Fimerse Privacy Policy

Last updated: 2026-08-23 · Effective: 2026-08-01

Fimerse ("Fimerse", "we", "us") is a personal-finance app (with multi-currency support) operated by Ozaar LLC, a US limited liability company registered in Delaware (the "data controller" for the purposes of EU/UK data-protection law). This policy explains what we collect, why, and your choices. Questions or requests: support@fimerse.com.

What we collect

We do not connect to your bank, use account-aggregation services, or collect data from third parties about you. Everything in Fimerse is data you gave us.

When you first sign up, Fimerse suggests a currency based on your device's own language and timezone settings. That guess is made inside your browser: your location is never looked up, and no request leaves your device to work it out. You can change the suggestion before finishing setup, and at any time afterwards.

Cookies and browser storage

Fimerse uses your browser's local storage to keep you signed in (a session token) and to remember interface preferences (like the screen you were last on). We do not use advertising or tracking cookies, and there are no third-party trackers on the site.

Our own visit counting stores nothing at all on your device, which is why you have not been asked to accept anything. See "How we count visits" below for exactly what it records.

How we count visits (first-party analytics)

We measure how the website and the app are used, on our own server, and no third party receives any of it. There is no Google Analytics, no advertising pixel, and no session-replay tool. This is also why our subprocessor list below gains no entry for analytics: there is nobody to add.

Nothing is stored on your device for this. No analytics cookie, and no identifier in local storage either, which matters legally as well as practically: EU/UK rules cover any storage on your device, not just cookies. Because we store nothing, you are not asked to accept anything.

What a recorded event contains:

How we count people without identifying them. Instead of storing an id on your device, our server derives a one-way code each day from a shortened form of your IP address (the last part is discarded) plus your browser's version string, mixed with a random secret that changes every day. The secret is deleted along with the events it covers, so once a day has aged out, those codes cannot be traced back to anyone, even by us, and even from a copy of our database. Being honest about the limits: this makes visitor counts an approximation, and because the secret changes daily we cannot tell whether you have visited before.

Campaign tags in a link. When we post a link on social media we add a few words to the end of the web address saying where we posted it, for example utm_source=instagram&utm_medium=bio. They record the post, not the person: everybody who clicks the same link sends exactly the same words, they are visible in your address bar and you can edit or delete them, and nothing about them is derived from you or your device. We keep three of them, shortened and stripped of anything but plain letters and digits, so we can tell which posts were worth making. We do not use the tag that carries search keywords.

Linking a visit to an account. If you sign up, the visit that brought you there is recorded on your account, so we can see which pages help people decide, along with the campaign tags of the link you arrived through, if there were any. Both are held in your browser's memory for that visit only, never a cookie, and both are deleted when you delete your account.

It shrinks with age. Individual events are deleted after 90 days and only anonymous daily totals remain, so what we hold about any single visit gets smaller over time rather than accumulating.

If we ever add a tracking cookie, a third-party script, or an advertising pixel, we will ask for your consent first, because at that point we would be required to.

How uploaded statements are handled

When you upload a statement, the file is written to a temporary, access-restricted directory on our server, read by our AI extraction step to pull out the account details and transactions, and then the file is deleted. We keep the extracted transactions, not the original document. Password-protected PDFs are decrypted in that same temporary directory only for long enough to read them, and the decrypted copy is removed afterward too. We also keep a cryptographic fingerprint (hash) of each imported file (not its contents), so re-uploading the same statement doesn't create duplicates; you can clear these fingerprints with the "clear all data" action.

Notifications on your phone

The Fimerse mobile app can send you a notification when a bill is due, when one is overdue, or when an account balance looks out of date. This is off until you turn it on, from the toggle in Settings. If you never turn it on, nothing in this section happens: no token is registered for your phone and no notification is ever sent, so none of your data reaches any of the parties below.

When you do turn it on, two things leave our server:

Delivering that to a lock screen is not something we can do ourselves. It travels through Expo, which operates the push service the app uses, and then through Apple's or Google's push network, which is the only way any app reaches your phone. All three are listed as subprocessors below.

You can turn notifications off again at any time from the same toggle, which removes the token. Signing out removes it too, and deleting your account deletes it with everything else.

