Building an End-to-End Encrypted Finance App with Tauri
I’ve been tracking my finances for six years. In that time, I’ve tried You Need a Budget, Money Lover and, recently, Wallet by BudgetBakers - none of them ever quite fit. This post is about why, and how those gaps shaped the app I ended up building.
What never fit
I had two main pain points with existing apps.
Bank connections were fragile. Linking an account sounds effortless, but in practice connections expire after some time and quietly stop collecting data. Or, when a bank changes its API, the link breaks and can stay broken for weeks while the provider catches up. Either way, I’d find gaps in my history long after they happened.
None of them was built for financial independence. They were good at budgets and categories, but the numbers I actually cared about - my savings rate, and how far I was from each FIRE milestone - weren’t there. So I kept a large spreadsheet on the side and copied everything into it at the end of each month to draw the charts myself.
Over time I settled into a routine that avoided both problems. At the end of each month I downloaded the statement from every bank and broker, worked out my income, categorised my spending and noted each account’s balance, all in that spreadsheet. It was slower than a live connection on paper, but it never broke, and nothing had to be shared with anyone. That routine is what Lume turns into an app.
How that shaped Lume
Almost every architectural decision in Lume follows from that routine:
- Statements, not bank connections. Lume reads the files your bank already gives you - CSV, Excel or OFX. There’s no aggregator in the middle, so there’s no connection to expire and nothing to break when a bank changes its API.
- Your mapping, not a list of supported banks. Every bank formats its statements differently, so instead of shipping presets that go stale, you tell Lume once which column is the date and which is the amount, and it remembers.
- The month is the unit. The app is built around a monthly close, the same routine I followed in the spreadsheet. FIRE numbers - your savings rate, and when you’ll reach each milestone - are the dashboard, not an add-on.
- Local first. Once your data comes from files on your own device, there’s no reason for it to leave. Lume works fully offline, needs no account, and sync is optional.
That last point is where privacy stops being a feature and becomes the default. If the data lives on your device, the job is to keep it safe there, and to make sure it stays yours even when you sync.
Why Tauri
I wanted Lume on the Mac and the iPhone without writing it twice. Tauri 2 made that possible: the interface is a web app (React and TypeScript) running in the system’s own web view, and a small native layer in Rust does what a web page can’t. The Mac and iPhone apps are the same code; on a narrow screen the sidebar simply becomes a tab bar.
It also leaves the door open. Tauri builds for Windows and Android from the same codebase, so if Lume ever goes beyond Apple’s platforms, it won’t mean starting again.
In Lume, the native layer is deliberately tiny. It talks to the Keychain, writes files, and handles iPhone details like Face ID. Everything else - reading statements, the maths, the encryption - runs in the web view, where the browser already provides solid, well-tested cryptography.
Sync through a server that can’t read it
Everything Lume stores is encrypted on your device, with a key that lives in your Keychain. When you turn sync on, your data is encrypted again, with a separate key, before it’s uploaded, so the server only ever stores something it can’t read.
The interesting part was recovery. My first version turned your passphrase directly into the encryption key. It works, until you forget the passphrase: then the data is gone for good, and even changing the passphrase means re-encrypting everything.
The fix was to encrypt your data with a random key, and then lock that key twice: once with your passphrase, once with a recovery code shown when you set up sync. Either one opens your data. Changing your passphrase just re-locks the key, and the recovery code is a real way back in rather than a promise I can’t keep.
End-to-end encryption doesn’t make everything invisible, though. The server still knows your email address, roughly how much data you have and when it changes, and price lookups for your investments pass through it with the ticker and your IP address attached. The privacy policy lists all of it.
Would I build it this way again?
Yes. The decisions that mattered most weren’t technical at all - they came from six years of watching what broke. Once the data came from statements instead of bank connections, the rest followed: an app that works offline, keeps your data on your device, and treats the monthly close as the heart of it. Tauri just made it possible to do that once, for two platforms, with room for more.
General information, not financial advice. Your taxes, pension and circumstances will differ from the examples here. More on that.