Who We Are & Your Consent
Fynora is operated by Fynora Technovation LLP, registered at 463, Sita Ram Compound, Chaman Ganj, Sipri Bazaar, Jhansi, Uttar Pradesh, 284003, India. Under the DPDP Act, Fynora Technovation LLP is the "Data Fiduciary" for the personal data described in this policy, and you are the "Data Principal." We process your personal data on the basis of the consent you give when you create an account and when you take actions in the app that involve sharing further data (such as importing a statement) — described in plain terms in the sections below, as the Act requires. You may withdraw consent at any time; since Fynora's core features depend on ongoing access to the data you've provided, withdrawing consent in practice means deleting your account (see Data Deletion below). Withdrawal does not affect the lawfulness of processing carried out before you withdrew it.
Information We Collect
Fynora collects the information you provide directly (registration details, account and transaction data you add or import) and a small amount of technical information needed to operate the Service securely (login timestamps, IP address at login, device/browser information for session security).
Personal Information
This includes your full name, email address, and mobile number, collected at registration and used for authentication (including email-or-phone login), account recovery, and OTP-based phone verification.
Financial Data
Fynora stores the accounts, transactions, budgets, goals, and categorization data you create or import. This data is used exclusively to power the features you use — dashboards, reports, budgets, and insights — and is never sold to third parties or used for advertising.
Uploaded Statements
When you import a bank or credit card statement, the original file is stored securely and linked to your account so you can re-download it or re-process it later from Statement History.
In most cases statements are processed entirely automatically by Fynora's own rule-based extraction logic — Fynora does not send your statement or its contents to third-party AI services such as OpenAI, Anthropic, or Google Gemini. When an import cannot be processed automatically, it is queued for review, and authorized staff may access the statement to diagnose and fix the problem. Every such access is logged and auditable; see Administrative Access below.
Gmail Sync & Google User Data
If you choose to connect a Gmail account (an optional feature, off unless you turn it on from Settings), Fynora requests read-only access to that mailbox (the gmail.readonly scope) to detect transactions automatically from receipt and payment-confirmation emails — nothing is ever sent, modified, or deleted in your mailbox, and Fynora never requests permission to do so.
Fynora only reads the content of messages from a known, authenticated list of merchant and payment providers (for example Amazon, Uber, or PhonePe) — mail from every other sender is skipped based on its headers alone, without its body ever being fetched. From a message it does read, Fynora extracts only the transaction details needed for your ledger (merchant, amount, date); the message itself is not stored — what's kept is Gmail's own message ID and the outcome of processing it (so a message is never re-processed), not its content.
You can disconnect a Gmail account at any time from Settings. Disconnecting revokes Fynora's access at Google immediately, in addition to deleting the stored credential — it is not merely a local on/off switch.
Fynora's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Cookies
Fynora uses essential, session-related storage (such as your authentication token) to keep you signed in. We do not currently use third-party advertising or tracking cookies.
Analytics
We may collect aggregated, non-identifying usage data (such as which features are used most) to improve the product. This is never combined with your individual financial data for any purpose outside operating and improving Fynora itself.
Data Usage
Your data is used to: provide the core features you sign up for; generate categorization suggestions and financial insights (via Fynora's own rule-based logic, not a third-party AI service — see Uploaded Statements above); detect duplicate or transfer transactions; and secure your account (fraud/lockout detection on repeated failed logins).
Infrastructure & Service Providers
Fynora runs on the following infrastructure and service providers, each processing only what its function requires:
- Firebase Authentication (Google) — sign-in and identity verification.
- Railway PostgreSQL — our primary database.
- Cloudflare R2 — storage for the original statement files you upload.
- Railway — backend application hosting.
- Cloudflare — frontend/website hosting and edge security.
- Resend — transactional email delivery (verification, password reset, notifications).
- TwoFactor — SMS/OTP delivery for phone verification.
Some of these providers operate outside India — see Cross-Border Data Transfer below for how that's handled under the DPDP Act.
Data Encryption & Security
Passwords are hashed with bcrypt and never stored or logged in plain text. Password reset tokens and session refresh tokens are stored hashed, not in plain text, so a database compromise alone cannot be used to reset an account or hijack a session. Sessions are scoped per device, visible and individually revocable from Settings, and bounded by several limits: the short-lived access token behind each request expires every 15 minutes; a session signs itself out after 30 minutes of inactivity, and in any case after 7 days from when you signed in, even with continuous use; and each use of a session automatically rotates it to a new token, so a token used more than once is treated as a sign of compromise and every session on the account is signed out as a precaution. All traffic between your device and Fynora's servers is encrypted in transit (HTTPS/TLS), and our website enforces HTTP Strict Transport Security (HSTS).
