Skip to content
OwnFi
  • Product
  • All features
  • Privacy
  • Support
Get OwnFi

Privacy Policy

Last updated: September 23, 2026

OwnFi is a privacy-first personal finance app. It is designed to run entirely on your device. Your financial data is not uploaded to an OwnFi server, and OwnFi does not sell, rent, or share your personal or financial information. This policy explains what data the app handles and how it stays on your device.

Local financial data

OwnFi stores your account email, password hash, imported statements, transactions, accounts and balances, portfolio holdings and investment transactions, asset valuations, net worth snapshots, target allocations, budgets, budget rollover, savings goals, debts and debt payments, subscriptions, receipts, financial memories, merchant rules and aliases, category corrections, import history, saved statement formats, wealth alerts, cached exchange rates, and preferences in the app database on this device. This financial data is not uploaded to an OwnFi server. From version 1.9 that database is encrypted on the device with a random key that lives only in the iOS keychain or the Android keystore, and the database, downloaded AI models, crash logs and the share inbox are excluded from iCloud and Finder backups on iOS and from cloud backup and device-to-device transfer on Android; OwnFi's own encrypted backup is the way to carry your data to another device.

Documents, camera, and photos

PDF, CSV, OFX, XLSX, receipt, and screenshot imports are used only to extract transactions and holdings you choose to add. Password-protected PDFs are unlocked on your device with the password you type. That password is held in memory only for as long as the import takes, is used for that one file, and is never written to the database, saved, logged, or transmitted. Camera access is used for receipt and screenshot capture. Photo access is used when you choose an image from the system picker.

Investments and net worth

Holdings can be entered by hand or imported from broker files you provide — OFX activity files, broker CSVs, Zerodha holdings spreadsheets, and CDSL consolidated account statement PDFs. These files are parsed on your device. OwnFi does not connect to a broker, does not log in on your behalf, and cannot see any account you have not imported yourself.

Net worth, the Investment Score, and the wealth forecast are computed on this device from the accounts, holdings, valuations, and debts you have entered. Net worth snapshots and score history are stored locally so the app can show change over time. The only outbound request any of this makes is a public market-price lookup for ticker symbols you add, described under Optional network access — the symbol is sent, never a quantity, a balance, a position size, or an account identifier.

Watched folder

You can point OwnFi at one folder on your device so that statements you drop there can be imported without picking each file. Choosing a folder grants the app read access to it: on iOS the grant is stored as a security-scoped bookmark, on Android as a folder URI. That grant is held in the device keychain or keystore, is never written to a plaintext file, a backup, or a log, and never leaves the device.

Nothing is scanned in the background and there is no timer. A scan happens only when you tap "Scan now", and files are read only to extract transactions and holdings you then confirm. You can change or stop watching the folder at any time in Settings, which discards the grant — and so does deleting your account.

Share Sheet and Voice Entry

On iOS, the OwnFi Share Extension lets you send PDFs, screenshots, and CSVs from other apps into OwnFi. On both platforms, voice entry and Siri Shortcuts / App Intents accept phrases like "add $15 coffee at Starbucks" and turn them into a transaction. Voice text is parsed on-device by the app's local parser; nothing is sent to an OwnFi server for transcription or interpretation. Where on-device dictation is used, it is handled by the operating system under its own privacy terms.

Quick Add gesture

You can bind a device gesture — Back Tap on iOS, Quick Tap or a launcher shortcut on Android — to log an expense without opening the app first. On iOS this uses OwnFi's Shortcuts actions: the amount, category, and note you enter are held in a shared container that only OwnFi and its own extensions can read, and are saved into the local database the next time you open the app. On Android the gesture simply opens OwnFi to a two-field quick-add form. Both paths run entirely on your device, add no permissions, and can be turned off in Settings.

Forecasts and projections

The Time Machine projects your future balance, and any "what if" changes you add, using only data already stored on this device — your recurring income, bills, debts, savings goals, and past spending. The calculation runs locally in the app; no forecast input or result is uploaded, and the "what if" changes you try are held in memory only — they are never written to your database and never leave the device. The wealth forecast projects net worth over longer horizons, up to twenty years, in the same way and on the same device. Projections are estimates based on your own data, not guarantees, and are not financial, investment, tax, legal, or accounting advice.

