Legal
OneFold privacy policy
Last updated: 2026-06-19
OneFold is a personal hobby project by an individual developer ("the developer"); there is no company behind it.
OneFold is a personal net-worth tracker that runs entirely on your device. The short version: your financial data stays on your device, OneFold has no account, and the only things that ever leave your device are the public market symbols needed to fetch prices, plus, only if you turn them on, context you send to your own AI provider or an end-to-end encrypted view you choose to share with someone you trust (see Optional family sharing).
What is collected
Nothing on any server, with one opt-in exception. OneFold has no sign-up, no account, no login, and no analytics, tracking, advertising, or telemetry. The developer does not receive, store, or sell your data. The only exception is live family sharing (below): if you turn it on, an end-to-end encrypted copy passes through a relay that only ever holds opaque ciphertext it cannot read. Nothing readable ever reaches any server.
Where your data lives
- Your assets, loans, insurance, spending, snapshots, vault notes, and settings are stored locally in your browser/device storage (and, for documents and passwords you add, encrypted on your device when App Lock is on).
- Backups (Excel
.xlsxor encrypted.nwx) are files you create and control. OneFold never uploads them; where you keep them (local, cloud folder, etc.) is your choice. - Statements you import (a CSV you export yourself from a bank, card, loan, or brokerage) are read entirely on your device. OneFold has no connection to your bank, asks for no banking login or credentials, and never uploads the file or sends it to any AI provider. Only the transactions you review and confirm are saved into your local data, and the whole import is one-tap undoable.
What leaves your device, and when
OneFold works offline except for fetching prices (delayed, not real-time). A price refresh, which you trigger, makes ordinary public web requests that reveal only public market identifiers, never your holdings, amounts, or account names:
- Currency codes / FX pairs (to convert between currencies). If you turn on the optional parallel market rates setting, a refresh also requests a public street-rate table from an additional rate provider; like the official rate request, it carries no information about your holdings.
- Metal symbols (gold, silver, platinum, palladium).
- Cryptocurrency identifiers.
- Indian mutual-fund scheme codes.
- Stock/ETF ticker symbols. By default these are looked up in a shared price file that every user downloads identically, so the request carries no information about which tickers you hold. You can also turn on "Expand ticker coverage" (off by default): once on, a price refresh sends the ticker symbols of holdings not in the shared file directly to the price provider, so they get a price. Only those symbols leave, never amounts or account names.
These requests go to the relevant public price provider (and to OneFold's shared price file). They include your device's normal network information (such as your IP address), the same as visiting any website. They do not include your financial data. The price providers are independent third parties with their own terms and privacy practices, which govern what they do with a request; OneFold neither controls them nor warrants the data they return.
Optional AI advisor
The advisor works on-device by default and sends nothing externally. If you choose to connect your own AI provider (your own account/key), the context you send is limited to what is needed for your question and is governed by that provider's privacy terms. This is off unless you enable it, and each send is subject to your consent. While you are viewing a shared profile (below), the advisor stays fully on-device and sends nothing.
Optional family sharing
OneFold can, if you turn it on, let a trusted person you pair with follow your finances live and read-only, and can let you follow theirs the same way. This is off by default; nothing is shared until you enable it and hand that person a pairing code and passphrase. When you enable it:
- What you share is end-to-end encrypted on your device with a family passphrase you set and share with that person separately (never in the pairing link). Only someone holding that passphrase can read it.
- The encrypted updates pass through a relay (run by the developer on Cloudflare's free tier, or one you self-host). The relay only ever stores and forwards opaque ciphertext, plus routing metadata such as message counts, timing, and a padded size bucket; it has no key and cannot read your figures, names, or passphrase.
- You choose the scope (a top-line summary, or your full ledger) and, separately, whether to include your documents and passwords (off unless you opt in). Because the person you share with holds the passphrase, they can read what you share by design, so share only what you would hand them anyway.
- The other person's view is read-only; they cannot change your data. You can pause or stop sharing at any time, and stopping removes the shared copy.
Children
OneFold is a personal finance tool and is not directed to children.
Changes
OneFold is free to use today; future versions may add paid features (see the Terms of Use). If how data is handled ever changes, the developer will update this policy and the date above. Material changes will be surfaced in the app.
Your rights and contact
Because your data stays on your device, you remain in control of it: you can export it, or erase everything from Settings, at any time. Depending on where you live, you may have rights under laws such as the EU/UK GDPR, the UAE PDPL, or India's DPDP Act; since the developer does not collect or process your data on any server, those requests are satisfied by the local controls in the app.
Questions: onefoldapp@protonmail.com