What makes a finance app actually private?
'We take privacy seriously' is not a privacy policy. Real privacy is architectural — it's what the app can't do, not what it promises not to do.
Your accounts, transactions and categories live on your device — not on the vendor's servers. If the vendor doesn't have the data, it can't leak, sell or subpoena it.
Free apps have to make money somehow. Ad-supported and data-sold models are structurally incompatible with financial privacy. Paid subscription aligns incentives.
AISP-only connections through a licensed provider mean the app cannot move money. Fewer permissions, smaller blast radius.
Sharing with a partner should go through your own iCloud, not the vendor's cloud, and you decide who's in.
A privacy policy that names its subprocessors, data types and retention is a good sign. Vague reassurances are a bad one.
Does 'local-first' mean no cloud at all? It means your financial data lives on your device by default. Optional iCloud household sync uses your own account, not the vendor's.
Isn't a paid app just more expensive? It's the trade for not being the product. A few euros a month is cheaper than years of profile-building.
How can I verify these claims? Read the privacy policy for specifics: named subprocessors, data locations, retention windows. Vague wording is a red flag.