Privacy Policy
Last updated: 11 August 2026
This Privacy Policy explains what personal data Finoha collects, why, who it is shared with, and what rights you have. It applies to finoha.net, the Finoha web application, and our support channels.
1. Who is responsible for your data
| Role | Company |
|---|---|
| Seller / Merchant of Record — your counterparty for subscriptions and payments | Alvin AI Studio LLC, 447 Broadway, 2nd Floor, Suite 3007, New York, NY 10013, United States |
| Technical Provider / Processor — develops, operates and technically supports the platform | RİSER YAZILIM REKLAM TEKNOLOJİLERİ ARAŞTIRMA GELİŞTİRME VE PAZARLAMA TİCARET ANONİM ŞİRKETİ, İçerenköy Mah. Topçu İbrahim Sk. Quick Tower No:8-10D, Ataşehir / İstanbul, Türkiye |
Because our technical team is in Türkiye, personal data is accessed from Türkiye as well as the United States. See Section 7 on international transfers.
Privacy contact: info@finoha.net
2. A note before we start: your account can begin anonymously
Finoha creates an account for you automatically when you first open the app, so you can start learning without giving us anything. At that point we hold a randomly generated account identifier and your learning progress — no name, no email address.
Your account becomes identifiable only when you choose to add an email address or make a purchase. Until then, that progress lives only on the device and browser you are using.
3. What we collect
3.1 Data you give us
| Data | When |
|---|---|
| Email address | When you add one to secure or restore your account, or when you subscribe |
| Support correspondence | When you contact info@finoha.net |
| Messages you type into the AI features | When you use the AI explainer or the in-app explainer character |
| Survey, quiz and onboarding answers | When you complete our pre-purchase questionnaire |
We do not collect your name, postal address, date of birth, government ID, financial account numbers, or brokerage information, because the Service does not need them.
We never collect or store your payment card details. Card data goes directly to Stripe. We receive only a payment status, a subscription state, and limited billing metadata (such as the last four digits, card brand, country, and expiry).
3.2 Data generated by your use of the Service
- Learning and simulator activity: lessons completed, quiz answers and scores, streaks, XP, day progress, simulated trades, simulated portfolio and balances, coin and credit transactions, leaderboard position.
- Account and subscription state: plan, status, renewal date, credit balance.
- Technical data: IP address, browser type and version, device and operating system, language, timestamps, referring page, and error/diagnostic logs.
3.3 Data we do not collect
We do not collect precise geolocation, contacts, microphone or camera data, health data, biometric data, or the special categories of data defined in Article 9 GDPR. Please do not send them to us, including through the AI features.
4. Why we use it, and our legal basis
| Purpose | Legal basis (GDPR / UK GDPR) |
|---|---|
| Create and maintain your account; deliver lessons and the simulator; save progress across devices | Performance of a contract |
| Process subscriptions, payments, renewals and refunds | Performance of a contract |
| Generate AI explanations you request | Performance of a contract |
| Provide customer support | Performance of a contract; legitimate interests |
| Keep the Service secure; prevent fraud, abuse, and multi-account exploitation; enforce usage limits | Legitimate interests |
| Diagnose faults, monitor performance and improve the product | Legitimate interests |
| Send service and transactional messages (confirmations, renewal and price-change notices, security alerts) | Performance of a contract; legal obligation |
| Send marketing emails about Finoha | Consent, or legitimate interests where permitted — you can opt out at any time |
| Keep accounting, tax and transaction records | Legal obligation |
| Establish, exercise or defend legal claims | Legitimate interests; legal obligation |
Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights. You may object — see Section 9.
We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
5. Who we share it with
We share personal data only with the service providers below, only for the purposes described, and under contracts requiring them to protect it.
5.1 Providers that process data on our instructions
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, server functions | Account ID, email, progress, simulator and credit data |
| Google Cloud Platform | Application hosting and delivery | Technical data, IP address, request logs |
| Stripe | Payment processing, subscription billing | Email, payment and subscription metadata (card data goes to Stripe, not to us) |
| web2wave | Pre-purchase questionnaire and checkout funnel | Questionnaire answers, email, purchase events |
| OpenRouter, and through it Google (Gemini models) | Generating AI explanations and explainer responses | The text of your prompt and the surrounding in-app context, sent from our servers |
| Email delivery provider | Sending confirmation, sign-in and service emails | Email address, message content |
5.2 Third parties your browser contacts directly
These services are called by your browser, not by our servers. That means they can see your IP address, approximate location, and browser characteristics independently of us, under their own privacy policies. We do not send them your account identity.
| Service | Why | What it sees |
|---|---|---|
| Finnhub | Live stock prices | Your IP address and the symbol requested |
| Binance (public market-data API) | Live cryptoasset prices | Your IP address and the symbol requested |
| TradingView | Embedded price chart | Your IP address, browser data, and cookies it sets |
5.3 Other disclosures
We may disclose personal data where necessary to comply with law or a valid legal request; to enforce our Terms; to detect or prevent fraud, security or technical issues; to protect the rights, property or safety of anyone; and, in connection with a merger, acquisition, financing or sale of assets, to the counterparty, subject to this Policy.
