privacy architecture local-first

Building a Privacy-First Finance App

PocketVault Finance Team 3 min read

Why privacy matters for finance apps

Your transaction history is one of the most revealing datasets about you that exists. It shows where you shop, roughly what you earn, what you spend on health, who you donate to, and what your week looks like. Most finance apps still ask you to hand your bank credentials to an aggregator like Plaid, which then holds all of it.

We didn’t want to be another company asking for that, so we built the app to never receive it.

The local-first approach

PocketVault Finance stores everything in an encrypted SQLite database on your device. The encryption key lives in your device’s own secure storage: Android Keystore, Apple Keychain, Windows DPAPI, or Linux libsecret. No server ever sees your transactions, because there is no server.

That choice buys more than privacy. Operations are fast because nothing waits on a network round trip. The app works on a plane, on the subway, and in a country where you haven’t bought a data plan. Your history outlives us, since a company shutdown can’t reach a database sitting on your phone. And when we say we can’t read your data, it isn’t a policy we’re asking you to trust us on; we genuinely have no way to.

The AI challenge

Running a language model was the hardest part by far. The usual route is to call a cloud API, which is a few days of work; we had to fit inference on a phone, inside a memory budget, without draining the battery.

We landed on Gemma models via flutter_gemma for on-device inference, and EmbeddingGemma 300M to find the records a question is about. On supported iOS devices, Apple Foundation Models do the same work with no model download at all. It took considerably longer than calling an API would have, and it is the reason a question about your money can be answered without a copy of the answer’s ingredients existing anywhere else.

One thing the model is not used for: categorising transactions, or reading your bank’s messages. Both are rule-based, deliberately, because a rule that gets something wrong gets it wrong reproducibly — and that is what lets us publish how often import fails.

What’s next

The remaining work is being built the same way: forecasting, anomaly detection and richer reports all run locally, on the device’s own arithmetic. Because of how the app is put together, we don’t have to weigh new features against what they’d expose. There’s nowhere for the data to go.