Security

Privacy is a product requirement, verified by architecture tests and a dependency tree that ships without a network client in V1.0.

Db

Encrypted vault

Household records live in an encrypted on-device database. Attachments are encrypted at rest in app-private storage.

Pin

App lock

Optional PIN with keystore-backed hash, auto-lock, biometric unlock and a Forgot PIN path that stays reachable during lockout.

Bk

Honest backups

`.flmbackup` files are created only when you ask, protected by a password or app PIN, with restore rollback if something goes wrong.

No silent cloud copy

Android auto-backup and iOS ubiquity backup of the vault are disabled so a device restore cannot recreate an encrypted database without the key you control.

Zero network for household data (V1.0)

The release dependency tree is checked so V1.0 does not ship an HTTP client for family, documents or expenses. No analytics SDK. No account server.

Screen privacy

Release builds can block casual screen capture of the vault on supported platforms. Debug builds stay capturable for development.

Delete everything

Settings offers Delete all data after typing a confirmation token. Uninstalling the app also removes the local vault unless you kept a backup file elsewhere.

Full policy: Privacy policy