification token” above).
You do not need to sign in to send one. If you are not signed in, the report is identified only by a randomly generated report number that is kept on this phone alone — after you switch phones or uninstall the app, you can no longer find those reports in the app. If you later sign in on this phone, its reports are linked to your account automatically and you can see them on any device you sign in to.
The problem-report cloud space (Firestore; screenshots in Cloud Storage). The developer can read every report; other users cannot
Diagnostic information attached to reports Each time you send a message, the app captures its current state and sends it along; before sending you can tap “View details” to see all of it. It contains:
• App: version and build number, whether initial setup is complete, sign-in method (Google / Apple / not signed in), and, if you are signed in, your internal account identifier
• Device: platform, OS version, device model, memory size, free storage, screen size, display density and font scale, system language and region settings, time zone, whether dark mode is on, network type (Wi-Fi, mobile data, etc.) and whether the connection is metered, the permission status for camera / microphone / photos / notifications / speech recognition, and whether a push token has been obtained
• App settings: theme, app language, primary currency, travel mode with its currency and exchange rate, the order and visibility of sections on the home and entry screens, calculator auto-open, budget chart and sort mode, the history screen's filter type (only whether a category filter is set — not which category, and never your search text), and how many tutorials you have seen
• Record counts: how many transactions, categories, recurring rules, quick-add presets, receipt groups and shared ledgers you have, the number and total size of photos, and how many deletions are pending — counts only, never any entry content
• Sync status: time and result of the last sync, current state, error type and error message, number of conflicts
• AI: the recognition engine and model you chose, whether each model is downloaded and its size, whether the device is supported, Apple Intelligence availability, whether inference runs on GPU or CPU, and the translation languages downloaded
• Recently visited screens: the names and times of roughly the last 20 screens you opened (screen names only, never what was on them)
The problem-report cloud space (Firestore); readable by the developer
App activity log and crash records Fino keeps a log of what its own code does, plus crash records, on your phone (see “Data that stays on your device” below). They are compressed and uploaded only when you send a problem report: the first time, everything currently kept on the phone is attached; later messages in the same report attach only what was added since the last upload.
Please note: the log may contain the item names and amounts parsed from receipt recognition, but not the full text recognised on the receipt, the store name, or the voice-entry transcript verbatim — those are reduced to a summary (such as character count, line count, elapsed time, and success/failure). The log does not contain your internal account identifier or the original file names of photos, but may contain technical details such as error messages.
Crash records are program errors that Fino catches itself (the error type and the call stack) — Fino's own record, separate from the automatic Crashlytics crash reports above: it is not affected by the “Send crash reports” switch and leaves the phone only when you send a problem report. Not every kind of crash can be captured, and only the most recent one is kept on the phone.
Only the developer can read these two kinds of file; once sent, you cannot view them in the app either.
The problem-report cloud file storage (Cloud Storage), readable only by the developer
Device integrity signals Android Play Integrity and iOS App Attest signals, via Firebase App Check. These are platform-generated technical attestations; they contain no personal data and exist to stop tampered clients from abusing our backend. This one is enabled at app launch and does not require you to sign in. Google / Apple platform services and Firebase App Check
Crash reports (Firebase Crashlytics) On by default; does not require you to sign in. When the app crashes, Google's Firebase Crashlytics automatically records a crash report and uploads it the next time you open the app: the call stack and error message at the moment of the crash, the app's state at that time, device information (manufacturer, model, OS version), the app identifier and version, and the Crashlytics installation identifier and Firebase installation ID. The Firebase Sessions feature that Crashlytics depends on also records each session in which you use the app (a randomly generated session ID, when the app came to the foreground, network type, and app and device information) so crash rates can be calculated.
Crash reports are not linked to your Fino account: we set no user ID and attach no custom logs or bookkeeping content.
You can turn this off under “Send crash reports” in the Settings tab: uploads stop immediately and crash reports on the phone that have not yet been sent are deleted; reports already sent cannot be recalled with this switch (see section 9 for how long they are kept).
Google (Firebase Crashlytics); the developer can view them in the Firebase console
Device and app technical information The Google SDKs Fino uses send some technical information back to Google automatically as they run, whether or not you sign in:
• Firebase (the SDKs behind push notifications, App Check, sign-in and cloud sync) attaches the device model, operating-system version, app identifier and version, and the Firebase SDK versions in use to its connections (on Android, also the app's install source, such as the Play Store). Push registration sends a Firebase installation ID, and on iPhone also the device's language and time zone.
• Google ML Kit (Android only; used for receipt text recognition, QR code scanning, item-name translation and language identification) reports, when you use those features, the device manufacturer, model and OS version, available machine-learning hardware accelerators, the app's package name and version, a per-installation identifier (which Google says is not intended to identify you or your phone), performance metrics (such as processing time), configuration parameters (such as image format and resolution), input and output sizes, feature version, event types and error codes. Translation additionally reports the source and target language codes and, through Firebase's remote configuration service, sends the country and language codes, time zone and OS version; language identification reports the detected language.
Google uses this data for diagnostics and usage statistics for its services. It contains no receipt images, no recognised text and no bookkeeping content.
Google (Firebase, ML Kit)

