Privacy Policy
Effective July 29, 2026
The short version: FREM reads your financial data to show you what happened with your money. Access to your bank is read-only and can never move funds. Your bank credentials never touch our servers. Access tokens are encrypted at rest. We do not sell your data. You can disconnect and delete at any time.
1. Who we are
FREM (“we,” “us”) provides a personal and business finance application at frem.app that helps you compare what you planned to spend with what you actually spent. This policy describes what data we collect, why, and what happens to it. Questions can be sent to the contact address published on our site.
2. What we collect
- Account information. When you sign in with Google, we receive your name, email address, and profile picture. We do not receive your Google password.
- Financial data, read-only. When you connect a bank through Plaid, we receive account names, balances, and transaction history (dates, amounts, merchant descriptions, categories). Your banking credentials are entered with Plaid, never with us, and are never transmitted to or stored on our servers. The access we hold cannot initiate transfers, payments, or any movement of money.
- Information you enter. Budgets, goals, income sources, business details (such as entity type and ownership percentage), spending estimates, investments, and debts you choose to add.
- Usage basics. Session data required to keep you signed in. We do not run third-party advertising trackers.
3. How we use it
- To display your accounts, transactions, budgets, and goals.
- To categorize transactions. Most categorization happens with rules and data already on our servers. For merchants we cannot identify, we send merchant names only — never amounts, dates, balances, account details, or your identity — to our AI provider (OpenAI) for classification, and cache the answer so it is not sent again.
- To generate financial reports and chat responses. These use a summary of your financial picture processed by our AI provider under our instructions; the provider is not permitted to use this data to train its models under our API terms.
- To operate, secure, and improve the service.
4. What we never do
- We never sell or rent your personal or financial data.
- We never initiate, authorize, or execute movement of your money.
- We never store your banking credentials.
- We never share your data with advertisers.
5. How data is protected
- Bank access tokens are encrypted at rest with AES-256-GCM. The decryption key is stored separately from the database, so a database compromise alone cannot expose usable bank access.
- All traffic is encrypted in transit with TLS.
- Every data query is scoped to your account; no user can read another user's records.
6. Third parties we rely on
- Plaid — bank connectivity. Governed by the Plaid End User Privacy Policy.
- Google — sign-in.
- OpenAI — transaction categorization and financial summaries, as limited in section 3.
- Vercel and Turso — hosting and database infrastructure.
7. Retention and deletion
Your data stays while your account is active. Disconnecting a bank removes our access token and revokes it with Plaid. You may request full deletion of your account and all associated data at any time via the contact address on our site; we will complete it within 30 days.
8. Changes
If this policy changes materially, we will note the new effective date here and flag the change in the application before it takes effect.
See also our Terms of Service.