Verify, don’t trust

Verify it yourself in five minutes

100% local — provable, not just promised

2Fin Desktop says your financial records stay on your machine. Here is how to test that with your own tools, on your own computer, without trusting anything on this page.

  1. Establish a baseline — start capturing with the network available

    Start your monitor before turning anything off. This is the stronger test: it shows whether the app phones home on its own, not just whether it can be stopped from doing so.

  2. Work normally while the capture runs

    Import a CSV of transactions, categorise a few of them and explore your dashboard — and on a paid plan, run a report and a tax export too. Nothing here is blocked — if 2Fin sent anything during these operations, this capture would show it.

  3. Review the baseline capture

    None of your work produced an outbound connection from the 2Fin process, even though your connection was fully available the entire time. That is the claim being tested — not "it can be stopped," but "it never tried." At most you may see the app’s one housekeeping request: an update check carrying a version number. It is listed in the outbound log, it can be switched off, and it carries nothing from your books.

  4. Enable Airplane mode and repeat the workflow

    In 2Fin Desktop, click the "On this PC" chip in the top bar to open the "Where your data lives" panel, and turn Airplane mode on. Run the same workflow again. Everything on your machine keeps working — importing, categorising, and every report or export your plan includes — and the capture stays as empty as the first one, which confirms the toggle genuinely blocks rather than just going unused.

  5. Re-enable one connection and compare capture with log

    Switch Airplane mode off and ask Fin to categorise something. The capture shows exactly one destination, and the app's own outbound log shows the same request. The two agreeing is what makes the log worth trusting the rest of the time.

The exact commands

macOS / Linuxtcpdump — terminal capture, loopback excluded
sudo tcpdump -i any -n "not host 127.0.0.1 and not host ::1"

Excludes loopback, because 2Fin talks to its own local server on 127.0.0.1 — that traffic never leaves your machine. tcpdump captures every process on your machine, not just 2Fin: close other network-heavy apps first, or use a per-process tool below for genuine attribution.

macOSLittle Snitch or LuLu — per-process firewall

Open the firewall’s rule list and filter it to “2Fin”. No command needed — the tool watches every process by itself.

A per-process firewall is the clearest view: it shows attempts, not just packets, so a blocked attempt would still be visible.

WindowsWireshark — display filter, loopback excluded
not ip.addr == 127.0.0.1 and not ipv6.addr == ::1

Paste into the Wireshark display filter. Use Resource Monitor to confirm which PID belongs to 2Fin.

AnyNo tools — disconnect entirely

Turn off Wi-Fi and unplug ethernet, then keep working.

The bluntest test of all: the app should carry on working normally. Anything requiring a connection says so plainly instead of failing silently.

What you are actually testing

Two different things, and it is worth separating them. The first is whether the app can work with no network at all — that tests where your records live and where the work happens. The second is whether the app’s own log of outbound requests tells the truth, which you test by turning one connection back on and checking that the capture and the log agree.

The second is the one that matters long term. Nobody runs a packet capture forever. But if the log matched reality when you checked, it is reasonable to rely on it afterwards — and that log is in the app, showing every request Fin has ever made, in counts rather than content.

The log records counts and destinations rather than the rows themselves for a deliberate reason: a log holding your transaction text would become exactly the copy of your data the claim says does not exist.

Questions people ask

Why does 2Fin Desktop show traffic to 127.0.0.1?

The app runs its own small server on your machine and the window talks to it. 127.0.0.1 is your own computer — that traffic never reaches your network card, let alone the internet. Filter it out of your capture and what remains is genuine outbound traffic.

What should I see when Airplane mode is on?

Nothing outbound from the 2Fin process. Importing, categorising by hand or with saved rules, and every report or export your plan includes all run on your machine, so none of them need a connection.

What will I see when I turn a connection back on?

Exactly one destination per feature you use, and the same request recorded in the app's own outbound log — described in counts rather than content. If the capture and the log ever disagreed, the log would be the thing to distrust.

Will the capture ever show requests I did not make?

One at most, and it carries none of your data: an update check (a version number). It appears in the app’s outbound log and can be switched off. A paid licence holds offline with no check-in; the app only contacts 2Fin about your plan when you link a device or open the Plan page. Anonymous usage analytics and crash reporting are off by default, so they appear only if you turned them on.

Can I do this on the cloud version too?

The cloud version is a website, so of course it talks to 2Fin — that is what it is. This test is for the desktop app, where the claim is that your records stay on your machine.

Read the whole story

What 2Fin Desktop keeps on your machine, what leaves and when, and how the free tier works without an account.

How local mode works
Get the Windows app →