Privacy Policy
Last updated: August 23, 2026
This Privacy Policy describes how 403 Finance, Inc., a Delaware corporation (referred to in this Privacy Policy as "Forbidden Finance," "403 Finance," "we," "us," or "our"), collects, uses, stores, shares, and protects information when you use the Forbidden Finance personal-finance application that 403 Finance, Inc. operates, available on iOS, Android, and the web (the "Service").
This Privacy Policy is incorporated by reference into our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms of Service.
The Service is offered in most countries. It is not offered where we are prohibited from offering it by applicable sanctions law, or in a small number of countries we have chosen not to serve; the current list of excluded countries is enforced at signup and is available on request. By creating an account, you represent that you are at least sixteen (16) years of age. If you are located in the EEA or the United Kingdom, Section 16 describes the legal bases on which we process your data, your rights under the GDPR and UK GDPR, how your data is transferred internationally, and how to reach our EU and UK representatives. If you are located elsewhere, Section 17 describes the rights that apply to you under your local data protection law.
1. Information We Collect
1.1 Personal Information you provide
When you create an account, subscribe to a paid plan, or use the Service, we collect the following information directly from you:
- Account identifiers — email address, username (3–30 characters), and the given name and family name you provide (synced from your sign-in provider where applicable).
- Email deliverability verification — when you sign up or change your email address, we check that the address is deliverable using our email-verification provider (Reoon), which processes the address for that purpose only.
- Account preferences — base currency, country of residence, and time zone.
- Age verification — birth month and birth year, retained only to verify the 16-and-over age representation.
- Manually entered financial data — transactions, budgets, categories, tags, assets, liabilities, goals, and notes.
- Reflection journal entries — if you choose to use the reflection-journal feature, the freeform text you enter is stored in association with your account. You may delete individual entries at any time, and all entries are deleted on account deletion in accordance with Section 4.2.
- Receipt images and receipt data — if you use the receipt features (available on paid tiers), we collect the receipt photos and documents you upload and the receipt emails you forward to your receipts inbox, including the text of the forwarded email. Emailed receipts are accepted only from your account email address and from additional sender addresses you have added and confirmed; mail from any other address is discarded without being stored. Images are re-encoded on upload — location metadata your camera may embed, such as GPS tags, is stripped — and both the images and anything read from them are stored encrypted under keys specific to your account. A receipt shows whatever the merchant printed on it, which can include, for example, the last four digits of the payment card you used; we store the document as you provided it. Separately, and only if you turn on the "Let AI read my receipts" setting (Settings → AI, off by default), we send your receipt images and forwarded receipt emails to an AI model that reads the document and returns the merchant, date, totals, taxes, individual line items, and the store's printed address, and suggests a spending category. Everything the model returns is presented to you for review before anything is saved, and is stored encrypted under the same account-specific keys. The store's printed address can be saved on the matching transaction as its location; if you have given another person access to your data (Section 6(b)), a saved location is visible to anyone who can see that transaction. While the setting is off, receipts are simply stored for you to fill in yourself and nothing you add is read by AI. Turning the setting off stops AI reading from your next receipt onward; receipts already read keep their extracted details until you delete them. See Section 11 for our position on AI features.
- Investment lot-level detail — when you connect a brokerage or investment account that provides lot-level information through Plaid, we receive and store that information as part of normal account ingestion (we do not control which fields Plaid sends). Lot-level data — including cost basis per lot, lot acquisition date, and the lot accounting method (FIFO, LIFO, average cost, or specific identification) — is stored for all eligible users but is only displayed in the application on the Premium tier.
- Recurring transaction detection signals — if you enable the recurring-transaction detection feature, we apply algorithmic analysis to your transaction history to identify recurring patterns. The feature is off by default; you can enable or disable it at any time in your settings.
- Achievements and behavioral processing — the Service includes achievements and transaction-analysis features that surface insights about your spending and savings activity. These features are gated by a single "transaction analysis" preference, which is off by default. If you turn it on, we evaluate your activity (such as budget adherence, savings milestones, and category trends) to award achievements and provide insights. If you turn it off, we cease the behavioral analysis going forward; previously earned achievements remain associated with your account. See Section 11 for our position on automated decision-making.
- Support chat messages — when you initiate a chat with us (via Charla) on the marketing site, in our help documentation, or within the application, we collect the contents of the chat session, including messages you send, the page or screen you were on when you started the chat, and any contact information you provide.
- Feedback and changelog portal content — when you open the in-app feedback and changelog surface, we pass your account identifier, your email address, and your subscription tier to that portal so your submissions are attributed to you and we can reply to you. Anything you then write there — feedback posts, comments, and votes — is stored alongside them. The portal is software we host ourselves; its database is hosted by Neon, LLC (a Databricks company) in the United States. No account, balance, transaction, or bank- and brokerage-connection data is shared with this portal.
- API and AI-assistant connection records — if you create an API key or connect an application or AI assistant to your account (a Premium feature), we collect the records of that connection: the application's name, the scopes you grant it, whether you have allowed it to make changes, the privacy profile you configure for it (hidden fields and excluded accounts or categories), and the dates it is created, used, and revoked. The key itself is shown to you once and stored only as a SHA-256 hash — we cannot recover it. Every request a connection makes is recorded in an access log — the surface used, the operation, the scope, the outcome, and the IP address it came from — which you can review in Settings → AI & API Connections. See Section 6(e) for what a connected application receives, and Section 11 for how an assistant you connect relates to the Service's own AI features.
- Push-notification token and preferences — when you opt in to push notifications.
- Consent records — records of consent you give for the Terms of Service, this Privacy Policy, age verification, marketing communications, bank connections, data sharing with other people, AI reading of receipts, authorizations you grant to connected applications and AI assistants, and similar matters.
