Skip to content

Last updated: 27 August 2026

Privacy policy

This privacy policy explains how Finch Money Ltd (‘Finch’, ‘we’, ‘us’, ‘our’) collects, uses, stores, and shares your personal information when you use the Finch app, our website at finchmoney.co.uk (including the early-access waitlist), and related services. Please read it carefully before you begin.

Finch is registered in England and Wales. We are the data controller for the personal information described in this policy. If you have questions, you can reach us at hello@finchmoney.co.uk.

1. What information we collect

Information you give us

User account information: When you create a user account, we collect your name and email address. If you sign in with Apple or Google, this is the information they pass to us, and it may include a link to your profile picture. If you provide other account information, such as your phone number, address, or National Insurance number, we store that too.

Financial information: The central purpose of Finch is to help you understand and plan your finances. During onboarding and ongoing use you may share information about your income, outgoings and expenses, debts (such as credit cards, loans, mortgages), savings and investments, pension contributions and workplace benefits, financial goals, and other aspects of your financial situation. You choose how much to share.

Conversation content: When you speak with Finch, your voice is captured and transcribed. The content of your conversations — including the questions you ask, the information you share, and the responses Finch gives — is stored so that Finch can maintain continuity, update your plan, and improve over time.

Waitlist information (our website): If you join our early-access waitlist at finchmoney.co.uk, we collect your email address and your answer to one question about whether you want Finch for your own money or work in or around financial services (your ‘segment’). We record that you consented to hear from us, the exact wording and version of the consent you agreed to, and the date and time you joined. So we can understand how people find Finch, we also capture any marketing-campaign parameters (UTM tags) contained in the link you followed and the web address that referred you.

Information we collect automatically

Usage data: When you use the app, we collect information about how you interact with it, such as which screens you visit, which buttons you tap, which features you use, when you start and end conversations, and how frequently you return. This helps us understand whether the product is working and where it could improve.

Device and technical data: We collect standard technical information including your device type, operating system version, app version, your device’s timezone and language settings, and network connection details (including connection quality and any interruptions during voice conversations). If you grant permission for push notifications, we also store a device token — a device-specific identifier provided by Apple that allows us to send push notifications to your device — and whether that permission is still granted, so we know whether we can reach you.

Payment status: If you subscribe, we receive confirmation of your subscription status from Apple. We do not receive or store your payment card details — these are handled entirely by Apple.

Website usage data: When you visit finchmoney.co.uk, we collect information about how you interact with the site, such as which pages you view and whether the waitlist form works. How we do this — and the cookies involved — is described in ‘Cookies and website analytics’ below.

Information we may collect in future

As Finch grows, we expect to add features that involve additional data. These may include:

Open Banking data: With your explicit consent, we may connect to your bank accounts to access transaction history and account balances, to power spending insights and automatic plan updates. This will be introduced as a distinct, opt-in feature.

Investment and product account data: If you choose to use in-app saving or investment journeys, we will process data related to those accounts and transactions.

We will update this policy and notify you before any material new data collection begins.

2. How we use your information

We use the information we collect to:

  • Provide the service: Generate your personalised financial plan, run voice conversations, update your plan as your circumstances change, and deliver our ongoing service.
  • Maintain continuity: Store a record of the facts, goals, and context you have shared so that Finch can pick up where you left off without you needing to repeat yourself.
  • Run AI and voice processing: The content of your conversations is processed by large language models (LLMs) to understand what you have said, extract relevant facts, and generate responses.
  • Personalise your experience: Tailor the tone, content, and timing of Finch’s service based on what we know about your situation and preferences. This includes personalising the messages we send you using the context you have shared (such as your first name, your goals, or where you are in your onboarding journey), which may include using AI to draft the copy.
  • Send notifications: Send push notifications about the services we provide, such as changes to your plan. We will not send marketing notifications without your explicit consent.
  • Send marketing communications, with your consent: Where you have opted in, send you emails containing helpful tips, plan reminders, and product updates. You can withdraw consent at any time, either via the unsubscribe link in every marketing email or in your in-app account settings.
  • Operate our waitlist: Use your email and segment to send you the right early-access welcome email, keep you informed about your access, and understand which audiences are joining Finch.
  • Manage your subscription: Track your subscription status and handle any billing events we are notified of by Apple.
  • Improve the product: Analyse usage patterns to understand what is and is not working and to improve the experience for all users.
  • Ensure security and prevent abuse: Monitor for fraudulent activity, enforce rate limits, and detect and respond to security incidents.
  • Meet our legal obligations: Keep records as required by law and respond to lawful requests from regulators or courts.

