Privacy Policy

Last updated: June 3, 2026

This policy explains, in plain language, what data Fintab collects, why, with whom we share it, and how you can exercise your rights under GDPR (EU 2016/679) and LGPD (Brazilian Law 13.709/2018).


1. Who we are (Data Controller)

Fintab is a personal finance app developed and operated by:

You may contact the DPO at any time via the email above.

2. What data we process

2.1 Account & authentication data

If you use Sign in with Apple and choose "Hide My Email", we only receive the relay address (@privaterelay.appleid.com). We treat this relay as a regular email.

2.2 Financial data you record

2.3 Local notifications

The app may schedule local reminders on your device (e.g., recurring transaction alerts) with your permission. These reminders are processed locally only; no notification content is sent to our servers. On iOS, we do not read system or third-party app notifications.

2.4 Pro subscription

Payment itself is processed by the Apple App Store or Google Play. We have no access to your credit card or payment method.

2.5 Account sharing (collaborators) — Pro

If you invite someone to share your account, we store: master's email and name, invitee's email, invitation status, and the collaborator's UID after acceptance.

2.6 Data stored only on your device

2.7 What we DO NOT collect

3. How we process data

4. Why we process (purpose + legal basis)

CategoryPurposeGDPR legal basis
Account / authenticationAllow login and identify you in the appArt. 6(1)(b) — Contract performance
Financial dataCore functionality: record and display your financesArt. 6(1)(b) — Contract performance
Pro subscriptionValidate active plan and unlock paid featuresArt. 6(1)(b) — Contract performance
Sharing invitationsAllow two users to access the same accountArt. 6(1)(b) — Contract performance
Support communicationsReply to emails you send usArt. 6(1)(f) — Legitimate interest

Under Brazilian LGPD the bases are equivalent: Art. 7, V (contract execution) and Art. 7, IX (legitimate interest).

5. Sharing with third parties (subprocessors)

We share the minimum necessary with the following processors:

SubprocessorData sharedPurpose
Google LLC — Firebase AuthenticationEmail, UID, password (hash), OAuth tokensAuthentication
Google LLC — Cloud FirestoreAll financial data linked to UIDBackend storage
Apple Inc. — Sign in with AppleNonce; in return: identityToken + email + name (only on first login)Authentication
Apple Inc. — App Store / StoreKitpurchaseToken, productIdProcess and validate Pro subscription (iOS)
Google LLC — Google Play BillingpurchaseToken, productIdProcess and validate Pro subscription (Android)

There are no other subprocessors. No advertising, analytics, or attribution SDKs.

About the "share" function

When you export a report as PDF/Excel, the app uses the OS-native share sheet. The destination (email, Drive, WhatsApp, etc.) is chosen by you; Fintab does not send anything automatically to third parties.

6. Where data is stored

7. How long we keep data

8. Your rights (GDPR Arts. 15–22 + LGPD Art. 18)

At any time and free of charge you may:

  1. Confirm whether we process data about you
  2. Access your data
  3. Rectify incomplete, inaccurate, or outdated data
  4. Erase data (right to be forgotten)
  5. Restrict processing
  6. Port your data to another provider
  7. Object to processing
  8. Withdraw consent
  9. Lodge a complaint with a supervisory authority

How to exercise each right

9. Security

We apply technical and organizational measures to protect your data:

10. Children

Fintab is not directed at children under 13 and does not knowingly collect data from children. If you are a guardian and identified that a child provided us with data, contact alexandreweb2@gmail.com for removal.

11. Auto-renewable Pro subscriptions

Fintab Pro is an auto-renewable subscription processed by the Apple App Store (iOS) or Google Play (Android). By subscribing:

See the Terms of Use for full subscription terms.

12. Changes to this policy

We may update this policy as the app evolves or to reflect regulatory changes. When there's a relevant change, we'll update the date at the top and, if the change significantly affects your rights, we'll notify you in-app or by email.

13. Other languages

This policy is available in:

14. Contact

Questions, requests, or complaints about privacy?

If you are unsatisfied with our response, you may contact your local Data Protection Authority. In Brazil: ANPD at gov.br/anpd.