Privacy and data
Where Does Your Expense Data Actually Live?
Every expense tracker makes a quiet decision about where your financial records physically live. That decision determines what happens when the app changes, the company is sold, or the servers go dark. Here is how to tell the models apart.
Published August 23, 2026 · 7 min read
TL;DR: Expense apps store your records in one of three places: a company cloud account, a bank aggregation feed, or storage on your own device. Local-first apps keep records on your device by default and give you export files you control. In Pludo Ledger, records start in device storage, .lbx exports work everywhere, and opt-in Google Drive backup stores copies in your own Drive, not ours.
What does local-first mean for a finance app?
Local-first means the app writes your records to storage on your own device, such as the browser-managed storage a web app uses or the app storage a phone provides, before anywhere else. A local-first expense tracker reads and writes your transactions, budgets, and reports from that local copy, and treats online services as optional additions rather than a requirement. The test is simple: turn off the network and see what still works. In a local-first tracker, your history, budgets, and reports still open.
Why the question matters more than it sounds
Finance apps are not like photo filters. When Mint was shut down by Intuit in 2024, millions of users had to move years of records to a replacement on a deadline they did not choose. The tool disappeared because the company decided it, and users who had depended on its cloud copy had to accept whatever migration path was offered. Where your records live decides who has that power next time: the company, or you.
There is a second, quieter dimension: aggregation. Apps that connect to your bank send your credentials or tokens through an aggregator, which then holds a running copy of your transaction history in order to refresh it. That copy does not disappear when you delete the app from your phone. Neither dimension is automatically disqualifying, but both deserve an explicit answer before you spend a year building records somewhere.
The three storage models compared
| Model | Where records live | If the service shuts down | What you must trust |
|---|---|---|---|
| Cloud account app | The company's servers, under your login | Records are gone unless the company exports them for you | The company's longevity and policy |
| Bank aggregation app | Your bank feed, mirrored in the company's cloud | History depends on the aggregator relationship | The aggregator and the company |
| Local-first app | Your device, with export files you hold | Your records and exports keep working offline | Your own backups, like any file |
Where records physically live under each app model, and what that means when something goes wrong.
How backups work in a local-first app
Local storage is only safe if it is backed up, and an honest local-first app treats backup as a first-class feature rather than an afterthought. In Pludo Ledger there are three layers. First, a manual export that writes your full history to a single .lbx file you can store anywhere, which works on every platform including the web app. Second, direct device-to-device transfer when you move phones. Third, an opt-in Google Drive backup that runs in the background into a private app-data area of your own Drive, keeps a version history, and can restore onto a new device when you sign in.
The .lbx file deserves a specific mention because it is a complete, single-file copy of your records, encrypted so only your account can open it, that you can import into a fresh install of the app on any device by signing back in. Keep copies of it the way you keep any important document, so a lost or replaced device is never a lost financial history. Read the security approach
Does local-first mean no internet at all?
No, and any app that implies otherwise is overselling. Signing in, exchanging rates, notifications, AI requests, and device transfer all use the network when you invoke them. The honest version of the claim is directional: core records begin on your device, online features are opt-in, and the manual workspace keeps working when the network does not. Pludo Ledger takes that position, and the AI assistant is optional and can be turned off entirely without disabling the rest of the app. See how AI requests handle your data
How to check where an app keeps your records
- Search the app or its help docs for an export function. No export, or export locked behind a paid tier, tells you who owns the copy.
- Turn on airplane mode and reopen the app. If your history is gone, it lives on a server, not your device.
- Read what the privacy policy says about aggregation and third-party processors, which names the companies that can see your data.
- Check whether backups go to storage you control, such as your own Drive account, or to storage the company controls.
Common mistakes when choosing a tracker for data ownership
- Confusing "encrypted in transit" with "stored on your device". The first is about the connection, the second is about where the copy lives.
- Trusting a cloud sync you cannot export from. Sync is not backup if the only readable copy is inside the company's system.
- Skipping local exports because a cloud feature exists. Even a good cloud backup deserves a file you hold.
- Assuming an app without bank connection stores nothing online. Sign-in, analytics, and AI features can still use network services.
Frequently asked questions
What does local-first mean?
An app is local-first when your records are written to storage on your own device and the core features keep working from that local copy. Online services, when present, are optional additions rather than a requirement for basic use.
Is my data safe if the app shuts down?
If the app is local-first and you keep export files, yes. Your records live on your device and in your exports, so a shutdown removes the tool, not your history. Cloud-account apps without export leave that answer to the company.
What is an .lbx file?
It is Pludo Ledger's native backup format: a single file containing your complete record history, which you can export anytime, store anywhere, and import into a fresh install on any device.
Does Google Drive backup store my data on Pludo's servers?
No. The optional Google Drive backup writes to a private app-data area of your own Google Drive. Pludo AI servers never hold the backup, and the feature is off until you turn it on.
Does a local-first app still use the internet?
Yes, for optional features. Signing in, exchange rates, notifications, AI requests, and device transfer use the network when invoked. Core records and the manual workspace stay local and keep working offline.
Own the copy, then choose the tool
Apps will come and go, and the category has already buried some of its biggest names. The records you build over years should not depend on any one of them lasting forever. Try a local-first expense tracker free and keep your history in files you hold.
More from the blog
See it in your own records.
Open Pludo Ledger and try the manual tools, or ask Plu for a specific task.