We share the minimum personal data necessary with every third-party processor we use. For example:

  • We never share the following with AI providers (unless you say any of them in a voice conversation, which is out of our control): any part of your name other than your first name or preferred name, your email address, your phone number, your National Insurance number, your exact date of birth, or your exact address — meaning the street address and postcode, whether it is yours or that of someone who depends on you. We do share what those details are for: your age rather than your date of birth, the town, county and country you live in rather than your street, and your financial details when required — your age so that we can plan around when you want to retire, for example, or the amount of cash you tell us you have in savings, so that we can generate and talk about your financial plan with you.
  • Analytics events are pseudonymised and never include your financial details.

We apply this principle across all third-party data sharing, and we review it as we add or change processors.

We do not use your information to train AI models.

We process your personal information on the following legal bases under UK GDPR:

Contractual necessity: Most of the processing described above is necessary to provide you with the Finch service you sign up for. This includes collecting your financial information, running voice conversations, generating your plan, and maintaining your account.

Legitimate interests: We process certain data — including usage analytics, error monitoring, rate limiting, and security monitoring — where we have a legitimate interest in operating a secure and well-functioning service, and where that interest is not overridden by your rights. We will not rely on this basis for processing your financial or conversation data for purposes beyond providing the service. On our website we also rely on legitimate interests to run cookieless analytics that store nothing on your device, and to protect the waitlist form from spam and abuse.

Consent: Where we process data for purposes that are optional — such as marketing communications, joining our early-access waitlist and receiving waitlist emails, non-essential website cookies and the analytics they enable, or future opt-in features like Open Banking — we ask for your consent before doing so. You can withdraw consent at any time.

Legal obligation: Where we are required by law and/or by regulators to retain or disclose data.

4. Who we share your information with

We do not sell your personal information. We share it only as described below.

Infrastructure providers including those used for our database, storage, server-side processing, authentication, voice stack and routing: Your account and financial data are stored and processed using Supabase, which provides our database, server-side processing and authentication infrastructure. Audio recordings of your conversations with Finch are stored using Cloudflare R2. Data is routed between you and our infrastructure using Cloudflare Workers. Voice conversations are routed through LiveKit.

AI providers: Where possible, Finch prefers on-device AI processing to preserve your privacy. For shorter personalised in-app text (such as welcome messages), Finch uses your device’s built-in AI capabilities where your device and its version of iOS support them (Apple Intelligence). Processing stays entirely on your device and your data is not transmitted to Apple. We record whether your device supports on-device AI processing — and if it does not, why — so we know which route was used for you. Where on-device capabilities are not available or not sufficiently capable for the required task, Finch uses third-party server-side providers. Your voice and conversation content and data about your personal and financial context may be processed by OpenAI, Google, and/or Anthropic for language understanding, response generation, and functionality such as fact extraction, plan generation, summarisation, and drafting personalised copy for the messages we send you. We may switch between these AI providers from time to time as we improve the service.

Email: We use Resend to send transactional emails (such as sign-in links and account notifications) and, where you have given consent, to send marketing emails and your early-access waitlist welcome and updates. Resend also manages the audiences used to deliver our marketing emails and the unsubscribe state of each contact within those audiences. Resend holds your name, email address, a record of the emails we send you and any replies from you, information about which links in those emails you click, and your marketing audience membership and unsubscribe state.

Analytics: We use PostHog to collect and analyse usage events in both the app and our website. This data is pseudonymised and never includes the content of your financial conversations. If you join our waitlist, we associate that website visit with your email address so we can understand our sign-up journey — this is the only direct identifier we send to PostHog from the website, and only for an address you have just given us. With your consent, we also use PostHog session recordings and heatmaps on the website, and Google Analytics, as described in ‘Cookies and website analytics’ below.

