FINCALC AI

Offline-first financial calculator — legal + support

View the Project on GitHub kmshihab7878/FINCALC-AI

Privacy Policy

Effective date: 2026-05-12

This is the privacy policy for FINCALC AI (“the app”), an offline-first financial calculator with optional AI features. The app is operated by the FINCALC AI team. Contact: privacy@fincalcai.com.


Summary

FINCALC AI is built to compute on your device. The 134-formula calculator engine, exports (XLSX / PDF), and calculation history all run locally and never leave your device.

When you choose to use a paid AI feature (AI Tutor, Assistant, or Elite Operator Mode), the text of your prompt is forwarded through our server proxy to one of two AI providers — Moonshot AI (Kimi K2.5) or OpenAI (GPT-4.1 Nano). We never call those providers directly from the mobile app, and our server proxy strips obvious personal patterns (emails, phone numbers, SSNs, credit-card-shaped strings) before forwarding.

We do not sell your data, do not run third-party advertising, and do not use your prompts to train any model on our side.


Data Stored on Your Device

The app stores the following on your device only, in an SQLite database:

This data never leaves your device unless you explicitly export or share it.


Data We Collect from You

When you sign in or subscribe, the following data is transmitted off-device:

Data Why Where it goes
Email address Authentication (Sign in with Apple / Google) Supabase Auth
Pseudonymous user ID Identifies your account in our systems Supabase, RevenueCat, Sentry
Subscription state Product ID, billing period, expiry, renewal flag RevenueCat (synced to Supabase user_subscriptions)
Crash diagnostics Stack traces, device model, OS version (PII scrubbed) Sentry
AI prompt text (only when you use an AI feature) Routes through ai-proxy to Moonshot AI and/or OpenAI; PII scrubbed Moonshot AI, OpenAI

The app’s core 134-formula calculator works fully offline. No data is transmitted while you compute, save history, or export — unless you sign in or use an AI feature.


AI Features and External Processing

What is sent

When you use AI Tutor, AI Assistant, or Elite Operator Mode, the following is sent to ai-proxy:

Where it goes

Our server proxy routes requests to one of two providers:

If one provider fails, the request is retried against the other. We do not pass your auth token to either provider — they receive only the prompt text and a server-side API key.

How long it is retained

How to avoid AI processing

Effect of deletion

Deleting your account removes all server-side rows tied to your user ID, including the AI request log. Provider-side abuse-detection retention follows the provider’s policy independent of our deletion.


Crash Reporting (Sentry)

We use Sentry for crash reporting and error monitoring. Sentry receives:

PII scrubbing is enabled in beforeSend. Sentry does not receive your financial inputs, calculation results, or AI prompts.

You can disable crash reporting at the OS level (iOS Settings → Privacy & Security → Analytics & Improvements; Android Settings → Google → Usage & diagnostics).


Subscriptions (RevenueCat)

We use RevenueCat to manage subscriptions. RevenueCat receives:

RevenueCat does not receive your financial inputs or AI prompts.


Authentication (Supabase)

We use Supabase Auth for Sign in with Apple and Sign in with Google. Supabase receives:

The app stores your auth tokens in the OS Keychain (iOS) or Keystore (Android) via expo-secure-store.

You can sign in or use the app without an account. The Free tier is fully usable without sign-in.


Account Deletion

In-app: Settings → Account → Delete account. The server-side delete-user Edge Function cascades to all rows tied to your user ID (user_subscriptions, ai_monthly_usage, ai_request_log, operator_runs, extension_sessions).

By email: send a request to privacy@fincalcai.com. We respond within 30 days (GDPR Art. 17 default).


Children and Student Use

FINCALC AI is built for students and professionals studying finance and accounting. The app does not knowingly collect personal information from children under 13. If a parent or guardian believes a child under 13 has provided personal information, contact privacy@fincalcai.com and we will delete the account.


Your Rights (GDPR / UK GDPR)

If you are in the EEA or UK, you have the right to access, correct, erase, restrict, port, or object to processing of your personal data. To exercise any right, email privacy@fincalcai.com. We will respond within 30 days.

Legal basis: contract (auth, subscription delivery, AI features), legitimate interests (crash diagnostics).


Security

You are responsible for the physical security of your device and any files you choose to export or share.


Changes to This Policy

We may update this policy. Material changes will be reflected in the “Effective date” above and in the app changelog. Continued use after a change constitutes acceptance.


Contact


Terms of Use Support Back to Legal & Support