Privacy Policy

Effective date: 31 August 2026

This Privacy Policy explains how Fineliner handles information when you use the app and related services.

1. Who we are and what this policy covers

Fineliner is developed by Filipe Rigolon. In this Privacy Policy, “Fineliner”, “we”, “us” and “our” refer to Filipe Rigolon as the developer and operator of the Fineliner app and associated services.

This Privacy Policy explains how information is handled when you use:

  • the Fineliner apps for iPhone, iPad and Mac;

  • Fineliner account, subscription and synchronisation features;

  • optional broker, Notion and Calendar integrations;

  • Fineliner’s supporting backend services; and

  • the Fineliner website and related support channels.

Fineliner is a trading journal and analysis tool. It is not a broker, does not place trades and does not provide financial, investment, tax or legal advice.

2. The short version

Fineliner is designed so that your private trading journal remains under your control.

  • Core trading records, journal entries, plans, strategies, portfolio records and related attachments are stored on your devices and, when enabled, in your private Apple iCloud/CloudKit account.

  • Your Fineliner account profile is separate from your private trading workspace and is stored using Supabase.

  • Optional usage analytics are disabled by default and use PostHog’s EU-hosted service only after you opt in.

  • Broker, SnapTrade, Notion, Calendar and market-data features transmit the information needed to provide the feature you choose to use.

  • Purchases are processed by Apple. Fineliner does not process or store your payment-card details.

  • On-device AI features use Apple Foundation Models and are designed to process their prompts on your device.

Some information necessarily leaves your device when you use account, broker, market-data, analytics, support or third-party integration features. The sections below explain those cases.

3. Information you provide

Depending on the features you use, you may provide the following information.

3.1 Account and profile information

A Fineliner account may include:

  • your name and email address;

  • a unique account identifier;

  • your country code;

  • primary and secondary broker preferences;

  • onboarding reasons and preferences;

  • preferred display currencies;

  • app version and platform information;

  • subscription status; and

  • whether you opted in to newsletters or development updates.

Fineliner uses email one-time codes for account registration and sign-in. Authentication is provided through Supabase.

3.2 Trading and transaction information

Trading records may include:

  • transaction identifiers and dates;

  • buy, sell or other action types;

  • ticker symbols, ISINs and instrument names;

  • broker and account identifiers;

  • quantities, prices and currencies;

  • exchange rates and total values;

  • realised profit or loss;

  • withholding tax and currency-conversion fees;

  • notes and source filenames; and

  • import, duplicate, rejected-row and validation information.

You may enter this information manually, import it from CSV files or retrieve it through an optional broker connection.

3.3 Journals, plans and other content

Content you create may include:

  • journal titles, text, rich text, moods and tags;

  • links between journal entries and trades;

  • images, drawings and markup;

  • voice-note audio, filenames, duration and related metadata;

  • trading-plan rules, risk limits, markets, sessions, entry and exit rules, psychology notes and checklists;

  • custom strategies, timeframes, regimes and invalidation rules;

  • portfolio entries for investments, savings, pensions, property, loans, cryptoassets, collectables and other assets;

  • notebook names, icons, colours, ordering and archive state; and

  • settings and preferences.

3.4 Files and permissions

If you choose to use the relevant features, Fineliner may access:

  • CSV and other files you select;

  • folders you authorise for watched-folder importing;

  • the microphone for journal voice notes;

  • Photos for journal image attachments;

  • Calendar to create and manage an optional Fineliner calendar;

  • notifications for reminders, market-session alerts, imports and broker-sync messages; and

  • Face ID, Touch ID or device authentication for app lock, saved login and sensitive actions.

These permissions are controlled through Apple’s permission system and may be withdrawn in your device settings.

4. Information generated by Fineliner

Fineliner calculates or derives information from the records you provide, including:

  • portfolio positions and balances;

  • cost basis and realised profit or loss;

  • performance summaries and reports;

  • import and broker-sync outcomes;

  • trading-plan reviews;

  • journal and workflow statistics; and

  • on-device AI summaries or responses.

Calculated outputs may be incomplete or inaccurate because of missing records, source-data errors, import assumptions, exchange-rate limitations or software defects. You should verify important figures against your broker or other authoritative records.

5. How your information is stored

5.1 Local storage

Fineliner uses Apple SwiftData and related Apple storage technologies to store core app records on your device. On supported iOS devices, the persistent store uses Apple data-protection controls. Sensitive files may use complete file protection.

