← Back to FinTracker

Privacy Policy

Last updated:

The short version

  • Your data lives on your device. There are no accounts and no cloud sync — we couldn’t read your transactions if we wanted to.
  • Waitlist signups are stored in the EU (Frankfurt) and used only to email you when FinTracker launches.
  • We don’t sell your data, we don’t run ads, and we don’t embed Google or Meta tracking.
  • AI features send the minimum needed for each task — short text and compact summaries, never audio, never your full history. OpenAI does not use your inputs to train its models.

1. Who we are

Data Controller: Bao Labs LLC, a Wyoming limited liability company, located at 30 N Gould St, Ste N, Sheridan, WY 82801, United States.

Privacy contact: privacy@baolabs.dev.

For users in the European Economic Area, United Kingdom, or Switzerland: Bao Labs LLC is the data controller under the General Data Protection Regulation (GDPR) and equivalent regulations. You may exercise your rights of access, rectification, erasure, restriction, portability, and objection by contacting privacy@baolabs.dev.

For users in California: under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), you have rights including the right to know, right to delete, and right to opt out of the sale or sharing of personal information. We do not sell personal information. Contact privacy@baolabs.dev to exercise your rights.

2. What this policy covers

This policy explains how we handle personal data in two contexts:

  • Today (waitlist phase): this website and the email waitlist.
  • At app launch: the FinTracker iOS app and the few AI features that talk to our servers.

We’ll update this policy before any new processing activity goes live.

3. What we collect on the website today

When you sign up for the waitlist, we collect:

  • Your email address.
  • The timestamp of your consent and the version of this policy you consented to.
  • The source that referred you (e.g. homepage hero form vs. footer form), so we know which channels are working.

We do not set tracking cookies on this website. We do not run analytics today. We do not embed third-party ad pixels.

4. How the app handles your data

The FinTracker iOS app is local-first, with no user accounts and no cloud sync: your transactions, budgets, goals, and notes live in an on-device SwiftData store. We never see them.

  • Backups and new phones: your data is included in your normal iPhone backup, and that’s how it moves to a new iPhone. The app also offers a manual JSON export and a restore-from-export — files you control.
  • Voice logging is transcribed on your device: speech-to-text runs entirely on your iPhone, and audio never leaves your device. Only the transcribed text of your short spoken sentence is sent to our server in Frankfurt (EU), which passes it to OpenAI to parse into a transaction.
  • Bao chat and weekly insights work from a compact summary the app builds on your device — category totals, budgets, goals, and streak, never your full transaction history and never your notes. Your message and that summary go through our EU server to OpenAI. Replies are stored on your device only; we keep no server-side copy of your conversations. The free tier includes 3 chat messages per month.
  • Subscription status (when FinTracker Premium launches) will be handled by Apple and RevenueCat. We never see your card data — Apple processes payment. See the Subscription Terms.
  • Apple Pay tracking (planned, opt-in): in a future release, iPhone users may optionally enable Apple Pay tracking via Apple’s Shortcuts app. When enabled, an Apple Shortcuts automation forwards transaction details (amount, merchant, date) directly to FinTracker on your device, where they are categorized — using the same text-only AI parsing as typed and spoken entries — and stored locally in SwiftData. Bao Labs LLC servers do not store this Apple Pay data. You can disable Apple Pay tracking at any time in your Shortcuts app or in FinTracker Settings. Apple is the data source; FinTracker is the local recipient; no third-party data aggregator is involved.
  • The only app data on our servers: an anonymous device identifier (a random UUID generated on your device — not derived from you or your hardware) plus monthly usage counters for voice, chat, and insight calls, stored in Supabase (Frankfurt, EU) solely to enforce fair-use limits. It cannot be linked to your name or email. To have it deleted, email privacy@baolabs.dev — see How to delete your data.

See the AI Disclaimer for exactly what data leaves your device for each AI feature. We may, in the future, offer additional optional integrations with banks, fintech wallets, or payment services. Any such integration will be opt-in, every data processor involved will be disclosed, and this Privacy Policy will be updated before such an integration ships. You will retain control of which connections (if any) you authorize. As of 2026-08-06, no such third-party financial integrations are active beyond those listed above.

5. What we never collect

  • Bank login credentials, account numbers, or sort codes.
  • Social Security numbers, national identifiers, or government IDs.
  • Your precise or coarse location — FinTracker has no geolocation.
  • Your contacts, calendar, or photos beyond receipts you explicitly attach.
  • Advertising identifiers. We skip the iOS App Tracking Transparency prompt because we do not track you across apps or websites and we do not use the IDFA. Our Apple Privacy Nutrition Label will reflect this — minimal data linked to you, no data used for tracking.

