Fimerse Privacy Policy
Last updated: 2026-08-04 · Effective: 2026-08-01
Fimerse ("Fimerse", "we", "us") is a personal-finance app (with multi-currency support) operated by Ozaar LLC, a US limited liability company registered in Delaware (the "data controller" for the purposes of EU/UK data-protection law). This policy explains what we collect, why, and your choices. Questions or requests: support@fimerse.com.
What we collect
- Account details. Your name, email address, and a securely hashed password. Your email is also used to verify your account and send transactional mail (verification, password reset).
- Financial data you enter or import. Accounts, balances, transactions, categories, budgets, savings goals, and bills. You provide this by typing it in, by importing a CSV, or by uploading a bank/card statement (PDF or image).
- Your questions to the AI advisor. The messages you send to the in-app money advisor, kept as chat history so the conversation has continuity. You can clear this history at any time from the advisor screen.
- Basic operational data. Standard server logs (which include your IP address) and rate-limiting counters needed to run and secure the service. If the app hits an error in your browser it also sends us a technical error report (the error message, page URL, and browser version, never your financial data), and we keep simple usage counters (e.g. that a statement import succeeded or failed, which bank the statement came from, and which currencies it held, never a payee, amount or account number). Category labels for recognized merchants are improved using anonymous merchant-name-to-category mappings aggregated across users: a shop name and its category only, never tied to any account, amount, date or person. **A name only ever becomes part of that shared list once several unrelated users have independently paid the same place**: what you alone type stays private to your account, so a person you pay, whose name means nothing to anyone else, is never shared, in any language. All of this is stored on our own server; we use no third-party analytics or error-tracking services, and the app's fonts and all other page assets are served from our own domain, so simply loading Fimerse makes no request to any third party.
We do not connect to your bank, use account-aggregation services, or collect data from third parties about you. Everything in Fimerse is data you gave us.
When you first sign up, Fimerse suggests a currency based on your device's own language and timezone settings. That guess is made inside your browser: your location is never looked up, and no request leaves your device to work it out. You can change the suggestion before finishing setup, and at any time afterwards.
Cookies and browser storage
Fimerse uses your browser's local storage to keep you signed in (a session token) and to remember interface preferences (like the screen you were last on). We do not use advertising or tracking cookies, and there are no third-party trackers on the site.
How uploaded statements are handled
When you upload a statement, the file is written to a temporary, access-restricted directory on our server, read by our AI extraction step to pull out the account details and transactions, and then the file is deleted. We keep the extracted transactions, not the original document. Password- protected PDFs are decrypted in that same temporary directory only for long enough to read them, and the decrypted copy is removed afterward too. We also keep a cryptographic fingerprint (hash) of each imported file (not its contents), so re-uploading the same statement doesn't create duplicates; you can clear these fingerprints with the "clear all data" action.
How we use AI
Fimerse's AI features are powered by Anthropic (the makers of Claude), acting as our processor. Two kinds of data are sent to Anthropic's API, and it's worth being precise:
- Statement import: when you upload a bank statement, the entire document (PDF, image, or CSV) is sent to Anthropic for extraction, as-is, with no redaction. That includes everything printed on it: the account holder's name, account and IBAN numbers, balances, and every transaction. If you don't want a document processed this way, don't upload it; you can always add transactions manually instead.
- Insights and the AI advisor: these send a compact summary of your finances (account balances, monthly income/spend totals, your largest transactions for the period, budgets, savings goals, upcoming bills) plus, for the advisor, your recent messages in that chat so the conversation stays coherent. They do not send your uploaded documents.
We do not use your data to train any AI model, and Anthropic's API terms commit it not to train on data submitted through the API. AI output in Fimerse (categorization suggestions, insights, advisor replies) is informational only; it produces no legal or similarly significant automated decision about you, and you can always review, correct, or ignore it.
Where your data is stored, and international transfers
Your data lives in a SQLite database on our own server (a virtual private server we operate in New York, USA). Transport to and from the app is encrypted with HTTPS. Passwords and session/reset/verification tokens are stored hashed, never in plain text. Every request is scoped to your own account, so users cannot see each other's data.
Fimerse is operated from the United States, so if you use it from outside the US (including the EU/UK), your data is transferred to and processed in the US. Where EU/UK law requires a transfer safeguard, we rely on your explicit, informed consent given when you create an account and on the contractual necessity of processing your data to provide the service you signed up for.
