Fimerse Privacy Policy
Last updated: 2026-08-23 · Effective: 2026-08-01
Fimerse ("Fimerse", "we", "us") is a personal-finance app (with multi-currency support) operated by Ozaar LLC, a US limited liability company registered in Delaware (the "data controller" for the purposes of EU/UK data-protection law). This policy explains what we collect, why, and your choices. Questions or requests: support@fimerse.com.
What we collect
- Account details. Your name, email address, and a securely hashed password. Your email is also used to verify your account and send transactional mail (verification, password reset).
- Financial data you enter or import. Accounts, balances, transactions, categories, budgets, savings goals, and bills. You provide this by typing it in, by importing a CSV, or by uploading a bank/card statement (PDF or image).
- A push token, if you turn on notifications. An identifier for one phone, issued by Apple or Google, so we can send you a bill reminder. Nothing is stored for this unless you turn it on, and turning it off removes it. See "Notifications on your phone" below.
- Your questions to the advisor. The messages you send to the in-app money advisor, kept as chat history so the conversation has continuity. You can clear this history at any time from the advisor screen.
- Basic operational data. Standard server logs (which include your IP address) and rate-limiting counters needed to run and secure the service. If the app hits an error in your browser it also sends us a technical error report (the error message, page URL, and browser version, never your financial data), and we keep simple usage counters (e.g. that a statement import succeeded or failed, which bank the statement came from, and which currencies it held, never a payee, amount or account number). Category labels for recognized merchants are improved using anonymous merchant-name-to-category mappings aggregated across users: a shop name and its category only, never tied to any account, amount, date or person. A name only ever becomes part of that shared list once several unrelated users have independently paid the same place: what you alone type stays private to your account, so a person you pay, whose name means nothing to anyone else, is never shared, in any language. All of this is stored on our own server; we use no third-party analytics or error-tracking services, and the app's fonts and all other page assets are served from our own domain, so simply loading Fimerse makes no request to any third party. The one exception is a payment: if you choose to upgrade, the checkout is provided by Paddle and their script is fetched at the moment you press the upgrade button, never on an ordinary page load. If you never upgrade, nothing about your visit ever reaches them.
We do not connect to your bank, use account-aggregation services, or collect data from third parties about you. Everything in Fimerse is data you gave us.
When you first sign up, Fimerse suggests a currency based on your device's own language and timezone settings. That guess is made inside your browser: your location is never looked up, and no request leaves your device to work it out. You can change the suggestion before finishing setup, and at any time afterwards.
Cookies and browser storage
Fimerse uses your browser's local storage to keep you signed in (a session token) and to remember interface preferences (like the screen you were last on). We do not use advertising or tracking cookies, and there are no third-party trackers on the site.
Our own visit counting stores nothing at all on your device, which is why you have not been asked to accept anything. See "How we count visits" below for exactly what it records.
How we count visits (first-party analytics)
We measure how the website and the app are used, on our own server, and no third party receives any of it. There is no Google Analytics, no advertising pixel, and no session-replay tool. This is also why our subprocessor list below gains no entry for analytics: there is nobody to add.
Nothing is stored on your device for this. No analytics cookie, and no identifier in local storage either, which matters legally as well as practically: EU/UK rules cover any storage on your device, not just cookies. Because we store nothing, you are not asked to accept anything.
What a recorded event contains:
- the page or screen, the time, how long you stayed, and how far you scrolled;
- the host of the site that linked you to us (for example
google.com), never the full address of the page you came from, so we never learn the search terms or query strings of another site; - your country, when our network provider tells us;
- your browser's language, timezone, window size and screen size;
- for the app: which screen you opened, and quality counters about a statement import (how many rows were read, how many needed your review, whether the balance reconciled). Never a payee name, never an amount, never an account name or number. Anything that looks like an email address or a long number is masked automatically before it is stored.
How we count people without identifying them. Instead of storing an id on your device, our server derives a one-way code each day from a shortened form of your IP address (the last part is discarded) plus your browser's version string, mixed with a random secret that changes every day. The secret is deleted along with the events it covers, so once a day has aged out, those codes cannot be traced back to anyone, even by us, and even from a copy of our database. Being honest about the limits: this makes visitor counts an approximation, and because the secret changes daily we cannot tell whether you have visited before.
Campaign tags in a link. When we post a link on social media we add a few words to the end of the web address saying where we posted it, for example utm_source=instagram&utm_medium=bio. They record the post, not the person: everybody who clicks the same link sends exactly the same words, they are visible in your address bar and you can edit or delete them, and nothing about them is derived from you or your device. We keep three of them, shortened and stripped of anything but plain letters and digits, so we can tell which posts were worth making. We do not use the tag that carries search keywords.
