Privacy Notice
Last updated: 22 September 2026 · Version: 2026-09-22
This notice explains what data FLIO processes, why, who we share it with, and what you can do about it. It is written to be read, not to defend us from you.
The Portuguese version of this notice is the authoritative one. FLIO is operated by a Brazilian company under Brazilian law (the LGPD), and this translation is provided for convenience.
In short
- FLIO exists to organise your financial life, which means it has to read your transactions. We do not sell your data and we do not use it for advertising.
- Your bank password never passes through FLIO. The connection is made by a regulated Open Finance provider, inside your bank's own environment, and it is read-only.
- Your database is in Brazil, in the São Paulo region, and that is where your data is stored. The server that runs the application is in the United States, so your data is read and processed there every time you use it. Section 5 explains this properly.
- The AI receives summarised totals to generate your insights. The exception is receipt scanning, where the photo you upload is processed by an AI provider.
- You can download everything we hold about you, or delete your account, at any time, by yourself, inside the app.
1. Who processes your data
The controller of your personal data is:
DASHFY CONSULTORIA EM SISTEMAS DE INFORMACAO LTDA CNPJ 56.098.018/0001-22 Rua Rio de Janeiro, 243, Sala 802, Centro, Belo Horizonte/MG, CEP 30.160-040, Brazil Phone: (27) 99508-3732
Data Protection Officer (Encarregado): privacidade@flio.com.br
That is the channel for any question, request or complaint about your personal data.
2. What data we process
Data you provide
- Sign-up details: name, email and password.
- A profile picture, if you upload one.
- Accounts, cards, goals, budgets and categories you create.
- Statements you upload (OFX files).
- Notes and attachments you add to transactions (images, PDFs, text).
- Receipts you photograph.
- Assets you register: properties and vehicles, with their identifying details.
Data from your bank, with your authorisation
- Identification of connected accounts and cards.
- Balances, limits and bills.
- Transactions: date, amount, description and merchant.
Data FLIO generates
- Categorisation of your transactions.
- Cash-flow and spending projections.
- Insights and reports on your financial behaviour.
- Suggestions for recurring payments, instalments and investments.
Your subscription data
- The plan you are on, the subscription's status and its renewal or end date.
- A customer identifier generated by Stripe, linking your account to their subscription record.
- Your card details never pass through FLIO. Payment happens on a page hosted by Stripe, and we neither receive nor store a card number, expiry date or security code.
Technical data
- IP address, browser and device, recorded on security and consent events.
- Application access logs.
3. What we use it for, and on what legal basis
| Purpose | Legal basis (LGPD Art. 7) |
|---|---|
| Importing, organising and categorising your transactions | Performance of a contract (V) |
| Generating projections, insights, goals and net worth | Performance of a contract (V) |
| Reading receipts you upload | Performance of a contract (V) |
| Authenticating you and maintaining your account | Performance of a contract (V) |
| Sending notifications about your own account | Performance of a contract (V) |
| Charging for and managing your subscription | Performance of a contract (V) |
| Preventing fraud, abuse and unauthorised access | Legitimate interest (IX) |
| Keeping access logs | Legal obligation (II), Marco Civil da Internet, Art. 15 |
| Sending marketing email | Consent (I), withdrawable at any time |
You can withdraw marketing consent whenever you like without affecting your use of the product. The contract-based purposes cannot be switched off individually: they are the service. If you do not want them, the route is to close your account, and that is also in your hands.
4. Who we share it with
We do not sell your data and we do not share it for advertising. We share it only with providers that perform part of the service, and only as far as necessary:
| Who | What for | Where |
|---|---|---|
| Pluggy | Open Finance connection to your bank | Brazil |
| Supabase | Database and files | Brazil (São Paulo) |
| Render | Application servers | United States (Virginia) |
| OpenAI, Google (Gemini), Anthropic (Claude) | Generating insights and reading receipts | United States |
| Ably | Real-time notifications | United States |
| Sentry | Application error monitoring | United States |
| Brevo | Sending transactional email | France |
| Stripe | Payment processing and subscription management | United States |
| SEFAZ | Looking up a receipt from its QR code | Brazil |
We may also share data where legally required, by court order or at the request of a competent authority.
5. International transfers
There is a distinction here that most privacy policies skip: where your data is stored and where it is processed are not the same thing.
Where it is stored: Brazil. The database and the files you upload live in the São Paulo region, and so do the backups. The durable copy of your data does not leave the country.
Where it is processed: the United States. The server that runs the application is in Virginia, because our infrastructure provider has no South American region. In practice, every time you open the app your data is read from the database in Brazil and processed on that server. It is not stored there, but it passes through.
Add to that the AI, notification, error-monitoring and payment providers, which also operate in the United States, and the email provider, which operates in France. That is the only destination outside Brazil which is not in the United States.