Legal bases (EU/UK users)
Where GDPR applies, we process your data on these bases:
| Data | Purpose | Legal basis |
|---|---|---|
| Account details | Creating and securing your account, transactional email | Contract (Art. 6(1)(b)) |
| Financial data & advisor messages | Providing the Fimerse service you asked for | Contract (Art. 6(1)(b)) |
| Server logs, rate limiting, error reports | Keeping the service secure and working | Legitimate interest (Art. 6(1)(f)) |
| Anonymous usage counters & merchant mappings | Improving the product (no profiling of you) | Legitimate interest (Art. 6(1)(f)) |
Subprocessors
We rely on a small number of third parties to run Fimerse:
| Subprocessor | Purpose |
|---|---|
| Anthropic | AI processing: statement extraction (receives full uploaded documents) and insights/advisor (receives financial summaries and recent chat messages). |
| Resend | Sending transactional email (verification, password reset). |
| DigitalOcean | The virtual server (New York, USA) that runs Fimerse and stores its database. |
| Cloudflare R2 | Continuous off-site backups of the database (US region; encrypted at rest by the provider). |
Fimerse is currently free and we collect no payment information. If we introduce paid plans, payment processing will be handled by a dedicated payment provider (never by us storing card details), and we will update this policy and notify you before that changes.
What we do NOT do
- We do not sell, rent, or share your personal or financial data with advertisers or data brokers.
- We do not use your financial data for anything other than providing the Fimerse service to you.
Who can access your data
Access to the production server is limited to Fimerse's operator, over key-based authentication. Day-to-day operations use aggregate signals (uptime, error counts, usage events like "a statement import succeeded"), not the contents of your accounts or transactions. We look at an individual account's data only if you ask us to (support) or if it's strictly necessary to investigate abuse or a security incident.
Your rights and choices
- Access & export. You can export your transaction history from within the app as a CSV file at any time. (The export covers transactions; if you want a copy of everything we hold about you, email us and we'll provide it.)
- Clear your data. The app has a "clear all data" action that deletes your accounts, transactions, bills, goals, budgets, transfer links, advisor history, and statement-import fingerprints, while keeping your login.
- Delete your account. The app supports full account deletion, which permanently removes your user record and all associated data from our database. This is irreversible. The only thing we retain is a minimal internal record that a deletion occurred (an event marker used for operational statistics); it contains no name, email, or financial data.
- Correct your data. Everything in Fimerse is editable in the app itself; your profile name and email can be changed in Settings.
- Depending on where you live (e.g. the EU/UK under GDPR, or California under CCPA/CPRA), you may have additional rights to access, correct, delete, or receive a portable copy of your data, and to not be discriminated against for exercising them. Email support@fimerse.com and we'll respond within 30 days. EU/UK users also have the right to lodge a complaint with their local data-protection supervisory authority.
Backups: after you delete data or your account, residual copies may persist in encrypted backups for a short retention window before they roll off (see our backup retention, currently 7 days).
Data retention
- Your account and financial data. Kept for as long as your account is active; purged when you delete your account (backups age out within 7 days, as above).
- AI advisor chat history. Only your most recent messages are kept: up to **200 messages or 90 days**, whichever is smaller; older messages are deleted automatically. You can also clear the whole history yourself at any time from the advisor screen.
- Server access logs. Kept for up to 90 days for security and troubleshooting, then deleted.
- Browser error reports. Capped at a fixed number of recent entries; older reports are automatically overwritten.
- Usage counters / event log. Kept in aggregate; rows tied to your account are deleted when your account is deleted (except the single deletion marker described above).
Security
We use HTTPS for all traffic, hash passwords (scrypt) and all sensitive tokens, isolate every user's data at the query layer, rate-limit authentication and AI endpoints, and sandbox uploaded files in restricted temporary directories. The database and statement-processing workspace live on an encrypted-at-rest storage volume, and off-site backups are stored with a provider that encrypts data at rest. No system is perfectly secure, but we take reasonable measures appropriate to a service of this kind.
If we become aware of a breach of security affecting your personal data, we will notify you and, where required, the relevant authorities without undue delay.
Children
Fimerse is not directed to children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
Changes to this policy
We may update this policy; we'll change the "Last updated" date and, for material changes, notify you by email or in the app.
Contact
Ozaar LLC, Delaware, USA. support@fimerse.com.