Finly / Privacy

What we store, and what never leaves your device

Finly is a money app, so this matters more than usual. This page describes what the software actually does, including the one place your data genuinely does reach someone else, which most policies skip.

Last updated 13 September 2026. This describes how Finly works and how it is operated. It is a plain description, not legal advice.

The short version

In one paragraph

Everything you enter is written to your own device first, and Finly works fully offline. If you create an account, six kinds of record sync to a server we run ourselves, but receipt photos never do. There are no advertising pixels and no third-party cloud holding your records in readable form: the nightly backup is encrypted before it leaves the server. Google Analytics sees page views and rough usage counts, never what you actually recorded, and Cloudflare passes requests through to the server without storing your records. One thing does involve someone else in a different way: voice input is processed by your browser's speech engine, explained below.

What stays on your device

Finly is local-first. When you type or speak an expense it is saved into your browser's own storage (IndexedDB) immediately, before anything touches the network. That is why the app keeps working on a plane or with no signal.

One kind of data never leaves that storage at all:

Receipt photos stay on your device, permanently. If you attach a photo of a receipt, the image is stored locally and is never uploaded, never synced, and never reaches our server, not even when you are signed in. It exists on that one device. If you clear the browser's data or lose the device, the photo is gone, and we cannot restore it for you because we never had it.

Your account

You can read existing data without an account. Adding or editing anything requires one, because that is what the sync is attached to.

When you sign up we store, on our own server:

What syncs, and what it contains

If you are signed in, these sync to our server so the same data appears on your other devices:

RecordWhat is in it
Expenses & incomeAmount, category, date, payment method, your description, currency
BudgetsPer-category limits you set
KhataMoney lent and borrowed, including the name you type for the other person
InvestmentsHoldings, buys and sells, quantities and prices
Recurring rulesExpenses or income you set to repeat: amount, category, your description and how often
Profile & settingsCurrency, language, and anything you fill in on the profile screen, which can include profession, employer, monthly income, a financial goal and a short bio

Two of those deserve calling out plainly rather than burying.

Khata records contain other people's names. If you write down that Ahmed owes you money, Ahmed's name is in your account, and Ahmed never agreed to anything with us. We do not contact those people, do not build profiles of them, and do not use those names for anything at all. They exist only so your ledger reads correctly.

The profile fields are genuinely personal. Income, employer and profession are optional and blank unless you fill them in. They are only used to render your own screens. If you would rather we did not hold them, leave them empty.

The parts where data reaches someone else

Everything above is on hardware we control. The exceptions are listed below.

1. Voice input goes through your browser's speech engine

Read this one

Finly's voice entry uses the Web Speech API built into your browser. We do not run our own speech service and we hold no audio. But in most browsers, Chrome and Edge included, that API is not local: your browser sends the audio to its own vendor's servers to be turned into text, under that vendor's privacy policy rather than ours.

In practice: if you speak an expense in Chrome, Google's speech service hears it. Finly only ever receives the text that comes back. If that is not acceptable to you, type your expenses instead: every feature works identically without the microphone, and Finly never opens it unless you press the button.

2. Investment prices are fetched by our server, not your browser

Live prices come from CoinGecko, Yahoo Finance and the Pakistan Stock Exchange. Those requests are made by our server, not by your device, which is a deliberate choice: it means those providers see our server asking about a symbol, and never your IP address, your device, or the fact that a particular person holds it. They are told a ticker and nothing else.

3. Webfonts: fixed on 20 August 2026

Resolved

Until 20 August 2026 the marketing home page requested its typefaces from Google's font servers, which meant your IP address reached Google simply for opening it. Those font files are now served from this domain, so they do not.

The site's Content-Security-Policy has been narrowed to match, so a remote font, script or pixel added later would be blocked by the browser rather than quietly start leaking visitor addresses. Google Analytics, below, is the one thing on the allow-list.

4. Google Analytics, added on 27 August 2026

Finly now runs Google Analytics across the marketing site and the app. It records page views, rough visit counts, browser and device type, and an approximate location derived from your IP address, never the address itself and nothing that identifies you by name or account. It is the one exception here that is a marketing tool rather than something the product needs to function.

It does not see your financial records. Expenses, khata entries and investment holdings are never sent to Google; Analytics only knows which screens you opened, not what is in them. Nothing is sold, and ad personalisation is off.

5. Cloudflare carries traffic to the server

Since 22 August 2026, requests to finlywallet.com pass through Cloudflare, which shields the site from attacks and keeps it reachable. Traffic is encrypted between your browser and Cloudflare, and again between Cloudflare and our server, but Cloudflare necessarily handles it in between. It does not store your records: the sync endpoints tell it never to cache anything.

6. Encrypted backups are emailed off the server

Every night the database is backed up, and that backup is encrypted on the server before a copy is emailed to the operator's Gmail mailbox, so it survives even if the server does not. Google holds that file but cannot read it, and neither can anyone who gets into the mailbox: the key that opens it is not on the server and not in that mailbox.

What we do not do

There is no session recording, no heatmaps, no A/B testing tools, and no third-party tags beyond Google Analytics (described above). No advertising pixels, no ad SDKs, no data broker of any kind.

We do not sell data, share it with advertisers, or use it to train anything. There is no mailing list, so signing up does not add you to one. The only email Finly sends is transactional: confirm your address, reset your password.

Where it lives

On a single server in Frankfurt, Germany, rented from Hostinger and operated by us. The database, the sign-in system and the mail sender all run on that one machine.

That is a deliberate difference from the usual setup: there is no third-party authentication provider holding your identity, no managed database vendor holding your records, and no email platform holding your address. Fewer companies hold your data because fewer companies are involved.

Honest about backups

The database is backed up every night, and each backup is encrypted and copied off the server (see above), so losing the server would not lose everyone's data. What it can still lose is anything synced since the last backup, which is up to about a day.

So the advice stands: treat your device as the real copy and the server as convenience. Finly has CSV export on the history screen. If your records matter to you, export occasionally.

Deleting your data

Your records are yours and you can take them or remove them:

If you are in the EU or UK, the rights you have under GDPR (access, correction, deletion, portability, objection) apply, and the export and deletion routes above are how they are served in practice. Ask if you need something the app does not already give you.

Children

Finly is not aimed at children and we do not knowingly create accounts for anyone under 13. If you believe a child has an account, tell us and we will remove it.

Changes to this page

If this changes in a way that affects what happens to your data, the date at the top changes and the substance is described here rather than summarised as "we updated our policy". This page describes things that are wrong as readily as things that are right. The Google Fonts request was one such thing and was fixed on 20 August 2026; Google Analytics was added on 27 August 2026 and is described above rather than left out; the backup schedule is still outstanding and is written above as it actually stands.

Contact

For anything about your data, a question, a correction, an export, or deletion, write to [email protected].

Finly is run by one person, so that address reaches Abdul Rehman directly rather than a support queue. A reply may take a few days, and that is the honest expectation to set rather than promising a response time nobody is staffed to meet.

You can also delete your data yourself at any time without asking: records are removed from the app, and CSV export works if you want a copy first. Receipt photos never left your device to begin with.