Privacy Policy
Privacy Policy
Last Updated: April 23, 2026
K25x is a personal finance app built to keep your data close to you. This page explains, in plain language, what we store, where we store it, and what you can do about it. If something here is unclear, email us (see the bottom of this page).
What data we collect
- Account info. If you sign in with Firebase Auth, we receive your email and (optionally) display name and photo URL from your provider.
- Financial data you enter. Accounts, transactions, budgets, goals, notes, and any documents you attach. You type it, we store it.
- Preferences. Theme, base currency, FIRE assumptions, feature toggles.
- Consent choices. What cookie categories you agreed to, with a timestamp.
- Connected-account metadata. Bank feeds aren't live yet — they're on our Q1 2027 roadmap; today you add accounts by manual entry and statement import. When feeds launch, if you link a bank via Plaid or Lean we'll store the identifiers and access tokens needed to refresh your data on our servers, access-controlled to your account. You'd enter bank credentials inside Plaid's or Lean's own secure screen — we never see or receive your bank username or password.
Where it's stored
- Mostly in your browser. The majority of your data lives in your device's
localStorageunder keys prefixedfintrack-. Clearing your browser storage erases it. - Optionally in Firestore. If you enable Cloud Sync in Settings, a copy is pushed to your own Firebase user document so you can access it on another device. Sync is off by default.
- On an AI provider's servers when you use AI features. Prompts you send to the AI advisor are processed by our configured AI provider — Google Gemini or Anthropic Claude by default, or your own provider (e.g. OpenAI) if you supply a BYOK key, or a self-hosted Ollama model in Local mode. We do not store your prompts separately.
Who we share it with (sub-processors)
We do not sell your data or hand it to brokers. We do rely on the following service providers to run the app; each receives only what its function needs:
- Firebase / Google Cloud — authentication and, if you enable it, Firestore cloud sync.
- Vercel — hosting and edge delivery of the app; processes request metadata and IP addresses to serve pages and apply security protections.
- Google Gemini and Anthropic Claude — process your AI-advisor prompts (whichever is configured). If you add a BYOK key, your chosen provider (e.g. OpenAI) processes those prompts instead.
- Plaid / Lean — when bank feeds launch (Q1 2027), and only if you explicitly link a bank account; they would fetch your data on your behalf.
- Stripe — payment processing if you subscribe to a paid plan.
- Upstash — rate-limiting to protect the API; stores IP addresses briefly to count requests.
- Sentry — error monitoring. It is configured to filter financial amounts out of error reports before they are sent; limited technical identifiers (such as a user ID) may still be present.
- Axiom — operational logging (e.g. sync and authentication events, tied to a user ID); we do not log account balances or transaction amounts.
- PostHog — pseudonymous product analytics, only if you opt in.
- Foreign-exchange rate providers — for the daily FX rates used in multi-currency math (no personal data sent).
We do not run ad networks or sell data to third-party brokers. One disclosure: our optional estate-planning (wills) feature can refer you to selected third-party partners — independent providers, not our sub-processors — who may pay us a referral fee if you use them. Any such fee is paid to us by the partner — we add nothing on top of the partner's own published price — and it is disclosed at the point of hand-off. No referral partner is live yet. If any of this changes, we'll update this page and notify you.
Your rights
- Export. Download everything as JSON from Settings → Data Rights.
- Delete. Delete all local data with one click in Settings. If you had cloud sync on, disable it first, or delete your Firestore doc via the Firebase console.
- Access. Your data is already visible in the app; export gives you a portable copy.
- Correct. Edit any record directly in the app.
- Withdraw consent. Change cookie categories any time from Settings or by clearing storage.
If you are in the EEA, UK, or California, these rights are backed by GDPR / UK GDPR / CCPA. The mechanisms above are how we fulfill them.
Retention
We keep your data for as long as you keep it. We have no background job that deletes your records on a schedule. If you delete your account, local data is wiped immediately; if you had cloud sync on, you should disable it first or clean up your Firestore document separately.
One exception: for security and fraud-prevention purposes we retain a limited audit log of security events — such as sign-ins, account changes, and account deletion itself — tied to your user ID, even after your account is deleted. These records hold only a user ID and the type of event, with a timestamp; they never include your financial data. We keep them on a legitimate security-and-fraud legal basis so we can investigate abuse and protect other users.
Cookies and similar storage
We don't use tracking cookies. We do use your browser's localStorage and IndexedDB for the app itself. The consent banner lets you opt in or out of:
- Necessary — always on. Auth state, your financial data, your preferences.
- Functional — remembers non-essential UI state (e.g. dismissed tips).
- Analytics — pseudonymous usage metrics (tied to a random ID, not your name), if we enable them. Off unless you opt in.
Security
We use Firebase Auth for sign-in and HTTPS for all network traffic. You can turn on device biometric unlock in Settings, which adds a local WebAuthn check before the app opens. Because data lives in your browser, the biggest risk is someone with access to your device; lock your device and enable biometrics.
Children
K25x is for adults. You must confirm you are 18 or older on first launch. We do not knowingly collect data from anyone under 18.
International transfers
Most of the service providers above (Google Cloud, Vercel, the AI providers, Stripe, Sentry, Axiom, PostHog, Upstash) are based in or process data in the United States and other regions, so using cloud sync, AI, or other online features means your data may be transferred outside the UAE, the EEA, and the UK. Where required, these transfers rely on the providers' standard contractual clauses or an adequacy decision. By opting in to those features, you accept the transfer. If you prefer to avoid it, keep the app in its local-first / local-only mode.
Changes to this policy
If we make a material change (new category of data, new third party), we'll update the date above and surface a notice in the app. Minor clarifications will just update silently.
Contact
Questions, requests, or complaints: privacy@k25x.ai. If you are in the EU, you can also complain to your local data protection authority.