Privacy and security in brief
What FullFi encrypts, what it keeps readable so it can add things up, and how to take your data with you or erase it. The privacy policy has the full detail.
This is a short overview. The privacy policy is the authoritative text, and wins wherever the two differ.
Text is encrypted, amounts are readable
FullFi encrypts the descriptive parts of your records with a key unique to your workspace, before they reach the database: names, descriptions, merchants, notes, account details, wallet addresses, and the files you import or upload.
Amounts, currencies, exchange rates, dates, and whether something is settled, pending, or expected stay readable by FullFi's servers. That's what lets FullFi add up totals, balances, and reports. On their own, they aren't linked to any readable description: the server can see −84.12 CAD on a date, but not that it was groceries.
What FullFi never asks for
- No bank or card passwords. You bring your bank's data in by importing a file.
- No private keys or recovery phrases, ever. A wallet is tracked by its public address, with no signature.
- No email address to sign in. You sign in with Google, GitHub, or an Ethereum wallet, and FullFi asks those providers for no email or profile.
FullFi is read-only: it never moves money.
Outside services are your choice
AI import, fetched exchange rates, and crypto prices are off until someone in your workspace turns them on in Settings. While they're off, nothing is sent to an AI provider or a rate feed. See importing and multiple currencies.
Taking your data with you
The owner or an admin can download everything in the workspace from Settings, under Export your data: one CSV file for each kind of record, plus your imported files and uploaded documents as a separate download. The data is decrypted on FullFi's servers and sent straight to your browser. Once it's on your device, the copy is no longer encrypted, so keep it somewhere safe.
Deleting everything
Normal use never erases financial records: archiving, voiding, and excluding keep them and mark them. Erasing is a separate step. The owner can delete the workspace and account from the bottom of Settings, by typing the workspace's name to confirm. The workspace's encryption key is destroyed first, so nothing encrypted with it can be read again, and then everything in the workspace and your account is erased. It can't be undone.
If other people belong to your workspace, remove them first. If you belong to someone else's workspace, leave it first.
Something wrong?
If you think something isn't as described here, tell us.