Legal
Privacy Policy
Last updated October 6, 2026
The English version of this document is the controlling version. Other languages are provided for convenience only.
This Privacy Policy explains how Finro (“Finro,” “we,” “us,” or “our”), operated for DriftTrail, handles information when you visit finro.si, upload files, purchase a report, contact support, or otherwise use the Finro service. Please read it in full. If you do not agree, do not use the service.
Finro is a pay-per-report document compiler. It is not an accounting platform, customer relationship system, bookkeeping subscription, or permanent archive of your books. We do not create user accounts for the ordinary report workflow, we do not operate a standing customer financial ledger, and we do not intend to keep your source documents after a paid report has been generated.
The English version of this Policy is the controlling version. Any translation of the interface is provided only for convenience and does not change the legal meaning of this document.
1. Who we are and how to contact us
Privacy, data-protection, and support requests should be sent to support@driftrail.com. Please do not send passwords, full payment-card numbers, government identity documents, or unnecessary copies of complete ledgers to that address unless we specifically request them to complete a verified support request.
If you write to us, we will use the contents of your message, your email address, and any attachments you choose to include solely to respond, to diagnose a problem, and to keep a limited support record.
2. Scope
This Policy covers the public website, the report-creation workflow, payment confirmation pages, support correspondence, and ordinary operational logs needed to run a commercial website. It does not cover independent websites or services that we may link to, including payment processors and independent model providers. Those parties publish their own policies. You should read them.
This Policy applies whether you are a visitor, a paying customer, a person whose details appear inside a file someone else uploads, or a correspondent writing to support.
3. What we mean by “we do not collect data”
Finro is built so that we do not maintain a standing customer database of your financial records. We do not require an account for the basic flow. We do not store a permanent library of your ledgers, invoices, receipts, or compiled reports on an ongoing customer profile. We do not sell lists of customers. We do not build advertising profiles from your books.
That statement is not a claim that no information is processed at all. Completing a paid report necessarily involves short-lived processing of the files you choose to submit, limited payment confirmation data from our payment provider, language and preference settings stored in your browser, and ordinary security, abuse-prevention, and diagnostic records. The design goal is minimization, transience, and deletion after the job is done. Completing the work still requires the service to handle the inputs you provide for that moment.
4. Categories of information that may be processed
Depending on how you use Finro, the following categories may be processed:
- Source files you attach, which may include bank statements, spreadsheets, invoices, receipts, images, correspondence, and similar financial documents, plus filenames, file sizes, and file types.
- Report preferences you select, such as report type, mapping framework, currency, period, entity type, and language.
- Payment confirmation and transaction identifiers provided by our payment processor, such as the fact of payment, amount, currency, time, and a checkout or session reference. We do not ourselves store full payment-card numbers.
- Short-lived job identifiers used to associate files you upload after payment with the report you purchased.
- Browser-stored items, including a language preference and, where needed to survive checkout, temporary local copies of files you already selected. Those local copies are intended to expire.
- Support emails and the limited records needed to answer them.
- Ordinary technical logs such as IP address, browser type, date and time of a request, referring URL, and coarse location inferred from IP, used for security, abuse prevention, and diagnosing failures.
Source files often contain personal data of third parties: payees, employees, customers, vendors, or account holders. You are responsible for having a lawful basis to submit that information.
5. How a report is created
When you pay for a report and submit files, Finro performs a bounded processing job. Structured tables are parsed directly. Visual or unstructured documents may be interpreted by an automated language model so that figures, dates, accounts, and descriptions can be extracted and mapped into a canonical report model. Totals, checks, and calculations are then applied in application code.
Temporary private objects may be used so that files can move from your browser to the processing job after payment. Access is intended to be short-lived. After generation succeeds, or after a short expiry if the job is abandoned, those temporary inputs are intended to be deleted. Finro is not a document-retention product. If you need an archive, keep your own copies.
Generated reports and exports are made available in the active browser session. We do not operate a login-based report library. If you close the session without downloading, we do not promise that the report will remain retrievable from Finro.
6. Payment information
Payments are handled by an independent payment processor. Card details, wallet credentials, and bank-account information used to pay are collected by that processor on its own pages or components, subject to its own terms and privacy policy. Finro receives confirmation that a payment succeeded or failed, and limited identifiers needed to unlock the corresponding report job and to keep commercial records required for accounting, tax, chargebacks, and fraud review.
We do not use payment data to profile your finances. We may refuse, delay, or reverse access where a payment is disputed, flagged, or required to be returned.
7. Cookies, local storage, and similar technologies
Finro uses a small amount of client-side storage so the product can function. This may include:
- a language preference saved in local storage;
- temporary browser storage of files you selected so they can be uploaded after you return from checkout;
- cookies or similar tokens that a payment processor, content delivery, or hosting provider may set to complete a transaction or protect the service.
We do not use third-party advertising cookies to follow you around the web, and we do not sell browsing history. You can clear browser storage at any time; doing so may remove a language preference or an unfinished checkout package.
8. Purposes of processing
We process information to:
- provide, operate, secure, and improve the Finro service;
- create the report you paid for and deliver exports;
- prevent fraud, abuse, prompt-injection, and security incidents;
- comply with law, including tax, accounting, and lawful requests;
- respond to support requests and service complaints;
- enforce the Terms of Service; and
- establish, exercise, or defend legal claims.
