Privacy Policy
Last Updated: October 10, 2026 • Effective Immediatelycom.finwallet.app) was engineered as an offline-first financial tracker. Your transactions, accounts, categories, and receipts are stored on your local device. We do not sell, rent, monetize, or broker your personal financial records under any circumstances.
1. Overview and Scope
This Privacy Policy describes how FinWallet Pro ("we", "our", or "the App") handles information across all supported operating systems, including Android, iOS, Windows, macOS, and Linux. This policy is written in full compliance with the Google Play User Data Policy, Apple App Store Review Guidelines, and the EU General Data Protection Regulation (GDPR).
2. Data We Do NOT Collect
To ensure total user anonymity, FinWallet Pro strictly avoids the collection of sensitive tracking information:
- No Bank Account Credentials: We never integrate with banking screen-scraping services (such as Plaid, MX, or Yodlee). Your banking credentials are never requested or known.
- No Advertising Trackers: The application contains zero advertising software development kits (SDKs), zero marketing cookies, and zero behavioral trackers.
- No Location Tracking: We do not request, track, or store your GPS or geolocation data.
3. Data Stored Locally on Your Device
The vast majority of your data never leaves your hardware:
- Ledger Records: Account names, balances, income/expense records, categories, and currency settings are stored in an encrypted local SQLCipher SQLite database inside your operating system's application sandbox.
- Biometric Credentials & PINs: Your master unlock PIN and decoy duress PIN are hashed locally using PBKDF2-HMAC-SHA256 with 10,000+ rounds. Raw PINs and fingerprint/Face ID templates are held only in hardware keymasters (Android Keystore / iOS Keychain) and cannot be extracted by the app or sent to servers.
- Receipt OCR Images: Images of receipts and bills captured with your device camera are analyzed using on-device ML Kit computer vision models. Scanned images are processed entirely offline without transmission to cloud servers.
4. Optional Cloud Services (Opt-In Only)
If you choose to use our optional features, the following limited data processing applies:
- Optional Cloud Synchronization (Supabase): If you enable Cloud Sync in settings, your encrypted records (transactions, budgets, goals, and categories) sync via Supabase over TLS 1.3 encryption. Your data is isolated by PostgreSQL Row Level Security (RLS) policies and accessible only with your authenticated JWT token.
- Account Authentication: If you sign in to sync across devices, your email address is used solely for authentication and password recovery. We will never send marketing or promotional newsletters to this address.
- Subscription Entitlements (RevenueCat): In-app purchases and subscriptions are verified securely through RevenueCat and Google Play Billing / Apple StoreKit. RevenueCat receives only anonymous transaction receipts and random installation IDs to unlock Pro entitlements. No bank details or financial ledgers are ever passed to RevenueCat.
5. Data Retention and Self-Service Deletion
You retain complete ownership and control over your financial records:
- Local Data Wipe: Uninstalling the application or selecting Settings > Reset Data instantly erases all local SQLite databases and Keystore cryptographic verifiers from your device.
- Cloud Account & Data Purge: If you have an active Cloud Sync account, you can permanently delete your credentials and purge all synchronized database rows at any time directly in the app or via our public Account Deletion Portal. Cloud deletions are executed immediately in real-time.
6. Children's Privacy
FinWallet Pro is intended for general audiences aged 18 and older. We do not knowingly collect personal identifiable information from children under 13. If you become aware that a child has provided us with personal information, please contact us immediately.
7. Contact and Inquiries
For privacy inquiries, audit requests, or technical security reports, contact our privacy officer directly:
- Privacy & Support Email: support@finwallet.app
- Website: https://finwallet.app