Fyxi

Legal · Español

Privacy Policy

Last updated: July 2026

Two-line summary. Your financial data is yours. We don't sell it. We don't use it to train AI models. Everything goes over HTTPS. You can export or request deletion at any time. If you live in California, you have additional rights explained on the California page.

1. Who is responsible for your data

The controller of your personal data under this Policy is Fyxi LLC, a limited liability company formed under the laws of the State of California, United States (California Filing #B20260341393), with registered office at 2108 N ST STE N, Sacramento, CA 95816 (“Fyxi”, “we”, or “the Service”). For privacy matters you may write to privacy@fyxi.ai.

When you use Fyxi as part of a company workspace, that company (the workspace owner) may be considered the “data controller” of the information uploaded or managed through the Service, and Fyxi acts as “processor” on its behalf. For Business plan customers we sign a separate Data Processing Agreement (DPA) upon request.

2. What information we collect

Account information. Email, name, password (hashed with bcrypt), or your Google identity if you sign in with OAuth. Language and notification preferences.

Workspace and business information. Business name, physical address in the United States, city, state (USPS), ZIP, business phone in E.164 format, chart of accounts, cost centers, custom tax categories, vendors you upload (including tax IDs if you enter them voluntarily), invited members (their email and assigned role).

Receipts and extracted data. Images and PDFs of receipts you upload via Web or WhatsApp; and fields extracted by AI from those images: vendor, date, total amount, per-item amount, taxes, payment method, suggested category, business or personal tag, notes, and a reference hash copy.

WhatsApp linking data. If you enable the WhatsApp integration, we store your phone number in E.164 format associated with your workspace, plus metadata about the last message processed. We do not read your conversations outside the receipt sandbox.

Bank data (if you use reconciliation). Rows from your bank statement in CSV that you manually upload: date, merchant description, amount. We do not connect directly with your bank in the current version of the Service. When we integrate Plaid or another provider, we will update this Policy and request your explicit authorization.

Usage data. Which pages you visit, which features you use, access time, device type, browser, truncated IP address (for privacy), and technical errors that occur. We use this data to operate and improve the Service.

Payment information. Processed by Stripe, Inc. Fyxi does not see or store your full card number. We only store a Stripe customer identifier, the brand (Visa/Mastercard), last 4 digits, and the status of your subscription (active, canceled, paused).

Support communications. Emails you send us, support tickets, chat messages if we enable them.

We do not collect special categories of personal data (race, ethnic origin, political opinions, religious beliefs, sexual orientation, union information, genetic, biometric, or health data) nor information about criminal convictions.

3. How we use your information

We use your data for the following purposes:

  • Operate the Service: extract receipt data, categorize, display reports, generate exports, run reconciliation, send suggestions.
  • Authentication and security: keep your session logged in, verify your identity, detect anomalous access, prevent fraud and abuse.
  • Operational communications: welcome emails, account verification, password reset, notifications of pending approvals, workspace invitations, weekly retention intelligence digest (if you are subscribed), relevant legal notices.
  • Billing: process your subscription through Stripe and respond to billing questions.
  • Legal compliance: respond to court orders, subpoenas, or requests from competent authorities (IRS, state agencies, courts).
  • Improve the Service: aggregated and non-identifiable analytics on feature usage. We do not use Your Content to train our own or third-party AI models.
  • Marketing communications: only if you explicitly accepted to receive them. You can unsubscribe at any time from each email.

4. Legal bases for processing

When applicable law requires a legal basis to process your personal data, we rely on:

  • Performance of a contract: to provide you the Service you contracted.
  • Legitimate interest: for security, fraud prevention, product improvement, and necessary administrative communications.
  • Consent: for marketing communications and optional integrations (for example, when automatic bank connection is enabled).
  • Legal obligation: when law or a competent authority requires us to process or disclose data.

5. Sub-processors

To operate the Service we rely on external providers that act as sub-processors. The updated list, with purpose, processing location, and link to each one's policy, is on the Sub-processors page. We update that list when we add or remove providers. Business plan customers may request proactive email notification of changes to the list.