1.2 Information we receive from your bank via our banking aggregators
If you choose to connect a bank account, we receive from our banking data aggregator — Plaid or Quiltt, depending on your institution — the information your financial institution makes available, which typically includes account identifying metadata (such as institution name, account name, account type and subtype, and the last 4 digits of your account number), balance information, and transaction history. The complete set of fields Plaid may share with us is documented in Plaid's End User Privacy Policy.
We do not receive your bank login credentials, full account numbers, or bank routing numbers. Bank credentials are entered into the aggregator's secure interface (Plaid or Quiltt), not into Forbidden Finance. Where Quiltt provides the connection, Quiltt engages Finicity (a Mastercard company) as its connected data aggregator on our behalf; Quiltt maintains its own disclosures of the downstream providers it engages.
1.3 Financial Information for subscriptions
If you subscribe to a paid plan, you provide payment information (such as a card number, expiration date, billing address, or platform receipt) to our payment processors — Stripe for web subscriptions, Apple for iOS in-app purchases, and Google for Android in-app purchases. We do not receive or store your card numbers. Our payment processors handle payment data under their own privacy policies.
1.4 Cookies and similar technologies
Within the application (web):
| Cookie | Purpose | Required for Service? | Duration |
|---|---|---|---|
Session cookie (__Secure-sid / sid) | Maintains login state | Yes (essential) | Browser session, subject to inactivity expiry |
remember_email | Pre-fills your email on the login page | No (requires consent) | 90 days |
Within the mobile application: the mobile application does not set HTTP cookies. Authentication is handled through native OAuth via your sign-in provider.
On the marketing site (403fin.io), help documentation (help.403fin.io), and feedback and changelog portal (feedback.403fin.io): we use a consent management platform (Consently) to gate optional cookies and similar tracking technologies. Optional categories include web analytics (Rybbit, a cookieless analytics service that sets no cookies and stores no identifiers on your device) and, on the marketing and help sites, support-chat persistence (Charla). Optional tracking is off by default until you affirmatively consent. When the feedback portal is displayed inside the application (see Section 13(f)), no consent platform and no analytics load there.
Within the application (app.403fin.io): we do not load a consent management platform, Google Analytics, or any other third-party web analytics (including Rybbit). The only optional processing is error and performance diagnostics (see Section 1.5), which are off by default and which you can turn on or off at any time in Settings → Privacy & Consent.
Page Shield script-integrity reports (marketing site only). We use Cloudflare Page Shield in report-only mode on the marketing site at 403fin.io. When your browser encounters a Content Security Policy violation, or when a third-party script loaded by the marketing site changes, your browser submits a small report — containing the violating script's URL, a hash of the script, the page URL, your IP address, and your User-Agent — to a Cloudflare-managed reporting endpoint. We use these reports solely to detect supply-chain tampering of third-party scripts. No cookies are set by Page Shield. Page Shield is not enabled on the application (app.403fin.io).
1.5 Information about your activity and device
When you use the Service, we automatically receive and log certain information for security, fraud prevention, and operational diagnostics:
- IP address (which may be static or dynamic).
- Browser type and language; operating system and version; type of mobile device.
- Application version; referring and exit pages or URLs (on the web).
- Date and time of requests; request and session identifiers.
- Details of your activity within the Service, such as feature usage, error reports, and crash diagnostics.
We do not collect mobile advertising identifiers (IDFA on iOS, AdID on Android), because we do not display advertising in the Service and do not share data with advertising networks. First-party analytics identifiers used by our diagnostics and analytics tools (such as anonymous session identifiers stored on your device by Grafana Faro in the web application) are not advertising identifiers and are not used for cross-app or cross-site behavioral advertising. The web analytics service on the marketing, help-documentation, and feedback-portal sites (Rybbit) stores no identifiers on your device at all.
While we do not deliberately collect your mobile network carrier or your network connection type (Wi-Fi, cellular, etc.), this information may be incidentally present in server logs, platform-provided metadata, or third-party SDKs (such as crash reporting). We do not use such information for advertising, profiling, or any purpose other than diagnosing operational issues and protecting the Service.
The lawful basis for the collection described in this Section 1.5 is our legitimate interest in operating, securing, and improving the Service.
Edge security processing. Before requests reach our application servers, our network provider Cloudflare inspects incoming requests at its edge to (i) filter malicious traffic and DDoS attempts (Web Application Firewall), (ii) compare credential-bearing fields submitted to our authentication endpoints against publicly known credential-breach corpora to detect known-leaked credentials (Cloudflare Leaked Credentials Detection), and (iii) compute a bot-likelihood score from TLS fingerprint and behavioral signals (Cloudflare Bot Management, currently monitor-only — no enforcement, scores are recorded but not used to allow or deny requests). Cloudflare processes this data as our processor under the Cloudflare Data Processing Addendum.
Device and network fingerprinting for security. Our edge security provider may compute a TLS-handshake fingerprint (JA3) and aggregate behavioral signals to distinguish automated traffic from human visitors. Any such fingerprint is used only for fraud and bot prevention. It is not used for advertising, individual user profiling, or any automated decision that produces legal or similarly significant effects (see Section 11).
1.6 Authentication and security data
To authenticate you, enforce account security, and respond to incidents, we collect and retain:
- Session identifiers and metadata — for each active or recently active session: the session identifier, the IP address from which the session was created, the user-agent string of the browser or mobile device, the device identifier and device name (if provided by the platform), and the date/time of session creation and last activity.
- Multi-factor authentication metadata — for each MFA device or factor you register: the device or factor type (e.g., TOTP, WebAuthn passkey, hardware security key), a user-supplied name for the device, the date the factor was registered, and the date it was last used. TOTP shared secrets are stored encrypted at rest using AES-256-GCM and are decrypted only at the moment of verification. WebAuthn passkey records contain only the public key and credential identifier issued by your device; we do not store passkey private keys, which never leave your device.