Where we hold a live credential to an external account on your behalf — currently, a connected Gmail account's access token — it is encrypted at rest with a dedicated application-level encryption key (AES-256), separate from and unrelated to your login password. Your other financial data (transactions, accounts, statements, budgets, goals) is protected by the security of the underlying infrastructure listed above (Railway, Cloudflare R2), rather than by an additional layer of Fynora-managed encryption on top of it.
Administrative Access
Access to customer data by Fynora staff is governed by role-based permissions — a staff member only has access to the specific data their role requires, not blanket access to all customer data. Every administrative access to your data is logged and auditable, and access is permitted only where necessary to operate and support the Service (for example, reviewing a statement that failed automated processing — see Uploaded Statements above).
Data Breach Notification
If a personal data breach occurs, we will notify the Data Protection Board of India and affected users as required under the DPDP Act, and take steps to contain and remediate the breach.
Data Retention
Your data is retained for as long as your account is active — Fynora does not automatically delete statements, transactions, or other data from an active account. If you delete an individual account (a bank/card/investment account you've added within Fynora), it and its statements continue to appear in Statement History for 7 days before being dropped from that view, purely so recent context isn't lost abruptly; there is no separate "undo delete" action.
We maintain routine backups of our production database for disaster recovery, with point-in-time recovery enabled. Because of this, a small amount of data may persist in encrypted backups for a limited period after you delete it from the live system, until those backups themselves cycle out — this is standard practice and does not mean the data remains accessible or in active use.
Security event logs (audit logs) of account activity are kept indefinitely for security purposes, but the detailed content of each event is cleared after 730 days, leaving only a minimal record (who, what, when) for as long as the log entry itself exists.
Your Rights Under the DPDP Act
As a Data Principal under the DPDP Act, you have the right to:
- Access a summary of the personal data Fynora holds about you and how it is being processed.
- Correct or update inaccurate or incomplete personal data — directly in the app (Settings, Accounts, Transactions) for most fields, or by contacting [email protected].
- Erase personal data that is no longer needed for the purpose it was collected for — see Data Deletion below.
- Withdraw consent at any time, as easily as you gave it.
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity, by contacting [email protected].
- Grievance redressal — see below — and, if unresolved, the right to file a complaint with the Data Protection Board of India.
Grievance Redressal
If you have a complaint about how Fynora handles your personal data, contact our Grievance Officer, Vishnu Narayan Tiwari, at [email protected] with the details of your concern. We aim to acknowledge and resolve grievances within 30 days. If you're not satisfied with the outcome, you may escalate the complaint to the Data Protection Board of India.
Data Export
You can export your Fynora data at any time from Settings, on both the web app and the mobile app. Your export downloads as a ZIP archive containing your accounts, transactions, budgets, goals, and other data as JSON files, plus the original statement files you uploaded in their original format, along with a manifest listing exactly what's included (and, for transparency, what's deliberately excluded and why). Exporting requires you to re-confirm your password (or Google/Apple sign-in), the same as account deletion.
Data Deletion
You can delete individual transactions, accounts, or statements at any time from within Fynora. You can also delete your entire Fynora account yourself, from Settings on either the web app or the mobile app — this requires you to re-confirm your password (or Google/Apple sign-in) plus a one-time code sent to you, as a safeguard against someone else deleting your account without your knowledge.
Account deletion is immediate and permanent once confirmed — there is no waiting period and no self-service way to undo it. Your transactions, budgets, and goals are permanently removed, and your personal information (name, phone number, email) is erased or replaced with an anonymized placeholder at that point.
Two known exceptions, disclosed here rather than left unstated: (1) a deleted statement's original filename and the account-holder name Fynora automatically detected on it are marked deleted but not currently erased from our database — and, for a statement imported before Fynora moved statement files to dedicated object storage, the original file itself may still be present in the database row the same way. We're aware of this and are working to close it. (2) As described under Data Retention above, a copy of your data may briefly persist in an encrypted backup until that backup cycles out. If you'd rather not go through the in-app flow, you can also request deletion by contacting [email protected].
Third-Party Services
Fynora does not sell your data to third parties. Each infrastructure and service provider listed above under Infrastructure & Service Providers receives only the minimum information needed to perform its specific function (for example, an email provider receives your email address and message content, not your transaction history).
Cross-Border Data Transfer
Fynora's application data is currently hosted and processed on servers located outside India (in the United States). Some third-party services we use for authentication and communications are also based outside India. The DPDP Act permits this kind of transfer except to countries the Government of India specifically restricts by notification; we do not transfer data to any such restricted country. Wherever your data is processed, it remains subject to the protections described in this policy.
Children's Data
Fynora is intended for users 18 years of age or older and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, contact our Grievance Officer at [email protected] and we will delete it.
Policy Updates
We may update this policy from time to time. Material changes will be reflected by an updated "Last updated" date at the top of this page.