Privacy policy
Effective July 22, 2026 · processor disclosure updated July 23, 2026
What débutFin processes
débutFin processes account-profile information, connected-account metadata, balances, transactions, debts, bills, goals, scenarios, uploaded financial documents, extraction corrections, credit-score snapshots, and security and audit events needed to operate your account.
Why it is processed
The information is used to provide account access, synchronize supported institutions, stage and confirm document facts, calculate deterministic financial plans, prevent abuse, investigate failures, fulfill exports, and complete account deletion.
Processors
- Supabase provides authentication, PostgreSQL, and private object storage.
- Cloudflare provides DNS, TLS, Workers hosting, abuse controls, operational logs, and encrypted off-site backup storage through R2 when backups are enabled.
- Plaid provides institution connection and supported financial data after your authorization.
- OpenAI processes an uploaded document only when automatic extraction is enabled and initiated. débutFin requests deletion of the temporary processor file immediately after processing, but provider retention or a failed deletion request may extend that copy.
- Resend delivers confirmation, recovery, and account-security messages through Supabase Auth.
- Configured malware scanner receives uploaded bytes only when that optional protection is enabled.
Data isolation and retention
User-owned database rows are protected by row-level security. Original documents are private. Routine deletion uses a recovery window before purge. Operational webhook, job, audit, rate-limit, and encrypted-backup retention is enforced by the scheduled maintenance paths documented in the operator runbook.
Your controls
You may correct imported facts, export your structured data and originals, revoke sessions, disconnect data sources, and request account deletion from Settings.
Security limits
No service can promise that loss or compromise is impossible. débutFin is designed to avoid preventable loss through encryption, least privilege, idempotent processing, backups, monitoring, and restore drills.