Privacy Policy

Your privacy is a core principle of finilog itself. We collect as little personal data as possible, and our encryption means we have no technical ability to access the contents of your vault.

🔒

Encryption First

The contents of your vault are encrypted on your own device before they are ever sent to our servers (Zero-Knowledge).

🇪🇺

GDPR Focused

finilog is designed around European privacy principles and GDPR compliance, and is operated from Germany.

🛡️

Data Minimization

We only process the data strictly necessary to provide our services and keep the platform secure.

1. Data Controller

The controller within the meaning of Art. 4 No. 7 GDPR for the processing of personal data in connection with this website and the finilog application is the person named in the imprint. Full contact details are provided there. For any questions about this Privacy Policy or your personal data, you can reach us at support@finilog.de.

2. Zero-Knowledge As A Foundational Principle

The content you store in your vault — credentials, notes, documents, crypto information and attached files — is encrypted exclusively on your own device (AES-256-GCM) before it ever reaches our servers. The key used for this is derived from your vault password (PBKDF2-SHA256, 1,000,000 iterations) and never leaves your device. For this content, we are technically unable to view it, disclose it to authorities in plaintext, or reset it on your behalf. This Privacy Policy accordingly focuses mainly on the metadata and account information that necessarily arises unencrypted to operate the service — not on the content of your vault itself. A full technical breakdown of which database column is encrypted and which is not is available on our data model page.

3. Data We Process

Account data: first and last name, email address, and a password hash (never the password itself), provided at registration. Vault metadata (unencrypted): technical row identifiers, timestamps, the keys wrapped for recovery purposes, and which beneficiary account an entry was encrypted for. The name and email address of the beneficiaries you designate also remain unencrypted, since we need to contact them if the worst happens. Vault content (encrypted): the title, category, and actual content of every entry, as well as attached files. We store only ciphertext for these, see Section 2. File metadata (unencrypted): file size, timestamps, and a randomly generated storage path that reveals neither the original filename nor file type. Technical and security data: IP address, timestamp, and device/browser information automatically processed by our authentication backend at sign-in to detect abuse, as well as our hosting/CDN provider's server logs. Usage statistics: a randomly generated, anonymous session identifier, the page visited, and the referring URL, used solely for our own aggregated traffic measurement — without cross-device recognition or sharing with third parties. Support communication: the content and contact details you provide when reaching out to support. Payment data: once paid subscriptions are actively usable, an external, specialized payment provider will process your payment data on our behalf. Full payment card data never passes through our own servers.

4. Purpose Of Processing

We process personal data to: provide and manage your account, technically operate the encrypted vault and its beneficiary/release features, run the automated check-in process described in Section 6, detect abuse and maintain system security, comply with legal obligations, and provide customer support.

5. Legal Basis

Depending on the purpose, processing is based on Art. 6(1)(b) GDPR (performance of the usage contract, including the beneficiary release you configure), Art. 6(1)(f) GDPR (legitimate interest in system security, abuse prevention, and anonymized traffic measurement), Art. 6(1)(c) GDPR (compliance with legal obligations, e.g. bookkeeping), and, where applicable, Art. 6(1)(a) GDPR (your explicit consent).

6. Automated Check-In And Data Release

A core part of the service is a fully automated, technical check on whether you have last confirmed activity with finilog within a period you configure yourself ("check-in"). If no confirmation is received, our system automatically sends a series of reminders, then contacts the beneficiaries you have designated, and — after a further, also configurable waiting period during which you can object — technically unlocks beneficiary access to the entries you assigned to them, which remain encrypted throughout. This process runs without any substantive review by us and without a human decision on our end; it is based purely on deadlines and on the response of the people you yourself designated (Art. 22 GDPR). We use it because it is necessary to fulfil the contract you chose, and because you configure the relevant parameters — check-in interval, reminders, final waiting period — yourself in your account settings and can interrupt the process at any time. The exact mechanics are further described in our Terms of Service.

