In ordinary words
- Your statements, transactions, categories, budgets, goals, and reports stay in the desktop app on your computer.
- The website sees what you submit to the waitlist, website sign-in, tester access, and license services.
- If you connect Gmail, the desktop app reads supported bank alerts; the website does not receive your Gmail.
- If you turn on a cloud AI provider, the app shows you what kind of information may be sent before asking for consent.
1. Two separate data boundaries
The GODFIN desktop application stores statements, transactions, balances, categories, budgets, merchant memory, reports, audit history, and local credentials in local storage controlled by you. We do not operate a remote transaction database for the app.
The GODFIN website processes account identifiers, email address, purchase records, license status, device activation hashes, download access, and separately submitted waitlist details.
2. Website services
- Vercel hosts the marketing and account website.
- Supabase provides website authentication and license records.
- Cashfree processes payments; GODFIN does not store full card details.
- Resend delivers transactional license and account email.
3. Why each website service needs data
- Waitlist details are used to confirm interest, choose suitable beta computers, and contact invited testers.
- Website sign-in identifies your tester or customer account.
- Purchase and license records provide access, invoices, fraud review, and device management.
- Support messages are used to answer the request you send.
These purposes do not authorize GODFIN to upload the ordinary finance record stored by the desktop app.
4. Google sign-in and Gmail are different
Google sign-in on the website is used to authenticate your GODFIN website account. Optional Gmail access in the desktop app is a separate local integration for bank-alert ingestion. Website authentication does not grant the website access to your Gmail.
The desktop integration requestshttps://www.googleapis.com/auth/gmail.readonly. That scope permits message and mailbox-settings viewing. GODFIN searches matching bank-alert messages and does not request Gmail send, edit, or delete access. The OAuth token and client configuration are encrypted on your device.
5. Optional cloud AI
If you choose a supported cloud AI provider using your own key, GODFIN asks for separate consent before sending a prompt. A classification prompt can include normalized vendor or merchant text, an amount band, payment-instrument text, and the allowed category list. An advanced-report prompt can include aggregate category totals converted to amount bands, ratios, counts, trend direction, the reporting period, and report instructions.
Before a cloud request, GODFIN replaces email or payment addresses, phone numbers, account fragments, transaction references, exact dates, exact financial amounts, and long number sequences. This reduces exposure but does not make the prompt anonymous. The chosen provider processes the remaining prompt and may log or retain it according to that provider's terms and retention settings. GODFIN does not operate a hosted-credit AI service.
6. Limited network activity from the desktop app
Most money work remains local, but “local-first” does not mean the app can never use the internet. It can check for updates and refresh a paid license. If you enable them, Gmail ingestion, cloud AI, reference rates, or market quotes can contact the service described at the point of use. The app's network-access setting controls whether another device on your local network can reach the local helper; it does not turn these optional internet services into a GODFIN transaction cloud.
7. License verification
The app can send a license key, a random installation identifier, generic operating-system/architecture label, app version, and verification timestamp to the website license API. The identifier is hashed before storage. We do not collect hardware serials, payment details, or persistent IP fingerprints for activation. Financial records are not part of this request.
8. Logs and security
Hosting and infrastructure providers may retain limited security, request, and error logs. We minimize application logging and do not intentionally place license keys, payment credentials, or desktop financial data in logs.
9. Optional website analytics
Google Analytics is disabled until you explicitly allow it. When enabled, it can receive page URLs, page titles, device/browser attributes, approximate region derived during collection, referrer and campaign fields, and website interaction events. GODFIN disables Google signals and advertising personalization. Google controls provider-side processing and retention; the configured retention period can be up to 14 months. The desktop app does not send analytics, statements, transactions, balances, or categories.
Website analytics are not configured in this environment.
10. Waitlist
The waitlist stores email, country, operating system, intended use, consent version, and campaign attribution. A confirmation email is required before the entry is treated as subscribed. Waitlist consent is separate from product analytics and any future compensated-data program.
11. Retention, access, correction, and deletion
Purchase and license records are retained as needed to provide your lifetime license, prevent fraud, and satisfy tax or legal duties. You may request deletion of optional account data, subject to records we must retain. Deleting the website account does not delete your local app database.
You may ask what optional website data is associated with your account, correct inaccurate contact details, withdraw optional consent, or request deletion where a legal or fraud-prevention duty does not require retention.
12. Your choices
Core requires no website account. Gmail, AI providers, embeddings, network access, and managed services are optional. You can export or delete local app data from the app.
13. Contact
Privacy requests can be sent to hello@godfin.dev. Waitlist confirmation messages use this address for replies.