Finch respects your privacy. We design our products around local-first operation, data minimization, and user control. This policy applies to the Finch desktop app, the official Finch website, and related services provided by Finch.
By using Finch, you acknowledge that you have read this policy. Where a feature involves a third-party service, that service's privacy policy also applies.
1. Information We Process
Website Usage Data
When you visit the official Finch website, our hosting, content delivery, and security providers may automatically process the technical information needed to serve your visit, such as your IP address, browser type, device type, access time, requested path, and error logs. We use this information primarily to provide the website, maintain security, troubleshoot issues, and prevent abuse.
Information You Provide
When you contact us through email, GitHub, or another public channel, we process the contact details, issue descriptions, feedback, and attachments you choose to send so that we can respond and resolve the matter. Please do not include unnecessary passwords, API keys, access tokens, or other sensitive information in your feedback.
Local Data in the Finch Desktop App
Finch stores data required for its operation on your device, including settings, sessions, Spaces, drafts, memories, logs, and file paths you choose to associate with the app. This local content is not automatically uploaded to us merely because you use Finch, unless you choose to use an internet-connected feature, select a third-party model or service, or explicitly send, upload, sync, or otherwise transfer it.
Data Processed by Models, Tools, and Mini Tools
When you connect a third-party model, MCP service, tool, or mini tool, Finch sends the prompts, context, file content, or tool parameters needed to complete the task to that service in accordance with your actions. The scope of any transfer depends on the capabilities you enable, permissions you grant, and the task at hand.
Third-party services process this data under their own terms. Before enabling one, review the provider, permission scope, intended data use, and retention practices. Do not grant a service you do not trust access to sensitive directories, keys, or accounts.
Updates, Downloads, and Authorization
When checking for app updates, downloading a release, or completing OAuth authorization, Finch may communicate with update servers, code-hosting platforms, identity providers, or download proxies. Those services may process the network and device information necessary to complete your request.
2. How We Use Information
We process information only to the extent necessary to provide and improve Finch, including to:
- provide the website, downloads, app features, and technical support;
- preserve preferences and workspace state that you choose to save;
- connect the models, tools, and third-party services you select;
- maintain security, detect abuse, and troubleshoot issues;
- analyze aggregated or de-identified information to improve reliability and experience; and
- comply with applicable legal obligations and protect the legitimate rights and interests of users, the public, and Finch.
We do not sell your personal information or use your local work content for cross-site advertising.
3. How Information Is Shared
We share only the information necessary in the following circumstances:
- At your direction: when you choose to connect or invoke a model, tool, mini tool, MCP service, OAuth service, or other third-party capability;
- With service providers: when needed to host the website, distribute downloads, deliver notifications, provide authentication, or maintain infrastructure;
- For security and legal reasons: to comply with valid legal process or prevent fraud, attacks, abuse, or threats to people or system security; and
- In connection with a business change: if the Finch operating entity is involved in a merger, reorganization, or transfer of assets, we will require the recipient to continue protecting relevant information and will notify users where appropriate.
4. Data Retention and Deletion
Local data generally remains on your device and is managed by you through app features or your file system. Uninstalling the app may not automatically remove all workspace directories, configuration files, caches, or backups; please review and remove them yourself when needed.
We retain website logs, support records, and security records for as long as necessary for the purposes described in this policy, then delete or anonymize them unless a longer retention period is required by law. Third-party services maintain their own retention practices; please review their policies directly.
5. Data Security
We use reasonable technical and organizational measures to protect the information we process, including access controls, system secure storage for supported credentials, and efforts to minimize unnecessary data transfers. No system can be completely secure, however, and you should:
- protect your device, accounts, API keys, and access tokens;
- install mini tools and Skills only from trusted sources, and review their permissions and scripts;
- send sensitive content only to models and services you trust; and
- install security updates promptly and maintain backups of important content.
If you believe you have discovered a security issue, please contact us at the email address below and avoid disclosing sensitive details through public channels.
6. Your Choices and Rights
Depending on the laws that apply where you live, you may have the right to access, correct, delete, restrict, or object to our processing of your personal information, and to withdraw consent you previously gave.
You can control your data by:
- not enabling internet-connected features or third-party services you do not need;
- adjusting model, tool, mini tool, and permission settings in Finch;
- deleting local sessions, Spaces, memories, logs, or related files; and
- contacting us with a request relating to your personal information.
To protect your account and data, we may need to verify your identity before processing a request.
7. Children's Privacy
Finch is intended for users with the legal capacity required to use it. Minors should use Finch with a parent or guardian's guidance and should avoid submitting sensitive personal information to models, tools, or third-party services. If you believe a minor has provided us with inappropriate personal information, please contact us.
8. International Data Transfers
The models, hosting platforms, identity providers, and other third-party services you select may process data outside your region. Before enabling a service, please review its service locations, privacy policy, and cross-border transfer arrangements.
9. Changes to This Policy
We may update this policy to reflect changes in our product, technology, law, or operations. The updated version will be posted on this page with a revised date. Where appropriate, we will provide notice of material changes through the website, the app, or another suitable method.
10. Contact Us
If you have questions about this policy, our handling of personal information, or a security issue, email us at [email protected].