Ficard app icon FicardPersonal finance

Privacy and data handling

Privacy Policy

This policy explains how this deployment of Ficard stores personal-finance information, connects to Google Drive and Microsoft OneDrive, and gives users control over their data.

Effective and last updated2 August 2026Policy version1.1
About this policy

This policy applies to Ficard hosted at ficard.pages.dev, operated by Vinod Balan in India.

1. Who operates this Ficard deployment

This instance of Ficard is operated by Vinod Balan, based in India.

Website or app address: https://ficard.pages.dev
Privacy contact: tapvinod@gmail.com

“Ficard,” “we,” “us,” and “our” in this policy refer to that operator. Google and Microsoft are independent service providers when a user chooses their cloud-backup services.

2. Privacy summary

Local by default

Accounts, transactions, people, categories, tags, notes, reminders, and settings are stored in the browser used to access Ficard.

Direct cloud transfer

When enabled, backup JSON files are sent from the browser directly to the user’s Google Drive or OneDrive account over HTTPS.

No built-in ads or analytics

The supplied Ficard application does not contain advertising trackers or analytics scripts. The hosting provider may still keep normal web-server logs.

3. Information Ficard handles

Financial and organisational data entered by the user

  • Account names, account types, groups, currencies, icons, balances, card limits, billing settings, and visibility preferences.
  • Transactions, dates and times, amounts, categories, child categories, tags, notes, refund status, recurrence settings, and transfers.
  • People records and amounts recorded as borrowed, lent, repaid, or expected.
  • Parsed bank-SMS text submitted to Ficard for review. Ficard does not independently read the phone’s general SMS inbox.
  • Notifications, reminder status, dashboard preferences, backup schedules, and application settings.

Cloud-connection information

  • The connected account label returned by Google or Microsoft.
  • Selected folder names, paths, file or folder identifiers, last-backup time, backup status, and retention settings.
  • Temporary OAuth access tokens and, for OneDrive, a refresh token when Microsoft issues one.

Technical information

The supplied application does not intentionally send device identifiers or usage analytics to a Ficard server. A web-hosting provider may automatically process ordinary request information such as IP address, user-agent string, requested page, timestamp, and error details. The operator should describe any hosting logs or additional monitoring used in this deployment.

4. How the information is used

Ficard processes the information to:

  • Display accounts, balances, running balances, dashboards, charts, searches, people ledgers, and reminders.
  • Create, edit, copy, move, repeat, import, and export transactions.
  • Generate local notifications and catch up missed browser-only schedules when the application reopens.
  • Create JSON backups and upload them to a cloud folder selected or approved by the user.
  • Maintain the app, prevent duplicate scheduled actions, and show backup or authentication errors.

5. Browser storage and retention

DataStorage locationTypical retention
Finance records and settingsBrowser localStorage for the Ficard siteUntil the user imports replacement data, selects Delete all data, clears site data, or the browser removes it
Google access tokenBrowser sessionStorageUntil expiry, disconnect, site data removal, or the browser session ends
Microsoft access and refresh tokensBrowser localStorage, separate from the finance datasetUntil disconnect, expiry/revocation, Delete all data, or site data removal
Application filesBrowser Cache Storage through the service workerUntil updated, cache-cleared, service-worker removal, or site-data removal
Cloud backup filesUser-selected Google Drive or OneDrive folderUntil removed by the user or Ficard’s configured timestamped-backup retention process

OAuth tokens are stored separately from the finance dataset and are excluded from Ficard’s JSON export and import files.

6. Google Drive and OneDrive backups

Cloud backup is optional. The user initiates connection through the provider’s official authentication and consent page. Ficard does not receive the user’s Google or Microsoft password.

Backup files are JSON documents containing the Ficard finance dataset. They travel from the browser to the selected provider over HTTPS. The supplied browser-only implementation does not relay the backup through a Ficard application server.

Ficard’s JSON backups are not end-to-end encrypted by the application. Anyone who gains access to the user’s cloud account or backup file may be able to read its contents. Users should protect their device and cloud account with appropriate security controls.

Browser-only scheduling runs while Ficard is open and attempts a catch-up backup when Ficard next opens after a missed scheduled time. It cannot guarantee an exact upload time while the browser and application are completely closed.

7. Cloud permissions and scopes

Google

  • openid, email, and profile to identify and display the connected account.
  • https://www.googleapis.com/auth/drive.file to create and manage files Ficard creates or files and folders the user explicitly makes available through the app.

Microsoft

  • openid, profile, and User.Read to authenticate and display the connected account.
  • offline_access so Microsoft may issue a refresh token for continued browser-based backup access.
  • Files.ReadWrite.AppFolder for the recommended restricted OneDrive application folder.
  • Files.ReadWrite only when the user chooses the broader custom-folder mode.

The operator configures public browser application identifiers in cloud-config.js. These identifiers are not account passwords or client secrets.

8. When information is shared

Ficard does not sell personal information. Data is disclosed only as needed for a feature selected by the user, including:

  • Google Identity Services, Google Drive API, and Google Picker when Google Drive backup or folder selection is used.
  • Microsoft identity services and Microsoft Graph when OneDrive backup or folder selection is used.
  • The operator’s hosting provider when the user downloads the application files or opens this policy, subject to the hosting provider’s request logs and infrastructure practices.
  • Authorities or other parties when the operator is legally required to disclose information it actually possesses. In a default local-only deployment, the operator may not possess the finance records stored solely in the user’s browser.

Google and Microsoft process information under their own privacy notices and account settings.

9. Security considerations

  • Cloud sign-in should be used only from an HTTPS deployment or localhost.
  • Passwords are entered only on Google’s or Microsoft’s official authentication pages.
  • Cloud tokens are excluded from exported finance JSON files.
  • The Load latest version function clears Ficard application caches while preserving browser finance data.

No browser application can guarantee absolute security. Browser local storage is not separately encrypted by Ficard and may be accessible to someone who can use the unlocked browser profile or compromise the site or device. The operator should keep the application, hosting platform, OAuth registrations, and dependencies properly secured.

10. User choices and data controls

  • Access and portability: review records in Ficard and use Export JSON to download a copy.
  • Correction: edit accounts, people, categories, transactions, schedules, and settings.
  • Deletion: delete individual records, use Delete all data, clear the Ficard site’s browser storage, and delete backup files from the cloud provider.
  • Cloud access: disconnect a provider in Ficard and revoke Ficard’s access through the Google or Microsoft account-security pages.
  • Notifications: disable daily reminders, provider schedules, or browser notification permission.

Where applicable law provides additional privacy rights, contact the operator using the details below. Because the default finance dataset remains in the user’s browser, the operator may need the user’s cooperation to identify or retrieve information and may not hold a server-side copy.

11. Children’s privacy

Ficard is intended as a personal finance-management tool and is not designed to knowingly collect information from children. The operator should set and disclose any minimum-age requirement that applies to the deployment and jurisdiction.

12. Changes to this policy

The policy may be updated when Ficard’s functionality, cloud permissions, hosting arrangements, or legal obligations change. The revised page should show a new “last updated” date and, for material changes, the operator should provide an appropriate notice in the application.

13. Contact

Questions, privacy requests, or complaints about this Ficard deployment can be sent to:

Vinod Balan
tapvinod@gmail.com
https://ficard.pages.dev
India