Notification and alert capture

On Android, if you explicitly grant the notification-listener permission, OwnFi reads bank and payment push notifications and turns them into transactions. It does not read SMS messages and requests no SMS permissions. Only notifications that look like a transaction alert are kept, and only from known bank and payment apps or apps you switch on in Settings — any other app that sends a money alert is listed by name so you can enable it, and its notification text is never read until you do. Processing is entirely on-device. On iOS, Apple Pay purchases, bank SMS alerts and (on iOS 27 and later) bank or payment app notifications can be captured only through Shortcuts automations you create yourself; those run the OwnFi actions you chose and hand the result to the app, which parses it on-device. You can revoke either at any time — in Android's Notification access settings, or by deleting the automation in Shortcuts — and captured alerts are only kept as parsed transactions in the local database.

Home-screen widgets

iOS and Android widgets display a small snapshot of budget progress, upcoming bills, savings goals, and exchange rates. Snapshots are generated on-device by the app and stored in a shared container that only OwnFi's widget extensions can read. Nothing is uploaded.

Apple Watch

If you pair an Apple Watch, the iPhone app sends the watch the same small on-device snapshot the widgets use — safe-to-spend, your next upcoming bill, and their display settings. The snapshot travels directly from your phone to your paired watch over Apple's device-to-device connection (Bluetooth or your local Wi-Fi); it does not pass through an OwnFi server or the internet, and the watch stores it locally so it can display it offline. The watch never accesses your full financial database. Voice quick-add on the watch uses the system dictation keyboard, which is provided by the operating system under Apple's own privacy terms; the resulting text is then parsed on your phone by the app's local parser, exactly like Siri voice entry.

Card & Debt Health

Card & Debt Health is a 0–100 figure OwnFi works out on your device from your own card balances, the credit limits you enter, your recorded payments, and your stated income. It is the app's own description of those inputs. It is not a score from any credit bureau, OwnFi never contacts a bureau, and no credit report is requested, received, or stored. Where a component has no data it is left out and the omission is shown alongside the figure rather than filled in with an assumption.

If you separately choose to type in a score you obtained elsewhere, it is stored locally like any other figure you enter, shown apart from OwnFi's own, and is never sent anywhere.

Backups and family sync

Backup and family sync packages are created only when you request them and are encrypted with AES-256 using a key derived from your account credentials, before any transfer. Inside that encrypted package, alongside your financial data, is your account email address — a backup carries it so a restore can be matched to the right account, and a sync package carries the sender's and the recipient's so the receiving device can confirm the package was meant for it. Because a package only exists when you create one and only goes where you send it, this is the one way your email address can leave the device, and it does so only in encrypted form under a key OwnFi never holds. Family sync offers two ways to deliver a package. Nearby sync discovers your family member's device on the same Wi-Fi network and sends the encrypted package directly from one device to the other over your local network — the data never touches the internet or any server. File sync travels through your device's standard share sheet, so you control where the file is saved or sent — Files, iCloud Drive, Google Drive, email, messaging, or elsewhere. In both cases, OwnFi never receives the package or the encryption key.

Cash plan answers. From version 2.0, the answers you save for your cash plan — the minimum you keep in chequing, your emergency savings target, money already set aside, the income and one-off expenses you expect, and the order of your priorities — are kept with your other settings. They are included in your encrypted backup and, if you use family sync, shared with the family members you sync with. Your confirmation that your balances are current is kept on the device where you made it and in your own encrypted backup; it is never included in a family sync package. What-if comparisons, the subscriptions you mark as still valued, and the investing-readiness view are worked out on screen and never saved.

What nearby sync announces. While the nearby-sync receiving screen is open, your device advertises itself on the local network so the sending device can find it. That advertisement is a generic label — the platform name and a random six-character code, such as "OwnFi Android K4J2H9" — and a one-way hash of your account that the sending device compares against the address it was given, so it knows it has found the right receiver. The hash cannot be turned back into your email address, though someone who already knew that address could compute the same hash and recognise it. Any device on the same Wi-Fi network can see the label for as long as the screen stays open; it stops the moment you leave. The financial package itself stays encrypted and is transferred only to the device you accept. If you would rather announce nothing at all, use file sync instead, which broadcasts nothing on the network.

