Settings

Detect the manipulation before the money moves.

Privacy

What FinShield stores

Analyses are saved in this browser's local storage on this device. There is no account, no server copy and no analytics on your content.

Local data

0 analysis records stored on this device.

Permissions

Camera

Requested only when you tap Scan QR

FinShield uses this permission only to decode a QR code you point it at.

Screen / screenshots

You choose the file each time

There is no background screen monitoring. OCR runs locally on the image you import.

Share sheet

Supported

Share text into FinShield and it opens straight in the message analyser.

Notifications

Enabled (local only)

Local, non-intrusive alerts for checks you run.

Security & language

App lockA 6-digit PIN is required to open FinShield. Only a PBKDF2-SHA256 digest of your PIN is stored on this device — never the PIN itself.

Threat intelligence

Live scam-pattern intelligence

FinShield scores against 10 fraud playbooks (RBI, NPCI, CERT-In, I4C, FTC) plus a live feed of active phishing and malware hosts from OpenPhish and abuse.ch URLhaus. The newest feed entries are distilled by the AI layer into emerging lure signatures, so detection keeps learning as scams change.

No live feed snapshot on this device yet.

Threat-pattern catalog

Version: baseline · update available 12 manipulation types, 10 patterns (0 live).

Served by the public patterns API at /api/public/threat-patterns, so the taxonomy and detection rules update without a new app build.

About

FinShield · version 1.0.0 (MVP)

AI model: Layer 1 is a deterministic rules and context-extraction engine that always runs in this app. Layer 2 is a real LLM pass (google/gemini-3.7-flash via the Lovable AI Gateway, called from a server function so no key is exposed) that reads intent and can add tactics the rules missed. Layer 3 fuses both into the score. If the AI layer fails, the result is labelled on-device only.

Architecture: local-first. QR decoding, screenshot OCR, rules, scoring and history all run on this device; only the interaction text is sent when the AI layer is enabled, and nothing is stored server-side.

Honesty note: FinShield cannot intercept SMS, WhatsApp or calls, and does not integrate with real banks. Demo scenarios are labelled as simulated.