Privacy & security
Your money plan should not become someone else’s product.
FinKind is designed around data minimization, explicit choices, secure sessions, and honest offline behavior.
Manual first
A bank connection is optional convenience, not an entry fee.
Free planning works with balances and scheduled money you enter. FinKind does not require account credentials or transaction imports to answer what is safe to spend.
- No ads and no sale of personal financial data
- No transaction categorization requirement
- Future connections remain review-before-import and revocable
Secure access
Sessions are protected without exposing passwords to the App.
Passwords are handled by the identity boundary and never written to browser storage. Protected API calls use credentialed, server-managed sessions with anti-forgery and origin controls.
- Generic registration and recovery responses resist account discovery
- Explicit sign-out and session expiry
- No secrets or connection strings shipped in client code
Bounded offline use
Offline does not mean silently pretending to be synchronized.
When an authorized member temporarily loses connectivity, FinKind can use an encrypted device copy of the approved planning data. It clearly labels device-only work and detects conflicts before overwriting a newer plan.
- Static application assets only in the service-worker cache
- Protected API payloads are not cached by the service worker
- Export and deletion controls are part of M1 release readiness
Money help, without judgment
See the product with fictional money first.
The Demo stays separate from member accounts and resets whenever you want.