Legal
Privacy policy
In short: we collect what the product needs to work, we do not sell your data, and analytics only run if you say yes. Below is the full GDPR disclosure β what we hold, why, on what legal basis, and what you can demand from us.
Last updated: 28 August 2026
Controller
Who is responsible for your data
The controller of the personal data described here is the operator of Finito (finito.guide). For any data-protection question or request, write to hello@finito.guide β that is the address monitored for these requests, and the one to use for the rights listed further down.
- hello@finito.guide
We have not appointed a data protection officer, because our processing does not meet the conditions of art. 37 of the GDPR. Requests are handled by the team at the address above.
Data
What we collect
We collect only what the platform needs in order to work:
- account data β email address, display name, handle, avatar, password stored as a cryptographic hash, or the identifier and basic profile your provider returns if you sign in with Google, Facebook or Apple;
- preferences β interface and content language, timezone, currency, notification and leaderboard settings, interests you selected;
- content you create β playbooks, steps, comments, reviews, reports, requests, and files you upload;
- activity β playbooks you open, start, progress through and finish, purchases, gifts, favourites, and badges earned;
- transaction data β amount, currency, date, playbook, and the payment identifiers Stripe returns. Card numbers go to Stripe and never reach our systems;
- technical data generated automatically β IP address, approximate region derived from it, browser and device type, pages requested, and error diagnostics.
We do not ask for and do not want special categories of data (health, beliefs, political opinions and the rest). Please do not put them into playbooks, comments or support messages.
Purposes
Why we use it, and on what legal basis
Every purpose has a legal basis under art. 6 of the GDPR. Where the basis is consent you can withdraw it at any time; where it is our legitimate interest you can object.
| Purpose | Legal basis | Retention |
|---|---|---|
| Running your account and giving you access to what you own | Performance of the contract β art. 6(1)(b) | While the account exists |
| Processing purchases, gifts and creator payouts | Contract β art. 6(1)(b); legal obligation for accounting β art. 6(1)(c) | 10 years for accounting records (Legea nr. 82/1991) |
| Service email β confirmations, password resets, security notices | Contract β art. 6(1)(b) | While the account exists |
| Reminders, digests and product news you opted into | Consent β art. 6(1)(a) | Until you unsubscribe or withdraw consent |
| Security, abuse and fraud prevention, rate limiting, error monitoring | Legitimate interest in a safe service β art. 6(1)(f) | Up to 12 months for logs and diagnostics |
| Product analytics and session replay, to see what to improve | Consent β art. 6(1)(a) | Up to 12 months, or until you withdraw consent |
| Recommendations and personalised rails built from your interests and activity | Legitimate interest in a relevant catalogue β art. 6(1)(f) | While the account exists |
We do not build advertising profiles, we do not sell or rent personal data, and we do not share it with advertising networks. To withdraw analytics consent, or object to a processing based on legitimate interest, use the cookie policy settings or write to hello@finito.guide.
Processors
Who else touches your data
We use a small number of providers, each under a data-processing agreement that lets them use the data only to deliver their service to us:
| Provider | What it does | Region |
|---|---|---|
| Vercel | Hosting and content delivery for the web app | EU / US |
| Supabase | Database and file storage | EU (eu-central-1) |
| Stripe | Payment processing and creator payouts | EU / US |
| Resend | Sending transactional and opted-in email | EU / US |
| PostHog | Product analytics and session replay, only with your consent | EU |
| Sentry | Error and crash monitoring | US |
| Upstash | Rate limiting and short-lived caching | EU |
| Google (Gemini) | Generating search embeddings and playbook cover images | EU / US |
Signing in with Google, Facebook or Apple involves those providers as separate controllers for the sign-in step itself; what they do with it is governed by their own policies.
Beyond this, we disclose data only where the law requires it β to a court or a competent authority acting within its powers β or where it is needed to establish, exercise or defend a legal claim.
Transfers
Transfers outside the EEA
Our database sits in the European Union (Frankfurt) and analytics run on the European PostHog instance. Some providers β error monitoring in particular β process data in the United States. Those transfers rely on the European Commission's standard contractual clauses, on an adequacy decision where one applies, and on the technical measures the provider documents. Write to hello@finito.guide if you want the details for a specific provider.
Retention
How long we keep it
The table above gives the period per purpose. As a rule: account data lives as long as your account, invoicing records are kept for 10 years because accounting law requires it, and technical logs are kept for up to 12 months.
After you delete your account we remove personal data within 30 days, except what we must keep by law. Public contributions such as reviews and comments may remain visible in anonymised form, detached from your identity, so that community ratings and discussions stay coherent.
Your rights
What you can ask of us
Under the GDPR (Regulation (EU) 2016/679) and Legea nr. 190/2018 you have the right to:
- access β a copy of the personal data we hold about you;
- rectification β correction of data that is wrong or incomplete;
- erasure β deletion of your data, in the cases art. 17 provides for;
- restriction β pausing processing while a dispute over it is resolved;
- portability β your data in a structured, machine-readable format, or sent directly to another controller where technically feasible;
- objection β to processing based on legitimate interest, including profiling for recommendations;
- withdrawal of consent β at any time, without affecting what was lawful before you withdrew it.
To exercise any of them, write to hello@finito.guide. We answer within one month, which we may extend by two months for complex requests, telling you why. Exercising these rights is free; we may charge a reasonable fee only for manifestly unfounded or excessive repeat requests.
If you believe we handled your data wrongly, you can complain to the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Bucharest, dataprotection.ro β or to the supervisory authority in the EU country where you live. You can also go to court.
Account deletion
Deleting your account and data
You can delete your account at any time: sign in, open your account settings, choose βDelete accountβ and confirm the link we email you. Deletion is permanent and removes your profile, preferences, uploaded files, activity and progress.
If you signed in with Google, Facebook or Apple and no longer have access to that account, write to hello@finito.guide from the address linked to your Finito account and we will delete your data within 30 days.
Automated processing
Recommendations and automated decisions
We rank the catalogue and build personalised rails automatically, from your interests and your activity. That is personalisation, not a decision producing legal effects or similarly significantly affecting you, so art. 22 of the GDPR does not apply β and you can object to it anyway. Moderation decisions may be supported by automated detection, but a person makes the final call on any restriction and you can contest it.
Cookies
Cookies and similar technologies
We set necessary cookies to keep you signed in and the site secure, and analytics cookies only if you consent. You can change or withdraw your choice at any time from the cookie settings. The full list and the details are in our cookie policy.
Minors
Age limit
The platform is not intended for people under 16, the age Legea nr. 190/2018 sets for consenting on your own to an information-society service. We do not knowingly collect data from children under that age; if you believe we hold such data, write to hello@finito.guide and we will delete it.
Security
How we protect the data
Data travels over encrypted connections, passwords are stored only as cryptographic hashes, access to production systems is restricted and logged, and card details never reach our servers. No system is perfectly secure; if a breach is likely to result in a high risk to your rights, we will notify you and the supervisory authority within the deadlines set by art. 33 and 34 of the GDPR.
Changes
Changes to this policy
We update this policy when the way we process data changes. The version in force is always the one on this page, dated at the top. For material changes we notify you by email or in the product before they take effect.
Contact
Write to us
For any question about your data or to exercise your rights, write to hello@finito.guide. See also our terms and conditions and our cookie policy.