2. Data that stays on your device

DataDetails
Original images from AI receipt scanning On-device only by default; not uploaded. Receipts you photograph with the camera or pick from your photo library stay in the app's own scratch area on your device, for on-device recognition. The one exception is when you choose to save it: the confirmation screen shown after recognition has an “Save receipt photo” switch that is off by default and is off again every time you reach that screen. If you turn it on and save, the receipt is compressed to WebP and becomes a transaction photo shared by that batch of entries, uploaded with cloud sync once you are signed in (handled the same way as “Photos you attach to a transaction” above). Scanning a receipt in a shared ledger offers the same switch, also off by default; turning it on and saving there attaches the receipt photo to that shared entry, where every member of the ledger can see it. If you leave it off, the original receipt image is only used for recognition — it is neither saved nor uploaded.
Receipt text recognition and AI inference Runs entirely on your device. On Android: ML Kit for text recognition (OCR) plus an on-device Gemma model for understanding. On iOS: Apple Vision for text recognition plus Apple Foundation Models, an on-device Gemma model, or an on-device MLX Qwen3-VL model (whichever engine you choose in Settings). No cloud AI is involved at any point — our codebase contains no calls to Gemini, Vertex AI, OpenAI, or Cloud Vision. The recognition process does not write the receipt's full text verbatim into the app activity log — what is recorded is a summary such as the parsed item names, amounts, and elapsed time (see below) — and it is uploaded to the developer with that log only if you choose to send a problem report.
Translation of item names Translation runs on your device; the item text itself is never sent anywhere. On the AI confirmation screen you can tap once to translate foreign-language item names into the app's display language. Android uses Google ML Kit's on-device translation; iOS uses the system's built-in Apple Translation. The language packs this needs are downloaded to your device by the platform (on Android from Google's servers, roughly 30MB per language; on iOS managed by the system), after which translation happens entirely offline.
Local database An on-device Room database (5 personal tables plus 9 shared-ledger tables). This is what lets the app work offline.
App activity log, crash records and screen trail Kept in the app's own storage on your phone. By default: the general log keeps the last 3 days, up to about 2MB; the receipt-recognition log keeps the last 10 receipts; only the most recent crash record is kept; the screen trail keeps roughly the last 20 entries (the developer can adjust these limits remotely). Never uploaded automatically — only attached when you send a problem report. Cleared when you delete your account.
Problem-report numbers and unsent items This phone remembers the numbers of the reports you have sent so it can list them for you; reports and screenshots that could not be sent while offline wait on the phone and are sent automatically once you are back online.
Preferences Local preference keys (primary currency, theme, language, travel mode, AI engine choice, notification toggle, last sync time, and similar). Not uploaded.

An honest note about operating-system backups: the files above live in the app's own sandbox and Fino never sends them to Fino's backend. The two platforms differ:

Android: Fino turns off system backup, so the app's database and image files are not saved to your Google account by Android Auto Backup. However, according to Android's own documentation, on phones from some manufacturers a device-to-device transfer when you switch phones may still move the app's data directly to your new phone.

iPhone: if you have iCloud Backup turned on, the system may include the app's sandboxed database and image files in a backup to your own Apple account (downloaded AI model files are excluded from backup). That is a platform feature governed by your device settings; we cannot read or obtain those backups. You can turn iCloud Backup off for Fino in your system settings.

3. Why we need this data

We do not use any of the above for purposes other than the ones listed here.

4. Shared ledgers

Shared ledgers are optional. Nothing here applies unless you create a ledger yourself or join someone else's with an invite code.

