1. Who operates this Ficard deployment
This instance of Ficard is operated by Vinod Balan, based in India.
Website or app address: https://ficard.pages.dev
Privacy contact: tapvinod@gmail.com
“Ficard,” “we,” “us,” and “our” in this policy refer to that operator. Google and Microsoft are independent service providers when a user chooses their cloud-backup services.
2. Privacy summary
Accounts, transactions, people, categories, tags, notes, reminders, and settings are stored in the browser used to access Ficard.
When enabled, backup JSON files are sent from the browser directly to the user’s Google Drive or OneDrive account over HTTPS.
The supplied Ficard application does not contain advertising trackers or analytics scripts. The hosting provider may still keep normal web-server logs.
3. Information Ficard handles
Financial and organisational data entered by the user
- Account names, account types, groups, currencies, icons, balances, card limits, billing settings, and visibility preferences.
- Transactions, dates and times, amounts, categories, child categories, tags, notes, refund status, recurrence settings, and transfers.
- People records and amounts recorded as borrowed, lent, repaid, or expected.
- Parsed bank-SMS text submitted to Ficard for review. Ficard does not independently read the phone’s general SMS inbox.
- Notifications, reminder status, dashboard preferences, backup schedules, and application settings.
Cloud-connection information
- The connected account label returned by Google or Microsoft.
- Selected folder names, paths, file or folder identifiers, last-backup time, backup status, and retention settings.
- Temporary OAuth access tokens and, for OneDrive, a refresh token when Microsoft issues one.
Technical information
The supplied application does not intentionally send device identifiers or usage analytics to a Ficard server. A web-hosting provider may automatically process ordinary request information such as IP address, user-agent string, requested page, timestamp, and error details. The operator should describe any hosting logs or additional monitoring used in this deployment.
4. How the information is used
Ficard processes the information to:
- Display accounts, balances, running balances, dashboards, charts, searches, people ledgers, and reminders.
- Create, edit, copy, move, repeat, import, and export transactions.
- Generate local notifications and catch up missed browser-only schedules when the application reopens.
- Create JSON backups and upload them to a cloud folder selected or approved by the user.
- Maintain the app, prevent duplicate scheduled actions, and show backup or authentication errors.
5. Browser storage and retention
| Data | Storage location | Typical retention |
|---|---|---|
| Finance records and settings | Browser localStorage for the Ficard site | Until the user imports replacement data, selects Delete all data, clears site data, or the browser removes it |
| Google access token | Browser sessionStorage | Until expiry, disconnect, site data removal, or the browser session ends |
| Microsoft access and refresh tokens | Browser localStorage, separate from the finance dataset | Until disconnect, expiry/revocation, Delete all data, or site data removal |
| Application files | Browser Cache Storage through the service worker | Until updated, cache-cleared, service-worker removal, or site-data removal |
| Cloud backup files | User-selected Google Drive or OneDrive folder | Until removed by the user or Ficard’s configured timestamped-backup retention process |
OAuth tokens are stored separately from the finance dataset and are excluded from Ficard’s JSON export and import files.
6. Google Drive and OneDrive backups
Cloud backup is optional. The user initiates connection through the provider’s official authentication and consent page. Ficard does not receive the user’s Google or Microsoft password.
Backup files are JSON documents containing the Ficard finance dataset. They travel from the browser to the selected provider over HTTPS. The supplied browser-only implementation does not relay the backup through a Ficard application server.
Ficard’s JSON backups are not end-to-end encrypted by the application. Anyone who gains access to the user’s cloud account or backup file may be able to read its contents. Users should protect their device and cloud account with appropriate security controls.
Browser-only scheduling runs while Ficard is open and attempts a catch-up backup when Ficard next opens after a missed scheduled time. It cannot guarantee an exact upload time while the browser and application are completely closed.
7. Cloud permissions and scopes
openid,email, andprofileto identify and display the connected account.https://www.googleapis.com/auth/drive.fileto create and manage files Ficard creates or files and folders the user explicitly makes available through the app.
Microsoft
openid,profile, andUser.Readto authenticate and display the connected account.offline_accessso Microsoft may issue a refresh token for continued browser-based backup access.Files.ReadWrite.AppFolderfor the recommended restricted OneDrive application folder.Files.ReadWriteonly when the user chooses the broader custom-folder mode.
The operator configures public browser application identifiers in cloud-config.js. These identifiers are not account passwords or client secrets.
9. Security considerations
- Cloud sign-in should be used only from an HTTPS deployment or localhost.
- Passwords are entered only on Google’s or Microsoft’s official authentication pages.
- Cloud tokens are excluded from exported finance JSON files.
- The Load latest version function clears Ficard application caches while preserving browser finance data.
No browser application can guarantee absolute security. Browser local storage is not separately encrypted by Ficard and may be accessible to someone who can use the unlocked browser profile or compromise the site or device. The operator should keep the application, hosting platform, OAuth registrations, and dependencies properly secured.
10. User choices and data controls
- Access and portability: review records in Ficard and use Export JSON to download a copy.
- Correction: edit accounts, people, categories, transactions, schedules, and settings.
- Deletion: delete individual records, use Delete all data, clear the Ficard site’s browser storage, and delete backup files from the cloud provider.
- Cloud access: disconnect a provider in Ficard and revoke Ficard’s access through the Google or Microsoft account-security pages.
- Notifications: disable daily reminders, provider schedules, or browser notification permission.
Where applicable law provides additional privacy rights, contact the operator using the details below. Because the default finance dataset remains in the user’s browser, the operator may need the user’s cooperation to identify or retrieve information and may not hold a server-side copy.
11. Children’s privacy
Ficard is intended as a personal finance-management tool and is not designed to knowingly collect information from children. The operator should set and disclose any minimum-age requirement that applies to the deployment and jurisdiction.
12. Changes to this policy
The policy may be updated when Ficard’s functionality, cloud permissions, hosting arrangements, or legal obligations change. The revised page should show a new “last updated” date and, for material changes, the operator should provide an appropriate notice in the application.
13. Contact
Questions, privacy requests, or complaints about this Ficard deployment can be sent to:
Vinod Balan
tapvinod@gmail.com
https://ficard.pages.dev
India