Privacy Policy for FinLet
Last updated: September 16, 2026. Section 3b applies to app version 1.0.3 and later.
In plain words: FinLet has no accounts, no ads, no ad tracking, no third-party analytics or tracking SDKs, and no location. Your child's first name, play money, chores, goals, progress, chat history and the parent PIN are stored only on your device. Three things leave the device, all to our own server: (1) AI mentor chat messages and a short progress summary, forwarded to our AI provider (Anthropic) to generate a reply; (2) anonymous usage statistics, such as "a chore was approved", which a parent can switch off; (3) a random technical ID that limits how much each installation can use the AI. None of this includes your child's name, and we do not sell any data.
1. Who we are
FinLet ("we", "us", or "the app") is a financial-literacy learning app for children, designed to be used together with a parent or guardian. It is developed by an individual developer, Leonid Martynov. This policy explains what information the app handles and how. Questions: leon130853@gmail.com.
2. Information stored on your device
The following is created and stored locally on your device only. It is not sent to us or uploaded to any server for storage:
- The child's first name (entered during setup) and the penguin's name
- In-app virtual balance, chores, savings goals, and transaction history (play money only — no real money is involved)
- Quiz progress, streaks, badges, stars, and penguin customization
- Chat history with the in-app AI mentor
- The parent PIN used to open the parent area
- App preferences (language, whether usage statistics are on)
Android backup
FinLet uses Android's standard backup feature (Auto Backup). If backup is enabled in your Android settings, a copy of the app's on-device data — including your child's first name and in-app progress — is stored in your own Google account backup, so that progress is not lost when you set up a new phone or reinstall the app. This copy is handled by Google under your account and your Google settings, not by us: we never receive it and cannot read it. You can turn this off in your device settings and delete existing backups from your Google account.
3. AI mentor and quiz: information sent to our server and AI provider
To make the AI mentor (a friendly penguin) and the daily quiz work, the app sends the following to our server (api.getfinlet.com), which forwards it to our AI provider, Anthropic PBC (the Claude API):
- AI mentor chat: the messages your child types, plus a short summary of in-app progress (such as the play-money balance, savings goals, number of chores and lessons completed). Your child's first name is never included.
- Quiz generation: the chosen quiz topic, difficulty, and language. No personal information is included.
We do not store these messages on our server; we relay them and return the AI's answer. Anthropic processes the request to generate the response under its own terms; per Anthropic's API policy, API inputs are not used to train its models by default.
3a. Safety filtering and reports
- Blocked before sending. If a message appears to describe self-harm, violence, adult topics, meeting strangers, or contains contact details such as a phone number, e-mail or home address, it is not sent to Anthropic at all. The app answers with a safe, supportive message that points your child to a trusted adult.
- Checked after generating. AI replies are screened before being shown, and unsuitable replies are replaced with a safe message.
- What we log. When the filter triggers we record only the category and the time — never the text your child wrote.
Every AI reply has a report button. If your child reports a reply, we receive the reported AI reply, the chosen reason, and the app language. Reports do not include your child's name or any identifier. We keep reports for up to 12 months to improve the filter.
3b. Anonymous usage statistics (version 1.0.3 and later)
To understand whether FinLet actually helps families — for example, whether children come back, which parts are confusing, and whether the app crashes — the app sends usage events to our own server.
What is sent. Only events from a fixed list, such as "app opened", "setup finished", "a chore was sent for review", "a chore was approved", "a quiz question was answered", "a savings goal was reached", "the parent area was opened", or "an app error happened". Each event carries: a random analytics ID created by the app, the event time (rounded to the minute), the date the app was first opened and the number of days since then, the app version and language, and a random session ID. Some events carry a simple yes/no or a range (for example, "reward of 3–5 coins", "approved within 2 hours", "streak of 4–7 days"). Error reports contain only the error type and a short fingerprint, never the error message.
What is never sent. Your child's or the penguin's name, chat text, names of chores or goals, exact amounts, the PIN, advertising IDs, device IDs (such as Android ID or IMEI), contacts, photos or location. We do not store IP addresses with usage events.
The analytics ID. It is a random number that is not linked to your name, your Google account or your device hardware. It is separate from the technical ID in section 3c, and the two are never sent together. Pressing "Reset progress" creates a new analytics ID, so the old history can no longer be connected to your family.
How we use it (internal operations only). We use usage statistics solely to maintain and analyze how the app functions: counting new installations, measuring whether families return after 1, 7 and 30 days, finding steps where families get stuck, and detecting crashes. We look at the numbers in aggregate. We do not use them to contact anyone, to build a profile of a child, for advertising, for measuring ad campaigns, or to train AI, and we do not share them with any other company.