- Consent-action audit data — for each consent grant or withdrawal you make, we retain the IP address and user-agent string of the action, in addition to the consent record itself, to evidence consent under applicable law. For certain consent categories — including email-preference consents, data-sharing consents, and billing-payment consents — we also record the application surface where consent was given (for example: onboarding flow, in-app settings, email-unsubscribe link, account-deletion confirmation, checkout button).
- Credential-breach-signal records — when Cloudflare's Leaked Credentials Detection (described in Section 1.5) flags credentials you submit at our authentication endpoints, we record a single row per user capturing only: the timestamp of first detection, the timestamp of most recent detection, a running count of detections, an opaque indicator of the kind of match returned by Cloudflare, and the resolution state (notified, dismissed by you in-app, or resolved by a password change). We use this record to show you an in-app recommendation banner and to send a single rotation-recommendation email per detection cycle (described in Section 5(c)). This record never blocks your access to the Service. The row is cleared automatically when you change your password.
- Mobile application-integrity signals — our iOS and Android applications include a runtime application self-protection SDK (Talsec freeRASP) that evaluates device-integrity signals — such as rooted or jailbroken status, the presence of a debugger or emulator, application tampering, and installation from an unofficial store — to protect the Service and your account against fraud and abuse. These signals are used only for security and are never used for advertising or profiling.
Lawful basis for the collection described in this Section 1.6 is our legitimate interest in operating, securing, and authenticating access to the Service, and (for consent-action data) our regulatory obligation to evidence consent.
2. Information We Explicitly Do Not Collect
- Your full bank account numbers or routing numbers.
- Your Social Security number or any government-issued identification number.
- Your bank login credentials (these are entered into the banking aggregator's secure widget and are not visible to us).
- Your full credit-card or debit-card numbers (these are handled by Stripe, Apple, or Google as the case may be).
- Your contacts, calendar, microphone, or precise device location. We never access your photo library; we receive only the individual images you choose to upload as receipts (Section 1.1), and location tags your camera embeds in them are removed on upload.
- Advertising identifiers (IDFA / AdID).
3. How We Store and Protect Your Data
- All Service data is stored in PostgreSQL databases hosted on Microsoft Azure in the East US region (Virginia), United States.
- Encrypted backups are written to Backblaze B2 (US-East region) and retained for thirty-five (35) days.
- Bank access tokens are encrypted using AES-256-GCM before being written to the database.
- All data in transit between you, your bank, and our infrastructure is encrypted using TLS 1.2 or higher (TLS 1.3 preferred).
- Each user's data is isolated at the database level by row-level security (RLS): our system enforces that no user can access another user's data, even in the event of an application bug.
- All monetary values are stored using fixed-precision decimals (
NUMERIC(19,4)) so that calculations are exact and free of floating-point rounding errors. - Marketing-site pages at 403fin.io may be served from Cloudflare's edge cache, including a long-term object-storage tier (Cache Reserve) and, if our origin is temporarily unavailable, from cached copies via Cloudflare Always Online. Cache keys strip common marketing query parameters (
utm_*,gclid,fbclid) and the cache is bypassed when a logged-in session cookie is present. No application data and no logged-in user data is cached at the edge; application traffic at app.403fin.io is not served from Cache Reserve or Always Online.
We take commercially reasonable steps to protect personal information from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. No security system is impenetrable; we cannot guarantee the security of our databases or those of third parties with which we share information, nor can we guarantee that information transmitted over the internet will not be intercepted.
4. Data Retention and Deletion
4.1 While your account is active
| Data category | Retention | Visible to you |
|---|---|---|
| Transaction history (per tier) | For the life of your account | Free: most recent 6 months. Starter: most recent 12 months. Pro: most recent 24 months. Premium: full history. |
| Bank connection tokens | Active while the connection is connected. On disconnect, retained through a thirty (30) day verification cycle to confirm the bank has revoked the token on its side, then permanently deleted (see Section 4.3). | — |
| Net worth history (per-account and aggregate) | For the life of your account | Free: most recent 6 months. Starter: most recent 12 months. Pro: most recent 24 months. Premium: full history. |
| Exchange rates and market prices | Indefinitely (this is not personal data) | — |
| Manually entered budgets, categories, tags, goals | For the life of your account | All entries |
| Manually entered assets and liabilities | For the life of your account | All entries |
| Receipt images and extracted receipt details | For the life of your account. A receipt you delete is removed immediately, and its stored images and extracted details are permanently erased by a scheduled cleanup that runs continuously (typically within hours). All receipts are deleted on account deletion (see Section 4.2). | All receipts you have added (paid tiers) |
| API and AI-assistant connection records and access log | For the life of the connection; revoking a connection takes effect immediately, and connection records and their access log are deleted with your account (Section 4.2). Registrations of third-party applications themselves (an application's name and redirect address — no data about you) are shared records and persist after account deletion. | All connections and their access log (Settings → AI & API Connections; Premium) |
| Consent records | Six (6) years (legal obligation) | — |
| Audit logs | Six (6) years (legal obligation) | — |
| Email send and notification logs | Twelve (12) months for delivery and bounce diagnostics | — |
| Error and performance telemetry (Grafana Faro, self-hosted) | Up to 365 days | — |
| Server application logs (IP, user agent, request identifiers) | Ninety (90) days hot retention with one (1) year cold retention in encrypted storage, for security and incident response. | — |
| Page Shield CSP / script-integrity reports (Cloudflare) | 30 days | — |
| Encrypted backups (Backblaze B2) | 35 days | — |
Why we retain beyond your display window. We keep the underlying transaction history for the life of your account so that if you upgrade your subscription, the additional history becomes immediately available without requiring you to reconnect your bank or re-import data. If you downgrade, we do not delete the data outside your new tier's display window; it becomes hidden in the application and is restored if you re-upgrade.
4.2 On account deletion
When you request account deletion:
(i) We immediately deactivate your account and block further sign-in, and bank syncing stops immediately.
