Privacy Policy
Last updated: June 4, 2026
Your financial data is sensitive, and protecting it is at the core of what we do. This policy explains what we collect, how we use it, and the choices you have.
1. Information we collect
We collect only what we need to provide the service:
- Account details — your name and email address, provided when you sign up (directly or via Google Sign-In). Passwords, where used, are stored only as a secure one-way hash.
- Statement data — the bank-statement PDFs you upload and the transactions, balances, and analysis we derive from them.
- Usage data — counts such as pages processed, statements analysed, and your current plan, used to operate your account.
- Payment data — handled by our payment processor (Stripe). We never see or store your full card details.
- Technical data — your IP address and device or browser type, used to keep your account secure, show your active sign-in sessions, and prevent abuse.
2. How we use your information
We use your information to:
- Convert your statements and generate the analysis, insights, and reports you request.
- Operate your account, enforce plan limits, and process subscriptions.
- Maintain security, prevent abuse, and provide support.
- Detect your approximate location to set a sensible default currency for your statements.
- Communicate important service or billing notices.
We do not sell your personal or financial data, and we do not use it for advertising.
3. Your uploaded documents
Your original uploaded PDF is used only to extract its contents. Once processing is complete — whether it succeeds or fails — the original file is securely deleted from our servers and is never stored long-term.
The structured data we keep (transaction descriptions, merchant names, and AI insights) is encrypted at rest using AES-256 encryption.
4. AI processing
To generate insights, recommendations, and chat answers, your statement data is sent to trusted third-party AI providers (currently Groq and Cerebras) solely to produce your results. It is processed to fulfil your request and returned to you.
We send only the financial data needed for the analysis. Your account details — such as your name, email address, and customer ids — are never sent to these AI providers.
These providers act as our processors. In line with their published data policies, Groq does not retain your inputs or outputs for standard inference requests, and Cerebras does not use client inference data to train its models. Your data is used only to generate your results.
5. Free tools
Our free tools (PDF, image, generator, and developer utilities) run entirely in your browser. Files you use with these tools are processed locally on your device and are never uploaded to our servers.
6. Cookies & local storage
We use your browser's local storage for essential functionality only — keeping you signed in, remembering your light/dark theme, and tracking which notifications you've seen. We do not use third-party advertising or tracking cookies.
7. Service providers
We rely on a small number of trusted providers to run the service, including a cloud database host, Stripe for payments, Google for sign-in, AI providers (Groq and Cerebras) for insight generation, and IP-based geolocation services used to suggest your default currency. Each only receives the data necessary to perform its function.
8. International data transfers
Some of our service providers — including our AI providers, payment processor, and sign-in provider — are based in the United States. Where your data is processed outside your own country, we rely on those providers' safeguards (such as standard contractual clauses) to keep it protected.
9. Data retention & your rights
We retain your account and statement data for as long as your account is active. You can delete individual statements at any time, and you may request deletion of your entire account — which permanently removes your associated data.
Depending on your location, you may have rights to access, correct, export, or delete your personal data. To exercise these rights, contact us using the details below.
10. Security
We protect your data with encryption in transit (HTTPS) and at rest, automatic deletion of uploaded documents after processing, and access controls. No method of transmission or storage is 100% secure, but we work hard to safeguard your information.
11. Children's privacy
AnFinAi is not intended for individuals under the age of 16, and we do not knowingly collect data from them.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the date at the top of this page.
13. Contact us
If you have any questions about this Privacy Policy or your data, contact us at support@anfinai.com.