5.2 iCloud and CloudKit

Cloud synchronisation is enabled by default using the private CloudKit container associated with Fineliner. When enabled, Apple synchronises supported records across devices signed in to your iCloud account.

Supported settings may also use iCloud key-value storage. Widgets and Live Activities may receive selected values through an app group. Privacy settings can hide sensitive values from these surfaces.

If you disable CloudKit, Fineliner uses a local SwiftData configuration without a CloudKit database. Apple controls iCloud infrastructure, synchronisation behaviour, backups and deletion propagation.

5.3 Keychain

Authentication sessions, broker credentials and Notion credentials use Apple Keychain rather than ordinary preferences.

Credentials are local-only by default and use device-protection settings. If you expressly enable credential synchronisation, eligible items may use iCloud Keychain and Apple’s synchronisable Keychain behaviour.

Fineliner does not have access to your iCloud account password.

6. Fineliner account and Supabase

Supabase provides Fineliner’s email authentication and remote account-profile storage. Supabase may process:

  • your email address and unique account ID;

  • authentication tokens and session information;

  • the profile fields described in section 3.1;

  • account-deletion requests; and

  • server-side records needed for optional SnapTrade connections.

Access and refresh tokens are stored in Apple Keychain on your device. Fineliner sends bearer tokens in secure authorisation headers when communicating with authenticated services.

Your remote profile is separate from the private trading records stored through SwiftData and iCloud.

7. Optional analytics

Fineliner uses PostHog’s EU-hosted service for optional product analytics. Analytics consent is off by default. If you opt in, events may describe:

  • app and screen usage;

  • platform, app/build version and major operating-system version;

  • appearance and coarse window-size information;

  • coarse account-age buckets;

  • feature and workflow names;

  • duration buckets and outcome categories;

  • import, broker-sync, journal, plan, strategy, report and widget activity; and

  • high-level settings or report configuration.

Fineliner’s analytics controls are designed to exclude trades, transaction amounts, tickers, portfolio values, broker credentials, CSV contents and journal text. Event properties are restricted to an allowed set. GeoIP processing, person profiles, automatic lifecycle capture, interaction capture, screen capture, session replay, surveys and feature flags are disabled in the app configuration.

If you turn analytics off, Fineliner opts the app out and attempts to remove known local PostHog queue, replay and log files. Turning analytics off does not itself prove deletion of records that may already have been transmitted. You may contact us to ask about rights that apply to previously collected analytics data.

No dedicated third-party crash-reporting SDK was identified in the audited app. Apple diagnostics, optional analytics, hosting logs or information you provide in a support request may nevertheless contain diagnostic information.

8. Broker connections and financial-data services

Broker features are optional.

8.1 Direct broker integrations

Fineliner contains direct or file-based integrations for services including Trading 212 and Interactive Brokers. Credentials supplied for supported direct broker integrations are stored in Apple Keychain. Requests may transmit account or transaction queries directly to the relevant provider.

8.2 SnapTrade

SnapTrade provides optional connections to supported financial institutions. Fineliner requests a read-only connection and uses it to retrieve account lists and transaction activity. Fineliner does not request authority to place trades through this connection.

SnapTrade requests pass through Fineliner’s backend hosted on Vercel and are authenticated with your Fineliner account session. Server-side integration records may include:

  • your Fineliner user ID;

  • a SnapTrade user ID;

  • connection status;

  • encrypted SnapTrade user-secret components;

  • encryption-version information; and

  • update timestamps.

The backend is configured for Vercel’s London region. Ordinary hosting infrastructure may also process IP addresses, request headers, timestamps and security or operational logs. Exact infrastructure retention periods are not specified in the app source.

You can disconnect individual institutions or request deletion of the associated SnapTrade identity through the available app controls. SnapTrade and each connected financial institution also operate under their own terms and privacy notices.

9. Market and currency data

To display market and currency information:

  • Fineliner’s backend may send ticker symbols and exchange codes to Marketstack for delayed, end-of-day or available intraday market data; and

  • the app may send requested currency codes directly to Frankfurter for exchange rates.

When these features are used, Fineliner’s Vercel backend receives the requested ticker symbols and may also receive an exchange code, chart range or interval. It does not receive your trade quantities, prices paid, portfolio values, journal text, broker credentials or CSV contents. Market responses are cached in Redis for between 5 minutes and 24 hours depending on the endpoint: 5 minutes for intraday data, 15 minutes for quotes, end-of-day data and stock prices, 6 hours for charts and 24 hours for ticker metadata. A SHA-256 hash derived from the request IP address is retained for up to 60 seconds for rate limiting; Fineliner does not store the raw address in that rate-limit key. Vercel, Marketstack and Frankfurter may separately process standard network and operational metadata under their own retention practices.

