Finvora
PrivacyTermsRiskSecurity
LEGAL / PRIVACY

Privacy Policy

This policy explains how the Finvora operator handles profile, chat, preference and technical data when you use the public service.

Effective: 6 October 2026Version 1.4

1. Controller and contact

The service is operated by Finvora. Privacy and data-rights requests may be sent to the production privacy contact.

2. Data we process

  • Email account identifier and salted one-way password hashes. Email/password login does not verify mailbox ownership; passwords are never saved as plaintext or sent to a mail, SMS or OAuth provider.
  • Server-issued session identifiers, profile nickname and avatar.
  • Messages, replies and attachments you choose to submit.
  • Language, timezone, chat layout and conversation preferences.
  • Security records such as request time, route, status, abuse-control counters and hashed audit subjects.
  • Public market data requests. Automatic timezone queries send your public IP address to ipapi.is over HTTPS to obtain an approximate IANA timezone; language selection is independent. Choose a manual timezone to stop automatic lookups.

Account access metadata: after login we keep only the latest observed IP, approximate country/region, state/province and city, and browser-reported device family/model for up to 30 days. Distinct phone, tablet and computer device/model combinations are appended; repeat visits update the last-seen time. Exact hardware models may be unavailable, and devices with indistinguishable browser reports cannot be identified separately. Public-IP queries use ipapi.is; private LAN IPs are not geolocated. No GPS, fingerprinting or browsing history is collected. Metadata is encrypted, restricted to authorized administrators, included in your data export, and erased with account deletion. This lookup is separate from timezone selection.

Superadministrator AI: only manually submitted project text and bounded conversation history are sent to the configured OpenAI API. No account metadata is attached automatically. Reviewed samples are encrypted locally; export does not upload them or launch model training.

3. Purposes and legal bases

We process data to provide the service and requested chat features, preserve user preferences, secure the service, prevent abuse, meet legal obligations and maintain system reliability. Where consent is required, such as sending selected text to a configured third-party translation service, the interface asks before transmission.

4. Service providers and international transfers

Infrastructure, market-data and optional translation providers may process limited information needed to deliver their service. The production operator must document its actual vendors, processing locations and transfer safeguards before launch. The automatic-timezone provider is ipapi.is. Only the necessary public IP is sent; profile, chat and account content are not sent. The timezone service keeps hashed cache subjects and timezone metadata in bounded memory, not raw IPs in its database. Provider processing and retention are governed by its privacy notice. If IP lookup fails, browser timezone is used and labelled; local previews may use this machine’s outbound IP, never the production server’s location.

5. Retention

Chat content is retained for the configured retention period, normally 30 days. Unattached uploads are removed after one day, security audit events after 90 days and expired sessions automatically. Account identifiers and password hashes remain until account deletion; hashes are not included in account exports. The operator may retain limited records longer when legally required or necessary to investigate abuse.

6. Your choices and rights

Depending on your location, you may have rights to access, correct, export, restrict or delete personal data and to object or complain to a supervisory authority. The controls below apply to the profile associated with this browser’s secure Finvora session.

7. Security

Finvora uses encrypted transport, HttpOnly session cookies, request-origin and CSRF checks, encrypted sensitive database fields, access controls, resource limits and backup verification. No internet service can guarantee absolute security.

8. Children

The service is not directed to children. The production operator must configure and publish an age threshold appropriate for each launch jurisdiction.

9. Changes

Material changes will be identified by a new version and effective date. Where required, notice or renewed consent will be provided.

© 2026 Finvora. Privacy questions: production privacy contact.