Security
Last updated: September 2026Your financial data is personal. Here is how Finone AI protects it — plainly, without marketing claims.
Encrypted connections
Everything the app sends to and receives from our servers travels over HTTPS (TLS). Your data is kept in a managed database on cloud infrastructure that only our service can reach.
Sign-in and access
- App lock: a 4-digit PIN with Face ID or fingerprint; the app locks again when you leave it
- Google and Apple sign-in is verified with the provider's signed ID token
- Passwords are stored only as salted hashes (bcrypt), never as plain text
- After five wrong passwords, sign-in to the account pauses for 30 minutes
- Your session is checked on every request and can be revoked
Infrastructure and AI
Finone runs on managed cloud infrastructure; the database is not open to the internet. AI features send only what a request needs — a note, a question or a receipt photo — to OpenAI's API, which does not use API data to train its models.
Your privacy
- We never sell your personal data
- We collect only what the app needs to work
- You can export your transactions to Excel at any time
- You can delete your account in the app — your data is removed at once
How we build
Every change to the app and the server is checked by automated tests before release, and those tests never touch real user data.
If something goes wrong
Our team gets automatic alerts about errors and unusual activity. If a security incident affects your data, we will tell you promptly, as the law requires.
Report a problem
Found a vulnerability or have a security question? Write to us on Telegram: @codestudiouz.