Privacy policy
Last changed 23 Sept 2026.
The data controller is EUROSIGN s.r.o., company ID 49446100, registered office Vysoká 532/8, Štýřice, 639 00 Brno. You can reach us at info@finisht.app.
What Finisht is
Finisht is a shelf of what you have watched, read, listened to, played and put in your headphones. Data about what you consume is yours. The application keeps it to show it back to you, not to monetise it.
What data is kept
- Account. E-mail, handle, display name, an optional bio. The password itself is not stored — the database holds only its hash (scrypt), from which the password cannot be recovered.
- Shelf. Items, status, rating, notes and records of when you consumed what. This is the content the application exists for.
- Import rows. The uploaded file is not stored, but its individual rows are — they carry the original titles and times as the other service wrote them. They are kept so that you can trace what was matched to what, and they stay as long as the account does. You can download them together with the rest of your data.
- Connected accounts. When you connect Spotify or sign in through another account, the identifier of your account at that service and the credentials it issued are stored. The credentials are encrypted in the database. Disconnecting also removes the data that came through the connection.
- Notifications. When you turn them on, the address issued by your browser and the keys used to encrypt the message are stored. Turning them off deletes them.
- Sign-in attempts. IP address and handle of failed sign-in attempts, for 30 days. It is the only defence against password guessing; without it, trying forever would be enough.
- Sessions. A random identifier in a cookie and a database record with creation and expiry time.
- Social layer. Whom you follow, what you reacted to and what you wrote in comments.
- Outgoing e-mails. The address and content of a password reset or address verification message. They are kept after sending too: the content for 7 days (as long as the longest link it carries stays valid), after which it is erased, and the delivery record — address, subject and timestamps — for 90 days.
Cookies
The application uses technical cookies only, no analytics
and no advertising. finisht_session keeps you signed in,
finisht_pre carries the anti-forgery token for a visitor
who is not signed in, and lang remembers the language
you picked. Three more exist only while you sign in through another
account or connect Spotify (finisht_oauth,
finisht_pending, finisht_spotify): they
hold the operation in progress and are removed as soon as it
finishes. No tracking, no advertising, no third party — which is
why there is no consent banner: the law does not require consent
for strictly necessary cookies.
What others can see
A shelf is public by default — that is the point of the social layer. You can switch it to private at any time in Settings; it then disappears from the feed, from search and from the profile, and individual items become inaccessible too. A single item can be hidden on its own.
Search engines are separate. A public shelf has an address anyone can open — but it does not reach Google or any other search engine until you explicitly turn that on in Settings. It is off by default and the pages carry a tag that forbids indexing. Turning it on is one click; taking back a page a search engine has already fetched takes more than one.
Your e-mail is never visible to anyone but you.
Who receives the data
Nobody who would profit from it. This is what leaves the server:
- Catalogue look-ups when matching titles and fetching covers: Open Library, MusicBrainz, Cover Art Archive, Steam, TMDb, Apple, TVmaze, Deezer, Wikipedia, Wikidata and Filmtoro. What is sent is the title of a work, not who has it on their shelf — the query is made for an item in the catalogue, not for a person, and it is the same for an item a hundred people have as for one that one person has.
- Running the application. The server and the database run at Hetzner Online GmbH (Germany), so everything listed above physically sits there. Traffic between your browser and the server goes through Cloudflare, which also serves the domain. Both are processors — they handle the data for us and on our instructions, not for themselves.
- E-mails through Resend (Resend, Inc., USA) — only password reset and address verification messages. What is sent is the recipient's address and the content of the message.
- Notifications through your browser's push service (Google, Apple or Mozilla, depending on which you use), and only if you turned them on. The message is encrypted with a key only your browser has — the service sees that something arrived, not what.
- Connected accounts, if you connect one: with Spotify, credentials are exchanged and your listening history is fetched; with a sign-in provider, only your identity is verified.
Covers from other catalogues are served through our own proxy precisely so that the other server does not learn who is looking at a shelf.
How long
Account and shelf data for as long as the account exists. Failed sign-in attempts for 30 days. Sessions until they expire or you sign out; changing the password ends all sessions immediately.
Your rights
Access, rectification, erasure, restriction of processing, data portability and the right to object. Two of them are built into the application and need no request:
- Download your data as JSON.
- Delete the account in Settings. This removes the account, the shelf, records, import rows, connected accounts, notification subscriptions, follows, reactions, comments and sessions. It is irreversible and no confirmation e-mail is sent. It also applies to an account that only signs in through another service and has no password — there you type the word SMAZAT to confirm.
A complaint can be lodged with the Czech Office for Personal Data Protection (uoou.gov.cz) or with the supervisory authority in your own EU country.
Security
Passwords through scrypt, sessions in the database, transport over HTTPS, a limited number of sign-in attempts, anti-forgery protection on every action. Nobody can promise absolute security; this is what has been done.
Changes
When the text changes, the date at the top changes. A substantial change will be announced by e-mail to the address on the account.