<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Asiv</title>
    <description>The latest articles on DEV Community by Asiv (@asiv).</description>
    <link>https://dev.to/asiv</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4116679%2F44770fa3-d25c-4a03-98c9-9b9944aad179.png</url>
      <title>DEV Community: Asiv</title>
      <link>https://dev.to/asiv</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/asiv"/>
    <language>en</language>
    <item>
      <title>Building a Zero-Telemetry Android Vault: Flutter, Encrypted SQLite, and Why We Ditched Cloud Sync</title>
      <dc:creator>Asiv</dc:creator>
      <pubDate>Sat, 26 Sep 2026 14:17:38 +0000</pubDate>
      <link>https://dev.to/asiv/building-a-zero-telemetry-android-vault-flutter-encrypted-sqlite-and-why-we-ditched-cloud-sync-35c1</link>
      <guid>https://dev.to/asiv/building-a-zero-telemetry-android-vault-flutter-encrypted-sqlite-and-why-we-ditched-cloud-sync-35c1</guid>
      <description>&lt;p&gt;When building personal finance software, standard engineering advice says:&amp;nbsp;&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;"Spin up Supabase, plug in Plaid for automatic bank scraping, and charge $12/month."&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;We rejected that premise entirely when architecting &lt;strong&gt;MyneWallet&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Handling money data requires extreme operational discipline. If your remote server stores a user's transaction ledger, you are one zero-day exploit, misconfigured S3 bucket, or sub-processor breach away from exposing their entire financial identity.&lt;/p&gt;

&lt;p&gt;Here is the engineering breakdown of how we built an offline-first, zero-telemetry financial vault in Flutter—handling decimal currency math without floating-point errors, deterministic envelope allocation, and client-side web verification.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;The Core Constraint: Zero Network Permissions&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The cleanest way to guarantee data privacy is architectural, not legal:&lt;/p&gt;

&lt;p&gt;No Firebase SDKs.&lt;/p&gt;

&lt;p&gt;No Mixpanel, Segment, or analytics beacons.&lt;/p&gt;

&lt;p&gt;No network requests carrying payload figures.&lt;/p&gt;

&lt;p&gt;Every ledger write, balance reconciliation, and category balance calculation runs strictly inside an on-device SQLite database encrypted with SQLCipher.&lt;/p&gt;

&lt;p&gt;[User Device]&amp;nbsp;&lt;br&gt;
&amp;nbsp; &amp;nbsp;└── Flutter UI Layer&amp;nbsp;&lt;br&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; └── Integer Math Engine&amp;nbsp;&lt;br&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;└── Encrypted SQLite Database (On-Device Storage Only)&lt;br&gt;
The app operates identically in airplane mode because it has zero remote dependencies.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Handling Currency Math Without Floating-Point Traps&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In financial software, standard IEEE 754 floating-point operations (0.1 + 0.2 = 0.30000000000000004) are unacceptable. Over multi-year ledgers with thousands of line items, floating-point rounding errors compound into balance drift.&lt;/p&gt;

&lt;p&gt;To guarantee precision, all monetary values in our SQLite database are stored as 64-bit Integers representing minor units (cents):&lt;/p&gt;

&lt;p&gt;Dart&lt;br&gt;
class Money {&lt;br&gt;
&amp;nbsp; final int minorUnits; // $14.99 is stored as 1499 integer cents&lt;/p&gt;

&lt;p&gt;&amp;nbsp; const Money(this.minorUnits);&lt;/p&gt;

&lt;p&gt;&amp;nbsp; Money operator +(Money other) =&amp;gt; Money(minorUnits + other.minorUnits);&lt;br&gt;
&amp;nbsp; Money operator -(Money other) =&amp;gt; Money(minorUnits - other.minorUnits);&lt;/p&gt;

&lt;p&gt;&amp;nbsp; String toFormattedString(String currencySymbol) {&lt;br&gt;
&amp;nbsp; &amp;nbsp; final double value = minorUnits / 100.0;&lt;br&gt;
&amp;nbsp; &amp;nbsp; return '(currencySymbol){value.toStringAsFixed(2)}';&lt;br&gt;
&amp;nbsp; }&lt;br&gt;
}&lt;br&gt;
By enforcing integer arithmetic, our envelope auto-allocation algorithms never lose a single cent to binary rounding residue.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;The Envelope Allocation Engine&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Under a True Zero-Based Budgeting (ZBB) model, every single unit of income must be assigned a job before the month begins:&lt;/p&gt;

