Privacy & Data Security Policy

Last updated: August 27, 2026

This document outlines the measures taken by the Finlens to ensure data privacy, security, and the protection of Personal Identifiable Information (PII) and Personal Financial Information (PFI), in compliance with the General Data Protection Regulation (GDPR).

1. Data Controller and Contact Information

The Data Controller for your personal data is the Finlens team. If you have any questions about this Privacy Policy or our data practices, please contact us at:

Email: privacy@warny.app

2. Legal Basis for Processing

We process your personal data under the following legal bases:

  • Contractual Necessity: To provide you with the warranty tracking and notification services you requested by creating an account.
  • Consent: For specific processing activities where we have requested and obtained your explicit consent.
  • Legitimate Interests: To improve our service and ensure the security of our platform.

3. Data Encryption

1.1 Data in Transit

  • End-to-End Encryption: All communications between the client application and the API server are encrypted using TLS 1.2 or higher.
  • Gateway Architecture: All data flows exclusively through the NestJS API gateway. Direct access to the database or storage from the client is prohibited, ensuring consistent security policy enforcement.
  • Authentication: Requests are secured via JWT (JSON Web Tokens) sent in the Authorization header.

3.2 Data at Rest

  • Database: All application data is stored in Supabase (PostgreSQL), which provides industry-standard encryption at rest (AES-256).
  • Storage: Files (invoices and product photos) are stored in Supabase Storage buckets with encryption at rest.
  • Private Buckets: Invoices are stored in a dedicated private bucket. These files are not publicly accessible.
  • Signed URLs: Access to private files is restricted to time-bound, cryptographically signed URLs (default expiry: 1 hour), generated on-demand by the API for authorized users only.

4. PII & PFI Protection

We prioritize data minimization to avoid collecting or storing sensitive personal or financial information.

4.1 AI-Driven Data Extraction (Invoices)

When an invoice is uploaded, the system uses Google Gemini AI for automated data extraction. The following measures are in place:

  • Strict Prompting: The AI is explicitly instructed to extract only product-related metadata (name, price, store, manufacturer, model, serial number, warranty dates).
  • PII Filtering: The system does not extract or store customer names, addresses, phone numbers, or email addresses from the invoices.
  • PFI Filtering: The extraction process explicitly skips credit card numbers, bank account details, and other financial identifiers.
  • Service/Tax Exclusion: Line items such as shipping fees, handling charges, and taxes are excluded from the database.

4.2 Storage Minimization

  • Limited Scope: We only store the data necessary to provide warranty tracking and firmware update notifications.
  • Public vs. Private: Product photos are considered public, while all documents containing potential purchase details (invoices) are strictly private.

4.3 Telemetry & Diagnostic Logging

The web client ships crash and uncaught-error reports to a third-party telemetry provider (Bugfender — see Section 8) so the team can investigate bugs affecting your account. The following safeguards apply:

  • Errors Only: Only uncaught exceptions and unhandled promise rejections are reported. Console output, navigation breadcrumbs, and UI-interaction events are not shipped.
  • Server Excluded: The API does not send any logs to Bugfender; server diagnostics remain on the hosting provider's own log stream.
  • PII Filtering: Reports exclude invoice file contents, parsed invoice line items, full names, addresses, phone numbers, credit-card or bank data, JWTs, Supabase service-role keys, and user-supplied API keys.
  • Identifiers Only: Each device/session is tagged with the Supabase user ID (a UUID). Email addresses and display names are not shipped to telemetry.

4.5 Analytics (Google Analytics 4) — Opt-In

The web client may ship anonymized usage events to Google Analytics 4 to help us understand which features are useful and where users get stuck. The following safeguards apply:

  • Opt-In Only: GA is not loaded until you explicitly accept the consent banner. If you decline, no GA scripts are loaded and no events are sent.
  • Anonymized Events: Only product-usage events (page views, button clicks, subscription funnel steps) are sent. No invoice contents, no parsed line items, no names, addresses, phone numbers, payment data, JWTs, or user-supplied API keys.
  • Identifier: Each session is tagged with your Supabase user ID (a UUID) so we can analyze funnels across your devices. Email addresses and display names are never sent.
  • IP Anonymization: GA is configured with anonymize_ip enabled.
  • Backend Events: A subset of business-outcome events (subscription captures, AI parse outcomes, channel link/unlink, scheduled-job results) are sent server-side via the GA Measurement Protocol for the same purpose.
  • Self-Service Control: You can revoke consent at any time from your profile settings; on revocation, GA scripts are disabled and _ga* cookies are cleared.
  • Retention: Event data is retained by Google per the property's retention setting (14 months default). You may request earlier deletion by emailing privacy@warny.app.

