The short version
Everything you enter is written to your own device first, and Finly works fully offline. If you create an account, six kinds of record sync to a server we run ourselves, but receipt photos never do. There are no advertising pixels and no third-party cloud holding your records in readable form: the nightly backup is encrypted before it leaves the server. Google Analytics sees page views and rough usage counts, never what you actually recorded, and Cloudflare passes requests through to the server without storing your records. One thing does involve someone else in a different way: voice input is processed by your browser's speech engine, explained below.
What stays on your device
Finly is local-first. When you type or speak an expense it is saved into your browser's own storage (IndexedDB) immediately, before anything touches the network. That is why the app keeps working on a plane or with no signal.
One kind of data never leaves that storage at all:
Receipt photos stay on your device, permanently. If you attach a photo of a receipt, the image is stored locally and is never uploaded, never synced, and never reaches our server, not even when you are signed in. It exists on that one device. If you clear the browser's data or lose the device, the photo is gone, and we cannot restore it for you because we never had it.
Your account
You can read existing data without an account. Adding or editing anything requires one, because that is what the sync is attached to.
When you sign up we store, on our own server:
- Your email address, and whether it has been confirmed.
- A hash of your password. It is a one-way hash, so we cannot read your password, and if you lose it we replace it rather than recover it.
- A session record while you are signed in, held in an httpOnly cookie your browser sends back to us.
- Short-lived verification codes for confirming your email or resetting your password. These are stored hashed and expire in ten minutes, so a copy of the database does not hand anyone a working code.
What syncs, and what it contains
If you are signed in, these sync to our server so the same data appears on your other devices:
| Record | What is in it |
|---|---|
| Expenses & income | Amount, category, date, payment method, your description, currency |
| Budgets | Per-category limits you set |
| Khata | Money lent and borrowed, including the name you type for the other person |
| Investments | Holdings, buys and sells, quantities and prices |
| Recurring rules | Expenses or income you set to repeat: amount, category, your description and how often |
| Profile & settings | Currency, language, and anything you fill in on the profile screen, which can include profession, employer, monthly income, a financial goal and a short bio |
Two of those deserve calling out plainly rather than burying.
Khata records contain other people's names. If you write down that Ahmed owes you money, Ahmed's name is in your account, and Ahmed never agreed to anything with us. We do not contact those people, do not build profiles of them, and do not use those names for anything at all. They exist only so your ledger reads correctly.
The profile fields are genuinely personal. Income, employer and profession are optional and blank unless you fill them in. They are only used to render your own screens. If you would rather we did not hold them, leave them empty.
The parts where data reaches someone else
Everything above is on hardware we control. The exceptions are listed below.
1. Voice input goes through your browser's speech engine
Finly's voice entry uses the Web Speech API built into your browser. We do not run our own speech service and we hold no audio. But in most browsers, Chrome and Edge included, that API is not local: your browser sends the audio to its own vendor's servers to be turned into text, under that vendor's privacy policy rather than ours.
In practice: if you speak an expense in Chrome, Google's speech service hears it. Finly only ever receives the text that comes back. If that is not acceptable to you, type your expenses instead: every feature works identically without the microphone, and Finly never opens it unless you press the button.
2. Investment prices are fetched by our server, not your browser
Live prices come from CoinGecko, Yahoo Finance and the Pakistan Stock Exchange. Those requests are made by our server, not by your device, which is a deliberate choice: it means those providers see our server asking about a symbol, and never your IP address, your device, or the fact that a particular person holds it. They are told a ticker and nothing else.
3. Webfonts: fixed on 20 August 2026
Until 20 August 2026 the marketing home page requested its typefaces from Google's font servers, which meant your IP address reached Google simply for opening it. Those font files are now served from this domain, so they do not.
The site's Content-Security-Policy has been narrowed to match, so a remote font, script or pixel added later would be blocked by the browser rather than quietly start leaking visitor addresses. Google Analytics, below, is the one thing on the allow-list.
4. Google Analytics, added on 27 August 2026
Finly now runs Google Analytics across the marketing site and the app. It records page views, rough visit counts, browser and device type, and an approximate location derived from your IP address, never the address itself and nothing that identifies you by name or account. It is the one exception here that is a marketing tool rather than something the product needs to function.
It does not see your financial records. Expenses, khata entries and investment holdings are never sent to Google; Analytics only knows which screens you opened, not what is in them. Nothing is sold, and ad personalisation is off.
5. Cloudflare carries traffic to the server
Since 22 August 2026, requests to finlywallet.com pass through Cloudflare, which shields the site from attacks and keeps it reachable. Traffic is encrypted between your browser and Cloudflare, and again between Cloudflare and our server, but Cloudflare necessarily handles it in between. It does not store your records: the sync endpoints tell it never to cache anything.
6. Encrypted backups are emailed off the server
Every night the database is backed up, and that backup is encrypted on the server before a copy is emailed to the operator's Gmail mailbox, so it survives even if the server does not. Google holds that file but cannot read it, and neither can anyone who gets into the mailbox: the key that opens it is not on the server and not in that mailbox.
What we do not do
There is no session recording, no heatmaps, no A/B testing tools, and no third-party tags beyond Google Analytics (described above). No advertising pixels, no ad SDKs, no data broker of any kind.
We do not sell data, share it with advertisers, or use it to train anything. There is no mailing list, so signing up does not add you to one. The only email Finly sends is transactional: confirm your address, reset your password.
Where it lives
On a single server in Frankfurt, Germany, rented from Hostinger and operated by us. The database, the sign-in system and the mail sender all run on that one machine.
That is a deliberate difference from the usual setup: there is no third-party authentication provider holding your identity, no managed database vendor holding your records, and no email platform holding your address. Fewer companies hold your data because fewer companies are involved.
The database is backed up every night, and each backup is encrypted and copied off the server (see above), so losing the server would not lose everyone's data. What it can still lose is anything synced since the last backup, which is up to about a day.
So the advice stands: treat your device as the real copy and the server as convenience. Finly has CSV export on the history screen. If your records matter to you, export occasionally.
Deleting your data
Your records are yours and you can take them or remove them:
- Export: CSV export of your history, from the History screen.
- Delete individual records: anything you delete in the app is removed from the server on the next sync, not merely hidden from you.
- Delete everything: Settings has a clear-all-data option for the copy on your device.
- Delete your account: ask us and we remove the account and everything attached to it from the server. Records are linked to your account with cascading deletes, so removing the account removes the rows rather than orphaning them.
If you are in the EU or UK, the rights you have under GDPR (access, correction, deletion, portability, objection) apply, and the export and deletion routes above are how they are served in practice. Ask if you need something the app does not already give you.
Children
Finly is not aimed at children and we do not knowingly create accounts for anyone under 13. If you believe a child has an account, tell us and we will remove it.
Changes to this page
If this changes in a way that affects what happens to your data, the date at the top changes and the substance is described here rather than summarised as "we updated our policy". This page describes things that are wrong as readily as things that are right. The Google Fonts request was one such thing and was fixed on 20 August 2026; Google Analytics was added on 27 August 2026 and is described above rather than left out; the backup schedule is still outstanding and is written above as it actually stands.
Contact
For anything about your data, a question, a correction, an export, or deletion, write to [email protected].
Finly is run by one person, so that address reaches Abdul Rehman directly rather than a support queue. A reply may take a few days, and that is the honest expectation to set rather than promising a response time nobody is staffed to meet.
You can also delete your data yourself at any time without asking: records are removed from the app, and CSV export works if you want a copy first. Receipt photos never left your device to begin with.