Private Finance Kit Local-first money tools

Privacy and safety

Local-First Privacy Model

Read how InCase File keeps workbook data local, generates XLSX files in the browser, encrypts backups before download, and avoids plaintext email or raw secrets.

Private Finance Kit is designed so emergency workbook contents, statement text, CSV files, and document packs stay in the browser unless the user chooses to download an output file.

No workbook upload

The core tools do not need an account, database, or server endpoint for workbook contents. Spreadsheet files, encrypted backups, repaired CSV files, and document-pack ZIP files are generated locally in the browser after the user chooses the input.

Workbook fields, statement contents, CSV contents, document-pack files, passphrases, and generated file bytes are not intentionally sent to an application server operated by Private Finance Kit. Downloaded files are under the user's control and should be stored like private financial records.

  • No plaintext spreadsheet email
  • No passphrase storage
  • No PIN, OTP, CVV, password, or seed phrase collection
  • No account required for the core tools
  • No bank login or account linking

Files, browser storage, and device responsibility

Local-first does not mean risk-free. The user's device, browser profile, extensions, downloads folder, cloud-sync settings, shared computer access, printer, screenshots, clipboard, and backup drive are still part of the privacy boundary.

If a user saves a plaintext XLSX, CSV, PDF printout, or ZIP pack, that file should be protected like any other sensitive financial file. Temporary files should be deleted when no longer needed, and shared or public computers should be avoided for private records.

  • Keep encrypted files and passphrases in separate places
  • Use a strong passphrase for encrypted backups
  • Test restore before relying on an encrypted file
  • Review every export before storing or sharing it

Email and contact policy

The app does not email workbook data. The contact form is for general product feedback, correction requests, accessibility issues, and privacy-safe questions.

Users should never email or submit plaintext PDFs, plaintext spreadsheets, workbook exports, statement files, document-pack ZIP files, passphrases, PINs, passwords, OTPs, CVV values, private keys, or recovery seed phrases. Encrypted files and passphrases should be kept in separate places.

  • Use fake or masked examples when reporting parser issues
  • Hide names, account references, phone numbers, and financial values in screenshots
  • Do not send private files through feedback forms
  • Do not send a passphrase with an encrypted file

Advertising and cookies

Private Finance Kit may display advertising in the future, including Google AdSense or similar ad services. If ads are enabled, Google and other third-party vendors may use cookies, web beacons, IP addresses, page URLs, browser information, or similar technologies to serve ads, measure ads, prevent fraud, and improve ad quality.

Google may use advertising cookies to serve ads based on a user's prior visits to this site or other sites, depending on user settings and applicable law. Google explains how it uses data from sites and apps that use its services at https://policies.google.com/technologies/partner-sites.

Advertising systems should never receive workbook contents, statement text, CSV contents, uploaded document-pack files, passphrases, PINs, passwords, OTPs, CVV values, private keys, or recovery seed phrases from Private Finance Kit tools.

  • Users can manage Google ad personalization in Google Ads Settings
  • Third-party ad vendors may have their own privacy policies
  • The local-first data rule remains the product boundary
  • Sensitive tool inputs should not be placed in contact forms or ad-related fields

Analytics and operational data

The site may use basic traffic or platform analytics to understand page views, browser errors, performance, and which public pages are useful. These signals are separate from private workbook fields and file contents.

Cloudflare Pages or the browser may handle normal web delivery details such as IP address, user agent, request URL, and security checks. That is different from uploading workbook, statement, CSV, or document-pack contents to the app.

  • Contact form responses are handled by Google Forms
  • The site should not request private file uploads through the contact form
  • Workbook and statement data should stay out of contact messages
  • Public guide pages are designed to be readable without entering private data