Anti-spam and security: We use Cloudflare Turnstile to check that waitlist sign-ups come from a real person rather than an automated bot. Turnstile assesses the submission in your browser and shares the result with us; it is designed to work without tracking you across websites.

Apple: When you use Sign in with Apple or make an in-app purchase, your interaction with Apple is subject to Apple’s own privacy policy. We receive only the information Apple provides to us (such as your name, if you choose to share it, a verified email address, and subscription status).

Google: When you use Sign in with Google, your interaction with Google is subject to Google’s own privacy policy. We receive only the information Google provides to us (your name, your email address, and a link to your Google profile picture).

Profile pictures: If no picture is stored for your Finch account, or available from your Google profile if you sign in with Google, we show the one attached to your email address at Gravatar, a service run by Automattic. Your device requests the picture directly, so Gravatar receives your IP address and a code calculated from your email address. We do not send the address itself, but that code is not anonymous: it is the same code every time, anyone who already knows an address can calculate it, and Gravatar can match it to your Gravatar account if you have one. Gravatar acts on its own behalf here rather than as our processor, so its own privacy policy governs what it does with the request. If there is no picture for your address, nothing is returned and the app shows a default icon instead. The same lookup happens when a member of our team views your account in our internal dashboard, from their browser rather than your device, so your IP address is not disclosed on that path.

Professional advisers and regulators: We may share data with our legal or professional advisers, or disclose it to regulators or law enforcement where we are legally required to do so.

Business transfers: If Finch is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you before any such transfer takes place and ensure your data remains protected under equivalent terms.

We require all third-party processors to process your data only as instructed, to maintain appropriate security measures, and to comply with UK GDPR. Gravatar is the exception described above: it acts on its own behalf rather than on our instructions.

5. Cookies and website analytics

This section applies to our website at finchmoney.co.uk. Our app does not use advertising cookies, and we do not track you across other apps or websites.

Always-on, cookieless measurement. We use PostHog to understand how our website is used — for example, which pages people visit and whether the waitlist form is working. On the website this runs in a cookieless mode that stores nothing on your device, so it does not need your consent. If you join the waitlist, we link that visit to your email address (see ‘Analytics’ above); this is the only personal identifier we send to PostHog from the website.

Non-essential cookies — your choice. With your consent, we enable additional analytics that rely on cookies or similar technologies:

  • Google Analytics (GA4) — aggregate measurement of how the website is performing.
  • PostHog session recordings and heatmaps — a record of how visitors move through and interact with pages, so we can see where the site is confusing and improve it. These recordings are configured to mask the text you type, including anything you enter in the waitlist form.

When you first visit, a cookie banner lets you Accept or Decline, with equal prominence. Nothing non-essential loads until you choose Accept; if you Decline, only the always-on cookieless measurement above continues. Google Analytics loads through Google Consent Mode v2 with every signal denied by default, so it activates only after you accept. You can change your choice at any time using the ‘Cookie choices’ link in the website footer.

Where you enable Google Analytics, Google may process data in the United States under the UK–US data bridge (see ‘Data processing locations’ below).

6. Data processing locations and international data transfers

We prioritise storing your data in the UK or EU wherever possible. In particular:

  • Our database, server-side processing, authentication and routing infrastructure (Supabase and Cloudflare Workers) are all hosted in Amazon Web Services’ eu-west-2 region, which uses data centres in and around London.
  • Our voice infrastructure (LiveKit) and analytics infrastructure (PostHog) are hosted in Amazon Web Services’ eu-central-1 region, which uses data centres in Germany.
  • Our storage infrastructure (Cloudflare R2) is located in Cloudflare’s EU jurisdiction.

Due to the nature of the internet, your data may be routed outside of the UK and EU when encrypted in transit.

