Privacy notice
What FinKind holds about you, and why.
FinKind is a planning tool that works from what you enter. This notice lists the personal data it holds, why it holds it, who processes it, how long it is kept, and how to take it back or remove it.
Version 1.0 · Effective 2026-09-17
1 · Scope
This notice covers the FinKind account you create.
It applies to the FinKind website, the member app, and the account behind them, all operated by CTSoftwares, LLC. The fictional demo is not covered because it needs no account: it runs in your browser on invented data and sends nothing to FinKind.
- Website and member app with a verified account
- The fictional demo stays anonymous and browser-local
- Versioned and dated, like the terms of service
2 · What is held
Your account, your plan, and the record of your subscription.
FinKind holds the email address you verified and the display name you chose; the planning data you enter, which is accounts and balances, scheduled money moves, goals, protected reserves, scenarios, and workspaces; a record of your sessions and devices so you can revoke them; security events such as sign-in attempts and password recovery, kept to protect the account; and, if you subscribe, the identifier linking you to your Stripe customer record together with the subscription states Stripe reports.
- Verified email address and display name
- The planning data you enter, and nothing collected from elsewhere
- Sessions, devices, and account-security events
- Subscription state and the Stripe customer link, if you subscribe
3 · What is not held
No card details, no bank credentials, no financial content in telemetry.
Card details are entered on Stripe and never reach FinKind. FinKind has no bank connections, so it never asks for or stores bank credentials or transaction feeds. Operational telemetry records that a request happened and how it performed, not what it contained: no balances, amounts, plan contents, query strings, or client addresses.
- No card numbers, expiry dates, or security codes
- No bank credentials and no imported transaction history
- Telemetry carries no financial content
4 · Why it is held
To run the service you asked for, and to keep it secure.
Your planning data exists to produce your forecast and safe-to-spend answer. Your email address exists to verify the account, recover access, and send the account and subscription messages FinKind must send. Security events exist to detect and stop attacks on accounts. Subscription state exists to know what you are entitled to.
FinKind does not sell personal data, does not share it for advertising, and runs no advertising.
- To provide planning, access, security, and billing
- Never sold, never shared for advertising
- No profiling or automated decisions about you
5 · Who processes it
Three processors, each for one job.
Microsoft Azure hosts the service and its database in the South Central United States region. Microsoft Graph sends account email from the FinKind-owned support@finkind.io mailbox. Stripe processes payments and holds the card details FinKind never sees.
- Microsoft Azure: hosting and database, South Central United States
- Microsoft Graph: account and security email from support@finkind.io
- Stripe: payment processing and card data
6 · How long it is kept
While your account exists, plus short operational windows.
Account and planning data are kept while the account exists and are removed when you delete it. The database keeps a 7-day point-in-time restore window, so a deleted account can persist in that window before it ages out. Operational logs and telemetry are kept for 30 days. Billing records held by Stripe follow Stripe’s own retention and the record-keeping the law requires.
- Planning data: for the life of the account
- Database point-in-time restore window: 7 days
- Operational logs and telemetry: 30 days
7 · Your controls
Export it, revoke access, or delete the account.
Account settings carries a portable JSON export of your profile, workspaces, accounts, scheduled money, goals, and protected reserves, which never includes passwords or session credentials. The same page lists your signed-in devices so you can revoke any of them, and deletes the account permanently when you ask it to.
To ask what is held about you, to correct it, or to raise a concern, write to support@finkind.io.
- Export a portable copy at any time
- Revoke any device session, including the current one
- Delete the account and everything the account holds
8 · Security and children
Encrypted in transit, least privilege at rest.
Traffic is encrypted in transit, passwords are stored only as adaptive hashes, the database is encrypted, and the service identity that reads it holds only the permissions it needs. Security reports are welcome at support@finkind.io; FinKind answers them itself and does not run a paid monitored response service.
FinKind is not intended for children. Do not create an account for someone under 13.
- Encryption in transit and at rest
- Passwords stored as adaptive hashes, never in readable form
- Security reports to support@finkind.io
Money help, without judgment
See the product with fictional money first.
The Demo stays separate from member accounts and resets whenever you want.