Once you join a shared ledger, the other members of that ledger can see:

What other members cannot see: the personal category you privately assign to a shared line item never enters the shared data — the server-side rules hard-block category information from being written into shared line items, and your personal categories stay in your own space. Your personal transactions, budgets and personal ledger are likewise not exposed by joining a shared ledger.

Two things to be aware of:

1. The audit trail is append-only: it cannot be edited or deleted. Once written, neither you nor we can remove it from the ledger. This is deliberate — shared bookkeeping needs a trustworthy record to settle disputes. Treat it as permanent.

2. The invite-code lookup table is readable by anyone signed in. The 6-digit invite code, together with the details of the ledger it points to, is stored in an invite-code lookup table, and any signed-in Fino user can read it. This is by design: someone entering an invite code must be able to look it up in order to join. The table contains the code, ledger ID, and creator, plus the ledger's name, the admin's display name, and the ledger's icon and colour (so that after entering a code, and before deciding whether to join, you can confirm you found the right ledger) — not ledger content or amounts. But it does mean an invite code is not a secret — nor are the ledger name and admin name that come with it: share codes only with people you trust, and ask the ledger admin to clean up codes you no longer need once everyone has joined.

Shared ledgers are a separate subsystem from personal bookkeeping, with their own storage location and access rules. Joining a ledger does not expose your personal transaction records to other members.

5. Device permissions

In addition, the Firebase push-notification and background-work libraries included in the Android app automatically add a few normal permissions (for example WAKE_LOCK, RECEIVE_BOOT_COMPLETED and the permission used to receive push messages) so that notifications can be delivered and background downloads can resume when needed. These are never prompted for and do not let Fino read your personal data.

When permissions are requested: the notification permission is requested when you sign in (recurring-transaction reminders and shared-ledger notifications both need it; on iPhone you may also be asked the first time you download an AI model; you are also asked the first time you send a problem report, so the developer's reply can reach you). Every other permission that needs your consent is requested only the first time you use the feature that needs it. You can decline; the related feature (or notification) simply will not work.

6. Voice entry (please read this section)

The guarantee differs between iOS and Android. Please read the part that applies to you.

iOS: audio never leaves your device. Fino uses SFSpeechRecognizer with on-device recognition enforced . Before listening starts we also check that the language supports on-device recognition; if it does not, we simply report the feature as unavailable rather than falling back to Apple's servers.

Recording with Siri on iOS is a separate path: if you record an entry by talking to Siri, listening and speech-to-text are handled by Siri, not by the Fino speech recognition described above, so that guarantee does not apply. This part is governed by Apple's privacy policy (please see the privacy policy on Apple's official website and the Siri notes in iPhone Settings). Fino only receives the text Siri produces.

Android: on-device recognition is preferred, but not guaranteed. Fino uses the system speech recogniser and requests offline recognition . On Android this is only a preference, not a hard constraint — if your device has no local model for that language, the system may still fall back to Google's servers, without telling us. So on Android, your recorded audio may be sent to Google's speech recognition servers for processing.

If audio does leave the device, that processing is governed by the platform's own privacy policy. Please also read Google's privacy policy (the privacy policy on Google's official website, plus the voice and voice-input notes in Android Settings). We deliberately do not print external URLs here so they cannot rot.

Where Fino stands: we do not store your audio, do not send audio to Fino's backend, and do not keep recordings. We only use the recognised text to create one bookkeeping entry. If you are on Android and do not want audio to have any chance of leaving your device, do not use voice entry — manual entry and receipt scanning involve no audio at all.