7. Recipients And Processors

Personal data is never sold. We use carefully selected processors under Art. 28 GDPR, in particular: Supabase (database, file storage, and backend functions, hosted in the EU region Frankfurt am Main), Cloudflare (delivery of the website via a global content delivery network), and Resend (delivery of transactional emails, e.g. check-in reminders or beneficiary notifications). Once paid subscriptions are actively usable, a payment provider will be added. Appropriate Art. 28 GDPR data processing agreements are or will be in place with all processors before productive use.

8. International Transfers

Our database and storage infrastructure is located in the EU (Frankfurt am Main). Some of the service providers we use, particularly for content delivery and email, may be headquartered or operate infrastructure outside the EU/EEA. In such cases, we ensure that any transfer only takes place on the basis of appropriate safeguards under Art. 44 et seq. GDPR, such as EU Standard Contractual Clauses or a European Commission adequacy decision. Achieving fully European sovereignty of our infrastructure is a stated strategic goal of our roadmap.

9. Data Retention

We retain account data and vault content for as long as your account exists. You can delete your account yourself at any time via the settings; doing so irrevocably removes your vault entries, your beneficiary list, and the associated account data. For data remaining after a beneficiary release has been triggered, the deletion approach described in Section 10 applies. Once paid subscriptions are active, we retain invoice and payment data for the statutory commercial and tax retention periods (in Germany typically six to ten years, §§ 147 AO, 257 HGB), even beyond account deletion. Security-related log files are kept only briefly and are then automatically deleted or anonymized.

10. Deletion After A Beneficiary Release

Even after a technical release to your beneficiaries, your vault data is not automatically deleted. Deletion only happens once every designated beneficiary has explicitly agreed to it, and even then only after a further 30-day waiting period during which any beneficiary can still revoke that agreement. Once deletion is carried out, we remove your vault entries in full. We retain the user account itself and its link to the beneficiaries involved as a minimal record of who agreed to the deletion and when, and so our support team can still match up any subsequent inquiries. These remaining records contain no vault content.

11. Cookies And Local Storage

finilog does not use advertising or tracking cookies, nor third-party analytics services. In your browser's local storage, we store only strictly necessary data: your login session, your appearance preference (light/dark), and the anonymous session identifier mentioned in Section 3 used for traffic measurement. This data is not shared with third parties and is not used for cross-device tracking.

12. No Sharing For Advertising Purposes

We do not run an advertising business. Your data is never sold, rented, or otherwise shared with third parties for marketing purposes, and no profiling for marketing purposes takes place.

13. Your Rights

Under the GDPR, you have the right to access (Art. 15), rectify (Art. 16), erase (Art. 17), restrict processing of (Art. 18), port (Art. 20), and object to the processing of (Art. 21) your personal data. You may withdraw any consent given at any time with future effect. For many of these rights — such as accessing and exporting your vault data, or deleting your account — the application itself provides you with the corresponding functionality. Otherwise, an informal message to support@finilog.de is sufficient to exercise them.

14. Right To Lodge A Complaint

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement. As we are based in Hesse, Germany, this is regularly the Hessischer Beauftragter für Datenschutz und Informationsfreiheit.

15. Data Security

In addition to the client-side encryption of your vault content (Section 2), we apply technical and organizational measures to protect all data processed by us: transport encryption (TLS) for all connections, strict database-level access controls (Row Level Security), restrictive security headers, and ongoing development of our security architecture, as described on our security page. Independent security reviews are a firm part of our roadmap.

16. Use By Minors

finilog is intended for legally competent, adult users. We do not knowingly collect personal data from minors. If we become aware that an account was created by a minor, we will delete the account and its associated data.

17. Changes To This Privacy Policy

We update this Privacy Policy whenever our processing of personal data or the applicable legal requirements change. The version shown here is always the current one.

18. Contact

If you have questions about this Privacy Policy or the processing of your personal data, you can reach us at support@finilog.de or through the contact details provided in the imprint.

💡 Our Transparency Commitment

finilog is committed to full transparency, strong data protection, and continuous improvement of our security practices as the platform evolves.