Legal

Privacy policy

Last updated 30 September 2026

The short version

  • Floya only reads. It can't move money, and it never asks for your card details, PIN, BVN or NIN.
  • Your bank statement files are read in memory and discarded. We keep the transactions, not the file.
  • We don't sell your data, don't use it for advertising, and don't allow it to be used to train AI models.
  • You can download everything or delete your account from the app's Settings at any time.
  • Questions go to our Data Protection Officer at privacy@floya.app.

Who we are

Floya is a personal finance app that brings your Nigerian bank accounts into one view, built in Lagos. In this policy, “Floya”, “we” and “us” mean Floya Labs Limited (RC 9892106), 1 Oyefeso Close, Ojota, Lagos, Nigeria. We are the data controller for the personal data described here.

This policy covers the Floya app and this website (floya.app), including the waitlist. It explains what we collect, why, who we share it with, and the rights you have under the Nigeria Data Protection Act 2023 (“NDPA”).

You can reach our Data Protection Officer at privacy@floya.app.

What Floya does, and doesn’t

Floya is read only. You upload statements from your bank app, and Floya organises the transactions so you can see where your money went.

Floya cannot send, pay, transfer or withdraw money. It doesn’t connect to your bank account, and it never asks for your card numbers, PINs, internet banking passwords, BVN or NIN.

Information we collect

When you join the waitlist

  • Your email address, so we can tell you when your spot opens.
  • A security check. Our bot check (Cloudflare Turnstile) looks at technical signals from your browser, such as your IP address and browser details, to confirm you’re a person. It doesn’t identify you to us.

When you use the app

  • Account details. Your name and email address, and a sign-in identifier if you use Sign in with Apple or Google. These are held by our sign-in provider, not in our main database.
  • Statement data. When you upload a statement, we read it and keep the transactions from it: date, amount, balance, the transaction description (“narration”) and the bank it came from. For each account we keep the bank name and the last four digits of the account number, never the full number. If a PDF statement is password protected, we use the password once to open it and then discard it.
  • Your edits. Category changes, labels you add, and transfers you mark as moving money between your own accounts.
  • Ask Floya conversations. The questions you ask, the answers you get, and a daily count of questions used.
  • Subscription status. Whether you have an active Floya Intelligence subscription.
  • Technical information. Basic request information, such as IP address, time and error codes, is processed by our servers to keep the service running and secure. Our logs automatically remove emails, long numbers, narrations, balances and access tokens before anything is written.

What we don’t collect

We don’t collect your BVN, NIN, card numbers, bank passwords or PINs, full account numbers, precise location, contacts or photos. The app has no advertising SDKs, no third-party analytics and no cross-app tracking.

If you use Face ID or a fingerprint to lock the app, that check happens on your phone. We never receive your biometric data.

How we use your information

Purpose Information Lawful basis (NDPA s.25)
Tell you when your waitlist spot opens and send launch updates Email address Your consent
Keep bots off the waitlist Browser and security signals Our legitimate interest in preventing abuse
Create and secure your account Name, email, sign-in identifiers Performing our contract with you
Read statements and show your accounts, spending and categories Statement data and your edits Performing our contract with you
Answer Ask Floya questions and write your monthly briefing Your questions and relevant transaction figures Performing our contract with you
Check your subscription Your Floya user ID Performing our contract with you
Keep Floya secure, fix problems and prevent fraud Technical information Our legitimate interest in running a safe service
Meet legal obligations, such as responding to lawful requests As required Legal obligation

We don’t use your information for advertising, we don’t sell it, and we don’t make decisions about you that have legal or similarly significant effects based solely on automated processing.

What happens to your bank statements

  1. You choose a statement file in the app and it’s sent to our servers over an encrypted connection.
  2. We read it in memory only. The file isn’t written to disk, saved to storage or recorded in logs.
  3. The transactions are extracted, and the file is discarded as soon as it has been read.
  4. The transactions are stored in your Floya account and on your phone, so the app works quickly and offline.

How we use AI

Some features use AI models from other companies:

  • Labelling transactions. To turn a cryptic narration into a clear name and category, we may send the narration to an AI provider (OpenAI or Google). Before it leaves our servers, we remove account and card numbers, reference codes and amounts. Merchant and person names stay in, because they’re what the label is based on.
  • Ask Floya. Your question, recent turns of the conversation, and the figures needed to answer it (for example, totals or matching transactions) are sent to OpenAI to write the answer. Our servers calculate the numbers; the model only phrases them.
  • Monthly briefing (Floya Intelligence). Your month’s computed figures are sent to OpenAI to write a plain-language summary.