&lt;p&gt;💡 The Core Equation:&lt;/p&gt;

&lt;p&gt;To Assign = Unallocated Cash − Total Assigned Envelopes&lt;/p&gt;

&lt;p&gt;When income arrives, our deterministic Auto-Assign engine allocates funds through a three-stage priority pipeline:&lt;/p&gt;

&lt;p&gt;Fixed Monthly Obligations: Rent, utilities, debt minimums.&lt;/p&gt;

&lt;p&gt;Sinking Fund Targets: Amortized monthly allocations for annual commitments.&lt;/p&gt;

&lt;p&gt;Flexible Spending: Groceries, personal allowances, dining.&lt;/p&gt;

&lt;p&gt;If a category overspends, the ledger flags the exact variance and prompts the user to reallocate from another envelope, keeping the core ledger balanced to zero.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Client-Side Web Companion &amp;amp; Open Methodology&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Alongside the mobile app, we built 10 standalone client-side financial calculators that run in the browser without cookies, tracking scripts, or server requests:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Web Suite:&lt;/strong&gt; &lt;a href="https://thebrinklabs.com/tools/" rel="noopener noreferrer"&gt;https://thebrinklabs.com/tools/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Formulas &amp;amp; Verification Gates:&lt;/strong&gt; &lt;a href="https://thebrinklabs.com/methodology" rel="noopener noreferrer"&gt;https://thebrinklabs.com/methodology&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Every formula, rounding rule, and mathematical test case is published openly, allowing users to verify our math directly in their browser's Network tab before downloading the mobile app.&lt;/p&gt;

&lt;p&gt;Conclusion &amp;amp; Open Discussion&lt;br&gt;
Privacy in software is often treated as a marketing bullet point. In practice, it is a set of hard architectural trade-offs: no password reset flows, no remote sync fallbacks, and total reliance on robust local database integrity.&lt;/p&gt;

&lt;p&gt;Google Play: &lt;a href="https://play.google.com/store/apps/details?id=com.thebrinklabs.mynewallet.expensetracker" rel="noopener noreferrer"&gt;https://play.google.com/store/apps/details?id=com.thebrinklabs.mynewallet.expensetracker&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Architecture Docs: &lt;a href="https://thebrinklabs.com/" rel="noopener noreferrer"&gt;https://thebrinklabs.com/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;How are other indie developers handling local encrypted storage and offline state management in Flutter? Let's discuss in the comments below!&lt;/p&gt;

</description>
      <category>flutter</category>
      <category>dart</category>
      <category>architecture</category>
      <category>privacy</category>
    </item>
    <item>
      <title>Why I stripped Firebase and built an offline-first budget vault on Flutter &amp; SQLite?</title>
      <dc:creator>Asiv</dc:creator>
      <pubDate>Wed, 09 Sep 2026 13:18:51 +0000</pubDate>
      <link>https://dev.to/asiv/why-i-stripped-firebase-and-built-an-offline-first-budget-vault-on-flutter-sqlite-577n</link>
      <guid>https://dev.to/asiv/why-i-stripped-firebase-and-built-an-offline-first-budget-vault-on-flutter-sqlite-577n</guid>
      <description>&lt;p&gt;I am a Banking Professional, and like many developers and finance enthusiasts, I hit a breaking point with modern personal finance software. &lt;/p&gt;

&lt;p&gt;Almost every mainstream budgeting app (YNAB, Monarch, Copilot) operates on the exact same playbook:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Mandatory cloud account synchronization.&lt;/li&gt;
&lt;li&gt;Third-party bank scraping integrations (Plaid/Yodlee).&lt;/li&gt;
&lt;li&gt;Recurring, aggressive annual subscriptions ($100+/year).&lt;/li&gt;
&lt;li&gt;Invasive corporate telemetry tracking your spending behavior.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;I wanted a personal financial command center with absolute data sovereignty. That led to engineering MyneWallet around a strict architectural constraint: the network is disabled by default.&lt;/p&gt;

