Mobile ApplicationMaintainedFeatured SystemJun 2026 – Present

FinLedger — Android Personal Finance & Wealth Management Engine

Local-first, zero-knowledge Android personal finance engine with SQLCipher encryption, on-device bank SMS detection, and zero double-counting accounting.

FinLedger — Android Personal Finance & Wealth Management Engine

Technologies & Architecture Stack

Kotlin 2.0Jetpack ComposeMaterial 3Android Room (v18)SQLCipher (256-bit AES)Android KeyStore (TEE/StrongBox)BiometricPromptGoogle Dagger HiltKotlin CoroutinesStateFlowAndroid WorkManagerGoogle Drive REST API v3Native PdfDocumentJUnit 5

Project Overview

FinLedger is a local-first, zero-knowledge personal finance management system engineered for Android (Kotlin 2.0, Jetpack Compose, Room v18, and SQLCipher). Unlike mainstream commercial finance apps that compromise financial privacy by scraping credentials or uploading raw banking data to remote servers, FinLedger executes 100% of ledger calculations, transaction classification, and SMS parsing on-device. The platform solves the fundamental accounting flaw present in popular budgeting apps: double-counting credit card liabilities and bill settlements. Built with Clean Architecture, an immutable domain LedgerEngine, 256-bit AES SQLCipher encryption anchored to Android KeyStore hardware (TEE/StrongBox), and zero-knowledge Google Drive cloud sync (REST API v3), FinLedger bridges deterministic financial precision with fluid 60 FPS Material 3 design.

The Engineering Problem

Mainstream personal finance applications suffer from critical architectural and mathematical flaws: 1. Severe Privacy Leakage: Banking SMS notifications and transaction histories are continuously uploaded to third-party analytics servers. 2. Flawed Financial Mathematics: Most apps double-count credit card purchases and subsequent bill payments, distorting liquid spendable cash and true net worth. 3. High Data Entry Friction: Manual expense logging is tedious, while automated cloud scrapers frequently fail or break due to bank security changes. 4. Database & State Inconsistency: Concurrent balance mutations, app process kills during imports, and multi-device synchronizations often corrupt ledger state.

The Solution

Engineered an offline-first Android financial operating system rooted in mathematical determinism and hardware-backed security: 1. Deterministic Ledger Engine: Developed a pure Kotlin Posting rules engine that cleanly isolates liquid cash, credit card liabilities, and illiquid wealth with zero double-counting. 2. Local On-Device Regex SMS Ingestion: Built a background broadcast receiver and inbox scanner with an early OTP-rejection shield that identifies financial transactions from 10+ Indian/global banks and UPI apps without sending a single byte over the network. 3. Cryptographic Hardware Vault: Encrypted the SQLite database at rest using SQLCipher 256-bit AES-CBC, derived from keys protected within the Android KeyStore (TEE / StrongBox) and salted PBKDF2 PIN authentication (50,000 iterations). 4. Zero-Knowledge Google Drive AppData Sync: Designed a lightweight REST API v3 sync engine that uploads client-side encrypted snapshots to the user's hidden Google Drive appDataFolder with bidirectional conflict resolution. 5. Client-Side Document Generation: Integrated native PdfDocument statement rendering and universal RFC-4180 CSV import/export with pre-import safety snapshots and 1-tap rollback.

System Architecture & Data Flow

Built on Clean Architecture and Unidirectional Data Flow (UDF) across three decoupled layers: - Presentation Layer: 24 Jetpack Compose navigation routes themed with Material 3. ViewModels expose immutable StateFlow collected via collectAsStateWithLifecycle. Startup data fetching is decoupled to ensure cold-boot primary balance emission in <3ms. - Domain Layer: Pure Kotlin business logic with zero Android/Room dependencies. Includes LedgerEngine (deterministic replay and delta calculation), Posting.kt (canonical accounting rules), SmartCategoryClassifier (merchant heuristic learning), and SyncMergeEngine. - Data Layer: Room Database v18 (21 Entities, 18 DAOs) wrapped by SQLCipher AES-256. A unified FinanceRepository facade coordinates specialized repositories (Transaction, Account, Category, Budget, Lending, and Sync). WorkManager handles periodic background budget threshold notifications, due-date alerts, and daily sync.