On payment: Stripe receives your email address, an internal identifier for your account, and whatever you type on their payment page. That page is Stripe's, not ours, which is why your card number never reaches us.
On error monitoring: when something breaks in the app we send Sentry the failure report, your account's internal identifier and the address of the screen it happened on. We do not send request contents, your IP address, or any screen recording. The identifier is there so we can tell whether a fault hit one person or everyone.
All of this is international transfer of personal data under LGPD Art. 33, and it happens on the basis of the standard contractual clauses approved by the ANPD (Resolution CD/ANPD No. 19/2024). The law permits these transfers; what it requires is that contractual safeguards exist and that you know they happen. That is why this section exists instead of a sentence claiming your data never leaves Brazil.
6. Artificial intelligence: what leaves here
This distinction matters, so it gets its own section:
- Insights, projections and reports: the AI provider receives summarised totals (how much went to each category, how the month behaved). Your name and your account numbers are not sent.
- Receipt scanning: this one is different. The photo you take is sent to the AI provider so the line items can be read, and it contains whatever is printed on the receipt, including your CPF if you gave it at the till. Scanning receipts is optional: your transactions arrive through your bank connection or your statements either way.
AI providers process this data only to answer FLIO's request. We do not use your data to train third-party models.
7. Automated decisions
FLIO makes automated decisions about your data. They are:
- Automatic categorisation of transactions.
- Detection of recurring payments and instalment plans.
- Cash-flow and spending projections.
- Automatic distribution of contributions across goals.
- Generation of insights and alerts.
These decisions are based on your history: amounts, dates, descriptions, merchants and how often they repeat. They are suggestions about your own financial life and have no effect on credit, scoring or access to third-party services.
Under LGPD Art. 20 you may request a review of any of them by writing to privacidade@flio.com.br. You can also turn off automatic application of suggestions in Settings, and review each one manually instead.
8. How long we keep it
| Data | Retention |
|---|---|
| Account, profile and settings | For as long as the account exists |
| Transactions, statements, receipts, goals and assets | For as long as the account exists |
| Uploaded files (profile picture, attachments) | For as long as the account exists |
| Your data export file | 7 days |
| Insights and reports | For as long as the account exists |
| Notifications | 12 months |
| Application technical logs | 90 days |
| Login attempt records | 30 days |
| Consent records | For as long as the account exists |
| Investments you deleted | 30 days until permanent removal |
| Record of your deletion request | Permanent |
| Application access logs | 6 months (Marco Civil da Internet, Art. 15) |
When you delete your account everything goes, with two exceptions: the access logs the law requires us to keep, and the record that you asked for deletion. That last one contains nothing about you or your finances, and exists so we can demonstrate your request was honoured.
9. Your rights
LGPD Art. 18 gives you:
- Confirmation and access: whether we process your data, and what it is.
- Portability: a machine-readable copy.
- Correction of incomplete or outdated data.
- Deletion of your data.
- Information about who we share it with.
- Withdrawal of consent, and information about the consequences of refusing it.
- Review of automated decisions (Art. 20).
Three of these you exercise yourself, without asking anyone, in Settings → Data:
- Download your data generates a file with everything we hold about you.
- Delete my account blocks access immediately and erases everything after 7 days. You can cancel during that period.
- Disconnect a bank revokes the authorisation at the institution.
For the others, write to privacidade@flio.com.br. We reply immediately in simplified form and in full within 15 days, under LGPD Art. 19.
You may also petition the ANPD, Brazil's National Data Protection Authority, directly.
10. Security
- All traffic is encrypted in transit (HTTPS/TLS), and data is encrypted at rest with AES-256.
- Isolation between accounts is enforced by the database itself, which refuses to return records that are not yours, and not by the application alone.
- Files you upload are held in private storage, reachable only by you and only when signed in.
- Bot protection on sign-in, progressive lockout after repeated attempts, and expiring access links.
- We do not have and do not store your bank password.
No system is immune. In the event of a security incident carrying relevant risk, we will notify you and the ANPD within the deadlines set by Resolution CD/ANPD No. 15/2024.
11. Cookies
We use only essential cookies: the ones that keep you signed in and remember preferences such as language. We do not use advertising or third-party tracking cookies. If that changes, we will ask for your consent first.
12. Children and adolescents
FLIO is not intended for anyone under 18 and we do not knowingly collect data from children or adolescents. If we identify such an account, it will be removed.
13. Changes to this notice
We may update this notice. The date and version at the top show what is in force. If a change is material we will tell you, and where the law requires it, ask you to accept it again.
14. Contact us
Questions, requests or complaints about your data:
DASHFY CONSULTORIA EM SISTEMAS DE INFORMACAO LTDA · CNPJ 56.098.018/0001-22 Rua Rio de Janeiro, 243, Sala 802, Centro, Belo Horizonte/MG, CEP 30.160-040, Brazil