Nuni FinancePTLegal document

Privacy Policy

Version 1.3 · updated on

This Policy explains what personal data Nuni Finance collects, why it collects it, whom it shares it with, and what you may require regarding it. It follows Brazilian Federal Law No. 13,709/2018 (Lei Geral de Proteção de Dados Pessoais — LGPD).

1. Who is the controller

Natan Ayres do Nascimento, registered with the Brazilian National Registry of Legal Entities (CNPJ) under No. 64.103.168/0001-05, headquartered in João Pessoa — Paraíba, Brazil.

Channel for any matter concerning your data, including exercising the rights described in Section 8: natan.nascimento.ayres@gmail.com.

This is also the channel of the Data Protection Officer. Nuni Finance is run by one person, and that person is responsible for responding.

2. What data we collect

Data you provide when creating and using an account:

  • Name and e-mail address (required for an account to exist).
  • Phone number — optional, and only required to use WhatsApp.
  • Password. We store only a cryptographic hash: we do not have your password and cannot recover it, only reset it.
  • Usage preferences: language, time zone, base currency and display settings.
  • CPF or CNPJ (Brazilian taxpayer registry numbers) — requested only when you subscribe to a paid plan. The payment institution (Section 5) requires the payer's registry number in order to issue the charge, and without it there is no way to bill you. Users on the free plan never provide it.

Financial data you enter: income and expense transactions, amounts, dates, categories, places, accounts, cards, statements, installments, goals, net worth, investments and any OFX statement data you import.

This is the core content of the service, and it is always you who enters it: we do not retrieve anything from your bank (see Section 4).

Data generated through use: audit records (who did what and when, for accountability — Article 6, X), AI assistant usage counts and, when you use it, the messages exchanged with the assistant.

Technical data: IP address and browser information inherent to any internet access.

3. Why we process each item (legal basis)

  • Performance of a contract (Article 7, V) — creating and maintaining the account, authenticating access, storing and calculating your transactions, billing the subscription and providing support. This is what the service is; without it, there is no product.
  • Compliance with a legal obligation (Article 7, II) — retaining tax and security records for the periods required by law.
  • Legitimate interests (Article 7, IX) — platform security, fraud and abuse prevention, and audit records.
  • Consent (Article 8) — for three optional product features: WhatsApp use, AI assistant use and group sharing. All three are detailed in the Consent Form, and refusing them does not prevent essential use of the product.

4. What we do NOT do

  • We do not sell your data. Ever, to anyone.
  • We do not use advertising or third-party tracking. The website has no Google Analytics, Tag Manager, social network pixel or session-recording tool. We do not build a profile of you for any advertiser.
  • We do not connect to your bank account. We do not request, receive or store bank passwords, tokens or Open Finance credentials.
  • We do not store your card data. It goes directly to the payment institution (Section 5) and does not pass through our systems.
  • We do not make automated decisions about you. There is no score, credit rating, approval or refusal decided by a machine.

5. Whom we share data with

Only with parties necessary for the service to operate, and only what is necessary:

  • Asaas Gestão Financeira Instituição de Pagamento S.A. — Payment and billing processing. Receives: name, e-mail address, CPF or CNPJ, billing data and payment method data. Processes data in Brazil.
  • Meta Platforms (WhatsApp Cloud API) — Sending and receiving WhatsApp messages. Receives: phone number and the content of messages exchanged. Processes data outside Brazil.
  • DeepSeek — Language model that generates the AI assistant responses. Receives: the submitted question and the financial context required to answer it. Processes data outside Brazil.
  • Upstash — Caching, request replay control and usage limits. Receives: technical session and request identifiers. Processes data outside Brazil.
  • Render — Hosting the API and database. Receives: all account data, so it can be stored. Processes data outside Brazil.
  • Vercel — Hosting the website and user interface. Receives: iP address and technical access data. Processes data outside Brazil.

We also share data when required by a court order or request from a competent authority and — if you choose to use groups — with the other group members, according to the permissions you grant.