Core Engineering Features

Deterministic Account-Based Accounting separating liquid cash, credit card liabilities, and investments with 0% double-counting.
Real-Time On-Device SMS Parser with OTP rejection shield detecting transactions across SBI, HDFC, ICICI, Axis, Kotak, and UPI apps.
Hardware-backed SQLCipher 256-bit AES-CBC database encryption at rest anchored to Android KeyStore TEE / StrongBox.
BiometricPrompt authentication gated by 50,000-iteration Salted PBKDF2-HMAC-SHA256 PIN hashing with constant-time verification.
Zero-Knowledge Google Drive AppData Cloud Sync (v3 REST API) with monotonic mutation journaling and 3-way conflict resolution.
Client-side PDF financial statement engine generating branded, filter-aware account statements with native PdfDocument.
Universal CSV Import/Export engine (RFC-4180) featuring column auto-mapping, pre-import safety snapshots, and 1-tap rollback.
Credit Card Hub with visual credit utilization warnings (>30%), billing cycle tracking, and 1-tap bank-to-card bill payment flow.
Split & Group Expenses subsystem with itemized debt tracking, partial repayment logging, and automatic ledger balance offset.
Period-based multi-tier ledger navigation (Daily, Monthly, Yearly matrix) rendered at 60 FPS using Compose stability configurations.

Technical Challenges & Overcoming Them

Eliminating Double-Counting in Credit Card Accounting: Formalized posting rules where card purchases increase liabilities without reducing bank balances, and bill payments act as balance settlement transfers.
Preventing Sensitive Financial Data Leaks via SMS Parsing: Built an on-device regex engine with bank header whitelists and an early OTP-shield, ensuring SMS messages are parsed locally and verified through an explicit user confirmation gate.
Securing Database Master Keys Against Root / Memory Extraction: Removed keys from unencrypted shared preferences, delegating cryptographic key generation and storage to Android KeyStore hardware (TEE / StrongBox).
Resolving Cloud Sync Conflicts Without a Dedicated Server: Implemented a monotonic revision journal with timestamp comparisons, presenting interactive 2-step resolution dialogues for concurrent multi-device modifications.
Preventing Cold-Boot Startup UI Jank: Offloaded complex balance aggregation and lending reconciliation to Dispatchers.Default, emitting cached primary balances in <3ms and streaming secondary data progressively.
Ensuring Data Safety During Batch CSV Imports: Divided ingestion into separate parse and persist phases wrapped in Room withTransaction blocks, creating an automatic pre-import safety snapshot for instant 1-tap rollback.

Results & Impact

- 158 automated unit tests across 21 test suites executing with 100% pass rate. - Cold-boot primary balance emission in <3ms on mid-range Android hardware. - 0% double-counting across multi-account transfers, credit settlements, and expense logging. - 256-bit AES database encryption at rest combined with 50,000 PBKDF2 iterations for zero plaintext leak. - 100% offline, zero-telemetry architecture with zero raw transaction data leaving the device. - Release candidate (v2.0.2, Build 8) verified with R8 minification, ProGuard log stripping, and WCAG AA contrast compliance.

Key Takeaways

- Mastered Clean Architecture and Unidirectional Data Flow (UDF) in Jetpack Compose, learning how to isolate pure business logic from UI and persistence frameworks. - Deepened expertise in cryptographic key management, TEE hardware security, side-channel attack mitigation (constant-time verification), and SQLCipher encryption. - Gained advanced experience in asynchronous Android systems: broadcast receivers, WorkManager scheduled tasks, and high-performance Kotlin Coroutines/Flow state modeling. - Learned the nuances of offline-first synchronization protocols, monotonic versioning, and deterministic state machines for conflict resolution without a central backend server.

Future Roadmap

- On-Device Receipt & Invoice OCR: Integrate Google ML Kit Text Recognition for automated receipt itemization and camera-to-transaction parsing. - Mutual Fund NAV Sync Engine: Daily automated background portfolio valuation via official AMFI India public APIs. - Advanced Financial Modeling: Multi-scenario retirement and FIRE (Financial Independence, Retire Early) forecasting with monte carlo simulations. - Excel (.xlsx) Multi-Tab Export: Native streaming generation of formatted multi-account workbooks.