Privacy Policy

Last updated: August 29, 2026

This Privacy Policy explains how data is handled in connection with the use of NovaFin (the “Service”), a personal finance simulator that runs mainly in your browser. It is written in accordance with Ecuador's Organic Law on Personal Data Protection (LOPDP) and its Regulation.

1. Data controller

Controller: Mateo Sebastián Pilco Pérez (a natural person), domiciled in Quito, Ecuador. Contact for privacy matters: soporte@novafin-app.com.

NovaFin does not appoint a Data Protection Officer, as it does not meet the thresholds in Article 47 of the LOPDP. All enquiries are handled at the email above.

2. Guiding principle: your financial data does not leave your device

The information you enter into NovaFin (salary, savings, spending, goals, configuration, transactions) is stored only in your browser's local storage (localStorage), on the device you are using. It is not sent to any Service server or stored in a central database. There are no user accounts and no sign-up process.

You control that data: you can export it as a backup file (JSON), import it on another device, or delete it at any time from within the app or by clearing the site data in your browser.

3. Optional device sync

If you enable sync, NovaFin uploads a copy of your data to a temporary storage service (Upstash) so you can restore it on another device. This copy is uploaded end-to-end encrypted (AES-256-GCM): the encryption key is generated and stays on your devices, and is never transmitted to the server. The Service operator and the storage provider cannot read the contents of that copy; they only see encrypted text tied to a random identifier.

  • Device pairing uses a temporary code that expires after 5 minutes and allows a limited number of attempts.
  • You can turn sync off at any time; doing so removes the sync keys from your device.
  • The feature is optional and off by default.

4. Data that is processed, and why

4.1. Technical operating data (hosting provider)

The Service is hosted on Vercel. Like any website, its infrastructure transiently processes connection data (IP address, browser type, date and time, requested page) in technical logs, in order to deliver the site and ensure its security and availability.

4.2. Aggregated, anonymous usage metrics

We use Vercel Web Analytics and Vercel Speed Insightsto see aggregated traffic and performance metrics (page views, approximate country, load times). These tools use no cookies, do not create a persistent visitor identifier, and do not allow you to be identified.

4.3. Error diagnostics

We use Sentry to detect technical failures. When an error occurs, a report is sent with technical context (error message, stack trace, browser, operating system, page path). These reports do not include the contents of your financial information. The IP address may be processed transiently for abuse prevention and is then discarded or anonymised.

4.4. Fonts

Fonts are served from the Service's own domain (bundled at build time). No requests are made to Google Fonts servers when you visit the site.

4.5. Contact and support form

If you write to us from the form in the Help tab (“Support and suggestions”), we process the data you include: name (optional), email address (optional) and the text of your message, for the sole purpose of reading and answering your request. The email of your request is delivered to the controller's support address via Resend (sending) and Cloudflare Email Routing (forwarding to the controller's inbox). If you don't leave your email, we can't reply. Sending the form is voluntary.

5. Lawful bases (Art. 7 LOPDP)

  • Performance of the relationship / provision of the Service: delivering the site and its features.
  • Legitimate interest: infrastructure security, abuse prevention and error diagnostics, with minimal impact on your rights.
  • Consent: enabling optional device sync, and sending the contact and support form.

6. Recipients and processors

We do not sell or transfer personal data. There is no third-party advertising. The only third parties acting as processors are the providers needed to operate the Service:

  • Vercel Inc. — hosting, CDN and technical logs.
  • Upstash, Inc. — temporary storage of the encrypted sync blob (only if you enable it).
  • Functional Software, Inc. (Sentry) — error telemetry.
  • Resend (Plus Five Five, Inc.) — sending the email generated by the contact form (only if you use it).
  • Cloudflare, Inc. — domain DNS and forwarding of support email to the controller's inbox.

7. International transfers

The providers listed operate servers outside Ecuador (mainly in the United States and the European Union). Those transfers rely on contractual clauses and adequate protection standards required by the providers, and in your case are limited to technical data, to encrypted data the recipient cannot decrypt (sync), or to the data you include in your message (contact form).

8. Retention period

  • Data on your device: kept until you delete it.
  • Sync blob: kept while the feature is active; deleted when you turn it off or when replaced by a newer version.
  • Technical and error logs: kept for each provider's standard periods (usually 30–90 days) and then deleted or anonymised.
  • Contact-form messages: remain in the controller's support inbox for as long as they are useful to handle your enquiry and its follow-up; you can request their deletion at any time.

9. Your rights

As a data subject you have the right to: access, rectification and updating, erasure, objection, cancellation, portability, restriction of processing, and not to be subject to automated decisions with legal effects.

Since most of your data is exclusively on your device, you can directly exercise access, rectification, portability (export) and erasure from within the app. For anything else, or if you need help, write to soporte@novafin-app.com. We will respond within the periods provided by the LOPDP.

If you believe the processing does not comply with the law, you may file a complaint with the Superintendency of Personal Data Protection of Ecuador.

10. Minors

The Service is aimed at adults. It is not designed to collect data from children or adolescents.

11. Security

The site is served over HTTPS. Optional sync uses end-to-end encryption. Even so, no system is infallible: keep backups of your JSON file and protect physical access to your devices.

12. Changes to this Policy

We may update this Policy to reflect changes in the Service or in the law. The “last updated” date indicates the current version. Relevant changes will be communicated within the app where appropriate.