2Fin Desktop for Windows

Your financial data, in a folder on your own computer

2Fin Desktop is a private finance and tax app for Windows that works offline. No account needed to start, no data sent while you work, and you can confirm that yourself with a packet capture in about five minutes.

A folder you can open

The app shows the real path and opens it for you. A database file and your receipts, as ordinary files. Copy the folder and you have a backup.

No account to start

The free tier needs no sign-up. Nothing to verify, no email captured, no profile created. Sign in only when you want paid features.

A log of everything sent

Every outbound request Fin has ever made, described in counts not content — and a switch to stop each one.

How it fits together

Everything you bring in is processed on your machine, and everything lands in one folder you choose.

Your records

CSV imports

Receipts

Manual entries

On your machine

2Fin Desktop

works offline

Your folder

A folder you choose

database + receipts your data

Your records

Bank statements, receipts and entries come in from you.

On your machine

Sorting, categorising and reporting all run locally.

Your folder

Every record lands in a folder on your computer — open it, copy it, back it up.

Verify it yourself

Privacy claims are easy to write and hard to check. This one takes about five minutes to check, with tools you already trust.

  1. Baseline — capture with the network available

    Start a packet capture (Wireshark, Little Snitch, or tcpdump) before changing any setting, then import a CSV, categorise a few transactions and explore your dashboard — and on a paid plan, run a report and a tax export too. Nothing here is stopped from reaching the network.

  2. Review the capture — your work sent nothing, though nothing was blocked

    None of your work produced an outbound request — not because a switch stopped it, but because it never tries. Then switch Airplane mode on (the "Where your data lives" panel from the top-bar chip) and repeat the same workflow: it still works, and the capture stays empty.

  3. Re-enable one connection and compare

    Switch Airplane mode off and ask Fin to categorise something. Compare the capture against the app's own outbound log — the two agree, which is what makes the log trustworthy the rest of the time.

The first ten minutes, step by step →The full procedure, with the exact commands →

What the log is for. The outbound record lists every request in counts and destinations, never content — a log that held your transaction text would itself be a copy of your data. The only request Fin makes unprompted is an update check; it carries nothing of yours, it appears in that log, and it can be switched off.

What does leave, and when

Being straight about this is the point. Nothing here happens in the background.

WhenWhat is sent
You ask Fin to categorise or answer somethingOnly the rows involved — processed, never stored
You read a receipt with FinThat image — processed, never stored
You connect a spreadsheetA read request to your own sheet
You send transactions to XeroThat batch, straight to Xero
Checking for an updateA version number. Nothing of yours
Crash reports and analyticsOff by default, and they stay off unless you turn them on

On any plan you can bring your own Anthropic, OpenAI or AWS Bedrock key — then those requests go straight from your machine to your provider, and 2Fin is not in the path at all. Or run a local model and nothing leaves.

Your safety net is on your machine too

Records that live in your own folder need looking after in that folder. 2Fin Desktop keeps its own copies there, checks each one, and uses them without being asked.

A checked copy, about once a day

When the newest copy is more than twenty hours old, 2Fin takes a fresh one, runs an integrity check over it and writes a list beside it of what it holds — how many tables, how many rows altogether and how many in each. Only a copy that passes is kept. They sit in a folder called “backups” beside your data: the newest three, then one a day for a week, then one a week for a month.

Repair that happens by itself

If your records file turns out to be damaged when the app starts, 2Fin restores from the best verified backup on its own and tells you it did. Nothing has to be sent anywhere for that to work, and nothing is deleted to make room for it.

An encrypted copy you can take with you

“Export everything…” writes one .finbak file, receipts included, sealed with a passphrase you choose (scrypt and AES-256-GCM). It is for moving to another computer or keeping a copy somewhere else, and “Import from an export…” brings it back on any machine, replacing what that copy of 2Fin is holding. Both sit in the “Where your data lives” panel, behind the chip at the top of the window.

What each one covers. The daily copies are plain files covering your records — not your receipts — and they stay with the computer that made them. The encrypted export is the one that includes receipts and is built to travel, so the passphrase is the only way back in: nobody, 2Fin included, can recover it or read the file without it. Keep it somewhere you will still have it. What a .finbak file is, and how to open one →

When Fin isn’t connected

2Fin Desktop works as your books without Fin connected at all. Fin’s chat and intelligent categorising need a model to think with — and you choose where that model lives: nowhere yet, behind a linked 2Fin account, or with a provider key of your own.

