What we hold, where it sits, who can reach it.
Finche listens to your meetings, so the only useful version of this page is a specific one. Below is what is actually stored, which companies process it, how long it stays, what each permission is for, and where our compliance work genuinely stands today. Where something is still in progress, it says so.
The ten questions people actually ask.
In the order they usually arrive, answered without hedging. Everything here is expanded in the sections that follow.
Who can see my recordings and notes?
Only you. Every table in the database is protected by row level security keyed to your account, and the audio and photo storage buckets are scoped to a folder path that only your account can read or write into. Our servers reach a recording through a separate service credential, and only to transcribe it.
Two deliberate exceptions, both yours to make: a share link you generate yourself, and anything you move into a team folder.
Where is my data stored?
On Supabase, running on Amazon Web Services. Postgres holds the structured data, Supabase Storage holds audio and photos, Supabase Auth holds sign-in credentials. Finche is operated by Hi Finche Pty Ltd, registered in New South Wales, Australia.
If your policy needs the hosting region named in writing, ask us and we will confirm it for your account rather than guess at it here.
Is my data used to train AI models?
No. Finche does not train any model on your content, and has no model of its own to train. Your transcripts are sent to AI providers only to produce the result you asked for, then the result comes back and that is the end of it.
Being precise: we are still completing signed data processing agreements with each AI provider. Until those are in place we will not claim a contractual guarantee on their behalf. Ask us for the current status and we will tell you exactly where it is.
Is the audio itself kept?
Yes, and it is worth being exact about this. The recording is uploaded to private storage so that transcription can run on our servers, and so that an interrupted or crashed recording can be recovered instead of lost. That recovery is the single most valuable thing we do when a two hour meeting goes wrong.
It sits in a folder belonging to your account, readable only by your account, for as long as your account exists. Deleting your account removes it.
What happens when I delete my account?
It runs immediately and it is a hard delete. Google tokens are revoked, your audio and photo folders are emptied object by object, every row keyed to your account is removed, and then the sign-in record itself is deleted.
There is no grace period and no hidden soft-delete flag. If any step fails, the whole operation stops and reports the failure rather than half deleting you.
Can anyone at Finche read my notes?
Nothing in the product gives staff a view of your data. Application access is row scoped, so no ordinary account, ours included, can read your rows.
The honest part: administrative database credentials exist, as they do at every company. Finche is a one person company today, so those are held by the founder alone and there is no separation of duties yet. That is written down as an open risk in our own register, and it changes with the first hire.
Does Finche read my email?
Not unless you connect it. Calendar and contact access carries no mail scope at all. If you choose to connect your inbox, Finche asks for a read-only scope and stores headers and a roughly 1000 character preview per message: subject, sender, recipients, date. Full bodies stay in your mailbox and are never stored by Finche.
What happens if I stop using Finche?
Export everything as JSON from your profile, at any time, without asking us. The export contains your contacts, notes, meeting transcripts, reminders, follow-ups, timeline, drafts, signals and profile. Audio files are not part of the export.
Nothing is deleted for non-payment. On the free plan older history is hidden rather than removed, and it reappears if you upgrade again.
What can other people in the meeting see?
Nothing, unless you send it to them. A share link is something you generate, one note at a time, and the shared page renders the external summary only. Private observations are stripped on the server before that page is built, not hidden with styling.
Does the Mac app watch what I am doing?
It watches for one thing: whether a video call application has started, so it can offer to record. That check happens on your machine, and nothing about it is transmitted or stored.
Recording never begins on its own. The microphone opens when you press record, and not before.
What happens to a recording, step by step.
Five steps, in order, from the microphone to the note on your screen. This is the whole journey.
- Captured on your device and written to local disk first, so a crash or a flat battery cannot lose the conversation.
- Uploaded over TLS into a folder that belongs to your account. No other account can list it, read it or write into it.
- Read by a server function holding a service credential, and passed to ElevenLabs for transcription.
- The transcript goes to Anthropic, which produces the note, the brief and the follow-ups. Text only at this stage, no audio.
- The result lands in Postgres, owner scoped, and your device reads back only its own rows.
How long each thing stays.
Where a fixed period exists, it is a real number taken from the code that enforces it. Where none exists, the row says so rather than implying one.
| Data | Kept for | Notes |
|---|---|---|
| Meeting and voice audio | While the account is active | Private per-account folder. No automatic expiry. Removed when the account is deleted. |
| Transcripts, notes, briefs | While the account is active | You can delete an individual note at any time from any of the apps. |
| Contacts and companies | While the account is active | Editable and deletable one at a time. |
| Connected messages (WhatsApp, LinkedIn, iMessage, email headers) | While the channel is connected | Only from channels you connected. Disconnecting stops new messages; deleting your account removes what was stored. |
| Calendar events | While the calendar is connected | Reading is opt-in. Disconnecting removes the connection and its stored tokens. |
| Company news signals | 14 days | Deleted automatically on a fixed 14 day window, then fetched again only if still relevant. |
| On-device support log | Last 2,500 entries | Rolling file on your own machine. No message content, no transcripts, no tokens. |
| Everything, on deletion | Removed immediately | Synchronous hard delete across storage and database. No grace period. |
Every permission we ask for, and why.