Linking a visit to an account. If you sign up, the visit that brought you there is recorded on your account, so we can see which pages help people decide, along with the campaign tags of the link you arrived through, if there were any. Both are held in your browser's memory for that visit only, never a cookie, and both are deleted when you delete your account.
It shrinks with age. Individual events are deleted after 90 days and only anonymous daily totals remain, so what we hold about any single visit gets smaller over time rather than accumulating.
If we ever add a tracking cookie, a third-party script, or an advertising pixel, we will ask for your consent first, because at that point we would be required to.
How uploaded statements are handled
When you upload a statement, the file is written to a temporary, access-restricted directory on our server, read by our AI extraction step to pull out the account details and transactions, and then the file is deleted. We keep the extracted transactions, not the original document. Password-protected PDFs are decrypted in that same temporary directory only for long enough to read them, and the decrypted copy is removed afterward too. We also keep a cryptographic fingerprint (hash) of each imported file (not its contents), so re-uploading the same statement doesn't create duplicates; you can clear these fingerprints with the "clear all data" action.
Notifications on your phone
The Fimerse mobile app can send you a notification when a bill is due, when one is overdue, or when an account balance looks out of date. This is off until you turn it on, from the toggle in Settings. If you never turn it on, nothing in this section happens: no token is registered for your phone and no notification is ever sent, so none of your data reaches any of the parties below.
When you do turn it on, two things leave our server:
- A push token for that phone, issued by Apple or Google and stored against your account so we know where to send. One token belongs to one account: if you sign in on a phone that someone else used for Fimerse, their token is removed, so a phone that changes hands cannot keep showing the previous person's figures.
- The text of the notification itself, which contains real detail about your money, because a notification that said nothing would be useless. A bill notification names the bill and its amount ("Netflix Premium (₨1,100) is due tomorrow"). A stale-balance notification names the account. No other financial data is included, and never a transaction, a payee you have not set up as a bill, or an account number.
Delivering that to a lock screen is not something we can do ourselves. It travels through Expo, which operates the push service the app uses, and then through Apple's or Google's push network, which is the only way any app reaches your phone. All three are listed as subprocessors below.
You can turn notifications off again at any time from the same toggle, which removes the token. Signing out removes it too, and deleting your account deletes it with everything else.
How we use AI
Statement import, insights and the advisor are powered by Anthropic (the makers of Claude), acting as our processor. Two kinds of data are sent to Anthropic's API, and it's worth being precise:
- Statement import: when you upload a bank statement, the entire document (PDF, image, or CSV) is sent to Anthropic for extraction, as-is, with no redaction. That includes everything printed on it: the account holder's name, account and IBAN numbers, balances, and every transaction. If you don't want a document processed this way, don't upload it; you can always add transactions manually instead.
- Insights and the advisor: these send a compact summary of your finances (account balances, monthly income/spend totals, your largest transactions for the period, budgets, savings goals, upcoming bills) plus, for the advisor, your recent messages in that chat so the conversation stays coherent. They do not send your uploaded documents.
We do not use your data to train any AI model, and Anthropic's API terms commit it not to train on data submitted through the API. AI output in Fimerse (categorization suggestions, insights, advisor replies) is informational only; it produces no legal or similarly significant automated decision about you, and you can always review, correct, or ignore it.
Where your data is stored, and international transfers
Your data lives in a SQLite database on our own server (a virtual private server we operate in New York, USA). Transport to and from the app is encrypted with HTTPS. Passwords and session/reset/verification tokens are stored hashed, never in plain text. Every request is scoped to your own account, so users cannot see each other's data.
Fimerse is operated from the United States, so if you use it from outside the US (including the EU/UK), your data is transferred to and processed in the US. Where EU/UK law requires a transfer safeguard, we rely on your explicit, informed consent given when you create an account and on the contractual necessity of processing your data to provide the service you signed up for.
Legal bases (EU/UK users)
Where GDPR applies, we process your data on these bases:
| Data | Purpose | Legal basis |
|---|---|---|
| Account details | Creating and securing your account, transactional email | Contract (Art. 6(1)(b)) |
| Financial data & advisor messages | Providing the Fimerse service you asked for | Contract (Art. 6(1)(b)) |
| Server logs, rate limiting, error reports | Keeping the service secure and working | Legitimate interest (Art. 6(1)(f)) |
| Anonymous usage counters & merchant mappings | Improving the product (no profiling of you) | Legitimate interest (Art. 6(1)(f)) |
Subprocessors
We rely on a small number of third parties to run Fimerse:
| Subprocessor | Purpose |
|---|---|
| Anthropic | AI processing: statement extraction (receives full uploaded documents) and insights/advisor (receives financial summaries and recent chat messages). |
| Resend | Sending transactional email (verification, password reset). |
| DigitalOcean | The virtual server (New York, USA) that runs Fimerse and stores its database. |
| Cloudflare R2 | Continuous off-site backups of the database (US region; encrypted at rest by the provider). |
| Expo | Delivering phone notifications, only if you turn them on. Receives your phone's push token and the text of the notification. See "Notifications on your phone" above. |
| Apple and Google | The push networks that carry a notification the last step to your phone, only if you turn notifications on. Which one applies depends on your phone. |
| Paddle | Taking payment, only if you buy something. Paddle is the merchant of record: they receive your name, address and card details directly, and Fimerse never sees them. They also handle refunds and sales tax. See "Payments" below. |
Payments. Paddle is the merchant of record for Fimerse Plus and for credit top-ups. That means Paddle, not Fimerse, takes the payment: your card details are entered on their checkout and are never sent to us, seen by us, or stored by us. What we keep is Paddle's own reference for your billing account and subscription, the plan you are on, and the date your period ends. To change your card, see your invoices or cancel, we send you to Paddle's customer portal, because they hold that information and we do not.
