Your privacy is a core principle of finilog itself. We collect as little personal data as possible, and our encryption means we have no technical ability to access the contents of your vault.
The contents of your vault are encrypted on your own device before they are ever sent to our servers (Zero-Knowledge).
finilog is designed around European privacy principles and GDPR compliance, and is operated from Germany.
We only process the data strictly necessary to provide our services and keep the platform secure.
The controller within the meaning of Art. 4 No. 7 GDPR for the processing of personal data in connection with this website and the finilog application is the person named in the imprint. Full contact details are provided there. For any questions about this Privacy Policy or your personal data, you can reach us at support@finilog.de.
The content you store in your vault — credentials, notes, documents, crypto information and attached files — is encrypted exclusively on your own device (AES-256-GCM) before it ever reaches our servers. The key used for this is derived from your vault password (PBKDF2-SHA256, 1,000,000 iterations) and never leaves your device. For this content, we are technically unable to view it, disclose it to authorities in plaintext, or reset it on your behalf. This Privacy Policy accordingly focuses mainly on the metadata and account information that necessarily arises unencrypted to operate the service — not on the content of your vault itself. A full technical breakdown of which database column is encrypted and which is not is available on our data model page. One exception concerns personal messages to recipients: these are delivered later as an email, at a moment when you can no longer take part. The key needed to decrypt them therefore sits on our server. For these messages — and only for these — we are technically able to view the content. For all other vault content, the preceding paragraph applies without qualification.
Account data: first and last name, email address, and a password hash (never the password itself), provided at registration. Vault metadata (unencrypted): technical row identifiers, timestamps, the keys wrapped for recovery purposes, and which legacy contact account an entry was encrypted for. The name and email address of the legacy contacts you designate also remain unencrypted, since we need to contact them if the worst happens. Vault content (encrypted): the title, category, and actual content of every entry, as well as attached files. We store only ciphertext for these, see Section 2. File metadata (unencrypted): file size, timestamps, and a randomly generated storage path that reveals neither the original filename nor file type. Technical and security data: IP address, timestamp, and device/browser information automatically processed by our authentication backend at sign-in to detect abuse, as well as our hosting/CDN provider's server logs. Usage statistics: the page visited and the referring URL, used solely for our own aggregated traffic measurement. Nothing is stored on or read from your device for this. The counting key is derived on our server from IP address, browser identification and the current date; it changes daily, and the IP address itself is not stored. Recognition beyond a single day is therefore impossible, and nothing is shared with third parties. Two-factor sign-in (if you enable it): the secret of your authenticator app and the time it was set up. Only your own account can reach it. Vault passkey (if you enable it): the credential identifier your device assigns and the matching public key. The key material itself never leaves your device. Messages to designated recipients: the recipients' names and email addresses unencrypted, because we have to write to them when the time comes, plus a delivery record of when a message was opened. The message content itself is encrypted. Folders: the structure you define and which folder is meant to reach which person. What a folder holds sits inside the ciphertext. Legacy contact key checks: one timestamp per person recording when we last verified that their personal key still matches the stored data. Email log: recipient, type and time of the messages we send — without their content. We need it to be able to show, if it is ever disputed, whether a reminder or a release notice actually went out. Check-in tokens: one-time identifiers from the links in our reminder emails, letting you confirm you are well without signing in. Support communication: the content and contact details you provide when reaching out to support. Payment data: once paid subscriptions are actively usable, an external, specialized payment provider will process your payment data on our behalf. Full payment card data never passes through our own servers.
We process personal data to: provide and manage your account, technically operate the encrypted vault and its legacy contact/release features, run the automated check-in process described in Section 6, detect abuse and maintain system security, comply with legal obligations, and provide customer support.
Depending on the purpose, processing is based on Art. 6(1)(b) GDPR (performance of the usage contract, including the legacy contact release you configure), Art. 6(1)(f) GDPR (legitimate interest in system security, abuse prevention, and anonymized traffic measurement), Art. 6(1)(c) GDPR (compliance with legal obligations, e.g. bookkeeping), and, where applicable, Art. 6(1)(a) GDPR (your explicit consent).
A core part of the service is a fully automated, technical check on whether you have last confirmed activity with finilog within a period you configure yourself ("check-in"). If no confirmation is received, our system automatically sends a series of reminders, then contacts the legacy contacts you have designated, and — after a further, also configurable waiting period during which you can object — technically unlocks legacy contact access to the entries you assigned to them, which remain encrypted throughout. This process runs without any substantive review by us and without a human decision on our end; it is based purely on deadlines and on the response of the people you yourself designated (Art. 22 GDPR). We use it because it is necessary to fulfil the contract you chose, and because you configure the relevant parameters — check-in interval, reminders, final waiting period — yourself in your account settings and can interrupt the process at any time. The exact mechanics are further described in our Terms of Service.
