Finora← Back to home
Finora · Legal centre

Privacy Policy

How Finora handles account details, ecommerce records, AI messages and subscription information.

Last updated · 26 September 2026

1. Who handles your information

Finora is operated by Jorge Rodrigues, an individual based in Brazil and trading as Finora. We determine how personal information is used for account administration, support, security and our own business records. The Legal Notice contains the operator and contact information.

When a business supplies information about its customers or staff for analysis, that business determines the purposes and lawful basis for that information. Finora processes it on the business’s documented instructions, under the applicable Data Processing Addendum. If your request concerns a store you bought from, contact that store first.

2. Information we receive

  • Account and access information: name, email address, authentication records, account preferences and workspace permissions. We use these to establish and secure access.
  • Ecommerce information you submit: sales, products, stock, costs, store/workspace identifiers and related records. Uploaded records may contain personal information if you include it.
  • AI interactions: the questions, conversation history and other content you submit to NORA or another AI feature, and the generated responses.
  • Purchase information: purchase email, Paddle customer and subscription identifiers, selected plan, transaction status and billing period. Payment-card details entered in checkout are handled by Paddle and its payment providers.
  • Communications: enquiries, support requests and the information you supply to resolve them. The contact form collects your name, reply email, subject, request topic and message. Framer delivers these submissions to Finora’s Gmail inbox, provided by Google, so we can handle and reply to your request.
  • Technical and usage information: IP address, browser/device information, authentication and error logs, and usage counters needed to operate and protect the service.

3. Why we use it

We process information to supply requested account access and analysis, administer subscriptions, answer requests and provide service communications. Where applicable, this is necessary to perform our contract with you or take steps at your request.

We use proportionate security and diagnostic information to prevent misuse, enforce access limits and keep the service working, relying on legitimate interests where permitted and after considering affected individuals’ rights. Records required for tax, accounting or legal requests are processed to meet legal obligations.

Where consent is required, including for optional marketing or non-essential tracking, that processing requires a separate lawful choice. Buying a plan or receiving an access email is not consent to unrelated marketing. Merchant-controlled data is processed on the merchant’s instructions; this notice does not establish the merchant’s lawful basis.

4. NORA and other AI features

AI requests are sent through Lovable’s AI service to the model provider configured for the feature. The current NORA integration uses an OpenAI model. Content you enter and relevant conversation history are transmitted to generate a response.

NORA keeps up to 60 recent messages in session storage in your browser. You can clear the conversation using its reset control or remove the site’s session storage. The current NORA route does not write a conversation record to Finora’s database. The request disables retrievable response storage, but that setting does not establish zero retention of security or operational records across the providers.

Avoid sending customer identifiers, passwords, payment details or sensitive personal information to AI features unless necessary, authorised and covered by appropriate processing arrangements. AI outputs may be incorrect and require human review.

5. Who receives information

Providers support website hosting, application hosting, databases, authentication, AI processing and email delivery. The provider page identifies the services verified in this deployment. Authorised team members may access the information their workspace permissions allow.

Paddle has its own responsibilities for checkout, billing, tax, receipts, fraud prevention and payment support. We may also disclose relevant information to professional advisers or authorities where needed to meet a lawful obligation, or to protect rights and investigate misuse.

Finora does not sell personal data. A service provider’s role and permitted use depend on the service and applicable agreement.

6. Storage and retention

Account and workspace records are retained while needed to provide your account and requested services. The retention criteria are your account status, the purposes for which the records were supplied, unresolved support requests or disputes, security needs and applicable record-keeping duties. We do not use a single fixed retention period for every category of information.

You can request account closure, access, export or deletion through the contact form. Identify the account and the action you want; we may verify your authority before disclosing or deleting information. Cancelling a subscription stops renewal and does not automatically delete the account. Records required for a legal duty, fraud investigation or dispute may be retained for that purpose and restricted accordingly.

Contact enquiries remain in the service inbox while needed to handle the request and any related complaint or legal obligation. Paddle controls retention of its own payment, tax and transaction records under its privacy notice.

Some workspace records, preferences and cached results remain in browser local storage until removed or replaced. NORA history uses session storage. Removing browser storage does not itself delete records held by Finora or its providers.

Deletion from active systems does not necessarily remove backup copies immediately. Lovable’s published processing terms allow deleted data to remain in backups for a limited time, without stating a fixed maximum there. Framer’s terms also provide for backups that are not separately accessible. Provider-held copies are addressed through the applicable deletion process; we do not promise instant erasure from every backup.

7. International processing and security

Finora is operated from Brazil. The configured application database is in Zurich, Switzerland. Website delivery, email, support and AI processing also involve international providers. Lovable lists OpenAI in the United States and infrastructure providers in Europe, the United States and other locations in its Trust Center. A database location is not a promise that all processing stays in that country.

International transfers must satisfy the law applicable to the information. Lovable and Framer publish contractual safeguards for the transfers covered by their processing terms, including European and UK mechanisms where applicable. Transfers subject to Brazil’s LGPD require a mechanism valid under that law; European clauses alone should not be treated as proof that Brazil’s requirements are met. Contact Finora for the safeguards applicable to a proposed transfer of your business’s personal data.

The application uses authenticated access, server-side permissions, per-account database controls and HTTPS. These controls reduce risk but cannot guarantee that a service is immune to loss, misuse or unauthorised access. Protect your login links and grant access only to authorised people.

8. Your rights and choices

Depending on the law that applies, you may request access, correction, deletion, restriction, portability, or object to processing. Where consent is the basis, you may withdraw it without affecting earlier lawful processing. We may need proportionate identity verification and will explain applicable limitations.

Where Brazil’s LGPD applies, you can request confirmation of processing, access, correction, information about data sharing, portability subject to regulation, and anonymisation, blocking or deletion of unnecessary, excessive or unlawfully processed data. You can revoke consent, ask about refusing it and its consequences, and request deletion of consent-based data subject to lawful retention. You may object to non-compliant processing and request review of solely automated decisions affecting your interests. Requests are free. Confirmation or access is provided immediately in simplified form or through a complete statement within 15 days, subject to applicable rules. You may petition the ANPD or a competent consumer-protection body.

For GDPR requests, the usual response period is one month, with extensions only as permitted by law and with notice. You may complain to a competent data-protection authority, including where you live, work or believe an infringement occurred.

Finora’s analysis supports business decisions; it is not intended to make decisions about individuals that produce legal or similarly significant effects solely through automation. The service is intended for adults authorised to operate a business account and is not directed to children.

9. Contact and changes

Use the contact form and select “Privacy or data request” for access, correction, export, deletion or other privacy enquiries. Provide enough information to identify the account and request, but do not send passwords or login links. Jorge Rodrigues is responsible for handling these enquiries. We will update this notice when relevant processing changes and provide further notice where required.