For the application orvi. Last updated 3 October 2026.
Your financial data is collected onto your own device and stays there. There is no account to create and no server that holds your records. If you choose to share a household's records with family members, only data encrypted on your device — with keys that never leave your devices — is synchronised, so whoever stores it, including us, cannot read it. Turn that off and nothing ever leaves your device at all.
orvi collects your own purchase and transaction history — from your email, your payment accounts and your retailer accounts — into a structured form you control. It runs on your device and keeps your records there.
It is local-first rather than a hosted service. That is a design decision with a privacy consequence: because there is no central database of users' financial records, there is none to breach, subpoena or sell.
Each source below is optional and separately authorised. Authorising none of them is a valid way to use the application: records can be entered by hand or imported from files you already have.
With your permission it reads your Gmail using the
https://www.googleapis.com/auth/gmail.readonly scope. That scope is
read-only: the application cannot send, modify, delete or label any message.
It does not read your whole mailbox. Messages are selected by a search query executed by Google's own servers, so only mail matching known transaction senders is ever transferred to your device. From each matching message it extracts the date, the amount, the counterparty where one is stated, and a reference; receipts attached as PDFs are parsed for their line items.
Where you choose to, you can register your own Google OAuth client and supply it to the application, so that the authorisation is between you and Google with nobody in between — the same arrangement as for payment accounts below. Otherwise the application's own registered client is used, in which case Google identifies the application to you by name on its consent screen before you grant anything. Either way the mail is fetched by your device directly from Google and is never routed through us.
If you want your payment accounts read, you register your own application with Enable Banking — a licensed Account Information Service Provider regulated by the Finnish Financial Supervisory Authority — and supply its key to the application on your device. That arrangement is deliberate and has three consequences worth stating plainly:
Access is account information only: the application requests no payment initiation capability and cannot move money. Only accounts you explicitly link are reachable, and only after you authenticate directly with your own bank — your banking credentials are entered at your bank, never in this application. From each transaction it reads the date, the amount, the counterparty name, a reference and the payment description. Consent lasts at most 180 days and can be withdrawn at your bank or at Enable Banking at any time, independently of this application.
You can import statement files you have downloaded from your own bank. These are read from your device and are not uploaded anywhere.
With your permission it reads your digital receipts from retailer accounts you hold — such as REWE, Lidl Plus and Kaufland Card — using each retailer's own interface with credentials you obtain by logging in yourself. These return your purchases and their line items.
A household's finances are often shared, so the application can share one set of records between family members you invite. This is off unless you turn it on.
When it is on, changes to your records are written to an encrypted log — a stream of changes rather than a copy of a database — which your family members' devices read in order to stay in step. Two things about that log matter:
You choose where that log is stored:
If you do not use family sharing, no log is ever transmitted and this entire section does not apply to you.
orvi's use of information received from Google APIs adheres to the
Google API
Services User Data Policy, including the
Limited Use requirements.
Specifically, data obtained from your Gmail account through
gmail.readonly — together with anything derived or aggregated from it:
These are not undertakings that rest on our conduct alone. The data is processed on your device and stored there, so there is no copy for us to transfer, read or sell.
Security procedures are in place to protect the confidentiality of your data:
The strongest protection is structural rather than procedural: your financial records are held on your device and not on a server we operate, so there is no central store of users' data to be breached.
Credentials are held on your device in your operating system's credential store or in files readable only by your user account, and are transmitted only to the service that issued them. They are never sent to us. Where the application encrypts your records, the encryption keys are likewise generated and kept on your device.
Your records are kept on your device for as long as you want them, and you can delete them by deleting them in the application or removing its local storage. Because the data is yours and local, export is a file operation rather than a request to us.
Access to each source can be withdrawn at any time, independently of this application:
If you used family sharing on infrastructure we operate, deleting the shared log removes the only thing we ever held — and since it was encrypted with keys we never had, deletion removes ciphertext we could not read.
Your data is never sold, rented, licensed, or disclosed for advertising, profiling, analytics, model training or any other purpose. It is shared only where you instruct it: with the family members you invite. No third party receives it otherwise, and there is no readable copy of it for anyone to receive.
Under the GDPR you have rights of access, rectification, erasure, restriction, portability and objection. For data on your device, those rights are exercised directly: you hold it, you can read, correct, export and delete it without asking anyone. For an encrypted shared log stored on infrastructure we operate, we can delete it on request, which is the extent of what we can do with something we cannot decrypt. You may also complain to your national data protection authority.
The application is not directed at children and is not intended for use by anyone under 16.
If this policy changes in a way that affects what leaves your device, the change will be stated in the application before it takes effect, not only on this page.
Questions about this policy, or a request concerning data we hold, can be sent to the contact address shown on the application's consent screens and in the application itself.