(ii) Your account enters a thirty (30) day recovery window. During this window your data is retained but is not accessible in the app, and your bank connection is left dormant (not synced) solely so that recovery is possible. We provide a single-use recovery link — shown on the deletion confirmation screen and emailed to you — that you may use at any time within the 30-day window to cancel the deletion and restore your account and all of its financial data. For your security, if you recover your account you will be asked to re-confirm each bank connection before syncing resumes.
(iii) We also email you a secure, time-limited link to export your data in CSV and JSON formats, valid for thirty (30) days, and the same link is displayed on the deletion confirmation screen in case email delivery fails.
(iv) At the end of the 30-day window, deletion becomes permanent: your financial data is permanently deleted, your data-export archive is destroyed, and your bank-access tokens are revoked with Plaid and thereafter handled under the disconnection lifecycle described in Section 4.3. Some records may persist briefly beyond day 30 due to upstream provider revocation requirements (for example, where a financial institution has not yet confirmed revocation of an access token issued through Plaid), in which case deletion completes once revocation is confirmed.
(v) Consent records and audit logs are retained for six (6) years as required by law, with personal identifiers minimized.
(vi) Aggregated, pseudonymized statistics that cannot reasonably be re-associated with you may be retained indefinitely.
During the 30-day recovery window you can restore your account and data using your recovery link. After the 30-day window closes, deletion is permanent and irreversible: your account and data cannot be recovered, so use your export link before then if you want a copy of your data.
4.3 When you disconnect a bank account
The bank-disconnection lifecycle is designed to revoke access to your bank as quickly as possible and to handle the rare case where a token appears to be revoked but is not yet fully removed on the financial institution's side.
(a) Immediately on disconnect. We call Plaid's /item/remove endpoint to revoke the access token. As soon as Plaid confirms revocation, your accounts and their data are hidden in the application — you will no longer see balances, transactions, or holdings from that connection.
(b) Verification window (Days 1–30). Despite Plaid's success response, we perform five subsequent verifications, scheduled at approximately Day 1, Day 4, Day 11, Day 20, and Day 30, to confirm that the token is in fact no longer active. Each verification queries Plaid for the item; we expect the item to be reported as not found. If during this window we discover the token is still live (for example, due to a transmission failure or partial revocation), we automatically re-issue the revocation request, restart the 30-day verification timer, and log the event.
(c) Deletion (Day 30). Once verification completes, the encrypted access token, the verification record, and the transaction and balance data from the disconnected connection are all permanently deleted from our database.
(d) Reconnecting after disconnect. Disconnection is final. If you wish to track the same bank again, you must re-connect through Plaid; we will import transaction history from your bank fresh, subject to whatever history your financial institution makes available at the time of the new connection.
4.4 On subscription downgrade
Subscription downgrades you request take effect at the end of your current billing period; until then, your existing tier remains active.
(a) At the end of your billing period. When the downgrade takes effect, if you have more bank connections than your new tier allows, the Service disconnects the excess. You may choose in advance which connections to disconnect using the downgrade-preview screen inside the application. If you do not make a selection, the Service automatically disconnects the most-recently-connected accounts first and preserves your longest-running connections, until the count fits within your new tier's allowance.
(b) Lifecycle of a disconnected connection. Disconnected connections follow the lifecycle described in Section 4.3 — token revocation, the 30-day verification window, and deletion at Day 30. We notify you of which connections were disconnected.
(c) Tier-gated views. Where a feature or data view is limited by tier (for example, the transaction-history window or net-worth-history view in Section 4.1), the in-app view contracts to the new tier's window after downgrade. The underlying data we already hold is not deleted on downgrade; if you upgrade again, the previously hidden window becomes visible without requiring re-import.
(d) Frozen or suspended states. The Service does not maintain a "frozen" or "suspended" connection state. A connection is either active (syncing) or disconnected (no further sync). There is no in-between state in which a connection sits idle but reattachable.
5. How We Use Your Information
We use the information we collect for the following purposes:
(a) To provide, operate, and maintain the Service — including authenticating you, syncing your bank data, computing budgets and net worth, generating reports, and delivering support chat responses.
(b) To process payments and manage your subscription.
(c) To send you transactional communications (account notices, security alerts, receipts, and support replies). Security-alert emails include, by way of example: login-verification codes, password-reset confirmations, new-device login notifications, and the one-time rotation-recommendation email we send when Cloudflare's Leaked Credentials Detection (Section 1.5) flags a password you submitted at our authentication endpoints. These communications are not opt-outable because they protect the security of your account.
(d) With your consent, to send you marketing communications about Forbidden Finance products and features. You can opt out at any time via the unsubscribe link in any marketing email or in your in-app preferences. You cannot opt out of transactional communications.
(e) To prevent fraud and abuse, detect security incidents, and protect the rights, property, and safety of Forbidden Finance, our users, and the public.
(f) To comply with applicable law, court order, or other governmental or regulatory request.
(g) To improve the Service through pseudonymized usage analytics and aggregated statistical analysis.
(h) With your consent, to read the receipt images and forwarded receipt emails you provide, so the Service can fill in transaction details — merchant, date, totals, line items, a category suggestion, and the store's printed address as the transaction's location — for your review (Section 1.1). The AI model runs on infrastructure provided by Cloudflare, Inc. (Workers AI), acting as our processor; receipt content is processed to produce the extraction, is not used by us for advertising or profiling, and, under our agreement with Cloudflare, is not used to train generative AI models.
(i) To operate the API and AI-assistant connections you create (Section 1.1) — authenticating each request a connection makes, applying the scopes and privacy choices you configured for it, recording the request in your access log, and attributing any change a connection makes to your data so you can see it was made through that connection.
6. How We Share Your Information
We share personal information only as described below:
(a) With sub-processors who act on our behalf. We engage third-party service providers to operate parts of the Service (such as bank-data aggregation, payment processing, identity and authentication, push notifications, email delivery, error tracking, support chat, and infrastructure hosting). These providers have access to information only as necessary to perform their functions and are contractually required to protect it. The current list of sub-processors is published at 403fin.io/forbidden-finance/legal/subprocessors and is updated as our processor relationships change. Under the California Consumer Privacy Act, the entities described in this paragraph are "service providers" as defined in §1798.140(ag); they process your personal information only on our behalf, for the purposes we direct, and under contractual restrictions that prohibit them from selling or sharing your personal information or from using it for their own commercial purposes.
