Privacy Policy
HelloFinity is a savings challenge app. We take your privacy seriously and try to collect as little data as possible to run the service. This policy explains what we collect, why, and what you can do about it.
HelloFinity is operated as a sole trader / small business based in the United Kingdom. For questions about this policy, contact us at [email protected].
1.What data we collect
We only collect what we need to run your account and save your progress.
- Email address — used to send you a magic sign-in link. We do not use it for marketing without your permission.
- Name — the first name or nickname you enter during setup. Used to personalise your experience inside the app.
- Savings challenge data — which envelopes you have filled, your chosen multiplier, your goal label, and when your challenge started. This is your progress data; without it the app cannot work.
- Last-seen timestamp — the date and time you last used the app. Used to identify inactive accounts.
We do not collect payment information, bank account details, or any financial account data. HelloFinity does not link to or integrate with any bank or financial institution.
We do not use advertising trackers, third-party analytics scripts, or social media pixels.
2.Why we collect it and our legal basis
Under UK GDPR, we must have a lawful basis for processing your personal data. We rely on the following:
- Contract performance — your email, name, and challenge data are necessary to provide the service you signed up for. Without them we cannot create your account or save your progress.
- Legitimate interests — last-seen timestamps help us maintain and improve the service, for example to identify and remove inactive accounts and understand broadly how the app is used. This does not override your rights.
We do not rely on consent as our lawful basis for core processing. If we ever send you optional communications (for example, product updates), we will ask for your consent separately and you can withdraw it at any time.
3.How we store your data
Your data is stored using Supabase, a database platform. Supabase stores data in data centres within the European Union (Frankfurt, Germany) by default, which means your data does not leave the EU/EEA under normal operation.
Supabase is certified under the EU-US Data Privacy Framework and maintains appropriate safeguards for international transfers where applicable. You can read Supabase's privacy and security documentation at supabase.com/privacy.
We use Supabase's built-in Row Level Security to ensure your data can only be accessed by you.
4.How long we keep your data
- Active accounts — we keep your data for as long as your account is active.
- Inactive accounts — if your account has had no activity for 24 months, we may delete it along with all associated data. We will send you an email before doing so.
- Deletion on request — if you ask us to delete your account, we will remove all your personal data within 30 days. See Section 6 for how to request this.
Anonymised, aggregated statistics (for example, total number of challenges completed across all users, with no identifying information) may be retained indefinitely.
5.Who we share your data with
We do not sell your data. We do not share your data with advertisers or third-party marketing platforms.
The only third party that processes your data is Supabase, which acts as our data processor. Supabase processes data only as we instruct and under a data processing agreement consistent with UK GDPR.
We may be required to disclose your data if required by law, for example in response to a court order or request from a UK regulatory authority.
6.Your rights
Under UK GDPR you have the following rights. You can exercise any of them by emailing [email protected].
- Access — you can ask us for a copy of all personal data we hold about you.
- Rectification — you can ask us to correct inaccurate data. You can also update your name and goal directly in the app at any time.
- Erasure — you can ask us to delete your account and all associated personal data.
- Restriction — you can ask us to pause processing of your data in certain circumstances, for example while a complaint is being investigated.
- Portability — you can ask us to provide your challenge data in a machine-readable format.
- Objection — you can object to processing based on legitimate interests. We will stop unless we have compelling legitimate grounds.
We will respond to all requests within one month. If your request is complex we may extend this by a further two months, in which case we will let you know.
7.Cookies and local storage
HelloFinity does not use advertising or tracking cookies.
We use browser local storage to remember your theme preference (light or dark mode). This data stays on your device and is never sent to our servers.
Supabase uses a session token stored in local storage to keep you signed in. This token is used only for authentication and expires automatically.
8.Children
HelloFinity is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has created an account, please contact us at [email protected] and we will delete it promptly.
9.Changes to this policy
If we make material changes to this policy we will notify you by email or by displaying a prominent notice in the app before the change takes effect.
Minor changes (for example, correcting a typo or clarifying existing wording) may be made without notice. The "Last updated" date at the top of this document will always reflect the most recent revision.
10.Complaints
If you are unhappy with how we have handled your personal data, you have the right to complain to the UK Information Commissioner's Office (ICO).
Website: ico.org.uk · Helpline: 0303 123 1113
We would always prefer to resolve any concerns directly first. Please email us at [email protected] before contacting the ICO.