6. How we use what we collect

  • Waitlist email: to send you one launch announcement plus occasional pre-launch updates if you opted in. You can unsubscribe from any email.
  • App data: to provide the FinTracker service — and because everything is stored on your device, that mostly means your iPhone doing the work: saving transactions, tracking budgets and goals, powering Bao chat and weekly insights.
  • Anonymous product analytics (live, with an opt-out): aggregated, de-identified usage events — feature counts and app version, never amounts, notes, or anything you typed or said — to understand which features matter and which break. You can opt out anytime in the app under Settings → Privacy & data, which stops analytics collection immediately. Crash reporting (section 8) is separate error telemetry and is not covered by this toggle.

We do not sell your data. We do not share it with advertisers. We do not use it to train AI models.

7. Where your data is stored

  • Website waitlist data: Supabase, Frankfurt, Germany (EU).
  • App fair-use counters (the only app-related data on our servers): Supabase, Frankfurt, Germany (EU).
  • Website hosting: Vercel, with global edge delivery for static assets. Form submissions land in the EU.

Some processing happens outside the EEA where strictly necessary:

  • OpenAI (United States) for parsing transcribed voice text, Bao chat, and weekly insights — short text and compact summaries only, never audio. We rely on the EU Standard Contractual Clauses and OpenAI’s enterprise privacy commitments.
  • Apple and RevenueCat for App Store delivery, payments, and subscription receipts.

8. Third parties we use

  • Supabase — waitlist storage and anonymous fair-use counters. Region: EU (Frankfurt).
  • Vercel — website hosting and edge delivery. Region: global with EU preference for compute.
  • OpenAI — parsing voice-transcript text into transactions, Bao chat, and weekly insights. Region: US, under SCCs.
  • PostHog — anonymous product analytics, live, with an in-app opt-out (Settings → Privacy & data). Region: PostHog EU Cloud.
  • Sentry — crash reporting, live, with PII sending disabled. Crash reports contain no finance data and are collected independently of the analytics opt-out — they are the error telemetry that keeps the app shippable. Region: EU (Frankfurt ingest).
  • RevenueCat (when Premium launches) — subscription receipt validation. Region: US, under SCCs.
  • Apple — App Store distribution and payment processing. Region: per Apple.

Each provider acts as a data processor on our instructions, with a contract that meets GDPR Article 28 requirements.

9. Your rights under GDPR

If you’re in the EEA or UK, you have the right to:

  • Access the personal data we hold about you.
  • Correct anything inaccurate.
  • Delete your data (the "right to be forgotten").
  • Export your data in a portable format.
  • Object to processing, or restrict it.
  • Withdraw consent at any time — for the waitlist, the unsubscribe link does this immediately.

To exercise any of these rights, email privacy@baolabs.dev. We’ll respond within 30 days, free of charge. Because your finance data lives on your device, you can exercise most of them yourself: export everything as JSON or delete everything, right in the app’s Settings — see How to delete your data.

You can also lodge a complaint with your local data protection authority. For UK residents, that’s the ICO (ico.org.uk). For EU residents, it’s your national DPA.

10. Children

FinTracker is not intended for users under 16. We do not knowingly collect data from children under 16. Users between 13 and 16 can only use FinTracker with verified parental consent, in line with Apple’s App Store policies and applicable national rules on the minimum age for digital consent.

If you believe a child has signed up to the waitlist, email privacy@baolabs.dev and we’ll delete the record.

11. How long we keep your data

  • Waitlist signups: until the launch announcement, then for 90 days, then deleted. If you unsubscribe earlier, your email is deleted within 14 days.
  • App data: lives on your device for as long as you keep it — we don’t have a copy. "Delete all data" in the app’s Settings erases the on-device store immediately; there is no account to close because none exists. The anonymous fair-use counter on our servers is deleted on request via privacy@baolabs.dev.
  • AI conversations: Bao’s replies are stored on your device only — we keep no server-side copy of your conversations. OpenAI may retain API content for up to 30 days for abuse monitoring and then deletes it.

12. Security

  • Everything sent to our servers is encrypted in transit (TLS 1.2+) and at rest (AES-256). On your iPhone, your data is protected by iOS device encryption.
  • Our Supabase database holds only waitlist emails and anonymous usage counters, protected with Row Level Security — there is no store of user finance data to breach, because we never collect it.
  • No team member has direct production database access without an audit trail.
  • We notify affected users and the relevant DPA of any qualifying breach within 72 hours, per GDPR Article 33.

13. Changes to this policy

We’ll update this page when our practices change and refresh the "last updated" date at the top. For substantive changes, waitlist members will receive an email at least 14 days before the new policy takes effect.

14. Contact