Fyntica

Privacy Policy

In two lines: Fyntica runs on your device by default and sends your data nowhere. If you choose to create an account for sync, your data is stored on a server in rows isolated to you alone.

We use no analytics, show no ads, do not track you, and never sell or share your data for marketing.

1. Who we are

Fyntica is an invoicing, expenses and cash-accounts app published by Fyntica. For any privacy question: contact@fyntica.com.

The controller of your personal data, in the sense of the General Data Protection Regulation (GDPR), is Fyntica, based in the Kingdom of Spain. This policy is governed by that Regulation and by Spanish data protection law.

Legal basis: in local mode there is no processing by us at all — your data never leaves your device. In account mode your data is processed to perform our contract with you, that is, to provide the sync service you asked for (Article 6(1)(b)). We rely on no “legitimate interest” basis for marketing or analytics, because we do neither.

2. Two modes — and the difference matters

a) Local mode (the default)

If you install and use the app without creating an account, all your data is stored in your device's browser storage (IndexedDB). Nothing is sent to any server, and neither we nor anyone else can read it. Even PDF generation and the tax QR code are produced on your device.

b) Account and sync mode (entirely optional)

If you create an account yourself, your data is uploaded so it is available on your other devices and recoverable if you lose your phone. The local copy remains the source of truth, and the app keeps working fully offline.

3. What is actually collected

Data When Purpose
Email address and password Only when you create an account Authenticating you and letting you recover access
Your business records: invoices, clients, suppliers, products, expenses, payments, financial accounts and company settings Only when sync is enabled Storing and syncing them across your devices
Last-modified timestamps During sync Deciding which version wins when two devices differ

Your password is never stored in plain text — the authentication provider hashes it and nobody can read it.

4. What is not collected

The only permissions the app may request relate to saving or sharing a PDF, or picking a receipt image you choose — used at that moment only.

Camera: the app requests camera access only when you open the barcode scanner, and uses it to read the code on your device frame by frame. No picture is captured, stored, or sent to any server — what is saved is the numeric code itself, as part of the product record. Declining the permission blocks nothing: typing the code by hand is always available.

Receipt scanning (OCR): when you ask the app to read a receipt image, the reading happens on your device, using an engine served only from our own domain. Neither the image nor its text is uploaded anywhere, and no third party is involved.

5. Who your data is shared with

We do not sell your data and do not share it for marketing. The only third party involved — and only if you enable sync — is our hosting and database provider (Supabase), acting as a processor on our behalf to store your data, not to use it.

The website and legal pages are served by a static hosting provider, which processes visitors' IP addresses as part of its ordinary technical logs and nothing more.

If you choose to share an invoice through WhatsApp or email, that happens through an app you pick on your device and is governed by that app's own policy.

Where your data is stored

Synced data is stored on servers in France (Paris), inside the European Economic Area. Your data is not transferred outside it.

Your own customers' data

When you record a client's name, tax number or phone in the app, that is personal data belonging to a third party. You are the controller of it, since you decided to collect it and for what purpose; we are only a processor acting on your behalf, storing it as you entered it and never using it for any purpose of our own.

The controller's duties towards your customers therefore fall on you — informing them, answering their requests, and keeping their data no longer than you actually need. If you require a written data processing agreement, ask for one at the contact address below.

6. How your data is protected

7. Retention

In local mode your data lives as long as the app is installed, and disappears when you uninstall it or clear browser data. In account mode it is kept until you delete it — see Delete Account & Data.

8. Your rights

We answer any such request within one month at the latest, the deadline the GDPR sets.

Right to complain: if you believe we have not respected your rights, you may lodge a complaint with the competent supervisory authority — in Spain the Spanish Data Protection Agency (AEPD), or the authority of your country of residence within the European Union.

9. Children

The app is aimed at business owners and freelancers, is not directed at children under 13, and we do not knowingly collect their data.

10. Changes to this policy

Any material change updates the "last updated" date at the top of this page, and the new version is published here. Continuing to use the app afterwards means you accept it.

11. Contact

For any question or request about your data: contact@fyntica.com