To pay you tell Paddle your name, address and card, which they need for the payment and for sales tax. They tell us none of it. We pass Paddle one thing about you: the internal reference for your Fimerse account, so a payment can be matched to the right account. Not your email, not your name.
What we do NOT do
- We do not sell, rent, or share your personal or financial data with advertisers or data brokers.
- We do not use your financial data for anything other than providing the Fimerse service to you.
- We do not use session-replay or screen-recording tools. A replay of a signed-in session would record your balances and individual transactions and send them to another company. We will not add one, and this is not a "not yet".
Who can access your data
Access to the production server is limited to Fimerse's operator, over key-based authentication. Day-to-day operations use aggregate signals (uptime, error counts, usage events like "a statement import succeeded"), not the contents of your accounts or transactions. We look at an individual account's data only if you ask us to (support) or if it's strictly necessary to investigate abuse or a security incident.
Your rights and choices
- Access & export. You can export your transaction history from within the app as a CSV file at any time. (The export covers transactions; if you want a copy of everything we hold about you, email us and we'll provide it.)
- Clear your data. The app has a "clear all data" action that deletes your accounts, transactions, bills, goals, budgets, transfer links, advisor history, and statement-import fingerprints, while keeping your login.
- Delete your account. The steps are on our delete-account page. The app supports full account deletion, which permanently removes your user record and all associated data from our database. This is irreversible. Deleting your account also withdraws the category corrections you contributed to the shared merchant list described above: a shop name that only appeared there because you had paid it is removed along with you, and one that several other people independently pay stays, as their contribution rather than yours. The only thing we retain is a minimal internal record that a deletion occurred (an event marker used for operational statistics); it contains no name, email, or financial data.
- Correct your data. Everything in Fimerse is editable in the app itself; your profile name and email can be changed in Settings.
- Depending on where you live (e.g. the EU/UK under GDPR, or California under CCPA/CPRA), you may have additional rights to access, correct, delete, or receive a portable copy of your data, and to not be discriminated against for exercising them. Email support@fimerse.com and we'll respond within 30 days. EU/UK users also have the right to lodge a complaint with their local data-protection supervisory authority.
Backups: after you delete data or your account, residual copies may persist in encrypted backups for a short retention window before they roll off (see our backup retention, currently 7 days).
Data retention
- Your account and financial data. Kept for as long as your account is active; purged when you delete your account (backups age out within 7 days, as above).
- advisor chat history. Only your most recent messages are kept: up to 200 messages or 90 days, whichever is smaller; older messages are deleted automatically. You can also clear the whole history yourself at any time from the advisor screen.
- Server access logs. Kept for up to 90 days for security and troubleshooting, then deleted.
- Browser error reports. Capped at a fixed number of recent entries; older reports are automatically overwritten.
- Usage counters / event log. Kept in aggregate; rows tied to your account are deleted when your account is deleted (except the single deletion marker described above).
- Visit analytics. Individual events for 90 days, after which only anonymous daily totals remain. The daily secret that makes visitor codes traceable is deleted at the same time, so aged-out visits cannot be re-identified afterwards. Events tied to your account, and the visit and campaign tags recorded on it, are deleted when you delete your account.
Security
We use HTTPS for all traffic, hash passwords (scrypt) and all sensitive tokens, isolate every user's data at the query layer, rate-limit authentication and AI endpoints, and sandbox uploaded files in restricted temporary directories. The database and statement-processing workspace live on an encrypted-at-rest storage volume, and off-site backups are stored with a provider that encrypts data at rest. No system is perfectly secure, but we take reasonable measures appropriate to a service of this kind.
If we become aware of a breach of security affecting your personal data, we will notify you and, where required, the relevant authorities without undue delay.
Children
Fimerse is not directed to children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
Changes to this policy
We may update this policy; we'll change the "Last updated" date and, for material changes, notify you by email or in the app.
Contact
Ozaar LLC, Delaware, USA. support@fimerse.com.