Back to home
Privacy · in plain language

Your data stays with you.

Floati is built so your information lives on your device, not our servers. There are no accounts to create, no trackers or ad networks, and the AI runs on your own machine, so your content is never sent to an AI company. Below is the whole truth, product by product, in plain words. And if you would rather not take my word for any of it, there is a way to check it in your own browser.

No accounts No trackers or ad pixels On-device AI Nothing sold, ever
If you read nothing else

Four promises the rest of this page keeps.

Everything below simply shows, product by product, exactly how each of those stays true, then hands you the tools to verify it.

The whole map

Where your data actually goes.

Four products, one principle. Here is the short version of each, before the detail: almost everything stays on your device, and the little that reaches a server is anonymous and, wherever possible, something you choose.

Product
Stays with you
Reaches our server
Desktop app
Everything you track, in one local file
Nothing at all
CV Builder
Your resume and the on-device AI
An anonymous auto-saved draft; a review only if you post one
Learn course
Your code, progress and on-device tutor
A certificate or review, only if you choose to make one
Floati Browser
Everything you browse, encrypted at rest
An update check; anonymous stats only if you opt in

The full detail

Every product, line by line.

The complete accounting: what stays on your device, and the short, anonymous list that ever touches a server.

Floati Desktop App

Windows (Microsoft Store) and macOS (Mac App Store)

Floati collects, stores, transmits and shares no personal data. In normal use it makes no network requests at all.

Stays on your device everything

  • Expenses, budgets, subscriptions, debts, savings and net worth
  • Habits, birthdays, notes, reminders and receipts
  • All of it in a single local database file on your machine
  • Optional AES-256 encrypted backups, unlocked by a passphrase only you hold
  • Export anytime as JSON, PDF, Excel or CSV; delete the file to erase everything

Leaves your device to anyone

Nothing.

  • No accounts, logins, sync, telemetry or crash reports
  • No location, device identifiers or cookies
  • Both store listings declare “Data Not Collected” in every category

Check it: watch the app with Little Snitch, LuLu or Wireshark and you will see no outbound connections.

CV Builder

The free resume tool at floati.life/cv

No account. The AI runs on your own device, and your resume is never sent to OpenAI, Anthropic, Google, my server, or anyone.

Stays in your browser your work

  • Your full resume content: experience, education, skills
  • The on-device AI improver and the deterministic ATS scorer, both run in your browser via WebGPU
  • PDF export, generated locally by your browser; nothing is uploaded
  • An optional, compressed profile photo if you add one

Reaches my server minimal

  • An auto-saved copy of your draft, keyed to a random cookie token, with no name and no email attached
  • If, and only if, you post a review: your display name, rating and comment (shown publicly), plus a one-way hashed id, never your raw IP address

The AI improver downloads its model once from a public code CDN, then runs entirely in your browser; your resume is never sent to that CDN or to any AI company. Remove everything anytime with “Remove all saved data” in the builder, or by clearing your cookies. Questions: nevintom2018@gmail.com.

Learn: Python + AI course

The free in-browser course at floati.life/learn

No account. Your lesson code runs in a sandbox in your browser, the AI tutor runs on your device, and your progress is saved on your own machine.

Stays in your browser your work

  • Lesson code runs in a Pyodide WebAssembly sandbox that is network-blocked; it is never executed or stored on my server
  • The optional AI tutor and “review my code” helper run on-device via WebGPU
  • Your progress, streak and XP live in your browser’s local storage; export them to a JSON file you control

Reaches my server opt-in only

  • A certificate, only if you mint one: the name you type, the course, your score and the date, made publicly verifiable, plus a one-way hashed id
  • A public review, only if you post one: display name, rating and comment, with the same hashed id

Like the CV Builder, the on-device tutor downloads its model once from a public code CDN, then runs entirely in your browser; the code you write and the answers you give are never sent to it, or to any AI company. No account, no email, and no analytics on your code or answers. Ever.

Floati Browser

A privacy-first desktop browser, in development. Live build numbers at floati.life/browser

Not downloadable yet; this covers the builds that exist today and will be kept current when it ships. By default it has no account, no telemetry and no cloud: it sends me nothing.

