← Back to FinanCards

Privacy Policy

Last updated: 21 July 2026

The short version: FinanCards stores everything on your device. There is no account, no ad tracking, and no analytics of any kind. The only time any data ever leaves your phone is if you choose to enable the optional Gemini API import feature for statements your phone can't read on its own — and even then, only the statement page images are sent, directly from your device to Google, using an API key you provide.

1. Who this applies to

This policy covers the FinanCards mobile app (Android and iOS), developed and operated by an individual developer as a personal, non-commercial project. FinanCards is not affiliated with, endorsed by, or sponsored by Maybank, RHB, HSBC, or any bank or financial institution. Bank names are used only to describe which statement formats the app can read.

2. What data FinanCards processes

When you import a credit card statement PDF, FinanCards extracts and stores, locally on your device only:

None of this data is transmitted anywhere by default. It is stored in a local database on your device and is never uploaded to any server operated by the developer, because no such server exists — FinanCards has no backend.

3. On-device processing

By default, statement PDFs are read entirely on your device: either by extracting the text layer directly, or — for statements that are scanned/image-only (some HSBC statements) — using Google's ML Kit on-device text recognition, which runs locally and does not send images anywhere.

4. Optional cloud processing (Gemini API)

Some statements have no usable text layer and on-device recognition alone isn't reliable enough to read them correctly. For these, FinanCards offers an optional, opt-in feature: if you generate and enter your own Google Gemini API key in Settings, FinanCards will send the rendered page images of that specific statement directly from your device to Google's Gemini API (generativelanguage.googleapis.com) to extract the data, using your API key.

5. Backup and export

FinanCards lets you export a backup of your data as a JSON file, and restore from one. This file is created and shared using your device's own share sheet (e.g. to save to a cloud drive, email to yourself, or transfer to another device) — FinanCards does not upload backups anywhere itself. Where that file ends up is entirely your choice and under your control.

6. Permissions

FinanCards does not request location, contacts, camera (beyond photo picking), microphone, or any other sensitive permission.

7. Data sharing

FinanCards does not sell, rent, or share your data with third parties, does not display ads, and does not use any analytics or tracking SDKs. The only third-party data flow is the optional Gemini API path described in Section 4, which only occurs when you explicitly enable it.

8. Data retention and deletion

Your data stays on your device for as long as you keep the app installed. Uninstalling FinanCards deletes its local database along with it. You can also delete individual cards, transactions, or categories at any time from within the app.

9. Children's privacy

FinanCards is a personal-finance tool intended for adult use and is not directed at children. It does not knowingly collect data from children.

10. Changes to this policy

If this policy changes, the "Last updated" date above will change accordingly. Since FinanCards has no accounts or push infrastructure, there is no mechanism to notify users directly — please check this page periodically.

11. Contact

Questions about this policy or your data can be sent to kenlowkahloong@gmail.com.