The exact OAuth scopes are printed rather than described, because that is what an IT policy is actually written against. Two of them are write capable, and we would rather you read that here than discover it on a consent screen.
| Permission | Where | What it is for |
|---|---|---|
| Microphone | Mac, iPhone | Records the conversation. Opens on a press of the record button and not before. |
| Screen recording | Mac | macOS routes system audio through this permission, so it is what lets Finche hear the other side of a video call. It is used for audio. |
| Calendar, on the device | iPhone | Off until you switch it on. Reads events from 365 days back to 90 days ahead, so past meetings can be matched to the right people. |
| Contacts, on the device | iPhone | A separate, optional step. The iOS limited access picker is supported, so you can share individual contacts rather than all of them. |
calendar.events |
Read and write on events. Write is used only when you ask Finche to create or move a meeting. | |
contacts.readonly |
Read only, alongside contacts.other.readonly. Names and contact details, to match people to meetings. |
|
Calendars.ReadWrite |
Microsoft | The same read and write on events. Many corporate tenants decline this scope. Finche detects that, leaves the calendar disconnected and carries on without it. |
Contacts.Read |
Microsoft | Read only. Also declined by some tenants, and handled the same way. |
| Optional | Off unless you connect your inbox. Read-only scope; headers and a short preview are stored, never full bodies. | |
| Full Disk Access | Mac, optional | Only if you connect Messages. Lets the app read the Messages database on your Mac, read-only. Nothing else on the disk is touched. |
| Contacts | iPhone, optional | Fills missing phone numbers and emails on contacts you already have. Never creates contacts by itself. |
Every company that touches your data.
The full list, with what each one does and what it actually sees. Several of them see nothing belonging to you at all, and are listed anyway so the list is complete.
| Company | Purpose | What it sees |
|---|---|---|
| Supabase | Database, authentication, file storage, server functions | All customer data |
| Amazon Web Services | The infrastructure Supabase runs on | All customer data, through Supabase |
| ElevenLabs | Speech to text, and the read-aloud voice | Meeting audio |
| Anthropic | Summaries, briefs, follow-ups, the assistant | Transcript and note text |
| Google AI | Alternative model inside the assistant | Transcript and note text |
| Perplexity | Public news and market search | A company name as the search query, nothing else |
| Calendar, contacts, and Gmail, only what you connect | Your calendar events and contacts; if you connect your inbox, message headers and a short preview | |
| Microsoft | Calendar, contacts, and Outlook mail, only what you connect | Your calendar events and contacts; if you connect your inbox, message headers and a short preview |
| Unipile | Messaging channel connections: WhatsApp and LinkedIn | The conversations in channels you choose to connect |
| Resend | Transactional and lifecycle email | Your name, email address, and meeting titles inside those emails |
| Mailgun | Inbound mail forwarded to Finche | Only mail you forward to us |
| Stripe | Payments on web and desktop | Billing details. Finche never sees a card number |
| RevenueCat | iPhone subscriptions | Purchase and entitlement status |
| Apple | App Store distribution and in-app purchase | App and purchase data |
| Cloudflare | Hosting the Mac app download | Nothing. Application binaries only |
| Expo | Mobile builds and over-the-air updates | Nothing. Application bundles only |
| GitHub | Source code hosting | Nothing. Source code only |
Where our compliance work genuinely stands.
A security page is the easiest place in the world to imply a certificate you do not hold. Here is the real state of each item, including the one that is not finished.
-
SOC 2
In progress, not completeOur internal security programme has been written and operating since June 2026: policies, a risk register reviewed quarterly, a vendor inventory, access reviews and a documented system description. The independent audit has not started. We are targeting a Type I report first, then a Type II observation window. There is no SOC 2 report we can hand you today, and we will not imply otherwise.
-
Encryption
In placeTLS on everything in transit. AES-256 at rest, managed by Supabase on AWS key management. Desktop session tokens are encrypted using the operating system keystore.
-
Data isolation
In placeRow level security on every table in the database, storage buckets scoped to a per-account folder path, and all provider API keys held server side, never in an app you download. An external security review in June and July 2026 closed eleven findings, each recorded with its date in our register.
-
Microsoft publisher verification
CompleteThe Microsoft consent screen shows Finche as a verified publisher, so corporate tenants are not being asked to approve an unknown application.
-
GDPR and UK GDPR
HonouredAccess, rectification, erasure, portability, objection and restriction. Email us with the subject line GDPR Request and we will respond within 30 days. Export and deletion are also self-service, so most requests need no one's involvement but yours.
How to evaluate this properly in an afternoon.
If you are assessing Finche on behalf of someone else, this is the shortest honest route to a decision.
- Read the scope table above against your tenant policy. The calendar scope is write capable. If that fails your policy, users can simply leave the calendar disconnected, and every other part of the product still works.
- Trial it with one person for a week, then have that person run the JSON export and read it. It is by far the fastest way to see precisely what is held about them, in their own words.
- Delete that test account and confirm the export no longer returns anything. Deletion is immediate, so this takes a minute rather than a support ticket.
What to ask us for.
Every item below is something we will answer in writing. If the answer is not yet a yes, we will say which one it is.
- The hosting region for your account, named in writing
- The current sub-processor list, plus notice before we add one
- A data processing agreement
- The status of our SOC 2 engagement, and the auditor once one is appointed
- Provider level confirmation of retention and no-training terms
- Our incident response process and notification timelines
- Anything on this page you want evidenced rather than asserted
The work that is not finished.
Publishing this is not a confession, it is the point. A security page with no open items is either very old or not being kept honestly.
- An independent SOC 2 audit. The programme is running, the audit has not begun
- Signed data processing agreements with each AI provider
- A documented restore test against the database backups, with recovery targets written down
- Code signing for the Windows installer, before Windows becomes generally available
- Separation of duties, which arrives with the first hire
Who to talk to.
Sam Newton, founder
Email the address above with the word Vulnerability in the subject line. It reaches a person, not a queue.
Read it, then try it with one person.
Finche is free to download for Mac and iPhone. Export and deletion are self-service from the first day, so nothing about evaluating it needs our permission.