7. Third-party services

ServiceProviderWhat it receives
Firebase Authentication Google Your sign-in identity: uid, email, avatar URL, sign-in provider.
Cloud Firestore Google All fields of your transactions (including your note text), categories, budgets, recurring rules, templates, currency setting, shared-ledger content and audit trail, the invite-code lookup table, and the problem reports, conversations and diagnostic information you send.
Cloud Storage Google Photos you attach to transactions (WebP), including receipt photos you choose to save on the AI receipt confirmation screen, and photos attached to shared-ledger entries; screenshots you attach to problem reports, and the app activity log and crash records attached when you send one. Not the original images from AI receipt scanning that you did not choose to save.
Cloud Functions Google Runs server-side logic (for example notifications for shared ledgers and problem reports, and consistency handling), which touches the Firestore data above while doing so.
Firebase App Check Google (with Play Integrity / Apple App Attest) Device integrity attestations. No personal data. Its connections also carry the device and app technical information common to Firebase SDKs (see “Device and app technical information” in section 2).
Firebase Cloud Messaging (FCM) and Firebase Installations Google The Firebase installation ID and push token registered when the app launches, device and app technical information (on iPhone including language and time zone; see section 2), and the notification content (which may include a member's name, an amount, a ledger name, or a problem report's title and the opening text of a message).
Firebase Crashlytics (including the Firebase Sessions feature it depends on) Google Crash reports and session data (full list under “Crash reports” in section 2). Not linked to your Fino account; can be turned off under “Send crash reports” in Settings.
Apple Push Notification service (APNs) Apple Push delivery on iOS: the device push identifier and the notification content.
Sign in with Google / Sign in with Apple Google / Apple Whichever provider you choose learns that you signed in to Fino, and gives us your email plus your avatar and display name if available.
Google ML Kit (text recognition, QR code scanning, translation, language identification) Google Android only: the models for text recognition (including Chinese / Japanese / Korean), QR code scanning and language identification are bundled inside the app and run on-device; the language packs used to translate item names are downloaded from Google's servers after you agree. No receipt images and no bookkeeping data are sent. Per Google's own disclosure, every ML Kit feature reports device and app technical information, a per-installation identifier, performance metrics and error codes; Translation additionally reports the source and target language codes and Language ID reports the detected language, for diagnostics and usage statistics (full list under “Device and app technical information” in section 2) — what is sent is this technical information and language codes, not your receipt images or item text.
huggingface.co Hugging Face Serves the on-device AI model weight files we download. No user data is sent. They see only what any web request reveals: your IP address and User-Agent.
tw.rter.info rter.info Provides live exchange rates. No user data is sent — we fetch the whole rate table and never tell it what you are converting. They see only your IP address and User-Agent.

What we require of these third parties: we only share data with third-party services that provide the same or equal protection of user data as stated in this policy. Each service listed above is governed by its own privacy policy and data processing terms, and we use them solely to the extent necessary to deliver Fino's features. We do not hand your data to any third party for advertising, analytics, or user profiling, and we embed no third-party advertising networks, analytics, or tracking SDKs; Firebase Crashlytics is used only for crash reporting, not tracking, and can be turned off. (The Firebase and ML Kit SDKs in the table above report technical information to Google on their own; see “Device and app technical information” in section 2 for what that covers.)

8. What we do not do

9. Data retention and deletion

Data you sync after signing in stays in your cloud space until you ask us to delete it.

When transaction photos are deleted: when you delete a transaction, or remove its photo while editing it, that change reaches the cloud on the next sync; the photo file in the cloud is then removed by a clean-up job that runs once a day, within about 8 days — not the moment you delete it. If the same photo is attached to several transactions (for example several items recognised from one receipt), it is only deleted once all of those transactions have been deleted or had the photo removed. Photos on shared-ledger entries work the same way: they are only deleted once no entry in the ledger uses them and no member's entries brought back into a personal ledger use them either. Deleting your account is different: your own photos are deleted immediately (see below).

You can delete your account from inside the app at any time: the Delete Account entry at the bottom of the Settings tab.

The flow first asks you to deal with any shared ledgers you administer (hand them over or delete them), then to confirm the consequences and type a confirmation phrase, then to sign in again with the same Google/Apple account so we know it is you. Deletion runs immediately after that and requires no manual processing: your Firebase Authentication account, everything in your cloud space (including push tokens, your ledger list and your personal category assignments), your transaction photos in Cloud Storage, and the local data on that device are all removed. The only photos kept are those attached to shared-ledger entries, or still used by other members' entries (see the shared-ledger paragraph below). Problem reports you have sent are not deleted but anonymised and kept (see below).

If you have already uninstalled the app or cannot sign in, you can still email liokhgf@gmail.com from the address you use to sign in to Fino (so we can confirm it is you); the developer will complete the same deletion within 30 days of receiving the request.

Full instructions: Account and data deletion.

There are two ways to clear the local data on a device: (1) Delete Account (above) — once the cloud deletion finishes, the app also wipes that device's transactions, categories, budgets, recurring rules, quick-add presets, receipt groups, shared-ledger cache, transaction photos, app activity log and crash records, problem-report numbers, and preferences; (2) uninstall the app, which additionally removes any downloaded AI model files. Separately, the change-main-currency wizard offers a “reset data” option, but that only clears historical transactions as part of switching currency — it is not a full reset.