Stays on your device everything you do

  • History, bookmarks, downloads, sessions and settings, in a local database encrypted at rest (SQLCipher), with the key in your system keychain
  • The memory features (Rewind, Time Capsule, Ask your reading): pages you read are indexed and answered on-device only, with an off switch and a per-site “never remember” list that also erases what was already saved
  • Passwords in a vault released only after Touch ID / Windows Hello
  • Ad, tracker and phishing protection evaluated locally against bundled lists; the browser never sends a URL anywhere to check it

Reaches my server two, both narrow

  • An update check: a plain request for the latest version number, carrying no identifier and no browsing data. Like any web request it necessarily shows my server an IP address; I do not store it
  • Shared stats, off by default. If you opt in, exactly this: a random install id, the app version, your OS name, and five counters (tabs opened, tabs suspended, trackers blocked, estimated memory saved, research-project count). Never URLs, searches, history, or anything typed. The aggregate is public at floati.life/browser

The sites you visit connect to their own servers, as in any browser, and the system web engine (from Apple or Microsoft) may make its own operating-system service connections that are outside my control. Turn shared stats off anytime in Settings; delete the local database and everything is gone. Because your data never reaches me, I cannot read it, and I also cannot recover it: keep your own backups.

Trust, but verify

Prefer to check? Watch this page audit itself.

A privacy policy is a promise; this part is an instrument. Your own browser lists every request this page makes, proves that whatever you type stays put, and lets you try to make it leak, on purpose, and watch it fail.

Live · outbound network monitor
0First-party
requests
0Trackers
reached
0Your content
transmitted
requests, newest first
Your browser is the witness. With JavaScript on, every request this page makes appears here, marked first-party (stays on floati.life) or third-party. On this page the third-party column stays at zero.
What the page ever sends
{
  "p": "/privacy/",   // page path
  "r": "",           // referring site
  "w": 1280,         // window width
  "l": "en"          // language
}
The single first-party analytics ping. From it the server derives an anonymous, one-way hashed visitor id; your raw IP address is never stored, and your content is never sent.
Don’t take the panel’s word for it either: open DevToolsNetwork and compare. On this page, every domain is floati.life.
01 · Type a secret
On your device 0 bytes Transmitted to me 0 bytes

Measured live: your browser has made 0 outbound requests so far, and your text appeared in 0 of them. The transmitted figure is a real tally, not a promise.

02 · Try to leak it out
Edit the URL to any tracker you like, then make this page try to POST your secret from box 01 to it. Watch it bounce.

This fires a real POST of your secret at the domain above, over fetch and XHR. Both are refused by this site’s Content-Security-Policy before a byte leaves; the verdict shown is your browser’s own, not mine.

Every website can read the signals below the moment you arrive; most quietly bank them to fingerprint you. Floati reads them too, to lay out the page, and then looks away. Computed live in your browser, never sent anywhere (the monitor above is your proof).

Timezoneyour local timezone discarded
Languageyour language discarded
Screenyour screen size discarded
Platformyour platform discarded
CPU threadsyour core count discarded
Themelight / dark discarded

Housekeeping

A few things true of the whole site.

Privacy-preserving analytics

The single first-party ping in the monitor above is nearly the whole story. From it the server keeps: the page path, the referring site, your window width and language, and, computed on the server, a one-way hashed visitor id (sha256 of your IP address and browser, truncated, so the raw IP is never stored), the browser’s user-agent string, and a device type (phone, tablet or desktop). There is no third-party analytics service, no cross-site tracking, and no advertising network anywhere on the site.

On-device AI and content delivery

The CV Builder and the Learn tutor run their AI in your browser. The model is downloaded once from public code CDNs (such as Cloudflare, jsDelivr and Hugging Face), then runs entirely on your device via WebGPU. You only ever download from those CDNs; your resume, your code and your answers are never sent to them or to any AI company. So if you watch DevTools while the AI loads, you will see those content downloads, and nothing of yours going out.

Cookies

The CV Builder uses one first-party cookie to link your saved draft across visits, plus a standard session cookie for security. No advertising or cross-site cookies, ever. The desktop app uses none; it is not a website.

Children’s privacy

The desktop app collects no data from anyone. The website does not knowingly collect personal data from children under 13. If you believe a child has submitted data, email me and I will remove it.

Your data, your responsibility

Floati’s products are free and provided as is, without warranty of any kind. The flip side of everything living on your device is that I hold no copy: I cannot read your data, and I also cannot recover or restore it if your device is lost or wiped. Keep your own backups; the desktop app and the browser both include export and encrypted-backup tools for exactly this.

When I would disclose data

For the products above I hold almost nothing to disclose. For the little the website does hold (saved CV drafts keyed to a random cookie, certificates, reviews, and hashed analytics), I would only disclose it if a law I am subject to compels it, and I have never been required to. I do not sell or share any of it with advertisers or data brokers, full stop.

Changes, and how to reach me

If anything changes, the updated policy is published at this URL with a new “last updated” date. No silent edits, and no weakening of the on-device principle without a clear, dated notice here.

Questions, corrections or deletion requests: nevintom2018@gmail.com. Built and operated by Nevin Tom in South Africa. Last updated July 2026.

Looking for the Bday Wishes iOS app? It is a separate product with its own privacy policy. Bday Wishes privacy

Free · Private · No account · Verifiable · floati.life