Biometrics and notifications

Face ID, Touch ID, or fingerprint authentication is used only to unlock the local app session, either at launch or from the sign-in screen. The enrollment record identifies which local account to reopen; it holds no password, and your biometric data itself is never available to OwnFi — it stays with the operating system. Signing out keeps the enrollment so you can unlock again; "Sign Out & Forget" in Settings erases it, and tells you if the erase did not succeed rather than claiming it did.

Budget, bill, subscription, and wealth alerts — such as a holding drifting from your target, a valuation going stale, or a savings goal falling behind — are evaluated on your device and scheduled locally through the operating system. There is no OwnFi push server; no alert is composed, routed, or delivered by us, and none of the data behind one leaves the device.

Optional network access

Financial transaction data is not uploaded for analysis. Optional network calls are strictly limited to the following, and only occur when you use the corresponding feature:

  • huggingface.co — downloading a language model file if you choose to install one from the Model Library, using a Hugging Face token you provide.
  • open.er-api.com — fetching daily exchange rates if you use multi-currency features.
  • query1.finance.yahoo.com — fetching public market prices for portfolio ticker symbols you add. Only the public ticker symbol is sent, never account or transaction data.

The app may also open documentation links, and the partner-offer links described below, in your browser when you tap them. Family sync's nearby transfer stays on your local Wi-Fi network and never reaches the internet — this is why the app asks for local network permission when you use the feature. Finding the other device is a broadcast rather than a private exchange: while you are receiving, your device announces a generic label and a one-way account hash to the network, as described under Backups and family sync — not your email address. Only the encrypted package that follows is sent solely to the device you accept. No other outbound network calls are made.

AI and financial guidance

AI insights run on-device. The advisor uses your operating system’s own on-device model where the device provides one, or a local Gemma model you install from the Model Library. When neither is available, a deterministic advisor answers from your data using pure calculations. In every case the model runs on this device: your questions and financial context are not transmitted to an OwnFi or third-party AI server.

Figures in an answer are computed by OwnFi’s own code before the model writes anything, and an answer whose numbers cannot be traced back to your data is withheld rather than shown. Text prepared for a model is masked first, so account numbers, card numbers, emails, and phone numbers are removed before the model sees it. A chat thread is held in memory for that conversation only — it is never written to the database, and starting a new chat discards it. AI-generated content is educational and informational only, and is not financial, investment, tax, legal, or accounting advice.

Partner offers

Settings has an optional Partner offers screen for approved brokers, tax-filing services, international money-transfer providers, and similar products. OwnFi may earn a commission if you sign up. You choose the offer country independently of your reporting currency. Tapping an offer hands an ownfiapp.com link to the system browser; no partner code runs inside the app and the app makes no request of its own.

OwnFi attaches only fixed source and placement labels, never an account, transaction, balance, email, or device identifier. Your browser and the destination websites still receive ordinary web-request information such as IP address and user agent. Their terms and privacy policies apply after you leave OwnFi. Offers are not selected from financial data and can be hidden at any time. See the partner offers page.

Tracking and analytics

OwnFi does not include advertising SDKs, third-party analytics SDKs, or cross-app tracking. There is no telemetry describing which features you use, which screens you open, or what your finances look like.

Deleting your data

You can delete your local account and app data from Settings. This removes local financial data — including holdings, valuations, net worth history, and alerts — along with preferences, model tokens, biometric session data, access to any folder you asked OwnFi to watch, cached widget snapshots, and scheduled finance notifications from this device. Signing out or deleting your data also pushes a signed-out snapshot to a paired Apple Watch, clearing the figures it displays. Uninstalling the app removes everything else, including any downloaded model files.

Questions about your privacy?
Contact us at info@ownfiapp.com. If this policy changes, the updated version will be posted on this page with a new "Last updated" date.
OwnFi

Private finance,
powered on-device.

ProductProduct tourAll featuresPrivacy proof
CompanySupportPrivacy policyTerms of servicePartner offersDelete your data
Compare & guidesMint alternative (Canada)YNAB alternative (Canada)Monarch alternative (Canada)Budget app without bank loginBudget app without subscriptionBank statement to CSVYNAB CSV from a statementCredit card statement analyzerUPI expense trackerExpense tracker for iPhone in IndiaCanada statement guideIndia statement guideCountry guides
Get OwnFiApp StoreGoogle Play
© 2026 OwnFi. All rights reserved. No trackers. No financial-data cloud.