1. Two separate data boundaries
The GODFIN desktop application stores statements, transactions, balances, categories, budgets, merchant memory, reports, audit history, and local credentials in local storage controlled by you. We do not operate a remote transaction database for the app.
The GODFIN website processes account identifiers, email address, purchase records, license status, device activation hashes, download access, and separately submitted waitlist details.
2. Website services
- Vercel hosts the marketing and account website.
- Supabase provides website authentication and license records.
- Stripe processes payments; GODFIN does not store full card details.
- Resend delivers transactional license and account email.
3. Google sign-in and Gmail are different
Google sign-in on the website is used to authenticate your GODFIN website account. Optional Gmail access in the desktop app is a separate local integration for bank-alert ingestion. Website authentication does not grant the website access to your Gmail.
4. License verification
The app can send a license key, a random installation identifier, generic operating-system/architecture label, app version, and verification timestamp to the website license API. The identifier is hashed before storage. We do not collect hardware serials, payment details, or persistent IP fingerprints for activation. Financial records are not part of this request.
5. Logs and security
Hosting and infrastructure providers may retain limited security, request, and error logs. We minimize application logging and do not intentionally place license keys, payment credentials, or desktop financial data in logs.
6. Optional website analytics
Anonymous Google Analytics is disabled until you explicitly allow it. When enabled, GODFIN requests IP anonymization and disables Google signals and advertising personalization. The desktop app does not send analytics, statements, transactions, balances, or categories.
Anonymous analytics are not configured on this environment.
7. Waitlist
The waitlist stores email, country, operating system, intended use, consent version, and campaign attribution. A confirmation email is required before the entry is treated as subscribed. Waitlist consent is separate from product analytics and any future compensated-data program.
8. Retention and deletion
Purchase and license records are retained as needed to provide your lifetime license, prevent fraud, and satisfy tax or legal duties. You may request deletion of optional account data, subject to records we must retain. Deleting the website account does not delete your local app database.
9. Your choices
Core requires no website account. Gmail, AI providers, embeddings, network access, and managed services are optional. You can export or delete local app data from the app.
10. Contact
Privacy requests can be sent to privacy@godfin.dev. Replace this address in your records if the production support address changes.