Fimerse

Fimerse Privacy Policy

Last updated: 2026-08-04 · Effective: 2026-08-01

Fimerse ("Fimerse", "we", "us") is a personal-finance app (with multi-currency support) operated by Ozaar LLC, a US limited liability company registered in Delaware (the "data controller" for the purposes of EU/UK data-protection law). This policy explains what we collect, why, and your choices. Questions or requests: support@fimerse.com.

What we collect

We do not connect to your bank, use account-aggregation services, or collect data from third parties about you. Everything in Fimerse is data you gave us.

When you first sign up, Fimerse suggests a currency based on your device's own language and timezone settings. That guess is made inside your browser: your location is never looked up, and no request leaves your device to work it out. You can change the suggestion before finishing setup, and at any time afterwards.

Cookies and browser storage

Fimerse uses your browser's local storage to keep you signed in (a session token) and to remember interface preferences (like the screen you were last on). We do not use advertising or tracking cookies, and there are no third-party trackers on the site.

How uploaded statements are handled

When you upload a statement, the file is written to a temporary, access-restricted directory on our server, read by our AI extraction step to pull out the account details and transactions, and then the file is deleted. We keep the extracted transactions, not the original document. Password- protected PDFs are decrypted in that same temporary directory only for long enough to read them, and the decrypted copy is removed afterward too. We also keep a cryptographic fingerprint (hash) of each imported file (not its contents), so re-uploading the same statement doesn't create duplicates; you can clear these fingerprints with the "clear all data" action.

How we use AI

Fimerse's AI features are powered by Anthropic (the makers of Claude), acting as our processor. Two kinds of data are sent to Anthropic's API, and it's worth being precise:

We do not use your data to train any AI model, and Anthropic's API terms commit it not to train on data submitted through the API. AI output in Fimerse (categorization suggestions, insights, advisor replies) is informational only; it produces no legal or similarly significant automated decision about you, and you can always review, correct, or ignore it.

Where your data is stored, and international transfers

Your data lives in a SQLite database on our own server (a virtual private server we operate in New York, USA). Transport to and from the app is encrypted with HTTPS. Passwords and session/reset/verification tokens are stored hashed, never in plain text. Every request is scoped to your own account, so users cannot see each other's data.

Fimerse is operated from the United States, so if you use it from outside the US (including the EU/UK), your data is transferred to and processed in the US. Where EU/UK law requires a transfer safeguard, we rely on your explicit, informed consent given when you create an account and on the contractual necessity of processing your data to provide the service you signed up for.

Legal bases (EU/UK users)

Where GDPR applies, we process your data on these bases:

DataPurposeLegal basis
Account detailsCreating and securing your account, transactional emailContract (Art. 6(1)(b))
Financial data & advisor messagesProviding the Fimerse service you asked forContract (Art. 6(1)(b))
Server logs, rate limiting, error reportsKeeping the service secure and workingLegitimate interest (Art. 6(1)(f))
Anonymous usage counters & merchant mappingsImproving the product (no profiling of you)Legitimate interest (Art. 6(1)(f))

Subprocessors

We rely on a small number of third parties to run Fimerse:

SubprocessorPurpose
AnthropicAI processing: statement extraction (receives full uploaded documents) and insights/advisor (receives financial summaries and recent chat messages).
ResendSending transactional email (verification, password reset).
DigitalOceanThe virtual server (New York, USA) that runs Fimerse and stores its database.
Cloudflare R2Continuous off-site backups of the database (US region; encrypted at rest by the provider).

Fimerse is currently free and we collect no payment information. If we introduce paid plans, payment processing will be handled by a dedicated payment provider (never by us storing card details), and we will update this policy and notify you before that changes.

What we do NOT do

Who can access your data

Access to the production server is limited to Fimerse's operator, over key-based authentication. Day-to-day operations use aggregate signals (uptime, error counts, usage events like "a statement import succeeded"), not the contents of your accounts or transactions. We look at an individual account's data only if you ask us to (support) or if it's strictly necessary to investigate abuse or a security incident.

Your rights and choices

Backups: after you delete data or your account, residual copies may persist in encrypted backups for a short retention window before they roll off (see our backup retention, currently 7 days).

Data retention

Security

We use HTTPS for all traffic, hash passwords (scrypt) and all sensitive tokens, isolate every user's data at the query layer, rate-limit authentication and AI endpoints, and sandbox uploaded files in restricted temporary directories. The database and statement-processing workspace live on an encrypted-at-rest storage volume, and off-site backups are stored with a provider that encrypts data at rest. No system is perfectly secure, but we take reasonable measures appropriate to a service of this kind.

If we become aware of a breach of security affecting your personal data, we will notify you and, where required, the relevant authorities without undue delay.

Children

Fimerse is not directed to children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.

Changes to this policy

We may update this policy; we'll change the "Last updated" date and, for material changes, notify you by email or in the app.

Contact

Ozaar LLC, Delaware, USA. support@fimerse.com.