6. How we protect your data

We apply reasonable technical and organizational measures, including:

  • All communications between your device and our servers go encrypted via HTTPS/TLS 1.2 or higher.
  • Receipt images and PDFs are stored in private Cloudflare R2 buckets, accessible only via short-lived signed URLs.
  • Passwords are stored hashed with bcrypt (via Better Auth). We never store passwords in plaintext.
  • Access to the Convex backend is restricted by authenticated session and by role within the workspace.
  • Each workspace is isolated: members of a workspace never see data from other workspaces under any circumstance.
  • We log sensitive access and actions in an internal audit log.
  • Fyxi team internal access to production data is limited by role, logged, and used only for technical support or legal compliance.

More details about our controls on the Security page.

Breach notification. If we detect a security breach affecting your personal data, we will notify you by email within 72 hours of the incident confirmation, as required by applicable laws, including California's ( California Civil Code § 1798.29).

7. Data retention

We retain your data according to the following timelines:

  • Active account: while your account is active and in use.
  • After canceling your account: 90 days grace to download your data from the Export section. After those 90 days, operational data (images, receipts, categories, reports) is irreversibly deleted.
  • Operational backups: may persist up to 30 additional days after deletion, for operational security, before being overwritten.
  • Data required by law: financial information related to Stripe transactions may be retained up to 7 years to comply with tax and audit obligations in the United States.
  • Audit logs: may be retained up to 2 years for security incident investigation.

8. Your general rights

Regardless of where you live, you have the right to:

  • Access the information we hold about you (most is visible directly in your Panel and Settings).
  • Correct any inaccurate data (editable from the application).
  • Export your data in CSV or PDF from the Export section.
  • Delete your account and workspace at any time (Settings → Business → Danger zone).
  • Withdraw consent to marketing communications at any time.
  • File a complaint with the data protection authority in your jurisdiction.

If you need something you cannot do from the app, write to privacy@fyxi.ai. We will respond within 30 days.

9. Specific rights for California residents

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). Those rights, how to exercise them, and our commitment to non-discrimination for exercising them are explained in detail on the California Privacy Rights page.

Fyxi does not sell or share your personal data with third parties for targeted advertising, and does not exchange data for money or value. If in the future this changes, we will update this policy and give you clear notice with the corresponding opt-out mechanism.

10. Cookies and tracking technologies

We use minimal cookies and local storage, all strictly necessary for Service operation:

  • Session: to keep you authenticated while using Fyxi.
  • Preferences: to remember filters you applied, active workspace, and language preferences.
  • Security (CSRF): to prevent cross-site request forgery attacks.

We do not use advertising tracking cookies, we do not share advertising identifiers with third parties, and we do not sell usage data. If we ever add analytics (for example, Sentry for error monitoring or PostHog for product analytics), we will update this section and give you control over those cookies.

Do Not Track. Due to the lack of a universal standard for processing browser “Do Not Track” signals, we currently do not respond to those signals in a differentiated way. However, we respect Global Privacy Control (GPC) requests for California residents as a valid opt-out under CPRA.

11. International transfers

Our main sub-processors operate in the United States. Some, like Cloudflare, may distribute data globally for performance and availability reasons. If in the future we have users in the European Union or United Kingdom, we will implement corresponding safeguards (European Commission Standard Contractual Clauses, or equivalent mechanisms).

12. Minors

The Service is intended for people over 18 years of age who operate a business. It is not intended for minors. We do not knowingly collect personal information from children under 13 under the Children's Online Privacy Protection Act (COPPA). If we discover that a user is a minor, we will close the account and delete associated data. If you suspect a minor has created an account, notify us at privacy@fyxi.ai.

13. Changes to this policy

We may update this Policy occasionally. If there are material changes, we will notify you by email at least 30 days in advance and update the “Last updated” date at the top of this page. Minor changes (typographical corrections, link updates) may be applied without individual notification.

14. Contact

For questions about privacy, exercise of rights, or incidents: privacy@fyxi.ai. For general support: support@fyxi.ai. For legal matters: legal@fyxi.ai.

Legal entity: Fyxi LLC · California Filing #B20260341393
Registered address: 2108 N ST STE N, Sacramento, CA 95816, United States

Legal review status. This document was drafted by the Fyxi team taking as reference common practices of financial SaaS services in the United States and general CCPA/CPRA requirements. It is pending audit by a California-licensed attorney. If you notice any omission or ambiguity, write to privacy@fyxi.ai.