Privacy Policy
Privacy Policy
Last Updated: September 8, 2026
K25x is a personal finance app built to keep your data close to you. This page explains, in plain language, what we store, where we store it, and what you can do about it. If something here is unclear, email us (see the bottom of this page).
What data we collect
- Account info. If you sign in with Firebase Auth, we receive your email and (optionally) display name and photo URL from your provider.
- Financial data you enter. Accounts, transactions, budgets, goals, notes, and any documents you attach. You type it, we store it.
- Preferences. Theme, base currency, FIRE assumptions, feature toggles.
- Consent choices. What cookie categories you agreed to, with a timestamp.
- Story submissions. If you send us a story for the Stories Wall we store the pseudonym, country, years in the UAE and text you submit, plus your e-mail address so a moderator can reach you. The address is removed the moment a story is published; a story we decline is deleted in full 90 days after the decision. Stories are not linked to an account, so to withdraw one write to privacy@k25x.ai from the address you submitted with.
- Connected-account metadata. Bank feeds aren't live yet — they're on our Q1 2027 roadmap; today you add accounts by manual entry and statement import. When feeds launch, if you link a bank via Plaid or Lean we'll store the identifiers and access tokens needed to refresh your data on our servers, access-controlled to your account. You'd enter bank credentials inside Plaid's or Lean's own secure screen — we never see or receive your bank username or password.
Where it's stored
- Mostly in your browser. The majority of your data lives in your device's
localStorageunder keys prefixedfintrack-. Clearing your browser storage erases it. - Optionally in Firestore. If you enable Cloud Sync in Settings, a copy is pushed to your own Firebase user document so you can access it on another device. Sync is off by default.
- On an AI provider's servers when you use AI features. Prompts you send to the AI advisor are processed by our configured AI provider — Google Gemini or Anthropic Claude by default, or your own provider (e.g. OpenAI) if you supply a BYOK key, or a self-hosted Ollama model in Local mode. We do not store your prompts separately.
Who we share it with (sub-processors)
We do not sell your data or hand it to brokers. We do rely on the following service providers to run the app; each receives only what its function needs:
- Firebase / Google Cloud — authentication and, if you enable it, Firestore cloud sync.
- Google Drive — only when you choose it: importing a spreadsheet you pick from your Drive, or saving a K25x PDF into a K25x folder in your own Drive. Both run in your browser with Google's narrowest file scope; the file goes straight between your browser and your Drive and never passes through our servers, and we never see or store your Google sign-in.
- Vercel — hosting and edge delivery of the app; processes request metadata and IP addresses to serve pages and apply security protections.
- Google Gemini and Anthropic Claude — process your AI-advisor prompts (whichever is configured). If you add a BYOK key, your chosen provider (e.g. OpenAI) processes those prompts instead.
- Plaid / Lean — when bank feeds launch (Q1 2027), and only if you explicitly link a bank account; they would fetch your data on your behalf.
- Stripe — payment processing if you subscribe to a paid plan. Invoices and receipts are kept for accounting retention; when you delete your account the Stripe customer profile (e-mail, name, and the link to your user ID) is redacted once no subscription is open.
- Upstash — rate-limiting (IP addresses, briefly, to count requests), sign-in and passkey challenge state for a few minutes, your daily AI usage counter, and short-lived caches of AI answers to public glossary lookups and transaction categorisation. The content of imported statements, e-mails and text messages is never cached there.
- Sentry — error monitoring. It is configured to filter financial amounts out of error reports before they are sent; limited technical identifiers (such as a user ID) may still be present.
- Axiom — operational logging (e.g. sync and authentication events, tied to a user ID); we do not log account balances or transaction amounts.
- PostHog — pseudonymous product analytics, only if you opt in.
- Resend — transactional e-mail: sign-in and step-up codes, account notices and, only if you opt in, the newsletter. It receives your e-mail address and the content of those messages, nothing from your financial data.
- Foreign-exchange and metal spot-price providers — daily FX rates for multi-currency math and gold/silver prices for the Zakat Nisab. Our server makes those requests; no personal data is sent.
