Privacy Policy
Last updated: January 11, 2025
FinMaxx ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and website.
Key Points: We use your financial data solely to calculate your wealth percentile and track your progress. We never sell your data. You can delete your account and all data at any time.
1. Information We Collect
Information You Provide:
- Account information (name, email via Sign in with Apple)
- Age and income range
- Manually entered financial data (net worth estimates, savings rate)
Information from Connected Accounts (via Plaid):
- Account balances (checking, savings, investment, retirement accounts)
- Liability balances (credit cards, loans, mortgages)
- Account and routing numbers are NOT collected or stored
Automatically Collected Information:
- Device information (device type, operating system)
- App usage data (features used, session duration)
- Crash reports and performance data
2. How We Use Your Information
| Purpose |
Data Used |
| Calculate wealth percentile |
Age, net worth, income range |
| Track financial progress |
Account balances, net worth history |
| Provide personalized insights |
Financial data, savings rate |
| Improve our services |
Aggregated, anonymized usage data |
3. Third-Party Services
We use the following third-party services to provide our app:
Plaid Inc. - Financial data aggregation
- Plaid securely connects to your bank accounts
- We never see or store your bank login credentials
- Plaid's privacy policy: plaid.com/legal
Supabase - Database and authentication
- Stores your account and financial data securely
- SOC 2 Type 2 certified
Vercel - API hosting
- Processes API requests
- SOC 2 Type 2 certified
Apple - Sign in with Apple authentication
- Handles user authentication
- We receive only your name, email (if shared), and a unique identifier
4. Data Security
We implement industry-standard security measures:
- Encryption in transit: All data transmitted using TLS 1.2+
- Encryption at rest: Database encrypted with AES-256
- Access tokens: Plaid tokens encrypted before storage
- Authentication: Biometric authentication (Face ID/Touch ID) via Sign in with Apple
- Access control: Multi-factor authentication required for all admin access
5. Data Retention
| Data Type |
Retention Period |
| Account information |
Until you delete your account |
| Financial snapshots |
2 years |
| Plaid access tokens |
Until you disconnect the account |
| Server logs |
30 days |
6. Your Rights
You have the right to:
- Access: Request a copy of your data
- Delete: Delete your account and all associated data
- Disconnect: Remove connected bank accounts at any time
- Opt-out: Disable analytics and tracking
- Export: Download your data in a portable format
To exercise these rights, go to Settings in the app or contact us at support@finmaxx.io.
7. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed
- Right to say no to the sale of personal information
- Right to delete personal information
- Right to non-discrimination for exercising CCPA rights
We do not sell your personal information. We never have and never will sell your data to third parties.
8. Children's Privacy
FinMaxx is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by:
- Posting the new policy on this page
- Updating the "Last updated" date
- Sending an in-app notification for material changes
10. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at: