Legal

Privacy Policy

What we collect, why we collect it, and the rights you have over it.

In short

Right now Finlio is a waitlist. The only thing we ask you for is an email address, and the only thing we do with it is tell you when the product is ready.

We do not sell your data, we do not run advertising trackers, and we do not have your bank or broker anywhere near this site. When the product itself arrives, your financial data stays on your own device by design, and this page will be updated before that happens, not after.

This summary is here to help you read the rest. The numbered sections below are the ones that apply.

On this page
  1. 1.Who is responsible for your data
  2. 2.What this policy covers
  3. 3.What we collect
  4. 4.Consent, and taking it back
  5. 5.Cookies
  6. 6.Who else touches it
  7. 7.Where your data is stored
  8. 8.How long we keep it
  9. 9.How we protect it
  10. 10.Your rights
  11. 11.Complaints and escalation
  12. 12.Children
  13. 13.If something goes wrong
  14. 14.What we never do
  15. 15.Changes to this policy

Who is responsible for your data

Finlio is built by Quarix, in India. For anything you give us through this website, we are the data fiduciary: the people who decide what is collected and why, and who answer for it.

You are what the Digital Personal Data Protection Act, 2023 calls a data principal. Every right described on this page is yours, and the way to use any of them is to email privacy@finlio.app.

We follow the DPDP Act and the Digital Personal Data Protection Rules, 2025 now. The law gives businesses until 13 May 2027 to comply in full. We would rather not build a habit we have to unlearn later.

What this policy covers

This policy covers finlio.app and the waitlist behind it, which is everything Finlio does today. It also covers the email we send you as a result.

It does not cover the Finlio product, because the product is not open yet. Signing in, connecting accounts and the on-device store all come with their own commitments, and this page will be rewritten to cover them before the first account is created.

What we collect

Itemised, because a list of categories is not much use to anyone. This is the whole of it.

Your email addressWhen you join the waitlistTo email you once, to confirm you are on the list, and again when Finlio opens
The date and time you joinedWhen you join the waitlistTo keep the list in order and to know when to stop holding an unused entry
Email delivery eventsWhen we email youWhether a message was delivered, bounced or marked as spam, so we stop sending to a dead or unwilling address
Anything you write to usWhen you email one of our published addressesTo answer you. Mail to hello@, privacy@ and grievance@finlio.app is relayed to a mailbox we read
Standard server logsEvery page requestYour IP address, browser and the page requested, kept briefly by our host to serve the site and absorb abuse
Your cookie choiceWhen you answer the cookie bannerTo remember the answer, so we do not ask again or override it
Anonymous usage statisticsOnly if you allow analyticsWhich parts of the page people read, so we can write a better one. Off unless you turn it on

We do not ask for your name, your phone number, your PAN, your address, your income, your holdings or anything from your bank or broker. Not on this site. If a page or an email ever asks you for those in Finlio's name today, it is not us.

Cookies

This site sets one cookie of its own, to remember your answer to the cookie banner. Nothing else is set unless you allow it, and nothing is used for advertising. The full list, with names and lifetimes, is in the Cookie Policy.

Who else touches it

Four suppliers, each doing one job, each processing data only on our instructions. We have no others, and we do not sell or rent your data to anybody.

SupabaseThe database that holds the waitlistYour email address, status and join date
ResendSending our email, and relaying mail sent to hello@finlio.appYour email address, the message, and delivery events
VercelHosting and serving the siteStandard request logs, including your IP address
PostHogUsage statistics, only with your consentAnonymous page interactions. Nothing at all until you allow analytics, which is not enabled yet

We will also disclose data if the law genuinely requires it, for example a valid order from a court or a regulator. If that ever happens and we are permitted to tell you, we will.

Where your data is stored

Our database is in a region we choose on Supabase. Email and hosting run through Resend and Vercel, which operate infrastructure outside India, so your email address is processed abroad in the course of being stored and sent.

The DPDP Act allows this, except to countries the Central Government specifically restricts. If a restriction ever applies to a supplier we use, we will move the data rather than argue about it.

How long we keep it

  • Your waitlist entry stays until Finlio launches and for twelve months after that, so we can invite you and follow up once. After that, an unused entry is deleted.
  • If you unsubscribe or ask us to delete you, we act within 30 days, and usually the same week.
  • Email you send us is kept as long as the conversation is useful, and no longer.
  • Server logs expire on our host's short rolling schedule. We do not archive them ourselves.
  • Your cookie choice lasts six months, then we ask again.

How we protect it

  • Everything travels over TLS. There is no unencrypted path into this site.
  • The waitlist table is protected at the database level, so a browser cannot read the list even if it asks nicely. Writes happen only from our server.
  • Keys and secrets live in our hosting provider's secret store, never in the code. The code itself is public, which keeps us honest about that.
  • Access to the database is limited to the two people who build Finlio.

No system is perfect, and we will not pretend otherwise. What we can promise is a small amount of data collected, held briefly, and reported honestly if something goes wrong.

Your rights

Under the DPDP Act you can ask us to:

  • Show you what we hold about you and who we have shared it with.
  • Correct, complete or update anything that is wrong.
  • Erase it, unless a law requires us to keep it.
  • Withdraw your consent, which stops the email.
  • Nominate someone to exercise these rights for you if you die or cannot act for yourself.
  • Complain, and be answered. See the next section.

Email privacy@finlio.app from the address you signed up with, or tell us which address it concerns. We reply within 30 days. We do not charge for any of this, and we will not ask you for extra personal details to prove who you are beyond what identifies the entry.

If you are reading this from the EU or the UK, the equivalent rights there are ones we honour too. Same email address, same answer.

Complaints and escalation

Write to grievance@finlio.app with “Grievance” in the subject. We will acknowledge it, tell you who is handling it, and resolve it within 90 days, which is the limit the DPDP Rules set.

If our answer does not satisfy you, you can take the matter to the Data Protection Board of India. You do not need our permission, and we will not treat it as a hostile act.

Children

Finlio is for adults. The waitlist is meant for people aged 18 and over, and we do not knowingly collect anything from a child. If you believe a child has joined the list, tell us and we will delete the entry. When Finlio does open, any account belonging to a child would need verifiable consent from a parent or guardian, and we will never profile or advertise to children.

If something goes wrong

If your data is exposed, we will tell you directly, in plain words, with what happened and what to do about it. We will also report it to the Data Protection Board of India without delay and file the detailed report within 72 hours, as the DPDP Rules require. We will not quietly sit on a breach.

What we never do

  • Sell, rent or trade your data. There is no version of Finlio where your data is the product.
  • Add you to a list you did not join, or buy a list you are on.
  • Run advertising or cross-site tracking pixels.
  • Ask for your bank or broker password. When Finlio does connect to your accounts, it will be through India's Account Aggregator framework, where you approve access in your own bank's app and we receive a revocable token, never your credentials.

Changes to this policy

When this policy changes materially, we will change the date at the top and, if the change affects what we collect or why, email everyone on the waitlist before it takes effect. Older versions are in the public commit history of this site, so you can see exactly what changed and when.

Questions about this page?

Write to hello@finlio.app and a person will read it. If you are asking about your data, say so in the subject line and we will treat it as a request under the Digital Personal Data Protection Act.

Also here: .