Some of our third-party providers process data outside the UK and EU. Where this occurs, we ensure appropriate safeguards are in place — such as the UK’s International Data Transfer Agreements, adequacy decisions, or Standard Contractual Clauses — to ensure your data receives equivalent protection to that provided under UK GDPR. In particular, AI processing by OpenAI, Google, and Anthropic may involve data being processed in the United States, and Resend processes data in the United States. Profile-picture lookups reach Gravatar in the United States. Because Gravatar acts on its own behalf rather than as our processor, those lookups rely on Gravatar’s own arrangements rather than the safeguards above. Where you consent to Google Analytics on our website, Google may also process data in the United States; this is covered by the UK Extension to the EU–US Data Privacy Framework (the ‘UK–US data bridge’).

7. How long we keep your data

Subject to the exceptions below, we keep your personal information for as long as your account is active, and for up to 90 days thereafter to allow you to reactivate your account, to handle outstanding queries, or to meet our legal obligations.

Exceptions:

  • Conversation audio recordings are kept for no more than 30 days. This is to allow us to diagnose any issues. Transcripts and extracted facts from your conversations are retained as part of your account data, as above.
  • If you start using Finch (for example, by beginning onboarding and having your first conversation) but never create an account using your email address, Apple ID or Google account, we delete the data associated with that anonymous use after 30 days of inactivity.
  • Unsubscribe and suppression records (the list of email addresses we must not contact for marketing) are kept indefinitely, because we need to remember not to email you even after your account is deleted.

When you request deletion of your account, after the 90 day period above, we only retain your data as required by law (which, for marketing, includes the suppression-list requirement described above).

As Finch evolves and regulations change, the period that we are required to retain your data may also change (for example, if we are required to retain your financial records for regulatory purposes). We will update this policy and notify you as our obligations change.

8. Security

We use appropriate technical and organisational measures to protect your data. These include:

  • Encryption of data in transit (TLS) and at rest
  • Secure authentication, including support for Sign in with Apple and Sign in with Google
  • Access controls that limit which staff and systems can access your data
  • Monitoring and alerting for security anomalies

Financial information is particularly sensitive, and we treat it accordingly. However, no system is completely immune from risk. If we become aware of a breach that is likely to affect your rights and freedoms, we will notify you and the relevant supervisory authority as required by law.

9. Your rights

Under UK GDPR, you have the following rights in relation to your personal information:

Right of access: You can request a copy of the personal information we hold about you.

Right to rectification: If information we hold about you is inaccurate or incomplete, you can ask us to correct it.

Right to erasure: You can ask us to delete your personal information. We will do so unless we have a legal obligation to retain it.

Right to restriction: You can ask us to restrict how we use your data while we resolve a dispute about it.

Right to portability: You can ask for your personal information in a structured, commonly used, machine-readable format so that you can transfer it to another service.

Right to object: You can object to our processing of your data where we rely on legitimate interests as our legal basis.

Rights relating to automated decision-making: Where we make decisions based solely on automated processing that significantly affect you, you have the right to request human review. Finch’s financial plan is a personalised recommendation generated by AI, but it is a tool to help you, not a binding decision with legal or financial effect, so Article 22 does not apply.

To exercise any of these rights, contact us at hello@finchmoney.co.uk. We will respond within one month.

You also have the right to lodge a complaint with the UK’s Information Commissioner’s Office (ICO) at ico.org.uk if you believe we have not handled your information correctly.

10. Children

Finch is not intended for children under the age of 18. We block children (anyone who tells us that their date of birth is less than 18 years ago) from signing up for Finch, and immediately delete any data they have shared up to that point. If you believe a child has provided us with their information under a false date of birth, please contact us and we will delete it.

11. Changes to this policy

We may update this policy from time to time as the product evolves or our legal obligations change. When we make material changes, we will notify you via the app or by email before the changes take effect, and update the ‘last updated’ date at the top of this page.

12. Contact us

Email: hello@finchmoney.co.uk

Post: Finch Money Ltd, 27 Lavender Close, Carshalton, SM5 3EH

If you have a question, concern, or request relating to your personal data, email us and we will respond promptly.

Get early access

We’re opening access in waves. Join the list and we’ll email you when it’s your turn.

Which sounds more like you?

By joining, you agree that we'll email you about Finch and your early access. Unsubscribe any time. See our privacy policy.