Sign in
back

Privacy policy

Last changed 23 Sept 2026.

This English text is provided for convenience. The Czech version is the binding one.

The data controller is EUROSIGN s.r.o., company ID 49446100, registered office Vysoká 532/8, Štýřice, 639 00 Brno. You can reach us at info@finisht.app.

What Finisht is

Finisht is a shelf of what you have watched, read, listened to, played and put in your headphones. Data about what you consume is yours. The application keeps it to show it back to you, not to monetise it.

What data is kept

Cookies

The application uses technical cookies only, no analytics and no advertising. finisht_session keeps you signed in, finisht_pre carries the anti-forgery token for a visitor who is not signed in, and lang remembers the language you picked. Three more exist only while you sign in through another account or connect Spotify (finisht_oauth, finisht_pending, finisht_spotify): they hold the operation in progress and are removed as soon as it finishes. No tracking, no advertising, no third party — which is why there is no consent banner: the law does not require consent for strictly necessary cookies.

What others can see

A shelf is public by default — that is the point of the social layer. You can switch it to private at any time in Settings; it then disappears from the feed, from search and from the profile, and individual items become inaccessible too. A single item can be hidden on its own.

Search engines are separate. A public shelf has an address anyone can open — but it does not reach Google or any other search engine until you explicitly turn that on in Settings. It is off by default and the pages carry a tag that forbids indexing. Turning it on is one click; taking back a page a search engine has already fetched takes more than one.

Your e-mail is never visible to anyone but you.

Who receives the data

Nobody who would profit from it. This is what leaves the server:

Covers from other catalogues are served through our own proxy precisely so that the other server does not learn who is looking at a shelf.

How long

Account and shelf data for as long as the account exists. Failed sign-in attempts for 30 days. Sessions until they expire or you sign out; changing the password ends all sessions immediately.

Your rights

Access, rectification, erasure, restriction of processing, data portability and the right to object. Two of them are built into the application and need no request:

A complaint can be lodged with the Czech Office for Personal Data Protection (uoou.gov.cz) or with the supervisory authority in your own EU country.

Security

Passwords through scrypt, sessions in the database, transport over HTTPS, a limited number of sign-in attempts, anti-forgery protection on every action. Nobody can promise absolute security; this is what has been done.

Changes

When the text changes, the date at the top changes. A substantial change will be announced by e-mail to the address on the account.