10. Notion integration

If you enable Notion synchronisation:

  • your Notion API key is stored in Apple Keychain;

  • selected database IDs, titles and synchronisation state are stored in app preferences; and

  • Fineliner sends selected transaction fields to the Notion API.

Those fields may include transaction date, action, ticker, instrument name, quantity, price, currency, GBP total, realised profit or loss, foreign-exchange fee, exchange rate and ISIN.

You control the Notion workspace and destination database. Notion processes the information under your Notion account and its own privacy terms. You can disable the integration and revoke the relevant Notion credential.

11. Calendar, notifications, Photos and microphone

If authorised, Fineliner may:

  • create an optional Fineliner calendar and events in Apple Calendar, preferably using your iCloud calendar source;

  • schedule local notifications for market sessions, reviews, journals, dividends, imports, broker synchronisation and app-security events;

  • use your microphone to record journal voice notes; and

  • read or write selected Photos content for journal images.

These features use Apple frameworks and the permissions you grant. Fineliner does not access these categories when the relevant permission or feature is not used.

12. On-device artificial intelligence

Fineliner uses Apple Foundation Models for supported AI summaries and question responses. The feature is designed to run on-device. Prompts instruct the model not to provide predictions, recommendations, ratings or buy, sell or hold guidance.

AI output may be incomplete, inaccurate or unsuitable for your circumstances. It is informational journal assistance only and must not be relied upon as financial, investment, tax or legal advice.

13. Subscriptions and payments

Apple StoreKit and the App Store process Fineliner subscriptions, purchase verification, renewals, restoration, expiry and revocation. Apple controls the payment interface and receives your payment information.

Fineliner receives subscription and entitlement status needed to enable Free or Plus features. Fineliner does not process or store your payment-card details. Prices, taxes, trials, billing periods, cancellation and refund availability are determined by the App Store information presented to you and Apple’s applicable terms.

14. How we use information

Depending on the context and applicable law, we use information to:

  • create, authenticate and maintain your account;

  • provide journal, portfolio, import, report, synchronisation and integration features;

  • calculate and display app outputs;

  • verify subscriptions and restore purchases;

  • protect accounts, credentials, services and users;

  • diagnose failures and provide support;

  • improve Fineliner where you have consented to optional analytics;

  • send development updates where you have opted in;

  • comply with legal obligations; and

  • establish, exercise or defend legal claims.

Where data-protection law requires a legal basis, the basis may be performance of our contract with you, your consent, compliance with law or our legitimate interests in providing, securing and improving Fineliner. You may withdraw consent for future processing where processing depends on consent.

15. When information is shared

We do not sell your personal information.

Information may be shared with:

  • Apple for iCloud, CloudKit, Keychain, StoreKit, notifications, Calendar, Photos, device authentication and related platform services;

  • Supabase for authentication and account-profile services;

  • PostHog if you enable optional analytics;

  • Vercel for backend hosting;

  • SnapTrade and financial institutions you choose to connect;

  • Marketstack and Frankfurter for requested market or currency data;

  • Notion when you enable Notion synchronisation;

  • Logo.dev when the app requests remote instrument logos;

  • professional advisers, service providers or authorities where reasonably necessary to comply with law, protect rights or secure the service; and

  • a successor organisation in connection with a genuine merger, acquisition, financing or transfer of the service, subject to applicable law.

Each independent provider may process information under its own terms and privacy policy. Redis is present as a backend support dependency, but the audited source does not establish the production provider or retention configuration; we therefore do not make a more specific representation here.

16. International transfers

Fineliner and its providers may process information in countries other than the one where you live. The app is configured to use EU-hosted PostHog analytics and a Vercel London backend region, but other providers may process information in additional locations.

Where applicable law requires transfer safeguards, we and relevant providers will rely on an available lawful transfer mechanism. Provider-specific transfer information is available in the provider’s own privacy documentation.

17. Retention

Retention depends on the type of information and the feature involved.

  • Local and iCloud content remains until you delete it, reset the relevant data or remove it through Apple’s iCloud controls, subject to Apple’s synchronisation and backup processes.

  • Account-profile and authentication information is retained while your Fineliner account remains active and as reasonably necessary for security, legal or operational purposes.

