lock
Local-First & Privacy-First by Design
1. Local-First Storage: Spendly runs in your browser and works offline. Your expenses, budgets, friend-ledger records, and settings are created and stored locally on your device using native IndexedDB and localStorage. For now this on-device data is stored in plain form (not encrypted at rest), so protect your device accordingly. Nothing leaves your device unless you explicitly turn on an optional feature below.
2. Optional Google Sign-In: To prepare for cross-device sync, Spendly can connect to your Google account. Sign-in is optional and identity-only: Google returns a signed token containing your account ID, name, email address, and profile photo, which Spendly keeps in your browser to recognize you. This version requests no access to your Google Drive, contacts, or any other Google data. You can sign out at any time from Settings ▸ Data & Privacy.
3. No Tracking & Full Control: We do not embed analytics trackers, advertising pixels, or third-party telemetry, and we never sell your personal or financial data. You own your data — export it to CSV/Excel or a JSON backup at any time, or permanently clear everything with a single click.
4. Encrypted Cloud Sync (Optional, Coming Soon): A future update will let you sync across devices without us ever being able to read your finances. Records will be encrypted on your device before upload, and our servers will only ever store unreadable ciphertext. The encryption key is generated on your device and kept in your own private Google Drive storage — never sent to us — so no one at Spendly can decrypt your data. This feature is not active yet; today, no financial data leaves your device.