Sølvi — Privacy Policy
Effective date: 2026-07-06
Applies to: Sølvi desktop application, version 0.1.0 and later
Provider: Leanora Ventures Pvt Ltd ("we", "us")
Contact: ledgersupport@leanoraventures.com
Sølvi is a local-first personal finance application. It is built so that your
financial life stays on your own device. This policy explains, in plain terms,
what data exists, where it lives, and the narrow cases in which anything leaves
your machine.
1. The core principle
Your financial data stays on your device. Balances, transactions, account
numbers, account names, person names, budgets, investments, properties,
vehicles, and every amount and date are stored only in a local SQLite database
on the computer where you installed Sølvi. We do not have a server that holds
your finances, and we cannot see them.
2. What leaves your device — and what never does
In Managed or BYOK mode (see §2.1), a small, specific set of data can leave
your device:
- Merchant name strings, for AI classification. When Sølvi categorizes a
transaction, it may send the merchant text (for example, WHOLEFDS #432) so
it can suggest a category. That request contains the merchant string and
nothing else.
- A digit-masked sample of statement lines, during import. When you import
a bank or card statement, Sølvi may send a short sample of the statement text
— every digit replaced with 9, so no real amount, date, balance, or account
number is legible — to detect the institution, account type, and currency,
and to read the account holder's name as printed on the statement so the
imported transactions can be attributed to the right household member. This
sample is at most a handful of lines (headers plus a few leading rows).
- Digit- and name-masked lines, if the layout-detection fallback runs. For
PDF statements Sølvi doesn't already recognize, it may additionally ask for
help identifying the column layout. Those lines have every digit masked, and
any printed all-caps name or email address is masked letter-for-letter
(length-preserving, so column positions are unaffected) before they leave
your device.
The following is never transmitted, in any mode:
- Real transaction amounts, dates, or balances
- Account numbers or the last four digits
- Investment values, or property/vehicle values
- Budgets
Note: the account holder's name printed on a statement may appear, unmasked,
in the import-detection sample described above — this is what lets Sølvi
attribute an import to the right person. Note also that the merchant text of a
transaction is sent exactly as your bank printed it: that text sometimes embeds
digits of the bank's own descriptor — a store number, a reference code, or, in
some payment descriptors, a card's last four (for example
ONLINE PAYMENT TO CRD 0392) — and Sølvi does not alter it. If you'd rather
nothing be sent at all, use Local only mode (§2.1).
Each merchant string is classified once and then cached permanently in your
local database, so the same merchant is not sent again.
2.1 You choose the privacy level (Settings → AI & privacy)
Sølvi lets you decide how much cloud AI it may use. There are three modes:
- Local only — no cloud AI at all. Categorization uses the on-device brand
database, rules, and your own past corrections. Nothing is sent for
classification; there are zero AI network requests.
- Managed AI (default) — merchant strings are sent through our Cloudflare
Worker to the Claude API, as described above. Requires an active license.
- Your own key (BYOK) — merchant strings are sent **directly to Anthropic
using your own API key**. Sølvi's servers are not in the path; that data goes
to your Anthropic account under your agreement with Anthropic. Your API key is
encrypted at rest with your operating system's keychain (macOS Keychain,
Windows DPAPI, or Linux libsecret) and is only ever held in memory while a
request is being made — it is never written to disk unencrypted, never shown
after saving (only the last four characters), and never sent anywhere except
Anthropic. Where an OS keychain is unavailable, the key is stored locally in
your app database instead, protected by your disk encryption and app lock, and
the app tells you so.
Optionally, in Managed or BYOK mode, you may also enable **masked header
analysis**, which sends redacted statement headers (digits masked; all-caps
names and email addresses masked) to improve institution and due-date
detection. It is off by default and has no effect in Local mode.
Egress ledger. Settings → AI & privacy shows a log of every AI request that
has left your device — when it happened, the mode, what kind of request, and the
destination. It records this metadata only, never the content that was sent.
3. License validation
To confirm your license is valid, Sølvi sends **your license key and an
app-generated device label** (a random identifier, not your computer's name)
to our Cloudflare Worker. No financial data is included in a license check. If the
device is offline, Sølvi uses a cached validation for up to 30 days (the
"offline grace period"). If a license lapses, Sølvi enters read-only mode — **your
data is never locked, deleted, or held hostage**, and remains fully readable and
exportable.
4. Service providers
Sølvi relies on a small number of providers for the limited functions above:
- Anthropic (Claude API) — receives merchant strings and, during import
detection, digit-masked statement samples as described in §2. In "Your own
key (BYOK)" mode, these requests go directly
from your device to Anthropic under your own account; in "Managed" mode they go
via our Cloudflare Worker. In "Local only" mode, Anthropic is not contacted.
- Cloudflare — operates the Worker that proxies the classification request
(Managed mode only) and validates license keys.
- Lemon Squeezy (Merchant of Record) — handles purchases and license-key
delivery on our behalf when you buy a license. Payment details (such as card
numbers) are entered on Lemon Squeezy's checkout and are handled by them; we
never receive or store your payment card information. See Lemon Squeezy's own
privacy policy for how they process checkout data.
We do not sell your data, and we do not run third-party advertising or analytics
on your financial information.
5. Retention and deletion
Because your data is local, you control it entirely. Deleting the Sølvi
database file, or uninstalling the application and removing its data folder,
permanently removes your financial data from your device. The merchant
classification cache lives in the same local database and is removed with it.
6. Children
Sølvi is intended for adults managing household finances and is not directed to
children.
7. Security
Your data's primary protection is that it does not leave your device. You are
responsible for the security of the device itself (disk encryption, account
passwords, and backups). Transmissions that do occur — merchant strings and
license checks — are sent over encrypted HTTPS connections.
8. Changes to this policy
We may update this policy as the application evolves. Material changes will be
reflected in an updated effective date and in the application's release notes.
9. Contact
Questions about privacy: ledgersupport@leanoraventures.com