Privacy Policy
Effective date: March 1, 2026
1. What We Collect
We collect the following information when you use FI-Project:
- Account data: email address and hashed password (managed by Supabase Auth)
- Profile data: optional display name, plan tier, onboarding status, and acceptance timestamps for these policies
- Financial projection data: the numbers you enter — salary, expenses, account balances, scenarios, goals, and events
- Usage data: anonymized analytics via PostHog (page views, feature interactions) to improve the product
We do not collect Social Security numbers, bank account numbers, brokerage credentials, or any data from external financial institutions. All numbers are entered manually by you.
2. How We Store Your Data
Your data is stored in a PostgreSQL database hosted by Supabase on Amazon Web Services infrastructure in the United States. All data in transit is encrypted via TLS. Data at rest is encrypted at the storage level. Row-Level Security (RLS) policies ensure that each user can only access their own data — even at the database query level.
3. How We Use Your Data
We use your data to:
- Provide and operate the FI-Project financial modeling service
- Authenticate you and maintain your session
- Store and retrieve your projections and scenarios across devices
- Send transactional emails (account confirmation, password reset)
- Improve the product using aggregated, anonymized analytics
4. Data Sharing
We do not sell, rent, or trade your personal data. We share data only with the following service providers, solely as necessary to operate the Service:
- Supabase — database and authentication infrastructure
- Resend — transactional email delivery
- PostHog — anonymized product analytics
- Stripe (paid plans only) — payment processing; we never see or store your full card number
We may disclose data if required by law or to protect the rights, property, or safety of FI-Project or its users.
5. Cookies and Tracking
We use cookies for authentication session management (Supabase Auth) and for anonymized analytics (PostHog). We do not use advertising cookies or third-party tracking pixels. You can disable cookies in your browser settings, but doing so will prevent you from staying logged in.
6. Your Rights
You have the right to:
- Access: request a copy of the data we hold about you
- Correction: update inaccurate information via your account settings
- Deletion: delete your account and all associated data at any time from your account settings, or by emailing us
- Portability: export your projection data in CSV format (Core and Lifetime plans)
When you delete your account, all profile data, financial projections, and scenarios are permanently deleted from our database within 30 days.
7. Data Retention
We retain your data for as long as your account is active. If your account is inactive for 3 consecutive years, we may delete it after providing 30 days' notice by email.
8. Children's Privacy
The Service is not directed to individuals under 18. We do not knowingly collect data from minors. If we learn that a minor has created an account, we will delete it promptly.
9. Changes to This Policy
We will notify you by email at least 14 days before any material changes to this policy take effect. The effective date at the top of this page will be updated with each revision.
10. Contact
Privacy questions or data requests: privacy@fi-project.com