(b) With people you authorize. If you grant a Shared Partner or Shared Viewer access to your data through the Service's sharing features (as described in our Terms of Service), they may view (and a Shared Partner may edit within the Service) the data you have authorized them to access. You can revoke this access at any time.
(c) When required by law. We may disclose information when required by law, court order, subpoena, or other governmental or regulatory request, or when we believe in good faith that disclosure is necessary to protect rights, property, or safety.
(d) In the event of a corporate transaction. If Forbidden Finance is involved in a merger, acquisition, financing, reorganization, or sale of substantially all of its assets, information about you may be part of the transferred assets, subject to the protections of this Privacy Policy.
(e) With applications and AI assistants you connect. The Service includes an API and an AI-assistant connector (available on Premium) that let you connect applications and AI assistants of your own choosing — for example, an AI assistant provided by Anthropic or OpenAI — to your data. Data flows to such a recipient only when you create the connection, and only within the scopes you grant it: a connection is read-only unless you separately allow it to make changes, you can hide individual fields and exclude whole accounts or categories from it, and you can revoke it at any time with immediate effect. What a connected application or assistant does with the data it receives is governed by its own privacy policy and terms, not this one — it acts on your instructions as a recipient you chose, and it is not one of our sub-processors, so it does not appear on our Sub-Processor List. If a connection you have allowed to make changes edits a transaction that came from your bank, we keep the bank's original values and you can restore any changed field. You never need to connect an application or assistant to use the Service.
We do not share information with third-party advertising networks, data brokers, or marketing partners outside of our subscription billing and direct sub-processor relationships described above.
7. No Sale or Sharing of Personal Information for Cross-Context Behavioral Advertising
Forbidden Finance does not sell personal information, and does not share personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA) and similar laws. We do not display advertising in the Service. We do not work with advertising networks. We do not transfer personal information to data brokers.
Forbidden Finance receives no monetary payment, no in-kind consideration, and no other valuable consideration of any kind in exchange for personal information about you. We pay our sub-processors for the services they provide to us; we do not receive payment or any other value from any party in exchange for transferring personal information.
8. Sub-Processors
A list of sub-processors that process personal information on our behalf, along with vendors we use that do not receive personally identifiable user data, is published at 403fin.io/forbidden-finance/legal/subprocessors and updated when our processor relationships change.
9. Your California Privacy Rights
If you are a resident of California, you have the following rights under the California Consumer Privacy Act and California Privacy Rights Act (collectively, "CCPA"):
- Right to know. You may request that we disclose the categories of personal information we have collected about you, the sources from which we collected it, the business or commercial purposes for collecting it, the categories of third parties with whom we shared it, and the specific pieces of personal information we have collected about you, going back twelve (12) months (or longer if you request).
- Right to data portability. When you exercise the Right to Know, you may also request that the personal information be delivered in a portable, readily usable format. We provide all data exports in CSV and JSON formats, which can be imported into spreadsheet, accounting, and personal-finance applications without modification.
- Right to delete. You may request that we delete the personal information we have collected from you, subject to exceptions permitted by law (such as records we are required to retain for security, fraud prevention, or legal compliance).
- Right to correct. You may request that we correct inaccurate personal information we have about you.
- Right to opt out of sale or sharing. As noted in Section 7, we do not sell or share personal information for cross-context behavioral advertising. There is nothing for you to opt out of, but you may submit a confirmation request at any time.
- Right to limit use of sensitive personal information. As noted in Section 2, we do not collect categories of sensitive personal information (such as Social Security numbers or government IDs) for which a limit-use right applies.
- Right to non-discrimination. We will not deny service, charge different prices, or provide different quality of service because you exercise any of these rights.
Categories of personal information we collect, and our business purposes:
| Category (CCPA §1798.140(o)) | Examples we collect | Business purposes |
|---|---|---|
| Identifiers | Email, username, name, IP address, device identifiers | Authentication, account management, security, fraud prevention |
| Customer records | Account preferences, support chat history | Service delivery, support |
| Commercial information | Subscription tier, billing history (via payment processors) | Billing, subscription management |
| Internet or network activity | Server logs, application usage telemetry | Security, operational diagnostics, product improvement |
| Geolocation data | Approximate country (from country preference and IP-derived region) | Tier eligibility, fraud prevention, regulatory compliance |
| Inferences | Aggregated usage patterns | Product improvement; not used for individualized decisions |
| Financial information | Bank balances, transactions, investments (via Plaid); receipt images and extracted receipt details you provide (including the store's printed address) | Core Service delivery |
We do not collect categories of "sensitive personal information" under §1798.140(ae) other than financial-account information, which is used solely to provide the Service you have requested and is never used for inferring characteristics about you.
Authorized agents. You may authorize an agent to submit a privacy request on your behalf. Please email us at privacy@403fin.io with proof of authorization (such as a signed power of attorney or a notarized authorization).
10. Your Other State Privacy Rights
We extend privacy rights — including the rights to know, delete, correct, and opt out — to residents of all U.S. states that have enacted comprehensive consumer privacy laws, including (as of the effective date of this Policy) Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Florida (FDBR), Montana (MCDPA), Tennessee (TIPA), Indiana (ICDPA), and other states whose laws take effect during the period this Policy is in force.
You may exercise the equivalent rights described in Section 9 using the contact methods in Section 12. We will respond within the period required by your state's law.
11. Automated Decision-Making
We do not use automated decision-making algorithms to make decisions about you that produce legal effects or similarly significant effects without human involvement.