&lt;p&gt;Here is why we tore out cloud infrastructure, stripped Firebase, and built a local-first financial engine on Flutter and SQLite.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The Problem with the Default "Firebase Stack" for Finance&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;When bootstrapping a mobile app in Flutter, the default advice is always: Throw Firebase Auth, Firestore, and Firebase Analytics at it.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;For a privacy-first financial vault, that default stack is a liability:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;- Third-Party Telemetry &amp;amp; Surveillance:&lt;/strong&gt; Even if you don't actively log sensitive transactions, including tracking SDKs links device IDs, IP addresses, and behavioral metrics back to corporate ad networks.&lt;br&gt;
&lt;strong&gt;- Binary Bloat &amp;amp; Cold Start:&lt;/strong&gt; Stripping Firebase SDKs immediately trimmed megabytes off the release APK and reduced cold-start initialization to under 300ms.&lt;br&gt;
&lt;strong&gt;- The "Always-Online" Trap:&lt;/strong&gt; When your app relies on cloud sync, an offline subway ride or poor reception turns a 2-second expense entry into a spinning loader.&lt;/p&gt;

&lt;p&gt;We decided that a financial breach cannot expose our users' data if we don't have servers to breach in the first place.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Key Architectural Decisions&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;- On-Device SQLite Sandbox:&lt;/strong&gt; The entire financial ledger resides in an encrypted SQLite database stored securely inside the Android OS application sandbox. No external servers, no account registration screens, and zero remote data storage.&lt;br&gt;
&lt;strong&gt;- Strict Integer Mathematics:&lt;/strong&gt; In fintech, 0.1 + 0.2 != 0.3 is an unacceptable failure mode. All currency calculations in MyneWallet are processed and stored as integer minor units (cents). Every ledger balance mutation runs in atomic database transactions, preventing rounding drift across multi-year projections.&lt;br&gt;
&lt;strong&gt;- Zero Telemetry SDKs:&lt;/strong&gt; There are no advertising SDKs, product trackers, or crash-reporting pipelines sending pings home. If a user turns on Airplane Mode, 100% of the app—including 60fps hardware-accelerated analytics—functions without friction.&lt;br&gt;
&lt;strong&gt;- Client-Side Cryptographic Backups:&lt;/strong&gt; Cloud backup is strictly opt-in to the user's personal Google Drive. The archive is encrypted locally on-device using AES-256 with randomized initialization vectors (IV) before any network socket is opened. We never hold the keys.&lt;br&gt;
&lt;strong&gt;- True Zero-Based Budgeting (ZBB) Engine:&lt;/strong&gt; Built strictly on the envelope methodology: every dollar gets a destination. We engineered a real-time Auto-Assign engine and an honest "Safe to Spend" metric that isolates liquid cash from money already committed to future bills or emergency reserves.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Why We Killed the Subscription Model&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Modern software suffers from massive subscription fatigue. Paying monthly rent just to track what you already earned makes no financial sense.&lt;/p&gt;

&lt;p&gt;The core tracking and budgeting engine in MyneWallet is free forever with zero ads. For power users wanting multi-year analytics, spending heatmaps, and Sankey cash-flow diagrams, it’s a single One-Time Lifetime Unlock. &lt;strong&gt;Buy it once, own it for life.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;- Google Play:&lt;/strong&gt; &lt;a href="https://play.google.com/store/apps/details?id=com.thebrinklabs.mynewallet.expensetracker" rel="noopener noreferrer"&gt;https://play.google.com/store/apps/details?id=com.thebrinklabs.mynewallet.expensetracker&lt;/a&gt;&lt;br&gt;
&lt;strong&gt;- Web &amp;amp; Architecture Manifesto:&lt;/strong&gt; &lt;a href="https://thebrinklabs.com/mynewallet/" rel="noopener noreferrer"&gt;https://thebrinklabs.com/mynewallet/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;We also deployed 6 client-side, zero-tracking financial instruments on the web (Zero-Based Budget Allocator, Subscription Bleed Audit, Debt Payoff, Net Worth Calculator):&lt;br&gt;
&lt;a href="https://thebrinklabs.com/tools/" rel="noopener noreferrer"&gt;https://thebrinklabs.com/tools/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Over to You&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I would love feedback from the community on our local-first constraints:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;How do you approach offline-first database synchronization without compromising privacy?&lt;/li&gt;
&lt;li&gt;Have you ditched third-party telemetry in your own apps?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;I’ll be in the comments answering questions and discussing the Flutter/SQLite architecture!&lt;/p&gt;

</description>
      <category>showdev</category>
      <category>flutter</category>
      <category>privacy</category>
      <category>android</category>
    </item>
  </channel>
</rss>