Clearing local data is not the same as deleting cloud data — as long as the account still exists, signing in again with it syncs your cloud data back. To actually delete cloud data, use Delete Account above.

After account deletion, shared-ledger entries are kept but you are anonymised: your display name and avatar are cleared, and other members see “Deleted user” in your place. Entries, splits and repayments still carry your internal account identifier (it determines whose money is whose — removing it would break the other members' balances outright), and the item names and entry notes you typed are kept as-is, because they are the ledger's content. Photos you attached to shared entries are kept too, and other members can still see them. Avoid putting personal information you would not want left behind into shared-ledger free-text fields or photos.

The shared-ledger audit trail is append-only: the server-side rules forbid any update or deletion. If you leave a ledger or your account is deleted, the audit entries already written stay in that ledger exactly as they are, because the remaining members still need that record to reconcile their accounts. The audit trail records only the actor's internal account identifier and the before/after values — not your display name or email. Please factor this in before joining a ledger.

Problem-report retention: the reports, conversations, screenshots and diagnostic information you send are kept in the problem-report cloud space with no automatic deletion period; the app activity log and crash-record files uploaded with a report are deleted automatically 90 days after upload. “Deleting” a report in the app only removes it from your list, and you can no longer read it yourself; the developer keeps the full record of that report (conversation, screenshots, diagnostic information and log files) to deal with the problem. If you want the developer to erase a report completely, email liokhgf@gmail.com with the report's title and roughly when you sent it, and the developer will action it within 30 days of receiving the request.

After account deletion, your problem reports are kept but anonymised: the link between each report and your account, the push token stored on it, and the internal account identifier in every message and in the diagnostic information are all cleared; the report content, screenshots, remaining diagnostic information and log files are kept. Log files are not rewritten one by one, so they may still contain your internal account identifier; they are deleted automatically under the 90-day period above. Reports you sent while not signed in, and that were never linked to an account, are outside the scope of account deletion (to have them deleted, use the email route above).

Crash-report retention: according to Firebase's official documentation, Crashlytics keeps crash stack traces and associated identifiers (Crashlytics installation identifiers and Firebase installation IDs) for 90 days before starting to remove them from live and backup systems. Crash reports are not linked to your account, so deleting your account does not, and cannot, delete crash reports already sent by account; they are removed on that schedule. If you do not want any more sent, turn off “Send crash reports”.

Third-party services also have their own retention behaviour: Google (Firebase, FCM, Crashlytics, ML Kit, Android cloud speech recognition) and Apple (APNs, Siri) retain and delete data according to their own policies, and we cannot delete records on their side on your behalf.

10. Children

Fino is a bookkeeping tool for general adult users. It is not designed for children under 13 and is not marketed to children. We do not knowingly collect personal data from children. If you are a parent or guardian and find that your child created a Fino account without your consent, email liokhgf@gmail.com and we will delete the account and its data.

11. Where your data is stored

Fino's Firebase backend is configured in asia-east1 (Taiwan), and every server-side function — shared-ledger notifications, problem-report notifications, transaction-photo clean-up and account deletion — is deployed in that same region, so your cloud data is primarily stored and processed in Taiwan.

Beyond that, Firebase is a global service operated by Google, and in the course of delivering it (network transit, redundancy, notification delivery) Google may process data in facilities in other regions. That part is governed by Google's data processing terms and is outside our control. Likewise, iOS notifications travel through Apple's APNs, speech for recording with Siri is processed by Apple, on Android speech recognition may run on Google's servers when the system falls back to the cloud, and the technical information ML Kit reports is received by Google, in locations those companies determine. Firebase Crashlytics is a global Google service not bound by the asia-east1 setting above: crash reports may be processed and stored in Google data centres outside Taiwan.

12. Security

To be honest about it: no system is perfectly secure. Fino is run by one independent developer. We use the standard security mechanisms the platforms provide and do our best, but we cannot guarantee that nothing will ever go wrong. If an incident affects the security of your data, we will explain it here and in the app.

13. Changes to this policy

If the way Fino handles data changes, we will update this page and change the "Last updated" date at the top. For significant changes — for example collecting a new category of data, or changing what gets uploaded to the cloud — we will tell you prominently inside the app before the change takes effect.

Questions about this policy: liokhgf@gmail.com.