Who is responsible for your data
Finlio is built by Quarix, in India. For anything you give us through this website, we are the data fiduciary: the people who decide what is collected and why, and who answer for it.
You are what the Digital Personal Data Protection Act, 2023 calls a data principal. Every right described on this page is yours, and the way to use any of them is to email privacy@finlio.app.
We follow the DPDP Act and the Digital Personal Data Protection Rules, 2025 now. The law gives businesses until 13 May 2027 to comply in full. We would rather not build a habit we have to unlearn later.
What this policy covers
This policy covers finlio.app and the waitlist behind it, which is everything Finlio does today. It also covers the email we send you as a result.
It does not cover the Finlio product, because the product is not open yet. Signing in, connecting accounts and the on-device store all come with their own commitments, and this page will be rewritten to cover them before the first account is created.
What we collect
Itemised, because a list of categories is not much use to anyone. This is the whole of it.
| Data | When | Why |
|---|---|---|
| Your email address | When you join the waitlist | To email you once, to confirm you are on the list, and again when Finlio opens |
| The date and time you joined | When you join the waitlist | To keep the list in order and to know when to stop holding an unused entry |
| Email delivery events | When we email you | Whether a message was delivered, bounced or marked as spam, so we stop sending to a dead or unwilling address |
| Anything you write to us | When you email one of our published addresses | To answer you. Mail to hello@, privacy@ and grievance@finlio.app is relayed to a mailbox we read |
| Standard server logs | Every page request | Your IP address, browser and the page requested, kept briefly by our host to serve the site and absorb abuse |
| Your cookie choice | When you answer the cookie banner | To remember the answer, so we do not ask again or override it |
| Anonymous usage statistics | Only if you allow analytics | Which parts of the page people read, so we can write a better one. Off unless you turn it on |
We do not ask for your name, your phone number, your PAN, your address, your income, your holdings or anything from your bank or broker. Not on this site. If a page or an email ever asks you for those in Finlio's name today, it is not us.
Consent, and taking it back
Typing your email into the waitlist form and submitting it is your consent for the two things above: the confirmation email and the launch email. That is a specific and informed act, which is exactly what the DPDP Act requires. Nothing is pre-ticked and nothing is bundled.
You can withdraw it whenever you like. Today that means one email to privacy@finlio.app asking to come off the list, and we act on it by hand, usually the same day. Before we send any product news beyond the confirmation, every message will carry a one-click unsubscribe link. Withdrawing consent stops the email; ask us to delete the entry and the address goes too.
Analytics consent is separate, off by default, and changeable at any time from the cookie preferences link in the footer.
Where your data is stored
Our database is in a region we choose on Supabase. Email and hosting run through Resend and Vercel, which operate infrastructure outside India, so your email address is processed abroad in the course of being stored and sent.
The DPDP Act allows this, except to countries the Central Government specifically restricts. If a restriction ever applies to a supplier we use, we will move the data rather than argue about it.
How long we keep it
- Your waitlist entry stays until Finlio launches and for twelve months after that, so we can invite you and follow up once. After that, an unused entry is deleted.
- If you unsubscribe or ask us to delete you, we act within 30 days, and usually the same week.
- Email you send us is kept as long as the conversation is useful, and no longer.
- Server logs expire on our host's short rolling schedule. We do not archive them ourselves.
- Your cookie choice lasts six months, then we ask again.
How we protect it
- Everything travels over TLS. There is no unencrypted path into this site.
- The waitlist table is protected at the database level, so a browser cannot read the list even if it asks nicely. Writes happen only from our server.
- Keys and secrets live in our hosting provider's secret store, never in the code. The code itself is public, which keeps us honest about that.
- Access to the database is limited to the two people who build Finlio.
No system is perfect, and we will not pretend otherwise. What we can promise is a small amount of data collected, held briefly, and reported honestly if something goes wrong.
Your rights
Under the DPDP Act you can ask us to:
- Show you what we hold about you and who we have shared it with.
- Correct, complete or update anything that is wrong.
- Erase it, unless a law requires us to keep it.
- Withdraw your consent, which stops the email.
- Nominate someone to exercise these rights for you if you die or cannot act for yourself.
- Complain, and be answered. See the next section.
Email privacy@finlio.app from the address you signed up with, or tell us which address it concerns. We reply within 30 days. We do not charge for any of this, and we will not ask you for extra personal details to prove who you are beyond what identifies the entry.
If you are reading this from the EU or the UK, the equivalent rights there are ones we honour too. Same email address, same answer.
Complaints and escalation
Write to grievance@finlio.app with “Grievance” in the subject. We will acknowledge it, tell you who is handling it, and resolve it within 90 days, which is the limit the DPDP Rules set.
If our answer does not satisfy you, you can take the matter to the Data Protection Board of India. You do not need our permission, and we will not treat it as a hostile act.
Children
Finlio is for adults. The waitlist is meant for people aged 18 and over, and we do not knowingly collect anything from a child. If you believe a child has joined the list, tell us and we will delete the entry. When Finlio does open, any account belonging to a child would need verifiable consent from a parent or guardian, and we will never profile or advertise to children.
If something goes wrong
If your data is exposed, we will tell you directly, in plain words, with what happened and what to do about it. We will also report it to the Data Protection Board of India without delay and file the detailed report within 72 hours, as the DPDP Rules require. We will not quietly sit on a breach.
What we never do
- Sell, rent or trade your data. There is no version of Finlio where your data is the product.
- Add you to a list you did not join, or buy a list you are on.
- Run advertising or cross-site tracking pixels.
- Ask for your bank or broker password. When Finlio does connect to your accounts, it will be through India's Account Aggregator framework, where you approve access in your own bank's app and we receive a revocable token, never your credentials.
Changes to this policy
When this policy changes materially, we will change the date at the top and, if the change affects what we collect or why, email everyone on the waitlist before it takes effect. Older versions are in the public commit history of this site, so you can see exactly what changed and when.
