Honest privacy. Your data stays yours.
Financial records are sensitive information. We treat them that way β in writing, not just in marketing.
Fugio makes money from subscriptions (coming soon), never from selling your data. This policy explains what we collect, why, how it is protected, and how you can leave.
1. Accountability
The privacy officer for Fugio is reachable at privacy@fugio.io and is responsible for this policy, for answering your requests, and for the safeguards described below. If you are in a jurisdiction with specific privacy legislation (for example PIPEDA in Canada or the GDPR in the EU), write to that address and we will respond under the applicable framework.
2. What we collect
- Account data: username and a hashed password; optionally an email or contact handle you provide with an invite request.
- Financial data you choose to save: accounts, schedules, budgets, debts, transactions, simulations and tool scenarios. You enter this data; we do not fetch it from banks or other institutions.
- Operational logs: minimal server logs (timestamps, request paths, error traces) needed to keep the service running. Logs do not include balances or transaction details.
3. Why we collect it
To run the service you asked for: storing your household model, computing projections and simulations, and keeping an audit trail of changes. As we grow, we may analyze aggregate usage or optional demographic inputs (like location) to offer relevant partner services β our business model is subscription-first, and we will be transparent about any new features or data partnerships before they launch.
4. How it is protected
- Encryption in transit (TLS) on every connection.
- Encrypted at rest for sensitive fields (credentials you connect, such as assistant or messaging tokens), and database-level protection for everything else.
- Per-user data isolation: every record is scoped to your account.
- An append-only, revert-not-delete ledger for financial history: changes are recorded as compensating entries rather than silent rewrites, so your history cannot be quietly altered β by you, by us, or by a bug.
- Restore-tested backups on managed cloud infrastructure (Google Cloud, us-central1). A backup we have never restored is a hypothesis; ours are exercised.
5. Where it lives
Production data is hosted on Google Cloud Platform in the us-central1 region (United States). We state this plainly rather than implying local residency anywhere else. During the invite beta, a small number of accounts exist; scale and additional regions are decisions we will publish here when they happen.
6. Consent, access and erasure
You control your data. You can export your view of it inside the app, and you can request erasure at any time by writing to privacy@fugio.io β we will delete your account and associated financial records, retaining only what law requires (audit entries needed to explain past ledger operations may be retained in anonymized form). Invite requests you submit from this website are reviewed manually and deleted once decided or after twelve months, whichever comes first.
7. Retention
- Account and financial data: until you request erasure or close your account.
- Invite requests: until decided, then removed; undecided requests expire after 12 months.
- Operational logs: rotated out within 30 days.
- Backups: rolling window of 30 days.
8. Children
Fugio is intended for adults managing household finances. We do not knowingly collect data from children.
9. Analytics
We use Google Analytics 4 (GA4) and Google Tag Manager to measure how visitors find and use our services β including pages viewed, features used, and invite requests submitted. Google processes this data under its own terms. Analytics help us understand product usage and improve the application; we configure these tools to respect the sensitive nature of financial usage patterns.
10. Changes to this policy
Material changes will be announced in-app and dated here. Last updated: 2026-09-20.