Forbidden Finance is built to help you take control of your own finances. We do not provide financial, investment, tax, or legal advice (see Section 14 of our Terms of Service). Where the Service generates suggestions, projections, or summaries — such as budget templates, debt payoff schedules, retirement projections, AI-generated summaries of your own data, or other tools we may describe as "AI features" — these are presented as options for you to consider, not recommendations or advice. They are derived from data you provided and from market data we have aggregated, and they are not used to make automated decisions that produce legal or similarly significant effects concerning you. You may modify, ignore, disable, or override any such suggestion at any time. AI capabilities in the Service are scoped to reading and summarizing your own data — for example, transcribing a receipt you photographed into transaction details for your review — rather than directing your financial choices. AI-extracted receipt details are suggestions that you can edit or discard; they are checked against the receipt's own arithmetic, they are always presented for your confirmation, and they are not used to make automated decisions that produce legal or similarly significant effects concerning you. The AI capabilities this Section describes are those built into the Service and operated by us. Separately, you may connect an AI assistant of your own choosing through our API and assistant connector (Section 6(e)); an assistant you bring is your tool, acting on your instructions — this Section's description of the Service's AI capabilities does not extend to it, and what it does with your data is governed by its own provider's terms and privacy policy.
If we change this practice in the future, we will update this Privacy Policy and provide you with the opportunity to object or opt out as required by applicable law.
12. How to Submit a Privacy Request
To submit a privacy request — including requests to know, delete, correct, or opt out of sale or sharing — you may contact us through any of the following channels:
- Email: privacy@403fin.io
- In-app chat: open the chat icon in Settings → Support within the Forbidden Finance application
- Authorized agents: please email privacy@403fin.io with proof of authorization
We will acknowledge receipt of your request within ten (10) business days and respond substantively within forty-five (45) days, as required by applicable law. If your request requires additional time, we will notify you of the extension before the initial period expires. We may need to verify your identity before fulfilling certain requests; we will use information already in our possession where possible and will collect only the additional information reasonably necessary to confirm that you are the person whose data is the subject of the request.
13. Global Privacy Control, Do Not Track, and Cross-Property Behavior
(a) Global Privacy Control. Forbidden Finance honors the Global Privacy Control ("GPC") browser signal as a valid opt-out of any sale or sharing of personal information for residents of California and other states whose laws recognize GPC. Our consent management platform (Consently) detects GPC signals automatically and applies them to optional tracking categories on our marketing site at 403fin.io and our help documentation at help.403fin.io. The web build of our application at app.403fin.io does not load a consent management platform or any optional product-analytics tracking; the only optional processing in the application is error and performance diagnostics, which are off by default and which you control through the Diagnostics setting in Settings → Privacy & Consent. Our native mobile applications (iOS and Android) do not receive GPC signals from the operating system; users on mobile manage their consent through the in-app settings.
(b) No cross-context behavioral advertising. The Forbidden Finance application does not display advertising and does not engage in cross-context behavioral advertising; we do not sell or share personal information for advertising purposes under any browser, device, or operating-system setting.
(c) Do Not Track. Because there is no industry standard for response to the "Do Not Track" ("DNT") browser header, we do not separately modify behavior based on DNT, but our default posture is to load no optional tracking absent affirmative consent — which is functionally equivalent to honoring DNT.
(d) Charla support-chat scope. Our support-chat provider Charla is embedded on the marketing site at 403fin.io and on the help documentation site at help.403fin.io. Inside the application at app.403fin.io, Charla is accessible via Settings → Application Support → Live Chat, which opens the Charla chat widget inside an embedded web view within the application itself — you stay in the app for the entire conversation; we do not redirect you to an external browser. All three surfaces route to the same Charla support team; an in-app chat and a marketing-site chat are seen by the same agent in the same Charla inbox.
(e) Consent and audit row for in-app live chat. The lawful basis for processing your name, email, and message contents during an in-app Charla live-chat session is your explicit consent under Article 6(1)(a) of the GDPR (and the analogous business-purpose basis under the CCPA). The first time you tap Live Chat from Settings → Application Support, the application shows you a consent dialog summarising what will be shared with Charla; the chat surface does not load until you tap Accept. You may withdraw your consent at any time from Settings → Privacy, which immediately disables the in-app chat widget and records the withdrawal in our audit log. Each grant and withdrawal is logged: we record the date, time, IP address, user-agent string, and consent method as a charla_support_chat entry in our consent audit log so we can evidence your decisions under applicable law. If you are logged in and have granted consent, your display name and email address are passed to the Charla chat widget inside the application so you do not have to retype them; this information is shared with Charla as a sub-processor under our Data Processing Agreement. Chat content is retained by Charla per their retention policy; you may request deletion of your chat transcripts at any time by emailing privacy@403fin.io.
(f) In-app feedback and changelog portal scope. The feedback and changelog surface inside the application is served from feedback.403fin.io, a separate origin from the application at app.403fin.io. It is software we host ourselves; its database is hosted by Neon, LLC (a Databricks company) in the United States, and Neon is listed in our Sub-Processor list. When you open the surface we pass your account identifier, email address, and subscription tier to it so that your submissions are attributed to you; the portal sets its own session on its own origin, which is cleared when you sign out of the application. It receives no account, balance, transaction, or connection data. If you visit the portal directly in your browser, it carries the same consent-gated, cookieless web analytics (Rybbit) as our marketing site — off by default until you accept “Analytics” in its consent banner; the surface embedded inside the application never loads the consent banner or any analytics. If you delete your account, your identity and content in the portal are deleted as part of that process.
