Privacy Policy

Last updated 20 August 2026

Finch is a time-tracking service run by an individual, not a company. This page explains what it records about you, who else sees it, and how to get it back or have it removed.

Who is responsible

Finch is operated by Nguyễn Tiến Lãm, an individual developer based in Vietnam. There is no registered company behind it at the time of writing. Questions about anything on this page go to lamnt.it@gmail.com.

What Finch records

Account details: your email address, your name, a username, a profile picture (either an uploaded image or a chosen colour), and your language preference.

Work you track: time entries with their start and end times and any description you write, along with the projects, organisations and roles they belong to.

A change log: every edit to a time entry is recorded, including who made it and what changed. This exists so the numbers in a shared report can be trusted, and it means edits are visible to the organisation the entry belongs to.

Invitations: the email address of anyone you invite, plus a single-use token and its expiry.

Billing references: if paid plans ever start, a customer identifier from the payment provider, along with the plan, seat count and billing period. Finch never sees or stores card numbers.

Housekeeping: notifications, your email-notification preference, onboarding progress, and a count of how many times AI features were used.

Why Finch records it

To provide the service you signed up for: tracking your time, showing it back to you, and sharing the parts of it that belong to an organisation you joined.

To send you the emails the product depends on — invitations, and notifications you have not turned off.

To keep shared numbers trustworthy, which is the reason the change log exists.

Who else sees your data

Supabase hosts the database and handles sign-in. Everything Finch stores lives there.

Vercel hosts the website and the application, and keeps ordinary server access logs.

Sentry receives a crash report when the application fails. A report contains the error message, the code path that failed, your account identifier and the organisation identifier. It does not contain your name, your email address, or anything you typed into a time entry — descriptions are stripped before the report leaves your browser. Reports are deleted within 90 days.

Resend sends transactional email. It receives the recipient address and the contents of the message.

Google handles sign-in if you choose to sign in with Google.

Paddle would handle payments if paid plans start. Paddle acts as the merchant of record, meaning Paddle is the seller and holds the payment details — Finch does not.

Google Gemini receives text you type, but only when you use an AI writing feature. If you ask Finch to rewrite a description, that description is sent to Google to be rewritten. If you never use those features, nothing you write leaves Finch's own infrastructure. This is the one place where your own words go to a third party, so it is worth stating plainly rather than burying.

What Finch does not do

Finch does not record your screen, take screenshots, log your keystrokes, or watch which applications or websites you open. It records time when you press start and stop, and nothing else about what you were doing.

Finch does not sell your data, and does not share it with advertisers.

Finch does not replay your session or record what is on screen when something goes wrong. A crash report describes the failure, not the page you were looking at.

Your rights

You can export everything you have tracked at any time, from inside the application, as CSV, Excel or PDF. No request needed.

You can ask for a copy of your data, ask for it to be corrected, or ask for it to be deleted. Email lamnt.it@gmail.com and it will be handled within 30 days.

Account deletion is currently handled by hand rather than by a button in the application. That is a gap, and it is stated here rather than implied otherwise. Deleting an organisation from within the app removes that organisation and the time entries inside it, but it does not remove your own profile — for that, email the address above.

These rights are offered to everyone who uses Finch, wherever they are. Finch does not maintain one set of rights for people in some countries and a lesser set for everyone else.

How long data is kept

While your account exists, your data is kept so the service can work.

After a deletion request, data is removed within 30 days.

Backups taken before a deletion request may retain a copy for a short period until they age out in the normal rotation.

Cookies and local storage

Finch stores a sign-in session so you do not have to log in on every visit, and remembers your light or dark theme choice in your browser.

There are no advertising cookies and no third-party analytics trackers. Finch does not measure which pages you visit or how long you spend on them. The one third-party script the application loads is a crash reporter, and it stays silent unless the application actually fails.

Children

Finch is a tool for working adults and is not directed at children. It should not be used by anyone under 16.

Changes to this page

If this policy changes in a way that affects you, you will be told before the change takes effect rather than after. The date at the top of this page shows when it was last revised.