Your choice. A parent can switch this off at any time: open the parent area (lock icon) → "Usage statistics" → turn off "Share anonymous statistics". The app then stops sending events and deletes any unsent ones and its analytics ID from the device. The app works exactly the same either way.
3c. Technical data needed to run the service
- Installation ID for AI limits. Requests to the AI mentor and quiz carry a random installation ID created by the app. Our server uses it only to enforce daily usage limits and to block abuse of the AI service. The server keeps per-installation counters in memory for the current day only; they are not written to disk and are reset daily and whenever the server restarts. This ID is not used for statistics or advertising.
- Web server logs. Like any website, our server's web software records the IP address, time, requested address and browser/app type of each request. We use these logs only for security and troubleshooting, and they are deleted automatically after 14 days.
- Service logs contain daily usage totals, filter categories and error notices without IP addresses, names or IDs.
4. What we do NOT do
- We do not require registration, accounts, email addresses, or phone numbers.
- We do not collect precise or approximate location.
- We do not show ads or include advertising SDKs.
- We do not use third-party analytics, attribution or tracking SDKs; usage statistics go only to our own server.
- We do not collect advertising identifiers or hardware device identifiers, and we do not build advertising profiles.
- We do not sell or rent personal information, or share it for advertising.
5. Service providers
- Anthropic PBC (United States) — provides the AI for the mentor chat and quiz. anthropic.com/legal/privacy
- DigitalOcean — hosts our server in Frankfurt, Germany. It stores our server data on our behalf and does not use it for its own purposes.
- Google — distributes the app through Google Play. If you allow your device to share usage and diagnostics with Google, Google may provide us with aggregated crash and performance reports under its own policies.
6. Children's privacy (COPPA and similar laws)
FinLet is directed to children and is meant to be set up and supervised by a parent or guardian. We collect only what is described above and designed the app to minimize data: no accounts, no ads, no third-party trackers.
- The random analytics ID and installation ID are used only to support the internal operations of the app described in sections 3b and 3c (maintaining and analyzing how the app functions, enforcing usage limits, and protecting the security and integrity of the service). They are not used to contact anyone, to build profiles, or for advertising, and they are not disclosed to third parties.
- Your child's first name is used only on the device and is never sent to our server or to Anthropic.
- Chat messages are sent to Anthropic only to generate the reply. Because a child could type personal details, our filter blocks messages that contain contact details before they are sent. Please remind your child not to share personal information in the chat.
- A parent or guardian may review or delete the app's data at any time (section 7), switch off usage statistics, or contact us to ask about or delete any data we hold.
7. Parental controls and how to delete data
- Parent area: protected by a PIN, where a parent manages chores, approvals, the child's name, usage statistics and other settings.
- Reset progress erases all locally stored data (name, balances, chores, goals, quiz progress, chat history) and creates a new analytics ID.
- Uninstalling the app removes all locally stored data from the device. If Android backup is enabled, a copy may remain in your Google account backup.
- Data on our server: usage events are not linked to your name or account, so we cannot pick out one family's events on request. Switching off usage statistics or resetting progress deletes the analytics ID on your device, which disconnects your family from past events, and those events are deleted automatically after 90 days. For reported AI replies or any other question, write to us.
8. Data retention
| Data | Where | How long |
| Name, progress, chat history, PIN | Your device | Until you reset progress or uninstall |
| Chat messages and progress summary | Relayed by our server to Anthropic | Not stored by us; Anthropic retains API data only as described in its policy |
| Usage events (with random analytics ID) | Our server | Deleted automatically after 90 days |
| Aggregated statistics (counts and percentages, no IDs) | Our server | Kept while the app is operated |
| Installation ID usage counters | Server memory | Current day only; reset daily and on restart |
| Web server logs (IP address, time, request) | Our server | 14 days |
| Reported AI replies | Our server | Up to 12 months |
9. Security
All communication between the app and our server uses encrypted HTTPS. Server access is restricted to key-based administrator access, secrets are kept in files readable only by the administrator, the AI service is reachable only through our server, and we review risks to the data at least once a year. No method of storage or transmission is 100% secure, but we take reasonable measures to protect the limited information the app handles.
10. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top of this page, and changes to what the app collects will be described here before they take effect.
11. Contact us
Questions or requests about this Privacy Policy or your child's data: leon130853@gmail.com