  • SnapTrade integration records remain while the connection is active and until the relevant integration or identity is deleted, subject to provider requirements.

  • Analytics records, hosting logs, support correspondence and third-party records follow the applicable service configuration and provider retention practices.

  • Apple retains purchase and transaction records under Apple’s own legal and operational requirements.

The audited app does not define fixed retention periods for every category. We do not claim a shorter or more precise period than can be supported. We aim not to retain personal information longer than reasonably necessary for the purpose for which it is processed, subject to legal obligations and provider-controlled retention.

18. Security

Fineliner uses measures intended to protect information, including:

  • HTTPS for identified network services;

  • Apple Keychain for sessions and integration credentials;

  • device-only Keychain accessibility by default;

  • optional biometric or device-owner authentication;

  • iOS data-protection settings for persistent and sensitive files;

  • encrypted server-side SnapTrade user secrets;

  • bearer tokens in authorisation headers rather than URL query strings;

  • sandboxing and user-selected file access on macOS; and

  • privacy controls for widgets and Live Activities.

No system is completely secure. You are responsible for protecting your devices, Apple account, email account, broker credentials and integration tokens. Contact us promptly if you believe your Fineliner account or connected services have been compromised.

19. Your controls, exports and deletion options

Fineliner provides several distinct controls. They do not all delete the same information.

19.1 Analytics

You can decline analytics during onboarding or turn it off later in Settings.

19.2 Export

You can export stored transactions to CSV. The verified CSV export covers transaction fields; it is not represented as a comprehensive export of every profile, journal, image, voice note, plan, strategy, setting, integration or analytics record.

19.3 Local and iCloud data

Settings provide controls to delete transactions and import history, reset configuration, or reset data and settings. Apple’s iCloud controls may also be required to remove synchronised CloudKit data.

A reset may not remove every Keychain credential or remote provider record. Review any prompt offering to restore saved API credentials and separately revoke integrations where required.

19.4 Fineliner account

Account deletion requires device-owner authentication. The app attempts to delete the SnapTrade integration, invokes the Fineliner account-deletion process and clears the local Supabase and biometric sessions.

Deleting your Fineliner account does not automatically delete transactions, journals, portfolio information or settings stored locally or in your iCloud account. Delete that content separately using the relevant app and Apple controls.

19.5 Third-party integrations

Disconnect brokers, delete the SnapTrade integration or identity, revoke Notion access and remove Calendar permissions separately where applicable. Third parties may retain information under their own legal obligations and policies.

20. Your privacy rights

Depending on where you live and the law that applies, you may have rights to:

  • request access to personal information we hold about you;

  • correct inaccurate or incomplete information;

  • request deletion;

  • restrict or object to certain processing;

  • withdraw consent for future processing;

  • receive certain information in a portable format; and

  • complain to an applicable data-protection authority.

These rights may be subject to legal conditions and exceptions. A request concerning data held solely in your private iCloud account may need to be completed by you through the app or Apple’s controls because that information is not part of the separate Fineliner account profile.

To make a request, contact hello@fineliner.co.uk. We may need to verify your identity before acting on a request.

21. Children

Fineliner is intended for adults managing or reviewing their own financial activity. It is not directed to children, and we do not knowingly seek to collect personal information from children. If you believe a child has provided account information to Fineliner, contact us so that the situation can be reviewed under applicable law.

22. Website, external links and third-party content

The Fineliner website and app may link to Apple, brokers, Notion, setup materials, legal documents and other external resources. Fineliner may also display instrument logos supplied through Logo.dev.

We do not control independent websites or services and are not responsible for their privacy practices. Review the terms and privacy notices of any service you choose to use. Normal website-hosting infrastructure may process IP addresses, browser information, request timestamps and security logs even when the website does not ask you to submit a form.

References to Apple, Trading 212, Interactive Brokers, Notion, SnapTrade, Logo.dev or other providers do not imply sponsorship or endorsement unless expressly stated.

23. Changes to this policy

We may update this Privacy Policy when Fineliner, its integrations or legal requirements change. The revised policy will show a new effective date. Where required by law, we will provide additional notice or request consent before materially different processing begins.

24. Contact

Questions, privacy requests and concerns may be sent to:

Filipe Rigolon, developer of Fineliner

Email: hello@fineliner.co.uk

No postal contact address or registered-company identity is stated here because those details were not confirmed in the audited product materials. They should be added before publication if legally required.

Select some of this text to see the custom selection colors.