FYNFLOW
1. Introduction
- Ryzr Studios ("we", "us", "our") operates the FynFlow mobile and web application. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use FynFlow ("the App").
- By using the App, you agree to the collection and use of information in accordance with this policy.
- This policy applies to all users of FynFlow regardless of the platform (Android, iOS, or web).
2. Information We Collect
Information you provide directly
- Account information: name, email address, handle (@username), city, profile photo, and password (stored as a secure hash — never in plain text).
- Financial data: transaction records, amounts, categories, merchants, notes, budget limits, savings goals, and net worth calculations that you manually enter or import.
- Committee data: committee names, member information, contribution amounts, payout schedules, and related records.
- Zakat information: asset values and Nisab calculations you enter for Zakat estimation.
- Documents: files you upload to the document storage feature.
- Voice recordings: audio captured when you use the voice logging feature (processed for transcription and not stored permanently).
- Profile photo: images you upload as your avatar (stored in our secure cloud storage).
Information collected automatically
- Device information: device type, operating system, and version.
- Usage data: features accessed, session duration, and interaction patterns (used to improve the App).
- Push notification token: a device token generated by Firebase to deliver push notifications (stored only if you enable notifications).
- IP address: collected as part of standard server logs and used for security and fraud prevention.
3. How We Use Your Information
- To provide and maintain the Service, including displaying your financial data, running AI features, and syncing data across your devices.
- To authenticate your identity and protect your account.
- To send push notifications about transactions, committee updates, and other activity you have subscribed to (you may opt out at any time in Settings).
- To process voice input for transcription via AI services to enable voice logging of transactions.
- To generate AI-powered financial insights and responses to your chat queries.
- To calculate and display Zakat estimates based on the data you provide.
- To communicate with you about your account, including email verification and password reset.
- To detect, prevent, and respond to security incidents, fraud, and abuse.
- To comply with legal obligations.
- We do NOT sell your personal data to third parties. We do NOT use your financial data for targeted advertising.
4. Data Sharing and Third Parties
Supabase
- Your account data, financial records, and documents are stored on Supabase, a cloud database platform. Data may be stored on servers in the United States or European Union. Supabase processes data in accordance with their Privacy Policy (supabase.com/privacy).
Firebase (Google)
- We use Firebase Cloud Messaging (FCM) by Google to deliver push notifications. Your device push token is shared with Firebase solely for this purpose. Firebase's data practices are governed by Google's Privacy Policy (policies.google.com/privacy).
AI Service Providers
- Voice transcription and AI chat features are powered by AI language model providers. Audio data and text queries are transmitted to these providers solely to fulfil your request. We do not permit providers to use your data for their model training without your explicit consent.
Legal Requirements
- We may disclose your information if required by law, court order, or government authority, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
Business Transfer
- In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you before your data is subject to a different privacy policy.
5. Data Storage and Security
- Your data is stored on Supabase's secure cloud infrastructure protected by industry-standard encryption (TLS in transit, AES-256 at rest).
- Passwords are never stored in plain text; they are hashed using bcrypt via Supabase Auth.
- Profile photos and documents are stored in Supabase Storage with access controlled by row-level security policies.
- We implement access controls ensuring that each user can only access their own data.
- While we implement reasonable security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
- In the event of a data breach that affects your personal information, we will notify you and relevant authorities as required by applicable law.
6. Data Retention
- Your account data is retained as long as your account is active.
- If you delete your account, your personal data and financial records will be permanently deleted within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention records).
- Voice recordings used for transcription are not stored beyond the duration of the transcription request.
- Server logs containing IP addresses are retained for up to 90 days for security purposes.
- To delete your account and data, go to Settings → Delete Account, or contact us at support@getfynflow.com.
7. Your Rights and Choices
- Access and portability: You can access your financial data at any time within the App. Contact us to request a full export of your data.
- Correction: You can edit your profile and financial data directly within the App.
- Deletion: You can delete your account and associated data from Settings or by contacting us.
- Notification opt-out: You can disable push notifications in the App Settings or through your device settings at any time.
- Voice feature opt-out: Voice logging features are optional. You may use text input instead at all times.
- GDPR rights (EU users): If you are located in the European Union, you have the right to access, rectify, erase, restrict processing, and port your data. You also have the right to object to processing and to lodge a complaint with your local supervisory authority.
- CCPA rights (California users): California residents have the right to know what personal information is collected, to request deletion, and to opt out of the sale of personal information (we do not sell personal information).
8. Permissions We Request
- Microphone: Required for the voice transaction logging feature. We only access the microphone when you actively tap the voice record button. We do not record audio in the background.
- Camera / Photo Library: Required for uploading a profile photo and for the receipt scanning feature. We only access photos when you explicitly initiate an upload or scan.
- Notifications: Optional. Used to deliver alerts for transactions, committee updates, and other in-app events. You can manage notification preferences in App Settings.
- Internet access: Required for core app functionality, data sync, and AI features.
- All permissions can be revoked at any time through your device's app settings. Revoking a permission will disable the associated feature.
9. Children's Privacy
- FynFlow is not directed to children under the age of 13 (or 16 in the EU/UK). We do not knowingly collect personal information from children under these ages.
- If you believe a child under the applicable age has provided us with personal information, please contact us immediately at support@getfynflow.com and we will delete that information.
- Parents or guardians who become aware of any such data collection are encouraged to contact us promptly.
10. International Data Transfers
- FynFlow is operated from Pakistan and serves users globally. Your data may be transferred to and processed in countries other than your own, including the United States and the European Union.
- For users in the European Economic Area (EEA), we ensure that any transfer of personal data is subject to appropriate safeguards, including standard contractual clauses where required.
11. Cookies and Tracking
- The FynFlow web application may use session cookies strictly necessary for authentication and session management. We do not use third-party advertising cookies.
- We do not track your activity across third-party websites.
- The mobile app does not use browser cookies but may use device identifiers for session management and push notification delivery.
12. Changes to This Policy
- We may update this Privacy Policy periodically. We will notify you of significant changes by posting a notice in the App or sending an email to your registered address.
- The "Last updated" date at the top of this policy indicates when it was last revised.
- Your continued use of the App after the effective date of any changes constitutes your acceptance of the updated policy.
13. Contact Us