No account, no key

Fully local

What works
Imports, categorising with your own rules, bills, budgets, travel and export. Reading and exporting your data is never blocked.
What Fin can do
Fin’s chat is waiting for a model. It says so plainly and offers two ways in: link this device, or connect your own key or a local model.
What leaves your machine
Nothing of yours. An update check, which stays silent when you are offline. Analytics and crash-report sharing start off, and crash reports are saved on your machine.
Where keys are kept
No keys involved.

Linked free account

Fin’s chat, with an allowance

What works
Everything that works with no account, plus Fin’s chat.
What Fin can do
Chat, within a monthly allowance. Categorising, summaries and receipt reading through Fin’s relay need a paid plan.
What leaves your machine
Linking sends an install ID, platform and app version. Chat messages go to Fin’s relay at api.ai2fin.com with account and card numbers, long reference codes, emails and phone numbers masked first. The relay is designed to record counts and usage, not content.
Where keys are kept
No provider key on your machine. The link holds offline, with no check-in.

Your own key or local model

Any plan

What works
Everything that works with no account, plus Fin — with no plan gate or monthly quota from 2Fin.
What Fin can do
Chat, categorising, receipt reading and summaries.
What leaves your machine
Requests go straight to the provider you chose — Anthropic, OpenAI or AWS Bedrock — under that provider’s terms, without 2Fin’s masking. A local model such as Ollama or LM Studio sends nothing, even in Airplane mode.
Where keys are kept
Encrypted (AES-256-GCM) in a file on your machine, not your system keychain. The key is never sent to 2Fin.

See what each plan adds on pricing, and how your data is protected on security.

How Fin keeps tax figures accurate

Fin calculates tax figures such as GST and income tax in code, from one dated rate ledger covering 88 countries, and points you to hand-checked official pages from authorities such as the ATO, HMRC and the IRS — as general information, not personal tax advice.

Calculated, not recalled

GST, income tax brackets, the Medicare levy and the estimators are worked out in code from one rate ledger, not remembered by a model — the same inputs give the same figure.

Rates carry their dates

The ledger covers GST, VAT and sales tax for 88 countries, and rates that change over time are dated, so a figure belongs to the period it applies to.

Official pages, with a last-checked date

Ask about a rule and Fin points you to hand-checked pages from the ATO, HMRC, the IRS, Inland Revenue (New Zealand), the CRA and India’s Income Tax Department — each showing when it was last checked.

General information, clearly labelled

Fin’s tax answers are general information and calculation help, not personal tax or financial advice. Only a registered tax agent can give you personalised tax agent services, and you remain responsible for your return.

Before you lodge. Rates change, and a ledger is only as current as its last check. Confirm the figure on the authority’s own page, and for a decision that depends on your circumstances, talk to a registered tax agent — Fin gives you organised records to take with you.

Questions people ask

Where exactly is my data stored?

In an ordinary folder on your computer — %APPDATA%\2Fin on Windows (macOS and Linux to follow). The app shows you the real path and opens the folder for you. Your records live in a single database file plus a folder of receipt files you can browse yourself.

Is anything backing up my records for me?

Yes, on your own machine. When the newest copy is more than twenty hours old, 2Fin Desktop takes a fresh copy of your records file, runs an integrity check over it and writes a list beside it of exactly what that copy holds — how many tables, how many rows altogether and how many in each. Only a copy that passes is kept. They live in a folder called “backups” beside your data: the newest three, then one a day for a week, then one a week for a month. Those copies are plain files covering your records rather than your receipts, they stay with the computer that made them, and they never leave it.

What happens if my records file is damaged?

If the app finds the file damaged when it starts, it restores from the best verified backup by itself and tells you that it did. Nothing is sent anywhere for that to happen, and the damaged file is kept rather than thrown away. For a copy that includes your receipts as well, take an encrypted export — ai2fin.com/restore explains what that file is and how to open one.

How do I move everything to another computer?

Use “Export everything…”, which writes a single .finbak file with your records and your receipts in it, sealed with a passphrase you choose (scrypt and AES-256-GCM). Both sit behind the top-bar chip that says where your data lives — “On this PC” on Windows — in the panel called “Where your data lives”. On the other Windows computer (macOS and Linux to follow), install 2Fin Desktop, open that panel and choose “Import from an export…”; importing replaces the records on that machine rather than merging with them. The passphrase is the only way into that file — nobody, 2Fin included, can recover it or read the file without it, so keep it somewhere you will still have it. Copying the “backups” folder across instead does not generally work: those copies are tied to the computer that made them.

How is Fin’s intelligence different from a chatbot?