6. About the AI features specifically
We want to be direct about this, because it is the least obvious data flow in the product.
When you use an AI explanation or send a message to the in-app explainer, the text you write is transmitted from our servers to OpenRouter and on to the underlying model provider (currently Google) to generate a response. The request goes through our backend, so the AI provider does not receive your IP address or your account identity — but it does receive your message.
We may retain the exchange to provide the feature, to account for credit usage, to debug, and to prevent abuse. We do not use your conversations to train our own models, and we instruct our providers not to use them to train theirs. However, we cannot guarantee the internal practices of every upstream provider.
Do not type confidential information, sensitive personal data, credentials, or payment details into the AI features.
7. International transfers
We operate from the United States, our technical provider operates from Türkiye, and our service providers operate in the United States, the European Union, and elsewhere. Using Finoha therefore involves transferring your personal data across borders, including to countries that may not provide the same level of protection as your own.
Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards, principally the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable), together with supplementary technical and organisational measures. You may request a copy of the relevant safeguards from info@finoha.net.
8. How long we keep it
| Data | Retention |
|---|---|
| Account, progress and simulator data | While your account is active, then up to 12 months after it becomes inactive or is closed |
| Email address and subscription state | While your account is active, then as needed for legal and accounting purposes |
| Payment and transaction records | Up to 10 years, as required by tax and accounting law |
| AI conversations | Up to 12 months, for support, abuse prevention and credit accounting |
| Support correspondence | Up to 3 years after the matter is closed |
| Security and diagnostic logs | Typically up to 12 months |
When a retention period ends we delete the data or irreversibly anonymise it. Anonymised or aggregated data, which can no longer identify you, may be kept indefinitely.
9. Your rights
Subject to the law that applies to you, you can ask us to:
- access the personal data we hold about you, and receive a copy;
- correct data that is inaccurate or incomplete;
- delete your data ("right to erasure");
- restrict or object to processing, including processing based on legitimate interests, and object to direct marketing at any time;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, without affecting processing already carried out;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions.
How to exercise them: email info@finoha.net. We will respond within 30 days (or one month under GDPR/UK GDPR, extendable where permitted). We may need to verify your identity first. Exercising these rights is free; we may charge a reasonable fee or refuse a request that is manifestly unfounded or excessive.
One practical note: if your account is still anonymous, we may be unable to locate your data from an email alone, because there is nothing linking that email to the account. In that case, send us the account ID shown in the app under Settings.
Complaints. You may lodge a complaint with your local supervisory authority — in the EU, your national data protection authority; in the UK, the Information Commissioner's Office; in Türkiye, the Personal Data Protection Authority (KVKK Kurumu). We would appreciate the chance to address your concern first.
9.1 If you are in the United States
Depending on your state, you may have the right to know, delete, correct, and obtain a portable copy of your personal information, and to appeal a refusal. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is no opt-out to exercise. We will not discriminate against you for exercising your rights. Use info@finoha.net.
9.2 If you are in Türkiye
You have the rights set out in Article 11 of Law No. 6698 on the Protection of Personal Data (KVKK), including learning whether your data is processed, requesting information about the processing, requesting correction or erasure, and claiming compensation for damage caused by unlawful processing. Requests go to info@finoha.net.
10. Cookies and similar technologies
Finoha uses:
- Strictly necessary storage — local storage and cookies that keep you signed in, hold your session and preferences, and preserve your progress. The Service does not work without these.
- Third-party cookies from the embedded TradingView chart, set by TradingView under its own policy.
- Analytics used to understand aggregate usage and improve the product, where enabled.
Where required by law, we ask for your consent before setting non-essential cookies, and you can change your choice at any time through the cookie settings on the site. You can also block or delete cookies in your browser, though the Service may not function correctly if you block essential ones.
11. Security
We use TLS encryption in transit, encryption at rest with our infrastructure providers, row-level access controls in the database, restricted staff access on a need-to-know basis, and server-side handling of secrets so that sensitive keys are never exposed to your browser.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach occurs that is likely to result in a risk to your rights, we will notify you and the relevant regulator as required by law.
12. Children
Finoha is for adults. It is not directed to anyone under 18, and we do not knowingly collect personal data from anyone under 18. If you believe a minor has given us personal data, contact info@finoha.net and we will delete it.
13. Changes to this Policy
We may update this Policy. We will change the "Last updated" date above and, for material changes, notify you by email or in-app before they take effect.
14. Contact
Questions, requests, or complaints about privacy: