What Finara collects, where it is kept, who else can see it, and how to have it removed. Written to be read, not to be survived.
Last updated 23 August 2026
Finara is an independent product operated by Leo Changani, a private individual based in Gothenburg, Sweden — not a company, and not a licensed financial institution. For anything in this policy — access to your data, corrections, deletion, or a complaint — write to privacy@finara.pro, which is a monitored address.
Only what the product needs to work. In full:
Signals, prices and market news are not personal data — they are the same for every user and are stored once, not per account.
Finara has no connection to any brokerage or bank. It cannot see your real accounts, cannot place or route an order, and cannot move money. Your portfolio here is what you typed in, and nothing else.
In a PostgreSQL database hosted by Supabase in the EU (AWS eu-west-1, Ireland), which also provides authentication. The application runs on Vercel, with its server functions in Dublin. Both are processors acting on Finara's instructions.
Your data is not sold, not shared for advertising, and not used to train anything.
The marketing site at finara.pro uses Google Analytics to count visits and see which buttons get clicked — ordinary marketing measurement, on a page that knows nothing about you. Since 18 August 2026, the application also uses Google Analytics, and since 21 August 2026 it additionally uses PostHog, hosted in the EU. Both are held to the same rule inside the app: no page, click, or figure that could identify what you hold is ever sent (see below for exactly what that means).
Google Signals and ad personalisation are switched off, so the data is not fed to advertising. PostHog's automatic click/DOM capture and session recording are switched off too — only the specific, named events below are ever sent. There is currently no cookie consent banner on the marketing site or in the app, which means analytics cookies are set when you visit either. If you would rather not be counted, any content blocker or Google's official opt-out add-on prevents the Google Analytics side of it entirely.
Inside the app there are the cookies that keep you signed in, plus Google Analytics' and PostHog's own cookies. Google's analytics cookie is set for the whole finara.pro domain, so it is shared between the marketing site and the app. Your browser also stores small local preferences, such as recent searches and whether you dismissed the install prompt, which never leave your device.
What app analytics does and does not see. Both tools record which screens are opened and which generic controls are used — a navigation tab, a tool shortcut, a header icon, a filter chip — so we can tell which parts of the product actually get used. Page addresses are normalised before being sent: a visit to an individual asset is reported as /asset/[symbol], never with the instrument name, and query strings are dropped. An interaction is reported as, for example, "opened the Suggest tool" or "filtered signals to Buy" — never which asset, order, or amount was involved. Nothing identifying you is attached — no account id, no email — and no figure from your portfolio, no symbol you traded or watched, and no screen recording is ever sent. Google and PostHog therefore learn that someone opened an asset page or used a feature, not which asset, whose, or what it is worth.
Your account data is kept until you ask for it to be deleted. Trades and watchlist entries persist so your history and performance stay correct over time.
Signals Finara has published are kept permanently, including the wrong ones, because the published track record depends on them. Those records are about assets, not about you, and contain nothing that identifies who followed what.
Under the GDPR you can ask for a copy of your data, have it corrected, have it deleted, object to how it is used, or take it elsewhere. Email privacy@finara.pro and it will be handled within 30 days.
Deletion is done by hand, deliberately. Removing an account is not automatic in Finara: deleting a sign-in does not by itself delete a trade ledger, so a request is carried out manually to make sure the right things go and nothing else does. Say what you want removed — the whole account, or specific records.
If you think your data has been mishandled you can complain to your national supervisory authority; in Sweden that is Integritetsskyddsmyndigheten (IMY).
Traffic is encrypted in transit, the database is not publicly reachable, passwords are managed by Supabase Auth rather than by Finara, and API keys are held server-side and never sent to your browser. Finara is a small independent product and has not been through an external security audit — it is worth knowing that, and worth remembering that the worst case here is exposure of a portfolio you typed in, because nothing connected to it can move money.
Finara is not intended for anyone under 18 and accounts should not be created for them.
If this policy changes in a way that affects what is collected or who sees it, the date at the top changes and material changes will be announced in the app. The version you are reading is the one in force.