Privacy Policy

Last updated: February 22, 2026

FinanceIQ (“we,” “us,” or “our”) respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application (the “Service”).

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

  • Email address
  • Password (stored in hashed form via Supabase Auth)
  • Company profile information you provide during onboarding (company name, industry, location, employee count range, revenue range, entity type, description)

1.2 Financial Data

When you upload financial statements, we store:

  • Uploaded files (CSV, XLSX, PDF) and their parsed contents
  • Financial data including profit & loss statements, balance sheets, and cash flow statements
  • Chart of accounts, period information, and financial line items
  • Computed KPIs, projections, scenarios, equipment analyses, and variance data

1.3 Usage Data

We automatically collect:

  • AI conversation history (questions you ask and AI responses)
  • AI usage counts for rate limiting
  • Upload timestamps and processing status

1.4 Technical Data

Standard web application data including browser type, IP address, and session information as processed by our hosting and authentication providers.

2. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve the Service
  • Process and analyze your uploaded financial data
  • Generate AI-powered financial analysis and insights
  • Compute KPIs, projections, and financial models
  • Authenticate your identity and manage your account
  • Enforce rate limits and prevent abuse
  • Communicate with you about the Service

3. Third-Party Services and Data Sharing

We use the following third-party services to operate the platform:

Supabase (Database & Authentication)

Stores your account information and financial data. Supabase processes data in accordance with their privacy policy and applicable data protection laws. Row-level security policies ensure your data is accessible only to you and your company members.

Anthropic (AI Analysis)

When you use the AI CFO feature, your financial data and conversation are sent to Anthropic's Claude API for processing. Anthropic processes this data in accordance with their API data usage policies. We use the API tier that does not use your data for model training.

Vercel (Hosting)

The Service is hosted on Vercel's infrastructure. Standard server logs may be collected by Vercel in accordance with their privacy policy.

We do not sell, rent, or trade your personal information or financial data to third parties. We do not share your data with third parties for marketing purposes.

4. Data Security

We implement commercially reasonable security measures to protect your data, including:

  • Encrypted data transmission (HTTPS/TLS)
  • Hashed password storage via Supabase Auth
  • Row-level security policies in the database
  • Company-scoped data isolation

However, no method of electronic storage or transmission is 100% secure. We cannot guarantee the absolute security of your data and accept no liability for unauthorized access resulting from factors beyond our reasonable control.

5. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymize your data within 30 days, except where retention is required by law or legitimate business purposes (e.g., preventing fraud, resolving disputes).

6. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your data
  • Export your data in a portable format (the Service provides CSV export functionality)
  • Withdraw consent for data processing

To exercise any of these rights, contact us at privacy@financeiq.app.

7. Children's Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18.

8. Cookies and Local Storage

The Service uses browser local storage to persist user preferences (theme selection, insights panel visibility, dashboard widget configuration). We use session cookies for authentication via Supabase Auth. We do not use third-party tracking cookies or analytics tools.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Service with a new “Last updated” date. Your continued use of the Service after changes constitutes acceptance.

10. Contact

For questions about this Privacy Policy, contact us at privacy@financeiq.app.