How we use AI

Statement import, insights and the advisor are powered by Anthropic (the makers of Claude), acting as our processor. Two kinds of data are sent to Anthropic's API, and it's worth being precise:

We do not use your data to train any AI model, and Anthropic's API terms commit it not to train on data submitted through the API. AI output in Fimerse (categorization suggestions, insights, advisor replies) is informational only; it produces no legal or similarly significant automated decision about you, and you can always review, correct, or ignore it.

Where your data is stored, and international transfers

Your data lives in a SQLite database on our own server (a virtual private server we operate in New York, USA). Transport to and from the app is encrypted with HTTPS. Passwords and session/reset/verification tokens are stored hashed, never in plain text. Every request is scoped to your own account, so users cannot see each other's data.

Fimerse is operated from the United States, so if you use it from outside the US (including the EU/UK), your data is transferred to and processed in the US. Where EU/UK law requires a transfer safeguard, we rely on your explicit, informed consent given when you create an account and on the contractual necessity of processing your data to provide the service you signed up for.

Legal bases (EU/UK users)

Where GDPR applies, we process your data on these bases:

DataPurposeLegal basis
Account detailsCreating and securing your account, transactional emailContract (Art. 6(1)(b))
Financial data & advisor messagesProviding the Fimerse service you asked forContract (Art. 6(1)(b))
Server logs, rate limiting, error reportsKeeping the service secure and workingLegitimate interest (Art. 6(1)(f))
Anonymous usage counters & merchant mappingsImproving the product (no profiling of you)Legitimate interest (Art. 6(1)(f))

Subprocessors

We rely on a small number of third parties to run Fimerse:

SubprocessorPurpose
AnthropicAI processing: statement extraction (receives full uploaded documents) and insights/advisor (receives financial summaries and recent chat messages).
ResendSending transactional email (verification, password reset).
DigitalOceanThe virtual server (New York, USA) that runs Fimerse and stores its database.
Cloudflare R2Continuous off-site backups of the database (US region; encrypted at rest by the provider).
ExpoDelivering phone notifications, only if you turn them on. Receives your phone's push token and the text of the notification. See "Notifications on your phone" above.
Apple and GoogleThe push networks that carry a notification the last step to your phone, only if you turn notifications on. Which one applies depends on your phone.
PaddleTaking payment, only if you buy something. Paddle is the merchant of record: they receive your name, address and card details directly, and Fimerse never sees them. They also handle refunds and sales tax. See "Payments" below.

Payments. Paddle is the merchant of record for Fimerse Plus and for credit top-ups. That means Paddle, not Fimerse, takes the payment: your card details are entered on their checkout and are never sent to us, seen by us, or stored by us. What we keep is Paddle's own reference for your billing account and subscription, the plan you are on, and the date your period ends. To change your card, see your invoices or cancel, we send you to Paddle's customer portal, because they hold that information and we do not.

To pay you tell Paddle your name, address and card, which they need for the payment and for sales tax. They tell us none of it. We pass Paddle one thing about you: the internal reference for your Fimerse account, so a payment can be matched to the right account. Not your email, not your name.

What we do NOT do

Who can access your data

Access to the production server is limited to Fimerse's operator, over key-based authentication. Day-to-day operations use aggregate signals (uptime, error counts, usage events like "a statement import succeeded"), not the contents of your accounts or transactions. We look at an individual account's data only if you ask us to (support) or if it's strictly necessary to investigate abuse or a security incident.

Your rights and choices

Backups: after you delete data or your account, residual copies may persist in encrypted backups for a short retention window before they roll off (see our backup retention, currently 7 days).

Data retention

Security

We use HTTPS for all traffic, hash passwords (scrypt) and all sensitive tokens, isolate every user's data at the query layer, rate-limit authentication and AI endpoints, and sandbox uploaded files in restricted temporary directories. The database and statement-processing workspace live on an encrypted-at-rest storage volume, and off-site backups are stored with a provider that encrypts data at rest. No system is perfectly secure, but we take reasonable measures appropriate to a service of this kind.

If we become aware of a breach of security affecting your personal data, we will notify you and, where required, the relevant authorities without undue delay.

Children

Fimerse is not directed to children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.

Changes to this policy

We may update this policy; we'll change the "Last updated" date and, for material changes, notify you by email or in the app.

Contact

Ozaar LLC, Delaware, USA. support@fimerse.com.