Fintok policies
Privacy policy
This policy names the information Fintok actually handles when you learn, get graded, pay, or ask for help.
Last updated August 3, 2026
Who this policy covers
BFAN CONSULTING INC, operating the Fintok AI service as Fintok, is responsible for the information described here. This policy covers the Fintok website, course, live model sandbox, placement run, community, and account services.
What Fintok collects
- Account information. Supabase authentication supplies the email address you use to sign in. If you choose to add them, Fintok also stores your name, profile photo, job title or role, company, LinkedIn profile link, and About text.
- Lesson conversations. Fintok stores the full conversation transcript, including what you type, attachment filename information, and the model responses. Keeping the transcript is what lets an active account resume a thread.
- Work and results. Fintok stores your lesson progress, graded submissions, grader feedback, saved asks, and placement results so the course can show what you completed and what level you demonstrated.
- Usage records. Fintok records which units were opened, which steps were graded, whether a graded attempt passed, and model spend assigned to an account or anonymous browser identity. These records are used to operate the course, measure where learners get stuck, and control model costs.
- Billing status. Fintok stores the Stripe customer and subscription status needed to grant paid access. Card details go directly to Stripe and are never stored by Fintok.
Using Fintok without an account
Parts of Fintok work without signing in. Fintok gives that browser a signed random identifier in a protected cookie. It is not a name or an email address, website scripts cannot read it, and editing that cookie or an identifier inside a page or request does not select another learner's records. Fintok does not know who it belongs to unless you sign in while that cookie is still present and your anonymous progress is attached to your account.
Anonymous conversations and related learning records are deleted by an automatic daily database job after 30 days without activity. Clearing cookies removes the identifier from that browser sooner. Without it, Fintok cannot identify or restore the anonymous work while it waits for automatic deletion. Sign in before clearing browser data if you want that work attached to an account.
What happens when you attach a document
The document contents, your message, and the conversation context are sent to Anthropic so its model can read the document and answer or grade the lesson. Do not attach a document unless you are allowed to share it with both Fintok and Anthropic.
Fintok checks the file in memory for the current request. Raw attachment bytes are not written to Fintok's database and are discarded after that request finishes. The record that can remain includes your typed message, the filename and basic file information, the model response, and the conversation transcript. If a later step needs the document again, you must attach it again.
Only upload synthetic, redacted, or authorized documents. Do not upload Social Security numbers, bank information, passwords, privileged legal material, or data you do not have permission to share.
How the information is used
Fintok uses the information above to:
- authenticate accounts and send sign-in email;
- run lesson conversations, generate responses, and grade submissions;
- save progress, restore threads, and produce learner-owned work products;
- show the profile details, weekly learning streak, and reminder settings you choose;
- send an occasional return reminder only when you opt in;
- manage subscriptions and paid access;
- measure course use, reliability, and model spend; and
- answer support, privacy, and legal requests.
Fintok does not sell personal data and does not run advertising.
The services that receive information
Fintok uses five service providers to deliver the product:
- Anthropic receives lesson messages, conversation context, and any document contents attached to that request to generate responses and grade work.
- Supabase handles authentication and stores the application database, including account-linked transcripts, progress, and private profile photos.
- Stripe processes payments. Stripe receives card details directly; Fintok does not.
- Resend delivers authentication, billing, and optional return-reminder email.
- Railway hosts the Fintok application.
Each provider processes information for its stated role and under its own terms and privacy commitments.
Retention and deletion
Account-linked information is kept while the account is active so a learner can resume work and see prior results. The profile page has a permanent account-deletion control. Deleting an account removes its conversations, submissions, placement results, progress, saved work, private profile photo, usage ledgers, public leaderboard entries, billing-access row, and the other Fintok records linked to that account. A limited recurring-payment consent and notice log is the exception: Fintok removes its account identifier and does not store the notice recipient's email in that log. The anonymized proof is kept for the legally required period, then automatically deleted.
Anonymous conversations and related learning records are deleted by a daily database job after 30 days without activity. This limit applies even if the browser identifier still exists.
If the account has a Stripe customer, deletion removes that Stripe customer, stored card details, and active subscription. Stripe can retain limited transaction history where it is required for financial, fraud-prevention, or legal records.
Fintok keeps anonymized recurring-payment consent proof until at least three years after acceptance or one year after the subscription ends, whichever is later. Billing notice delivery logs are kept for three years. Daily database jobs remove each record after its retention period ends.
Your choices and rights
The profile page lets you download a JSON copy of the information linked to your account (including your profile photo), change or stop optional return reminders, or permanently delete the account. Every return reminder also includes an unsubscribe link. You may also ask to access, correct, delete, or export information by emailing support@fintokai.com from the address on the account so Fintok can verify the request.
Changes to this policy
If this policy changes in a material way, Fintok will update the date above and give notice through the service or by email when the change affects account holders.
Contact
Privacy, support, and legal questions all go to support@fintokai.com.