A general chatbot answers from memory. Fin works from your own records, and tax figures such as GST and income tax brackets are calculated in code from a dated rate ledger rather than recalled by a model. When you ask about a tax rule, Fin points you to hand-checked official pages, such as the ATO’s, so you can read the rule in the authority’s own words.

Do I need an account to use it?

No. The free tier of 2Fin Desktop needs no sign-up at all. You download it, open it, and start. Linking a free account adds a monthly allowance of Fin chat; paid plans add intelligent categorising and receipt reading. Or connect your own model key, which works on any plan. Keeping your PCs in step through a folder you choose needs no account either, on any plan.

What works in 2Fin Desktop without an account or a model key?

Your books do. Imports, categorising with your own rules, bills, budgets, travel and export all work on your machine, and reading or exporting your data is never blocked. What waits is Fin’s chat: it tells you it needs a model to think with, and offers two ways in — sign in and link this device, or connect your own key or a local model.

What changes when I link a free account to the desktop app?

Linking turns on Fin’s chat, with a monthly allowance. The link itself sends an install ID, your platform and the app version — not your records. When you chat, your messages go to Fin’s relay at api.ai2fin.com with account and card numbers, long reference codes, emails and phone numbers masked first; amounts, dates and merchant names stay so Fin can answer. The relay is designed to record counts and usage, not content. Categorising, summaries and receipt reading through that relay need a paid plan.

Does anything leave my computer?

Only when you ask for something that needs it, such as linking a plan or opening the Plan page, plus one housekeeping request that carries nothing of yours: an update check (a version number). A paid licence holds offline for its whole period with no check-in. The app keeps a readable log of every request it has ever made — the destination, what it was for, and how many records were involved, described in counts rather than content. You can switch each connection off individually, or use Airplane mode to stop all of them. With Airplane mode on, a packet capture shows nothing leaving. Anonymous usage analytics and crash reports are off by default.

Does categorising my transactions send them anywhere?

Categorising by hand, or with the rules you have saved, happens entirely on your machine and sends nothing. Asking Fin to categorise is different, and depends on how Fin is connected. Through a linked account it is a paid feature: the rows involved go to Fin’s relay, are processed, and are not kept. With your own key, on any plan, the rows go straight from your machine to the provider you chose. With a local model, they never leave your computer.

Can I use my own model provider key?

Yes, on any plan in the desktop app. Connect an Anthropic, OpenAI or AWS Bedrock key, or a local OpenAI-compatible model such as Ollama or LM Studio. It covers chat, categorising, receipt reading and summaries, with no plan gate or monthly quota from 2Fin. Requests go directly to the provider you chose, under that provider’s terms — 2Fin is not in the path, so 2Fin’s identifier masking does not apply. A local model keeps everything on your computer, even in Airplane mode.

Where does the desktop app keep my own provider key?

Encrypted with AES-256-GCM, in a file on your own machine — not in your operating system’s keychain. The app’s interface never hands the key back once it is saved, and the key is never sent to 2Fin.

Where does Fin get its tax rates from?

Tax figures such as GST, income tax brackets, the Medicare levy and the estimators are calculated in code from one rate ledger, which covers GST, VAT and sales tax for 88 countries and dates the rates that change over time. For questions about the rules themselves, Fin points you to hand-checked official pages — the ATO, HMRC, the IRS, Inland Revenue (New Zealand), the CRA and India’s Income Tax Department — each carrying the date it was last checked. Rates do change, so confirm the figure on the authority’s page before you lodge.

Is what Fin tells me about tax personal tax advice?

No. Fin gives general information and calculation help, not personal tax or financial advice. In Australia only a registered tax agent can give you personalised tax agent services, and you remain responsible for what goes in your return. When your situation calls for it, Fin suggests speaking with a registered tax agent — and gives you organised records to take into that conversation.

What happens to my data if I stop paying?

Nothing. The app reverts to the free tier and everything you already have stays readable, editable and exportable. Your own financial records are never held back as leverage — that is written into the licence, not just the marketing.

Is this the same app as the 2Fin web version?

It is the same product, built from the same code. The difference is where your records are kept and what the app is allowed to reach. The desktop build keeps them on your machine; the cloud build keeps them in your 2Fin account so they follow you between devices.

Can I run it on my own server instead?

Yes. A single-tenant build runs on your own infrastructure with Docker Compose, or on AWS in your own account with a one-stack CloudFormation template. It is intended for a business running its own books — offering it to third parties as a service needs a separate commercial agreement.

Start with the free tier

No account, no email, no card. Bring a CSV and see your own numbers in a few minutes.

Would a browser or your phone suit you better? Compare the Windows app and the web app

Get the Windows app →