We do not use the contents of your financial files to train a public marketing model for Finro, to sell advertising, or to build a secondary dossier about your business. Independent providers that help interpret documents publish their own rules about how they process inputs; see the independent-provider section at the end of this Policy.
9. Legal bases (EEA, UK, and similar regimes)
Where a legal basis is required, we rely on:
- Contract: processing needed to deliver the report you purchase, including temporary hosting, interpretation, calculation, and export.
- Legitimate interests: operating a secure website, preventing abuse, keeping minimal diagnostic logs, and answering support mail, balanced against your rights.
- Legal obligation: retaining limited payment and tax records, and responding to lawful demands.
- Consent: where a specific optional technology requires it, or where you email us information we did not request.
You may object to processing based on legitimate interests by writing to support@driftrail.com. Some objections cannot be honored if they would prevent us from providing a paid job, securing the service, or meeting a legal duty.
10. Sharing
We do not sell your financial files. We do not share source documents with unrelated third parties for their independent marketing. We may disclose information:
- to vendors that host the website, transmit files, process payments, provide security, or help interpret unstructured documents, each acting on instructions or under their own independent terms as applicable;
- to professional advisers under confidentiality duties;
- if we believe disclosure is required by law, regulation, legal process, or to protect the rights, safety, or property of Finro, users, or the public;
- in connection with a merger, acquisition, or reorganization, in which case this Policy will still govern or a successor will provide notice.
Independent providers are not Finro. Their processing is governed by their documents, which may allow uses we do not ourselves perform.
11. Retention
Source files and intermediate extraction objects are intended to exist only for the life of the paid job plus a short safety window, then to be deleted. Browser-side checkout copies are intended to expire after about one hour. Report outputs remain in your session until you leave or the session ends.
We may retain longer: payment confirmations and invoices needed for tax and accounting; records of abuse, chargebacks, or legal holds; and support correspondence. When we no longer need a record, we delete or irreversibly de-identify it. Residual copies may remain in encrypted backups for a limited rotation period.
We cannot retrieve a deleted job for you later. Keep your own downloads.
12. Security
We use administrative, technical, and organizational measures appropriate to a lightweight document-processing service, including encrypted transport, access controls, isolation of untrusted document text from application instructions, and validation of machine output before calculations run. No method of transmission or storage is perfectly secure. You remain responsible for the device, browser, and network you use.
Do not upload files that contain secrets you are unwilling to transmit, such as private keys, live production passwords, or unrestricted identity-document scans, unless those materials are strictly required for the report and you accept the residual risk.
13. International transfers
Finro may be accessed from many countries. Providers that help us operate the service may process information in the United States and other jurisdictions. Where required, we rely on appropriate transfer mechanisms used by those providers, such as contractual clauses they offer to customers. By using the service from outside those jurisdictions, you understand that your files may be processed abroad for the limited purposes in this Policy.
14. Children
Finro is intended for business and professional use by adults. It is not directed to children, and we do not knowingly process children’s financial information. If you believe a child has submitted data, write to support@driftrail.com and we will take reasonable steps to delete residual records we can locate.
15. Your rights
Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, or portability, to withdraw consent where processing is based on consent, and to lodge a complaint with a supervisory authority. Because Finro does not keep a standing customer ledger, we may need information from you to locate any residual records, such as a payment receipt, approximate time of use, or the email used for support. Submit requests to support@driftrail.com. We may need to verify that the request comes from the relevant person.
We will not discriminate against you for exercising privacy rights. Some rights have exceptions, including where we must keep a record for law, security, or the establishment of legal claims.
16. Additional notice for California and similar US state laws
We do not sell personal information as “sale” is commonly understood in an advertising-exchange sense, and we do not share personal information for cross-context behavioral advertising. We do not use sensitive financial-file contents to infer characteristics for advertising. Categories that may be processed are described above. To exercise access, deletion, or correction rights, email support@driftrail.com. We will not require you to create an account to make a request. Authorized-agent requests must include proof of authorization.
17. Automated processing
Finro uses automated interpretation to classify and extract figures from documents you upload. The output is a management-reporting aid. It is not an audit, tax filing, legal opinion, credit decision, or solely automated decision producing legal effects about you as an individual. You must review mappings, warnings, and source quality before relying on a report. Low-confidence items are flagged for human review precisely because automation is imperfect.
18. Third-party sites
The site may link to independent pages, including payment pages and provider policies. Their content and practices are outside Finro’s control. This Policy does not govern them.
19. Data incidents
If we become aware of a security incident affecting personal data we still hold, we will take steps we reasonably consider appropriate, including containment, assessment, and, where required by law, notice to regulators and affected persons. Because jobs are designed to be short-lived, the window in which source files remain retrievable is intended to be narrow.
20. Changes
We may update this Policy from time to time. The “Last updated” date will change when we do. Material changes will be posted on this page. Continued use after an update constitutes acceptance of the revised Policy. If you do not agree, discontinue use and do not upload further files.
21. Independent Google and Gemini terms
Unstructured documents and images submitted for interpretation may be processed by Google Gemini. Google’s own privacy and terms documents apply to Google’s processing and may change independently of Finro. Finro does not control Google’s independent practices. Please review the following, which are incorporated here by reference as they apply to that processing:
- Google Privacy Policy
- Google Terms of Service
- Gemini API Additional Terms of Service
- Google Generative AI Prohibited Use Policy
Questions about Finro’s handling of information should still be sent to support@driftrail.com. Questions about Google’s independent practices should be directed to Google through the mechanisms in those documents.