4.6 Gmail Integration (Optional)

You may optionally connect your Gmail account so Finlens can help locate purchase receipts in your mailbox. The following measures are in place:

  • Server-Side Only: The OAuth connection is handled entirely by our backend. Your Gmail refresh token is never sent to, or stored in, your browser — this closes off a whole class of attacks (e.g. a browser-based script) that could otherwise reach it.
  • Read-Only Scope: We request only the gmail.readonly scope — Finlens cannot send, delete, or modify anything in your mailbox.
  • Encrypted at Rest: The refresh token is encrypted (AES-256-GCM) before being stored, using the same mechanism described in Section 3.2.
  • No Import Yet: Connecting your account does not, by itself, read or import any email content. Searching your mailbox for receipts is a feature we have not built yet; this step only establishes the connection.
  • Revocable Anytime: You can disconnect from your Profile page at any time. Disconnecting revokes the grant with Google and deletes the stored token.
  • Remove from review: When you remove a pending or rejected analysis from the review list, we store a sanitized copy of that email and the analysis result so we can improve extraction prompts. This copy is not shown in the app and is deleted when your account is deleted.

5. Your Data Subject Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of Access: You can request a copy of the data we hold about you.
  • Right to Rectification: You can ask us to correct inaccurate or incomplete data.
  • Right to Erasure (Right to be Forgotten): You can request the deletion of your data.
  • Right to Restriction of Processing: You can ask us to temporarily stop processing your data.
  • Right to Data Portability: You can request your data in a structured, commonly used, and machine-readable format.
  • Right to Object: You can object to the processing of your data based on legitimate interests.

To exercise any of these rights, please contact us at privacy@warny.app.

6. Data Retention

We retain your personal data only for as long as your account is active or as needed to provide you with our services. When you delete your account or a specific product, associated data is permanently removed as described in Section 7.2.

7. Access Control

7.1 Authorization & Roles

  • RBAC: A Role-Based Access Control system distinguishes between user and admin roles.
  • Row Level Security (RLS): Supabase RLS policies ensure that users can only access their own products and related data (invoices, claims, notifications).
  • Service-Role Bypass: Database operations are performed via a secure service-role client within the NestJS backend, preventing direct database exposure.

7.2 Secure Deletion

  • Cascading Deletes: When a product is deleted, all associated metadata, product images, and invoice files are permanently removed from both the database and storage buckets.

8. Third-Party Integrations and International Transfers

We use third-party service providers that may process your data outside the European Economic Area (EEA). We ensure that appropriate safeguards are in place (such as Standard Contractual Clauses) to protect your data.

  • Supabase: Used for database, auth, and storage. Complies with SOC2, GDPR, and HIPAA. Data is hosted in regions selected to optimize performance and compliance.
  • Google Gemini: Used for invoice parsing. Data is processed in accordance with Google Cloud's data privacy commitments for Enterprise/API users (data is not used to train models).
  • n8n: Used for background tasks and Telegram integration. Communications are secured via webhooks and API keys.
  • Bugfender (bugfender.com): Used for crash and uncaught-error reporting from the web client only. Operated by Mobile Jazz S.L. (Spain, EU). Receives crash payloads tagged with a Supabase user ID; invoice contents, names, addresses, payment data, JWTs, and user-supplied API keys are stripped before transmission. Data is processed inside the EU under GDPR safeguards.
  • Google Analytics 4 (marketingplatform.google.com): Used for anonymized usage analytics on the web client only, and a small set of business-outcome events from the NestJS backend (subscription captures, AI parse outcomes, channel link/unlink, scheduled-job results). Requires explicit opt-in via the consent banner. Operated by Google LLC. Subject to the §4.5 PII filter: invoice contents, full names, addresses, payment data, JWTs, and user-supplied API keys are stripped before transmission. Data is processed under Google's Standard Contractual Clauses for international transfers.
  • Google OAuth (Gmail): Used only if you choose to connect your Gmail account (see Section 4.6). We request read-only mailbox access; the connection is handled server-side and the refresh token never reaches your browser. Subject to Google's Privacy Policy.

9. Right to Lodge a Complaint

If you believe that our processing of your personal data infringes GDPR, you have the right to lodge a complaint with a supervisory authority in the Member State of your habitual residence, place of work, or place of the alleged infringement.