We use these providers under business terms that don’t allow your data to be used to train their models. They may keep requests for a limited period to detect abuse, as their terms describe.

AI can get things wrong. Treat answers as a helpful summary, not as financial advice, and check anything important against your bank’s records.

Who we share it with

We share personal data only with service providers that help us run Floya, only what each one needs, and only under contracts that require them to protect it. We never sell it.

Provider What they do What they receive Where
Supabase Sign-in and accounts Name, email, sign-in identifiers Ireland (EU)
Hetzner Hosts our servers and database Your Floya account data Germany (EU)
Cloudflare Website hosting, bot checks, encrypted backups Website requests, Turnstile signals, encrypted database backups Global network
OpenAI AI features described above Redacted narrations, questions and figures United States
Google (Gemini) Transaction labelling, when used Redacted narrations United States
RevenueCat Subscription status Your Floya user ID (no bank data) United States
Apple and Google App stores, payments, Sign in with Apple or Google Purchase and sign-in details, under their own privacy policies Various
Resend Waitlist and service emails Email address and email content United States

We may also disclose information if the law requires it, to protect the rights and safety of our users or others, or as part of a merger or sale of the business, in which case this policy continues to apply.

International transfers

Some of these providers process data outside Nigeria, in the European Union and the United States. Where we transfer personal data outside Nigeria, we do so as the NDPA permits: to countries with adequate protection, or under contractual safeguards that require the recipient to protect your data to the standard the NDPA expects.

How long we keep it

  • Statement files: not kept. They’re discarded as soon as they’ve been read.
  • Account and transaction data: kept while your account is open. When you delete your account, it’s removed straight away.
  • Backups: our database is backed up daily in encrypted form, and backups are kept for 30 days. Deleted data is fully gone once the backups that contain it expire.
  • Deletion records: to show that a deletion happened, we keep a timestamp and a one-way coded identifier that can’t be traced back to you.
  • Waitlist email: kept until you ask us to remove it, or until we’ve invited you and you’ve decided whether to join.
  • Technical logs: kept for a short period for security and troubleshooting, then deleted.

How we protect it

  • Data is encrypted in transit between the app, website and our servers.
  • Our database has no public internet access, and backups are encrypted.
  • Every request to your data is checked against your signed-in session, and each account can only reach its own data.
  • Logs automatically remove sensitive details before they’re written.
  • On your phone, your sign-in is kept in the device’s secure storage, and money screens are hidden in the app switcher and protected from screenshots where the phone supports it.

No system is perfectly secure. If a breach affects your personal data and puts you at risk, we’ll notify you and the Nigeria Data Protection Commission as the NDPA requires.

Your rights

Under the NDPA you have the right to:

  • Access your personal data and get a copy of it.
  • Correct data that’s inaccurate or incomplete.
  • Delete your data.
  • Restrict or object to how we use it.
  • Move it: receive it in a common, machine-readable format.
  • Withdraw consent at any time, where we rely on consent. This doesn’t affect anything we did before you withdrew it.
  • Not be subject to decisions based solely on automated processing that significantly affect you.

The quickest way to use most of these is in the app, under Settings:

  • Download my data gives you a copy of your accounts, transactions and Ask Floya conversations.
  • Delete account permanently removes your account and data.
  • Clear data removes your transactions but keeps your sign-in.

To leave the waitlist, reply to any of our emails or write to hello@floya.app. For anything else, email our Data Protection Officer at privacy@floya.app. We’ll respond within 30 days, and we may need to confirm your identity first.

Complaints

If you’re unhappy with how we’ve handled your data, contact us first at disputes@floya.app and we’ll try to put it right. You also have the right to complain to the Nigeria Data Protection Commission at ndpc.gov.ng.

Children

Floya is for people aged 18 and over. We don’t knowingly collect data from anyone younger. If you believe a child has given us personal data, contact privacy@floya.app and we’ll delete it.

Cookies

This website doesn’t use advertising or analytics cookies. Our bot check and hosting provider may use strictly necessary technical storage to keep the site secure. The app doesn’t use advertising identifiers.

Changes to this policy

We’ll update this policy when Floya changes. The date at the top shows the latest version. If a change significantly affects how we use your data, we’ll tell you in the app or by email before it takes effect.

Contact us