Privacy & local-first data
Understand where Finvue keeps normal finance records, what can leave this browser, and how to protect or move your data safely.
The 30-second version
The important boundaries, without the implementation details.
Normal finance stays local
Accounts, transactions, cards, loans, schedules, reports, and backups stay in this browser during normal use. Finvue does not automatically upload them to a hosted financial database.
Separate contexts
Another browser, browser profile, device, site origin, or installed-app context can have separate Finvue data. Finvue does not provide cross-device or cross-profile finance synchronization.
Backup is deliberate
Browser storage is not a backup. A current full Finvue JSON backup is the recovery and deliberate-transfer mechanism; a transaction CSV is not a complete recovery backup.
Optional AI is the exception
When you explicitly use a real AI review or column-mapping action, selected import rows or sample cells and required account, taxonomy, and counterparty context are sent through Finvue's server API to the configured OpenAI or Gemini provider. Do not use a real AI action if you do not want that selected context transmitted.
Where your data lives
Local-first describes the normal working location of Finvue finance records.
Finvue stores normal finance data in browser-local IndexedDB, through Dexie. Here, browser-local means the current browser profile and site-origin storage context—not a shared Finvue account database on a server.
Reports and Data Health are computed from that local data in the browser. Finvue has no hosted financial database for the normal household ledger.
- Household and member details
- Accounts, balances, and transactions
- Counterparties and transaction categories
- Credit-card, loan, and scheduled cash records
- Reports and Data Health results derived from those records
Local does not mean backed up
The browser copy is the active database, but it is not a guaranteed recovery copy.
Clearing browser or site data, removing a profile, losing a device, or browser storage eviction can make the local database unavailable. Private or incognito browsing is unsuitable for durable finance use.
A browser persistence grant can reduce some automatic-eviction risk, but it is not guaranteed, does not prevent deliberate clearing, and never replaces a full Finvue JSON backup.
No automatic sync
Finvue does not synchronize finance records across browser, profile, device, origin, or installed-app contexts.
On iPhone and iPad, Safari Finvue and Finvue opened from a Home Screen icon can use separate IndexedDB storage contexts. An empty Home Screen app does not, by itself, mean the Safari data was deleted.
What Finvue's server receives
Normal hosting requests and optional AI requests have different data boundaries.
Normal app use
Finvue’s Vercel-hosted application serves the HTML, JavaScript, CSS, icons, manifest, and deployment health metadata needed to run the app. Normal finance records are not automatically uploaded to a Finvue-hosted financial database as part of those operations.
Optional AI review and mapping
When you explicitly use a real AI review or column-mapping action, selected import rows or sample cells and required account, taxonomy, and counterparty context are sent through Finvue's server API to the configured OpenAI or Gemini provider. Do not use a real AI action if you do not want that selected context transmitted.
AI is optional for core finance use. These actions do not send a full Finvue backup or the entire database. Finvue does not claim zero retention by providers or hosting infrastructure; handling is subject to the configured provider and account controls.
Local-key mode
A provider key saved in local-key mode is stored in this browser, but each real AI request sends that key to Finvue's server route so it can call the selected provider. Finvue application code does not persist the key on the server.
Backup, persistence, and sync are different things
Similar words describe different protections and capabilities.
- Browser storage
- The active working copy of your finance records in this browser profile and site origin.
- Persistent storage
- A browser durability request that may reduce automatic eviction risk. It is not guaranteed and is not a backup.
- Full JSON backup
- A portable recovery copy you control. Use it to recover data or deliberately move Finvue to another context.
- Linked backup file
- An optional file-saving convenience where the browser supports it. It is not Finvue cloud synchronization.
- Synchronization
- Finvue does not currently synchronize finance records across browsers, profiles, devices, or app contexts.
Moving or recovering Finvue safely
Use the full JSON backup workflow when changing browser, profile, device, origin, or app context.
- Create a current full Finvue JSON backup in the source context.
- Open Finvue in the intended destination context.
- Import the full backup there; restore replaces rather than merges.
- Verify key records, reports, and Data Health.
- Keep the backup until you are satisfied with the destination.
- Do not clear the source site’s data before that verification.
This same procedure applies when deliberately moving from Safari to a Home Screen Finvue context. It is a manual transfer, not migration or synchronization performed by installation.
Installing Finvue
Installation changes how the app is launched; it does not create a hosted finance account.
Safe habits
- Keep current full Finvue JSON backups in a durable location you control.
- Use a normal browser profile rather than private or incognito storage.
- Do not clear site data until you have a current, verified backup.
- Remember that another browser, profile, device, or app context can start separately.
- Read the disclosure before invoking a real AI review or mapping action.
What this page is not
This page explains Finvue’s product data boundaries. It is not a legal privacy policy, a compliance or security certification, or a guarantee about third-party provider or hosting-infrastructure retention.