Personal data is never sold. We use carefully selected processors under Art. 28 GDPR, in particular: Supabase (database, file storage, and backend functions, hosted in the EU region Frankfurt am Main), Cloudflare (delivery of the website via a global content delivery network), and Resend (delivery of transactional emails, e.g. check-in reminders or legacy contact notifications). Once paid subscriptions are actively usable, a payment provider will be added. Appropriate Art. 28 GDPR data processing agreements are or will be in place with all processors before productive use.
Our database and storage infrastructure is located in the EU (Frankfurt am Main). Some of the service providers we use, particularly for content delivery and email, may be headquartered or operate infrastructure outside the EU/EEA. In such cases, we ensure that any transfer only takes place on the basis of appropriate safeguards under Art. 44 et seq. GDPR, such as EU Standard Contractual Clauses or a European Commission adequacy decision. Achieving fully European sovereignty of our infrastructure is a stated strategic goal of our roadmap.
We retain account data and vault content for as long as your account exists. You can request deletion yourself at any time via the settings. It does not happen immediately: it is scheduled for a point 14 days ahead, your account stays fully usable until then, and you can revoke it at any time. That is deliberate — for a legacy vault, an irreversible act behind a single click is the wrong construction. Once the period has passed, your vault entries, your legacy contact list and the associated account data are irrevocably removed. Instead of deleting, you can also pause your account. Your data stays untouched and access rests until you reactivate it. For data remaining after a legacy contact release has been triggered, the deletion approach described in Section 10 applies. Once paid subscriptions are active, we retain invoice and payment data for the statutory commercial and tax retention periods (in Germany typically six to ten years, §§ 147 AO, 257 HGB), even beyond account deletion. Security-related log files are kept only briefly and are then automatically deleted or anonymized.
Even after a technical release to your legacy contacts, your vault data is not automatically deleted. Deletion only happens once every designated legacy contact has explicitly agreed to it, and even then only after a further 30-day waiting period during which any legacy contact can still revoke that agreement. There is also a second route: once the legacy case has been triggered, deletion can be initiated from the owner's account — for instance by someone holding the stored credentials. In that case every designated legacy contact is notified and has seven days to collect what was left for them before the deletion actually happens. Once deletion is carried out, we remove your vault entries in full. We retain the user account itself and its link to the legacy contacts involved as a minimal record of who agreed to the deletion and when, and so our support team can still match up any subsequent inquiries. These remaining records contain no vault content.
finilog sets no cookies, uses no third-party analytics services and embeds no third-party content — including no fonts from external servers. We serve the typeface ourselves, so that opening this page creates no connection to anyone else. In your browser's storage we keep only what the service you asked for requires: your login session, your appearance preference (light or dark), the auto-lock delay you chose for the vault, and a few notes about which hints you have already dismissed. None of it serves traffic measurement or advertising. That is why you see no consent banner here. One would be required under § 25 TDDDG as soon as we store or read anything on your device beyond what is necessary — and we do not. The traffic measurement described in Section 3 works without touching your device at all. No banner is, to us, the more honest answer than a well-built one.
We do not run an advertising business. Your data is never sold, rented, or otherwise shared with third parties for marketing purposes, and no profiling for marketing purposes takes place.
Under the GDPR, you have the right to access (Art. 15), rectify (Art. 16), erase (Art. 17), restrict processing of (Art. 18), port (Art. 20), and object to the processing of (Art. 21) your personal data. You may withdraw any consent given at any time with future effect. For many of these rights — such as accessing and exporting your vault data, correcting your name and email address, or deleting your account — the application itself provides you with the corresponding functionality. Otherwise, an informal message to support@finilog.de is sufficient to exercise them.
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement. As we are based in Hesse, Germany, this is regularly the Hessischer Beauftragter für Datenschutz und Informationsfreiheit.
In addition to the client-side encryption of your vault content (Section 2), we apply technical and organizational measures to protect all data processed by us: transport encryption (TLS) for all connections, strict database-level access controls (Row Level Security), restrictive security headers, and ongoing development of our security architecture, as described on our security page. Independent security reviews are a firm part of our roadmap.
finilog is intended for legally competent, adult users. We do not knowingly collect personal data from minors. If we become aware that an account was created by a minor, we will delete the account and its associated data.
We update this Privacy Policy whenever our processing of personal data or the applicable legal requirements change. The version shown here is always the current one.
If you have questions about this Privacy Policy or the processing of your personal data, you can reach us at support@finilog.de or through the contact details provided in the imprint.
Our Transparency Commitment
finilog is committed to full transparency, strong data protection, and continuous improvement of our security practices as the platform evolves.