We do not run ad networks or sell data to third-party brokers. One disclosure: our optional estate-planning (wills) feature can refer you to selected third-party partners — independent providers, not our sub-processors — who may pay us a referral fee if you use them. Any such fee is paid to us by the partner — we add nothing on top of the partner's own published price — and it is disclosed at the point of hand-off. No referral partner is live yet. If any of this changes, we'll update this page and notify you.
Your rights
- Export. Download everything as JSON or CSV, and your reports as PDF, from Settings → Data Rights.
- Delete. To remove everything K25x has saved in your browser without closing your account, use “Remove data from this device” in Settings → Data Rights, or choose “Log out and remove data from this device” when you log out; both sign you out and leave your cloud copy (if you use sync) in place. K25x keeps one account per browser: if you sign in to a browser holding another account's data, nothing opens until you remove that data from the browser or sign out (only that account can export its data, while signed in as itself); if a browser holds data from before this rule that K25x cannot match to an account, you are asked whether it is yours. To close your account entirely, delete it from Settings → Data Rights. Account deletion asks for a fresh sign-in check, then erases your cloud copy (if you had sync on), your sign-in identity and your local data. If any step cannot finish at once, it is retried automatically every day until it does, within 30 days of your request at most.
- Access. Your data is already visible in the app; export gives you a portable copy.
- Correct. Edit any record directly in the app.
- Withdraw consent. Change cookie categories any time from Settings or by clearing storage.
If you are in the EEA, UK, or California, these rights are backed by GDPR / UK GDPR / CCPA. The mechanisms above are how we fulfill them.
Retention
We keep your data for as long as you keep it; nothing deletes your active records on a schedule. When you delete your account, local data is wiped immediately and the cloud copy and your sign-in identity are erased, with a daily job retrying any step that could not finish at once so the whole erasure completes within 30 days. If you had a paid plan, your Stripe customer record is redacted once no subscription is open; invoices stay for accounting. Declined story submissions are deleted 90 days after the decision.
One exception: for security and fraud-prevention purposes we retain a limited audit log of security events — such as sign-ins, account changes, and account deletion itself — tied to your user ID, even after your account is deleted. These records hold a user ID, the type of event and a timestamp, plus a small set of non-financial details about the event itself (for a will referral: the partner you chose, the domain of your e-mail address and the provider’s message id). They never include your financial data, your name or your network address; the audit writer redacts amounts and IP addresses by construction. We keep them on a legitimate security-and-fraud legal basis so we can investigate abuse and protect other users.
Cookies and similar storage
We don't use tracking cookies. We do use your browser's localStorage and IndexedDB for the app itself. The consent banner lets you opt in or out of:
- Necessary — always on. Auth state, your financial data, your preferences.
- Functional — remembers non-essential UI state (e.g. dismissed tips).
- Analytics — pseudonymous usage metrics (tied to a random ID, not your name), if we enable them. Off unless you opt in.
Security
We use Firebase Auth for sign-in and HTTPS for all network traffic. From Settings you can add an authenticator-app code (TOTP) or a passkey to sign-in, a password lock that re-prompts after 30 minutes idle, and device biometric unlock, which adds a local WebAuthn check before the app opens. Your two-factor secret and the AI advisor's learned facts are AES-GCM encrypted before they touch browser storage. Because data lives in your browser, the biggest risk is someone with access to your device; lock your device and enable a lock here too. The full threat model is on our Security page and every claim is traced to shipped code in the Trust Center.
Children
K25x is for adults. You must confirm you are 18 or older on first launch. We do not knowingly collect data from anyone under 18.
International transfers
Most of the service providers above (Google Cloud, Vercel, the AI providers, Stripe, Sentry, Axiom, PostHog, Upstash) are based in or process data in the United States and other regions, so using cloud sync, AI, or other online features means your data may be transferred outside the UAE, the EEA, and the UK. Where required, these transfers rely on the providers' standard contractual clauses or an adequacy decision. By opting in to those features, you accept the transfer. If you prefer to avoid it, keep the app in its local-first / local-only mode.
Changes to this policy
If we make a material change (new category of data, new third party), we'll update the date above and surface a notice in the app. Minor clarifications will just update silently.
Contact
Questions, requests, or complaints: privacy@k25x.ai. If you are in the EU, you can also complain to your local data protection authority.