Privacy Policy
Last updated: 16 August 2026
Finances is a personal finance app for your desktop, made by Steve Harrison, an independent developer based in Australia ("we", "us"). This policy explains what data the Finances app and the thefinances.app website collect, why, and what happens to it.
Finances is built local-first. Your financial data — transactions, accounts, budgets, attachments — lives in a database on your own computer. You can make this encrypted or not. We can't access it.
The app: your data stays on your computer
Everything you put into Finances is stored in an SQLite database on your device. New databases are encrypted by default (you can turn this off); on macOS, the encryption key is stored in your Keychain and unlocking can be protected by Touch ID or your system password. There is no account to create, no cloud sync of your financial data, and no code path that uploads your transaction history to us.
Because your data lives only on your machine, you're also responsible for backing it up — see our Terms of Service.
What the app does send over the network
The app makes a small number of network requests to function. Here is the complete list:
License checks
When you activate or use a paid license, the app sends your license key to our server so we can confirm the license is valid. Offline license keys are verified entirely on your device and send nothing.
Update checks
The app periodically checks our server for new versions. This sends standard update-check information such as your current app version and platform.
Usage analytics
The app sends anonymous usage events (such as "app opened", "page viewed", or "feature used") to Aptabase, a privacy-focused analytics service, hosted in the EU. These events tell us which features are used so we know what to improve. They never include any financial data.
Merchant lookup
If you create or edit a merchant and use the autocomplete search field, that query is sent to a maps provider to find the business. Normally that's Apple Maps — the query goes from your device straight to Apple, and we can't see it. If Apple Maps isn't available, the lookup falls back to Google Maps: either directly from your device using a Google API key you supply, or through our server, which forwards the query to Google and uses your license key (or trial status) to meter lookups — in that case the query does pass through our server. Merchant logos and photos are loaded by your device from the sites that host them.
Reference data lookups
A few features fetch reference data that includes nothing about you or your finances: converting a foreign-currency transaction fetches that day's exchange rate from Frankfurter (only the date and currency are sent, never amounts), and the "What if" comparison fetches historical prices for a fixed set of market tickers from Yahoo Finance.
Bank connections (optional)
If you choose to connect a bank instead of importing files, the app talks to the provider you pick:
- Up Bank and Redbark — your device talks to these APIs directly using API keys you provide. Nothing passes through our servers.
API keys are stored on your device, encrypted using the operating system's secure storage. Bank connections are entirely optional — you can use Finances purely with manual file imports.
The website
When you use thefinances.app, we collect:
Purchases
Payments are processed by Stripe. Your card details go directly to Stripe and never touch our servers. After a purchase we store your email address, your license key, your plan type, and Stripe reference IDs so we can deliver your license, manage your subscription, and provide support. Your license key is emailed to you via Resend, our email delivery provider.
"Keep updated" sign-up
If you enter your email to hear about updates, we store that email address and use it only to send you news about Finances. Ask us at any time and we'll remove it.
Support emails
If you email us at finances@steveharrison.dev, we keep your message and email address so we can reply and follow up on your request.
Analytics and cookies
The website uses two analytics services: Google Analytics, which sets cookies to distinguish visitors, and Plausible, which is cookieless. We use these to understand how people find and use the site. Google Analytics cookies are the only cookies the site sets — we don't use advertising or cross-site tracking cookies. If you prefer not to be counted, browser settings or content blockers that block analytics will not affect your use of the site.
Third-party services we rely on
These are the services that may process data on our behalf, and what they handle:
- Stripe — payment processing (card details, billing email)
- Resend — sending license emails
- Railway — hosting our server and licence key database
- Redbark — optional bank API connection
- Google — website analytics, and Maps merchant lookup when Apple Maps isn't used
- Apple — Maps merchant lookup
- Aptabase — anonymous app usage analytics (EU-hosted)
- Plausible — cookieless website analytics
Each of these processes only what's described above. We don't sell or rent your personal information to anyone, and we don't share it with anyone else except where required by law.
How long we keep data
- License records (email, license key, plan, Stripe IDs) — for as long as your license exists, plus whatever period tax and accounting law requires.
- Mailing list emails — until you ask to be removed.
- Support emails — for as long as they're useful for helping you and improving the app; ask and we'll delete yours.
- Your financial data — we never had it. Deleting the app's data folder from your computer deletes it completely.
Security
If encryption is enabled (the default), your local database is encrypted at rest with a key held in your operating system's keychain. If the encryption feature is turned off, we recommend you keep your hard drive and user account secure. On our side, payment details are handled entirely by Stripe, our server stores the minimum described above, and access to it is limited to us.
Your rights
You can ask us to access, correct, or delete the personal information we hold about you (your email, license record, or support correspondence), or object to how we use it. We handle personal information in accordance with the Australian Privacy Act 1988 and the Australian Privacy Principles; if you're in the UK or EU, you have equivalent rights under the GDPR. Email us at finances@steveharrison.dev and we'll respond promptly. If you're unsatisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) or your local data protection authority.
Changes to this policy
If we change this policy, we'll update this page and the date at the top. If a change meaningfully affects how we handle your data — for example, a new service that processes personal information — we'll say so prominently.
Contact
Questions about privacy? Email us at finances@steveharrison.dev and we'll get back to you.