What we collect, why, and how long it lives.
This is the whole policy, in the order it matters. What Finche accesses, what it does with it, every company that processes it, what is never kept, and how to take all of it back. Where a rule is absolute, it says so plainly.
Your Data, Your Control
Your data belongs to you. Finche stores it on your behalf. We do not sell, share, or use it to train AI models.
Overview
Finche is operated by Hi Finche Pty Ltd (ACN 697 488 743) (“we”, “us”, “our”), a company registered in New South Wales, Australia. Finche is a relationship intelligence and productivity application that integrates with your calendar, contacts, and communication tools to help you manage and strengthen professional relationships.
This Privacy Policy explains what information we collect, how we use it, and how we protect it. By using Finche, you agree to the practices described below.
Information We Access
When you connect Finche to Google or Microsoft, we may access:
Calendar Data
- Event titles, times, dates, and attendees
- Event descriptions (if applicable)
This allows Finche to:
- Provide pre-meeting briefings
- Track relationship activity
- Create and modify calendar events when instructed by you
Contacts
Name, email address, phone number, and contact metadata.
Used to identify relationship connections, suggest engagement, and enrich profiles with publicly available professional information.
Voice Notes & Meeting Recordings
When you record a voice note or meeting:
- Audio is processed to generate a text transcript.
- The transcript is used to produce structured summaries, action items, follow-ups, and relationship insights.
- These summaries are stored securely under your account.
Team Data
If you join or create a team within Finche, certain data may be shared with other team members, including:
- Contacts you choose to share with your team
- Meeting notes and action items assigned to team members
- Opportunity signals relevant to the team
You control what is shared. Contacts and notes are only visible to your team when you explicitly share them or move them to a team folder.
Connected Messaging Channels
You can choose to connect messaging channels so your conversations there join the same relationship timeline as your meetings. Every one of these is optional, off by default, and disconnectable at any time:
- WhatsApp and LinkedIn. Connected through Unipile, a messaging infrastructure provider. When you connect a channel, Finche receives your conversations from it: message text, sender names and handles (including phone numbers), and timestamps. Messages are attributed to your existing contacts and stored in your private timeline.
- Messages on Mac (iMessage). With your permission (macOS Full Disk Access), the desktop app reads your Messages history directly on your Mac, read-only, and stores the text of those conversations against your contacts. Nothing else on your disk is read.
- Email (Gmail or Outlook). If you connect your inbox, Finche requests a read-only scope from Google or Microsoft and stores message headers and a short preview only: subject, sender, recipients, date and roughly the first 1000 characters of the message, with quoted replies and signatures stripped out. Full email bodies stay in your mailbox and are not stored by Finche. Email connects directly to your provider — it does not pass through Unipile.
- Apple Contacts. On iPhone, with your permission, Finche can read your address book to fill in missing phone numbers and email addresses on contacts you already have. It never creates new contacts from your address book by itself.
Connected-channel messages are used for the same purposes as your meeting notes: briefings, follow-ups and the relationship timeline. They are never sold, never used for advertising, and never used to train AI models.
Audio Recordings
When you record a voice note or meeting, the audio is uploaded to a private, per-account storage folder that only your account can access, and it is kept there while your account is active. Keeping it is what lets us re-run a transcription that failed, recover a recording after an interruption, and improve a transcript on request — without it, an interrupted recording would simply be lost.
Transcription is performed by ElevenLabs. Audio is sent to ElevenLabs solely to produce the transcript, and ElevenLabs does not retain it after the transcript is returned. Our own stored copy remains in your private folder as described above.
When you delete a recording, or delete your account, the audio is deleted from our storage. Account deletion removes your audio and photo folders object by object — a hard delete, not a flag. The full retention table is on the Security page.
How We Use Your Information
Finche uses your information to:
- Generate pre-meeting briefings
- Suggest follow-ups and action items
- Draft communications (emails, messages)
- Create calendar invites at your direction
- Calculate relationship engagement signals
- Produce daily and weekly relationship summaries
- Surface business opportunities by analysing meeting transcripts and publicly available news about companies your contacts work at
- Read aloud responses using text-to-speech
- Improve relationship visibility and organisation
Finche does not sell your data. Finche does not use your data for advertising.
AI Processing
Finche uses artificial intelligence to:
- Transcribe and summarise voice notes and meetings
- Generate suggested follow-up messages and action items
- Extract structured insights from conversations
- Power the Ask Finche conversational assistant
- Detect business opportunities from meeting transcripts
- Search publicly available news and market information relevant to your contacts’ companies
- Convert text responses to speech for the read-aloud feature
- Evaluate and rate the quality of response suggestions based on your feedback
AI-generated content is produced automatically and may not always be accurate. You are responsible for reviewing any drafted content before sending.
We do not use your personal data to train public AI models.
AI Service Providers
We use the following AI services to deliver core functionality:
Data sent to these providers is processed solely for the purpose of generating your results. These providers do not retain your data or use it for model training.
Audio sent to ElevenLabs for transcription is not stored by ElevenLabs after processing (our own copy stays in your private folder, per section 4). Text sent to ElevenLabs for speech synthesis is not stored after the audio is returned. Text-based prompts sent to Anthropic, Perplexity, and Google AI contain only the data necessary to generate your results and are not used to train their models.
