Security & Data Handling
Last Updated: September 21, 2026
This page describes how Fiscify handles data in the shipped product. It is the plain-language source of truth for security claims. The Privacy Policy remains the legal disclosure.
1. What this page covers
Fiscify is a natural language-first expense tracker for iOS and Android. You add data by typing or speaking a transaction, photographing a receipt, importing a bank statement file, or entering details manually. We do not require bank login credentials.
2. What stays on your device
- An offline-first local store of your accounts, transactions, and related records so the app works without a constant network connection
- Optional biometric app lock (Face ID, fingerprint, or similar). That lock stays on your device and is not a Fiscify account password
- On-device speech-to-text when you use voice entry. The transcribed text is what we process for extraction
3. What is processed on our servers
When you are signed in, your data syncs to our backend so you can use Fiscify across devices and recover after reinstall. Extraction and categorization for natural language text, receipt images, and statement files run on Fiscify's API with Google Gemini. We use that processing to propose amounts, dates, merchants, and categories for your review. We do not use your personal data to train Fiscify models. Provider practices are governed by Google's terms and privacy policy.
4. Processors we rely on
- Supabase: authentication, database, and file storage
- Google Gemini (via our API): extraction and categorization of content you submit
- RevenueCat with Apple App Store and Google Play Billing: subscription entitlement and purchase status
- Analytics: Google Analytics and PostHog, subject to your cookie and tracking preferences where applicable
Full processor detail and legal basis live in the Privacy Policy.
5. Encryption and account access
- TLS in transit: data between the app and our services is encrypted with Transport Layer Security
- Encryption at rest: data stored with our infrastructure providers is encrypted at rest using their standard controls
- Sign-in: email auth and Sign in with Apple or Google where available
We do not claim end-to-end encryption with client-held keys for your financial records. We do not offer user-facing multi-factor authentication or a security-audit / login-history screen in the app today.
6. Offline-first, explained
Offline-first means you can view and edit local records without network access. When connectivity returns, changes sync to our servers. It does not mean your data never leaves the device, and it does not mean extraction runs only on-device.
7. Export and deletion
You can request access, correction, export, or deletion of your personal data by using in-app controls where available or by emailing support@fiscify.com. Retention, backup windows, and rights under GDPR and similar laws are described in the Privacy Policy.
8. Not supported
Fiscify does not currently offer:
- Live bank sync or Plaid-style account linking
- Bank login credentials collected or stored by Fiscify
- End-to-end encryption with client-held keys
- A chat coach, Fisca assistant, or open-ended ask-anything finance Q&A
- Autonomous financial actions (pay bills, renegotiate, move money)
- Concierge bill negotiation
9. Questions
Privacy or security questions: support@fiscify.com. Subject line: Security Inquiry.