Gravity Fintracker

Privacy Policy

Your money is your business. By default, nothing about it ever leaves your device.

The short version: Gravity Fintracker stores every account, transaction and category locally on your device. There is no account to create, no server we operate that sees your data, and no ads or analytics of any kind. Multi-device sync is opt-in, off by default, and end-to-end encrypted so that even we — or anyone who ever gained access to a sync server — could not read your financial data.

1 Data we collect

None, by default. Gravity Fintracker does not require sign-up, does not contain analytics or crash-reporting SDKs, and does not phone home. Every account balance, transaction, category and recurring rule you create is written to a local database on your device and stays there.

2 Optional sync — end-to-end encrypted

Sync across your own devices is an opt-in feature and is off by default. If you turn it on:

  • Your data is encrypted before it ever leaves your device. Gravity Fintracker derives a per-session key using HKDF-SHA512 and encrypts your snapshot with AES-256-GCM. The encryption key is generated from a passphrase only you know and is never transmitted.
  • The sync server only ever stores ciphertext. The backend (Supabase, a third-party database provider) cannot decrypt your data — it has no access to your passphrase or derived keys. This is a zero-knowledge design: even we cannot read your synced data.
  • You can turn sync off at any time from Settings, which stops any further transmission.

3 No ads, no analytics, no third parties

Unlike some of our other apps, Gravity Fintracker does not use Google AdMob or any advertising SDK. It contains no analytics, no attribution tracking, and no crash-reporting service that phones out. The only third party involved anywhere in the app is Supabase, and only if you explicitly enable sync — and even then it only ever receives encrypted ciphertext, as described above.

4 App Lock & biometrics

If you enable App Lock, Gravity Fintracker asks your device's operating system to verify your fingerprint, face, or device PIN/pattern before the app opens. This authentication happens entirely within your device's secure hardware — your biometric data is never accessible to the app itself, is never stored by us, and is never transmitted anywhere.

5 Device permissions

Gravity Fintracker requests only what it needs to function:

  • Storage: to let you export a backup (JSON or CSV) to a file of your choosing, and to import one back in.
  • Biometric / Fingerprint: only used if you enable App Lock, to unlock the app using your device's own authentication.
  • Internet: only used if you enable optional sync. If sync is off, this permission is requested by the OS but nothing is ever sent.

6 Your data, your control

  • Export anytime. Full JSON or CSV backups are one tap away in Settings.
  • Delete anytime. Uninstalling the app removes its local database. If you ever enabled sync, disabling it and deleting your account from within the app removes your encrypted snapshot from the sync server.
  • No lock-in. Your exported data is plain JSON/CSV — readable and portable, not a proprietary format.

7 Children

Gravity Fintracker is a general-audience finance utility and is not directed at children under 13. We do not knowingly collect personal information from anyone, children included — consistent with section 1, we don't collect personal information from anyone at all.

8 Changes & contact

If this policy changes — for example, when optional sync moves from opt-in beta to general availability — we will update this page and revise the date below. Questions or concerns? Email hello@teamantigravity.com.

Last updated: July 2026