FinState

Privacy Policy

Last updated: 19 September 2026

FinState (“we”, “us”) is a personal net worth and household finance tracker. This policy explains what information we collect, why, and how it's protected. It applies to everyone who creates a FinState account.

1. Information we collect

Account information

Your email address, and if you sign in with Google, your name and profile picture as shared by Google. Authentication itself (passwords, session tokens) is handled by our database provider, Supabase - we never see or store your raw password.

Financial data you provide

Anything you enter directly: account names and balances (cash, investments, property and other tangible assets, liabilities, credit accounts), expenses, income sources and entries, and any notes attached to them. This is the core of the service - a personal record only you (and anyone you explicitly choose to share it with) can see.

Data from connected platforms

If you choose to connect Luno or EasyEquities, we store your API key/login credentials in encrypted form and use them solely to fetch your account balances and holdings from those platforms on your behalf. We never request or store trading/withdrawal permissions for Luno - only read access to balances. See “Third-party services” below.

Security and device settings

Whether you've enabled two-factor authentication (TOTP) or device-level app lock (Face ID/Touch ID/passcode via your device's passkey support), and a log of security-relevant events on your account (sign-ins, credential changes) so you can review them yourself under Security.

2. How we use your information

  • To provide the service itself - storing and displaying your financial picture
  • To sync balances from platforms you've connected, and keep them current
  • To authenticate you and keep your account secure
  • To send account-relevant notifications you've opted into (e.g. a security event, a platform disconnecting)
  • To calculate reference figures shown alongside your data (e.g. SARB prime rate, CPI, currency conversion) - these come from public data sources and involve none of your personal information

We do not sell your data, and we do not use it for advertising.

3. Third-party services

  • Supabase - our database, authentication, and hosting provider (EU-hosted). Everything described above is stored there, behind row-level security rules that scope every query to your own account or household.
  • Google - only if you choose “Continue with Google” to sign in, per Google's own privacy policy for the sign-in itself.
  • Luno / EasyEquities - only if you connect them; we send your stored credentials to their official (Luno) or unofficial (EasyEquities) APIs solely to read your balances back.
  • SARB reference rates and Frankfurter (currency rates) - public data sources for reference figures shown in the app. No personal or account data is ever sent to these.

4. Household sharing

FinState supports multiple people in one household. Sharing is opt-in and per category (Cash, Investments, Expenses, etc.) and reciprocal - someone only sees a category of yours once you've shared it, and once they've shared theirs back. You can turn sharing off for any category at any time.

5. Data security

  • All traffic between your device and FinState is encrypted (HTTPS).
  • Connected-platform credentials are encrypted at rest, separately from the rest of your data.
  • Database access is scoped by row-level security, not just application-level checks.
  • Optional two-factor authentication and device-level app lock are available under Security.

6. Data retention and deletion

If you delete your household, its data is retained for 90 days (in case of a mistake) and then permanently and automatically purged. Leaving a shared household follows the same pattern with a 30-day grace period. You can disconnect Luno or EasyEquities at any time, which immediately removes the stored credential and any holdings synced from it.

7. Your rights

You can access, correct, or delete your data directly in the app at any time. Under South Africa's Protection of Personal Information Act (POPIA), you also have the right to object to certain processing and to lodge a complaint with the Information Regulator. Contact us using the details below for anything you can't do yourself in-app.

8. Children

FinState isn't directed at, or knowingly used by, children.

9. Changes to this policy

We may update this policy as the service changes. Meaningful changes will be reflected here with an updated date above.

10. Contact

Questions about this policy or your data: privacy@open-platforms.co.za

Back to sign in