Privacy Policy

Last updated: July 30, 2026

OpenFi ("we," "our," or "the app") is a personal finance application for macOS. This Privacy Policy explains what data we collect, how it's used, and your rights.

Our Core Principle: Local-First

OpenFi is designed so your financial data stays on your device. Your transactions, balances, categories, goals, and reports are stored in a local database on your Mac — not on our servers.

What Data Stays on Your Device

The following data is persisted only on your Mac; we do not keep a server-side ledger or backup of it. Specific excerpts may be transmitted temporarily to the processors described below when you use a connected or AI feature:

What "No Server-Side Backup" Means for You

That data is stored in a SQLite database encrypted with SQLCipher. The encryption key is 32 random bytes generated on your Mac at first launch and kept in that Mac's Keychain (kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly). It is not derived from your password, it is never uploaded to us, and it is never synced to iCloud. Nobody outside your Mac — including us — can read that database.

The direct consequence is that we cannot restore your data for you. There is no server-side copy to fall back on, and no key escrow or recovery phrase. So:

This is a deliberate trade-off, not an oversight: the same property that stops anyone else reading your finances also stops us handing them back.

What Data Is Shared with Third Parties

To provide core functionality, OpenFi communicates with the following services:

Plaid (Bank Connectivity)

Google Gemini API (AI Features)

Firebase (Authentication, Sync Notifications & Crash Reporting)

Public Beta Signup, Cloudflare Turnstile & Resend

Apple TestFlight & App Store Connect (Beta Provisioning)

Discord (Internal Notifications)

Stripe (Payments)

NHTSA Vehicle API (VIN Decoding)

Hugging Face (Voice Model Download)

Analytics

OpenFi collects minimal, privacy-respecting analytics stored locally on your device:

This data is stored in your local database and is not transmitted to our servers. Settings can copy a privacy-safe report containing only aggregate counts and app/OS versions, which you may choose to share with us.

Data Security

Limited Records Retained After Account Deletion

Account deletion removes your Firebase authentication account, Stripe customer, active OpenFi account and beta-provisioning records, stored integration credentials, per-user rate-limit records, local financial database, and per-account Keychain credentials. The following narrowly scoped exceptions are retained to prevent deleted accounts from being recreated by delayed automation and to finish revocation requests that a third party has not yet confirmed:

Your Rights

Children's Privacy

OpenFi is not intended for anyone under 18, and the public-beta form requires confirmation that the requester is at least 18. We do not knowingly collect data from children.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes through the app or by email.

Contact

For privacy questions or data deletion requests: