Privacy Policy
EFFECTIVE: AUGUST 2026 · LAST UPDATED: SEPTEMBER 2026Finights is a personal finance application operated by Nikklab Inc., an Ontario, Canada corporation ("we", "us"). This policy describes what we collect when you use Finights, why, how long we keep it, and the choices you have. It is written to be read, not skimmed past.
Contact: admin@nikklab.com
We collect your financial account data through Plaid (and, for brokerage accounts, SnapTrade), with your explicit consent, to show you your money in one place and forecast your cash flow.
We never see or store your bank username or password. You sign in to your bank directly through our data provider.
We keep your transaction history for as long as you keep your account — including beyond the window your bank or Plaid provides — because your long-term history is the product. You can export or delete it at any time.
We do not sell your data, and we do not show ads. Finights is paid for by subscriptions, not by you being the product.
What we collect
Account information. When you sign in with Apple or Google, we receive your email address, your name if you choose to share it, and an identifier from the provider. We never receive or store a password. If you use Apple's Hide My Email, we receive the relay address Apple generates.
Financial data, via Plaid. When you connect a financial account, you authenticate directly with your institution through Plaid Link. Your banking credentials go to your institution and to Plaid — never to us. With your consent, Plaid then provides us: account details (institution, account type, masked account number, balances), transactions (date, amount, merchant, category), and — depending on your subscription and account types — recurring payment patterns, liabilities (card balances, APRs, due dates), and investment holdings. Plaid's own handling of your data is described in Plaid's End User Privacy Policy.
Brokerage data, via SnapTrade. If you connect an investment or brokerage account, you sign in with your brokerage through SnapTrade, and your brokerage credentials never reach us. With your consent, SnapTrade provides us read-only account details (brokerage, account type such as RRSP or TFSA, masked account number, balances), holdings, and account activity such as contributions, withdrawals, dividends and trades. We can't place trades or move money.
Statements you upload. For a bank we can't connect to, such as Rogers Bank, you can upload a PDF statement. We read the account's last four digits, statement dates, balances, payment due and the transactions from it. The PDF itself is processed in memory and is not stored.
Data you create. Budgets, goals, manually added assets (such as cash, property, vehicles, or precious metals), categorisation rules, notes, and household sharing choices.
Operational data. Standard technical logs (with sensitive values redacted), your time zone (so "this week" means your week), device push tokens if you enable notifications, subscription status from Apple (through RevenueCat), and error reports that help us fix problems. We do not use advertising trackers or analytics that profile you across other apps or sites.
On your device. So the app works without a connection, a copy of what you last viewed is stored on your phone, protected by iOS data protection and removed when you sign out. The home screen widget keeps only your latest runway figures.
How we use it
To provide the service: displaying your accounts and transactions, detecting recurring payments, forecasting your cash flow, tracking budgets and goals, computing net worth, and sending the notifications you've enabled. To operate the business: processing subscriptions, providing support, keeping the service secure, and meeting legal obligations.
We do not sell personal information, and we do not share it with third parties for their marketing.
How long we keep it
Transaction history: for the life of your account, by design. Financial institutions and Plaid provide a limited window of history. Finights retains what it has synced so your record grows over time rather than rolling away — this is deliberate, and it is the reason the app can show you multi-year trends. If you delete your account, it is deleted.
Connections to your institutions remain active while your subscription is active. If your subscription lapses, we sever your connections at our data providers about 30 days later; your already-synced history remains in your account. Technical logs and processing records are purged after 90 days. Billing records are kept as long as tax law requires.
Household sharing
On a family plan, you and one partner each have your own Finights account and your own data. When you're in a family, you can each see combined totals, such as combined net worth and a combined runway, and each other's total net worth, but never each other's accounts or transactions. Goals and budgets are only shared if you choose to share them. Leaving or being removed from the family stops all sharing immediately.
Who processes your data
We use a small number of service providers to operate Finights: Amazon Web Services (Canada region — hosting and storage), Plaid and SnapTrade (financial data connectivity), Apple and Google (sign-in), Apple (subscription billing and push notifications), RevenueCat (subscription management), and Sentry (error monitoring). Each receives only what its function requires. We also fetch market prices and exchange rates from public sources; no personal information is sent to them.
Some of these providers are based in, or process data in, the United States and other countries. When your information is processed outside Canada, it may be accessible to the courts, law enforcement and national security authorities of those countries.
How we protect it
All data is encrypted in transit (TLS 1.2+) and at rest. The tokens that authorise access to your financial data receive an additional layer of application-level encryption (AES-256-GCM), with keys held outside the database. Access to your data inside the app is governed by strict per-user isolation, enforced in code and verified by automated tests. Our systems never handle your banking credentials at any point.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant authorities as required by law.
Your choices and rights
Access and export. You can view everything Finights holds about you in the app, and download a copy of your data (JSON and a CSV of transactions). We prepare it in the background and notify you in the app when it's ready; the download is available for 24 hours, after which the file is deleted from our systems. We never send it by email.
Disconnect. You can disconnect any financial account at any time, which severs our access at the data provider.
Delete. You can delete your account in the app. Your account is closed straight away, and within 30 days we sever every bank and brokerage connection and then permanently delete your data. You can cancel within that window; after it, deletion is not reversible. Records we must keep for tax purposes (billing) are retained for the statutory period only.
Notifications. Every notification category can be turned off in settings.
Residents of Canada have rights under PIPEDA, and residents of certain U.S. states have rights under state privacy laws, including access, correction, deletion, and portability. Exercise any of these in the app or by emailing admin@nikklab.com. We respond to verified requests within the time the applicable law requires, and we do not discriminate against you for exercising your rights.
Age
Finights is not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account, contact us and we will delete it.
Changes
If we materially change what we collect or how long we keep it, we will update this policy and notify you before the change takes effect. The retention of your financial history will never change without notice to you.
Contact
Nikklab Inc. · Mississauga, Ontario, Canada
admin@nikklab.com