(g) Community server scope. 403 Finance runs a community server on Discord. It is a separate property, not part of the Service, and it is entirely optional — you have to join it yourself, we have no way to add anyone, and you never need it to use Forbidden Finance. Unlike the feedback portal described in (f), the application passes Discord nothing about you: no identity, and no account, balance, transaction, or connection data. Discord acts as an independent data controller of your Discord account and of what you post there, under its own privacy policy; we are the controller only of what we can see as the operator of the server and of the moderation records we create. The full description is in Section 5 of our Organizational Privacy Policy, and the rules of the community are in our Community Guidelines. Support scope: general questions may be answered in the community, but it is not a support channel of record — report bugs through the in-app feedback portal, and take anything account-specific to the in-app live chat described in (d) or to support@403fin.io. We will never ask you for your account details, balances, transactions, bank connections, passwords, or one-time codes in the community server, and you should not post them there.
14. Children Under 16
The Service is not directed to and may not be used by anyone under the age of sixteen (16). By creating an account, you represent that you are at least sixteen years of age. We do not knowingly collect personal information from anyone under 16. If we learn we have collected personal information from a person under 16, we will delete it. A parent or guardian who believes their child has provided us with personal information may contact us at privacy@403fin.io and we will take reasonable steps to delete it promptly.
15. Data Breach Notification
In the event of a security breach affecting your personal data that is likely to result in harm to you, we will notify you by email to the address associated with your account without undue delay after becoming aware of the breach. Where required by applicable law, we will also notify the relevant supervisory authorities and law enforcement. Our notification will include, to the extent known: the nature of the breach, the categories and approximate number of users affected, the likely consequences, and the measures we have taken or propose to take.
16. Users in the EEA and the United Kingdom; International Data Transfers
This Section applies if you are located in the European Economic Area or the United Kingdom. For your processing, 403 Finance, Inc. is the controller under the EU General Data Protection Regulation ("GDPR") and the UK GDPR.
16.1 Feature availability in your region
All core features of the Service — manual account entry, budgets, net-worth tracking, goals, imports, and exports — are available in every country where the Service is offered. Automatic bank connections through our primary banking aggregators (Section 1.2) cover United States and Canadian financial institutions. If your accounts are elsewhere, the optional Lunch Flow "bring your own connections" feature can connect banks in the United Kingdom, Europe, Asia-Pacific, Brazil, and New Zealand: you subscribe to Lunch Flow directly and authorize your banks with them, we receive your account and transaction data from your Lunch Flow account, and your bank credentials are never collected by us — see our Sub-Processor List for details of this relationship. Brokerage connections through SnapTrade cover United States, Canadian, United Kingdom, and European brokerages. Where no connection provider covers your institutions, manual entry and file imports remain available, and no bank-connection data is collected from you. When we add or change connection providers, we update this Privacy Policy and our Sub-Processor List.
16.2 Legal bases for processing (Article 6)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
(a) Performance of a contract (Article 6(1)(b)). We process your account identifiers, preferences, and the financial data you enter or import in order to create and administer your account, authenticate you, compute budgets, net worth, and reports, provide in-app features you use, operate the API and AI-assistant connections you create (Sections 1.1 and 6(e)), and respond to support requests.
(b) Legal obligation (Article 6(1)(c)). We retain consent records and audit logs, and process billing records, to meet our recordkeeping, tax, and accounting obligations.
(c) Legitimate interests (Article 6(1)(f)). We process the activity, device, and security data described in Sections 1.5 and 1.6 to operate, secure, and improve the Service, prevent fraud and abuse, and investigate incidents. We have weighed these interests against your rights and freedoms: this data is minimized, is not used to build marketing profiles or for advertising, and is limited to security, integrity, and diagnostic purposes — so we consider that our interests are not overridden.
(d) Consent (Article 6(1)(a)). We rely on your consent for marketing communications (Section 5(d)), optional consent-gated analytics on the marketing and help-documentation sites (Section 1.4), the in-app live-chat feature (Section 13(e)), AI reading of receipts (Section 1.1), and the optional preference-gated features described in Section 1.1 (such as transaction analysis and the recurring-detection feature). You may withdraw any consent at any time without affecting processing already carried out.
16.3 Your rights
You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on our legitimate interests. Many of these are self-service inside the application: you can correct your data directly, export it in CSV and JSON formats, and delete your account (Section 4.2) from Settings. For anything else, contact us at privacy@403fin.io. We may need to verify your identity before acting on a request. We will respond within one month of a verifiable request and may extend that period by up to two further months for complex or numerous requests, in which case we will tell you within the first month.
16.4 International data transfers
The Service is hosted and operated in the United States (Section 3). When you create an account and use the Service, you provide your information directly to 403 Finance, Inc. in the United States, and it is processed on infrastructure located there. Where personal data of EEA or UK users is transferred to, or accessed from, a country that has not received an adequacy decision — including onward transfers to the sub-processors listed at 403fin.io/forbidden-finance/legal/subprocessors — those transfers are protected by appropriate safeguards: the EU Standard Contractual Clauses, together with the UK International Data Transfer Addendum where UK data protection law applies, incorporated into our data-processing agreements with each provider, supported by technical measures including TLS 1.2+ encryption in transit, AES-256-GCM encryption of bank credentials and other sensitive tokens at rest, and database-level row isolation (Section 3). You may request a copy or summary of the relevant safeguards by emailing privacy@403fin.io.
16.5 EU and UK representatives (Article 27)
If you are located in the EU/EEA or the UK, you may contact our appointed GDPR representatives:
- EU Representative: Euverify Ltd (Ireland), Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork, T23 AT2P, Ireland. Email: gdpr@euverify.com
- UK Representative: Euverify Ltd (UK), 3rd Floor, 86–90 Paul Street, London, EC2A 4NE, United Kingdom. Email: gdpr@euverify.com
To submit a Data Subject Access Request or any other GDPR-related inquiry, you may use our representatives' secure verification and request portal, or contact us directly at privacy@403fin.io. Our representatives are also listed in our organizational privacy policy.
16.6 Complaints
You have the right to lodge a complaint with a supervisory authority — in particular in the EU/EEA country of your habitual residence, place of work, or the place of an alleged infringement, or with the UK Information Commissioner's Office (ico.org.uk) if you are in the UK. We would appreciate the chance to address your concern first at privacy@403fin.io.