6. International data transfers

Some of the processors above process data outside Brazil (Meta Platforms, DeepSeek, Upstash, Render, Vercel), which constitutes an international data transfer (Articles 33 through 36 of the LGPD).

The case that deserves your attention is the AI assistant: to generate a response, the question and the required financial context are sent to the language model provider, which processes them abroad. This is why using AI depends on your specific consent and may be refused without losing the other features.

7. How long we retain data

While your account exists, data is retained so the service can operate — a financial history is, by nature, meant to remain available.

When the account is closed, deletion is immediate and permanent: your data is removed from our database when the account is deleted. There is no recovery period, no "deactivated" account that continues to exist, and we do not retain a copy of your transactions for our own use. If you want to take your history with you, export it first — after deletion, we cannot return it.

There are three exceptions, and only these:

  • Backups: database backup routines may contain your data for up to 7 days after deletion, until the next cycle overwrites them. They exist for disaster recovery and are not accessed for any other purpose.
  • Billing records: subscription and payment data is retained for 5 years after closure to comply with statutory tax recordkeeping obligations. It is held by the payment processor and in accounting records. Within the app, your subscription is deleted along with the account; what remains is the record of the notifications received from the processor, which identifies the charge (number, amount, date and status) and serves as an audit trail of what was paid. For that reason, an erasure request does not reach the billing history (LGPD, Article 16, I): deleting the account is not the same as deleting what the law requires us to keep.
  • Audit records: critical system operations, including account deletion itself, are logged with the identity of the person who performed them. These records are retained for security and accountability (LGPD, Article 6, X) and are not used for any other purpose.

Security incident records are retained for 5 years under Resolution CD/ANPD No. 15/2024.

8. Your rights (Article 18 of the LGPD)

At any time and at no cost, you may request:

  1. Confirmation that we process your data.
  2. Access to the data.
  3. Correction of incomplete, inaccurate or outdated data.
  4. Anonymization, blocking or deletion of unnecessary or excessive data, or data processed in violation of the law.
  5. Portability of data to another provider.
  6. Deletion of data processed based on your consent.
  7. Information about whom we share your data with.
  8. Information about the possibility and consequences of withholding consent.
  9. Withdrawal of consent.

Write to natan.nascimento.ayres@gmail.com. We respond within 15 days, under Article 19, II of the LGPD. We may request confirmation of your identity before delivering personal data — this protects you; it is not an obstacle.

9. Security

Access is authenticated through an HttpOnly session cookie — meaning it is inaccessible to JavaScript, including a malicious script injected into the page — transmitted only over an encrypted connection and protected against forged requests from another website (SameSite).

Passwords are stored only as hashes. All traffic between your browser and the platform is encrypted. Operations are audited, and attempts are rate-limited to contain abuse.

No measure eliminates risk entirely. If a security incident poses a relevant risk to your rights, we will notify you and the ANPD within the periods set by Resolution CD/ANPD No. 15/2024.

10. Cookies

We use only what is strictly necessary, and nothing for advertising:

  • `finay_sessao` — an essential cookie that keeps you authenticated. Without it, there is no login.
  • Browser local storage — stores preferences (language and theme) and a temporary read cache so the app does not reload the same data on every screen. It remains on your device and is deleted when you clear the website data.

We do not use tracking, third-party or advertising cookies — therefore, this website does not display a cookie consent banner.

11. Children's and teenagers' data

The service is intended for people aged 18 or older and is not directed to minors. If we learn that an account was created by a minor without a legal guardian, it will be closed and the data deleted.

12. Changes to this Policy

We may update this Policy. The current version and date will always appear at the top of this page, and material changes will be communicated.

13. How to contact us

natan.nascimento.ayres@gmail.com

Natan Ayres do Nascimento — CNPJ 64.103.168/0001-05 — João Pessoa — Paraíba, Brazil.

You may also file a complaint with the Brazilian National Data Protection Authority (ANPD) at https://www.gov.br/anpd.

← Back to the home page