Loading…
Founding-member offer — ends December 31.Get started

Data Retention Policy

Effective date: August 10th, 2026

This policy describes how long Finent keeps the different categories of data it holds, and how you can request earlier deletion.

1 Principles

We retain data for the minimum period necessary to:

  • Provide the Finent service to you
  • Diagnose and fix technical issues
  • Meet any applicable legal obligations

Data that is no longer needed is deleted or anonymised. We do not archive personal data beyond the periods set out below.

2 Retention Schedule

Data categoryRetention periodTrigger for deletion
Account credentials
Email address, password hash, 2FA settings
While account is activeAccount deletion request
Financial records
Incomes, expenses, and utilities
While account is activeAccount deletion request
Billing references
Stripe customer and subscription IDs, plan, status, and period end — no card details
While account is activeAccount deletion request
Email confirmation & password-reset tokensUntil used or expired (typically 24 hours)Automatic expiry
Application logs
Error and diagnostic entries (no financial amounts are logged)
7 days (rolling)Automatic rolling deletion
Rate-limit counters
In-memory IP-based request counters
1 minute window (in memory only)Automatic — not persisted to disk
Session / authentication cookies14 days (sliding expiry)Sign out, expiry, or account deletion
Mobile sign-in tokens
Held in the device keystore; the server keeps only a hash
Access 15 minutes, refresh 60 daysSign out, expiry, or account deletion
Push notification tokens
Only if you allow notifications in the app
While the app stays installed and in useSign out, account deletion, uninstalling the app, or 180 days without use
Offline cache
An encrypted copy of your budget, stored on your device — never on our servers
24 hoursAutomatic expiry, sign out, a different account signing in, or uninstalling the app
Cookie consent preference1 yearBrowser cookie cleared by user

3 Account Deletion

When you delete your account, all of the following are permanently removed from our database:

  • Your email address and password hash
  • All income, expense, and utility records associated with your account
  • Your sinking funds and your pay-period history
  • Your bill-reminder preferences
  • Any active login sessions, on the website and on every mobile device
  • Any push notification tokens, so no notification can outlive the account
  • Your Stripe customer and subscription references, if you had a paid plan

You can delete your account from Account → Personal data on the website, or from More → Delete my account in the mobile app. See Delete your account for the full detail.

The encrypted copy of your budget held on your own device is not on our servers and is not ours to delete. Signing out erases it, and so does uninstalling the app — deleting your account signs every device out, which erases it there too.

If you had a paid plan, deleting your account also cancels the subscription so you are not billed again. Stripe keeps its own record of payments you made — invoices and receipts — as it is legally required to do for tax and accounting purposes; that record is held by Stripe under their policy, not by Finent, and deleting your Finent account does not erase it.

Deletion is permanent and irreversible. Once your account is deleted, your data cannot be recovered. We recommend downloading your data before you delete.

4 Application Logs

Finent writes rolling log files for error diagnostics. Log files are retained for 7 days and then deleted automatically.

Log entries may contain:

  • Timestamps and error messages
  • The user identifier (not the email address) when an error occurs during an authenticated request
  • HTTP status codes and request paths

Log entries do not contain passwords, financial amounts, or other sensitive personal data.

5 No Third-Party Backups or Archives

Finent does not maintain off-site backups of user data in a third-party archive. When data is deleted from the primary database, there is no secondary copy to retrieve it from.

If the application is hosted on a cloud platform, the platform's own backup policies may apply to the underlying infrastructure. Those backups are typically overwritten on short rotation cycles and are not accessible for individual data-restoration requests.

6 Changes to This Policy

We may update this Data Retention Policy from time to time. The effective date at the top of this page will reflect when the policy was last revised. Continued use of Finent after changes are posted constitutes acceptance of the updated policy.