Desktop Application Features
The Finche desktop application includes the following features that interact with your system:
Video Call Detection
Finche monitors running applications and network activity on your computer to detect when you are on a video call (Zoom, Slack, Microsoft Teams, Discord, or Webex). This is used solely to offer to transcribe your meeting. No data about your network activity or running applications is stored or transmitted: detection happens locally on your device.
Global Voice Capture
You may configure a system-wide keyboard shortcut to capture voice notes from any application. When activated, Finche accesses your microphone to record audio, which is then transcribed and processed as described in Sections 3 and 4. The audio is kept in your private storage folder, as described in section 4.
System Audio Capture
During meeting transcription, Finche may capture system audio (with your permission) to transcribe both sides of a conversation. This requires Screen Recording permission on macOS. This audio is handled the same way as any other recording — transcribed, and kept in your private storage folder per section 4.
Opportunity Detection
Finche analyses your meeting transcripts and contact network to surface business opportunities. As part of this feature:
- Meeting transcripts are analysed by AI to identify potential opportunities, introductions, or follow-up actions
- Finche searches publicly available news sources for information about companies your contacts work at, using their company name only
- No private or confidential information about your contacts is shared with external news search providers: only the company name is used as a search query
You can dismiss, save, or act on any opportunity surfaced. Dismissed opportunities are suppressed and will not be shown again.
Data Storage & Security
We implement appropriate technical and organisational safeguards, including:
- Encrypted storage of OAuth tokens
- Secure HTTPS transmission for all data
- Row-level access controls preventing cross-user access
- Restricted server-side token handling
- Encrypted local storage for session data on desktop
All data is isolated per user with row-level access controls: no other user or Finche employee can access your information, except where you have explicitly shared data with a team.
OAuth tokens are stored encrypted and are revoked upon disconnection or account deletion.
OAuth & Third-Party Services
Finche integrates with:
- Google APIs (Contacts, Calendar, and Gmail if you connect your inbox)
- Microsoft Graph API (Contacts, Calendar, and Outlook mail if you connect your inbox)
Finche only requests the minimum permissions necessary to function. Calendar and contact access never includes your email content. If you separately connect your inbox, Finche uses a read-only scope and stores headers and a short preview only, as described in Section 3.
You may disconnect your account at any time from your profile settings.
Google API Services User Data Policy
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
In practice, this means Finche:
- Only uses Google user data to provide and improve user-facing features within the application
- Does not transfer Google user data to others except as necessary to provide or improve user-facing features, comply with applicable law, or as part of a merger, acquisition, or sale of assets with user consent
- Does not use Google user data for serving advertisements
- Does not allow humans to read Google user data unless we have obtained the user’s affirmative agreement, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or the data is aggregated and used for internal operations in accordance with applicable privacy and other laws
- Does not use Google user data to train, develop, or improve generalised or non-personalised AI or machine learning models
Third-Party Service Providers
To deliver our service, we use the following sub-processors:
All sub-processors are contractually prohibited from using your data for their own purposes, including training AI models.
Response Feedback
When you rate a Finche response (thumbs up or thumbs down), the rating and a short excerpt of the response text are stored to improve the quality of future responses for your account. This feedback is not shared with other users or used to train external AI models.
Data Retention
We retain data only as long as your account remains active.
If you delete your account:
- OAuth tokens are revoked
- Stored notes, transcripts, and action items are deleted
- Contact data is removed
- Calendar connection data is removed
- Meeting transcripts are deleted
- Connected-channel messages (WhatsApp, LinkedIn, iMessage) and email headers are deleted, and channel connections are severed
- Opportunity signals are deleted
- Chat history and feedback are deleted
- Team memberships are removed
- All other personal data is permanently erased
Deletion is permanent. We do not retain backups of deleted user data.
Your Rights
You may:
- Disconnect integrations at any time
- Export all your data
- Request account deletion
- Access, modify, or delete your stored data
- Control what data is shared with your team
- Opt out of opportunity detection
To request deletion, contact: support@finche.app
EU/UK Data Subject Rights
If you are located in the EU or UK, you have the following rights under GDPR/UK GDPR:
- Right of access: request a copy of your personal data
- Right to rectification: correct inaccurate personal data
- Right to erasure: request deletion of your personal data
- Right to data portability: receive your data in a machine-readable format
- Right to object: object to processing of your personal data
- Right to restriction: request restriction of processing
- Right to lodge a complaint with a supervisory authority
To exercise these rights, email support@finche.app with subject line “GDPR Request”. We will respond within 30 days.
Children’s Data
Finche is not intended for use by anyone under the age of 16. We do not knowingly collect personal data from children.
If we become aware that we have collected personal data from a child under 16, we will take steps to delete that data promptly.
Cookies
Finche uses essential cookies only for authentication and session management. We do not use advertising cookies, tracking pixels, or third-party analytics cookies.
Changes to This Policy
We may update this Privacy Policy periodically.
The “Last Updated” date reflects the most recent revision. Material changes will be communicated via in-app notification or email.
Your data, and the door out.
Export everything as JSON from your profile settings, and delete your account and all of its data in one tap. Neither needs our permission, and we keep no copies afterwards.