16.7 Automated decision-making and children
Our position on automated decision-making is in Section 11, and it applies without change under the GDPR: we do not make solely automated decisions producing legal or similarly significant effects. The Service requires users to be at least sixteen (16) years of age (Section 14), which meets or exceeds the age of digital consent in every EEA member state and the UK.
16.8 Other regions
This Section 16 applies to users located in the EEA and the United Kingdom. If you are located elsewhere, Section 17 describes the rights that apply to you — including the country-specific provisions for Singapore, Brazil, and New Zealand in Sections 17.1 to 17.3, and the general provision in Section 17.4 that applies wherever you are located. Where the Service is not offered in your country, you may join a waitlist — a form provided by Tally that collects your email address and stated location — to be notified if the Service becomes available there; joining the waitlist does not create an account and is not an offer of the Service. If you access the Service from a country where it is not offered — for example, through a virtual private network — you acknowledge that your information will be processed in the United States as described in this Privacy Policy.
17. Users in Other Jurisdictions
This Section describes rights that apply to users located outside the United States, the EEA, and the United Kingdom. Section 17.4 applies to you wherever you are located. Nothing in this Section limits the rights described elsewhere in this Policy.
17.1 Singapore
If you are located in Singapore, we process your personal data in accordance with the Personal Data Protection Act 2012 (PDPA). We have designated a Data Protection Officer, who may be contacted at privacy@403fin.io, and who is responsible for ensuring our compliance with the PDPA. You have the right to request access to the personal data we hold about you, to request correction of any error or omission in it, and to withdraw consent to our processing at any time — withdrawal may mean we can no longer provide some or all of the Service. We will respond to access and correction requests within the timeframes required by the PDPA.
Because we process personal data outside Singapore, we comply with the PDPA's Transfer Limitation Obligation by ensuring, through binding contractual arrangements with each recipient, that your personal data receives a standard of protection comparable to that under the PDPA. Details of the service providers involved are in our Sub-Processor List.
If we determine that a data breach affecting your personal data is notifiable, we will notify the Personal Data Protection Commission within three calendar days of that determination, and will notify you as soon as practicable where the breach is likely to result in significant harm. If you are not satisfied with how we have handled your personal data, you may lodge a complaint with the Personal Data Protection Commission (pdpc.gov.sg).
17.2 Brazil
If you are located in Brazil, we process your personal data in accordance with the Lei Geral de Proteção de Dados (Law No. 13.709/2018, LGPD). You have the rights to confirmation of processing; access; correction of incomplete, inaccurate, or outdated data; anonymisation, blocking, or deletion of unnecessary or excessive data; data portability; deletion of data processed with your consent; information about the entities with which we have shared your data; information about the consequences of refusing consent; and revocation of consent.
Our communication channel for data subjects and the National Data Protection Authority (ANPD) is privacy@403fin.io. We will respond to your requests within the deadlines applicable under the LGPD.
We transfer personal data outside Brazil to the service providers listed in our Sub-Processor List, under binding contractual safeguards in accordance with the LGPD. You may lodge a complaint with the ANPD (gov.br/anpd).
17.3 New Zealand
If you are located in New Zealand, we process your personal information in accordance with the Privacy Act 2020 and the Information Privacy Principles. You have the right to request access to, and correction of, the personal information we hold about you; contact us at privacy@403fin.io. We disclose personal information outside New Zealand only where we are satisfied, in accordance with Information Privacy Principle 12, that the recipient is subject to safeguards comparable to those in the Privacy Act — which we achieve through binding contractual arrangements with each recipient. Where a privacy breach has caused, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as soon as practicable. You may complain to the Office of the Privacy Commissioner (privacy.org.nz).
17.4 Other jurisdictions
The Service is available in most countries. Where your local data protection law grants you rights that are not specifically described in this Policy, those rights still apply, and we will honour them on request — write to privacy@403fin.io and tell us which law you are relying on. Wherever you are located, we apply the same core protections to your personal data: we process it only for the purposes described in this Policy, we transfer it internationally only under binding contractual safeguards, and we give you access, correction, and deletion rights. Some features may be unavailable in your country for legal or technical reasons.
18. App Stores and External Links
Your app store (such as the Apple App Store or Google Play) may collect information in connection with your installation, use, or in-app purchases relating to the Service. We have no control over such collection by a third-party app store, and that collection is governed by the store operator's own privacy practices. We publish App Privacy Labels on the Apple App Store and a Data Safety form on Google Play; these disclosures are reviewed at each release.
The Service may contain links to third-party websites or resources. We have no control over the privacy practices or content of those third parties. You should review the applicable privacy policies and terms before providing information to any third party.
19. Changes to This Privacy Policy
We may modify this Privacy Policy from time to time. For material changes, we will notify you by email at the address associated with your account at least thirty (30) days before the change takes effect. The most current version is always available at 403fin.io/forbidden-finance/legal/privacy. If you do not agree to a change, you may terminate your account before the effective date and request a refund of any prepaid Fees as described in our Terms of Service. Continued use of the Service after a change becomes effective constitutes acceptance of the change.
20. Contact Us
You may contact Forbidden Finance using the email address appropriate to your inquiry:
| Reason | |
|---|---|
| Privacy requests (data access, deletion, correction) | privacy@403fin.io |
| General questions about this Privacy Policy or our Terms; legal notices; copyright concerns | legal@403fin.io |
| Security incidents or vulnerability reports | security@403fin.io |
| Billing and subscription questions | billing@403fin.io |
| All other support | support@403fin.io |
Mailing address:
403 Finance, Inc.
1111B S Governors Ave, Ste 92573
Dover, DE 19904
21. Relationship to the Terms of Service
This Privacy Policy is incorporated by reference into the Forbidden Finance Terms of Service available at 403fin.io/forbidden-finance/legal/terms. If there is any conflict between this Privacy Policy and the Terms of Service with respect to how we handle personal information, this Privacy Policy controls.