Privacy
What FinShield stores
Local data
0 analysis records stored on this device.
Permissions
Camera
Requested only when you tap Scan QR
FinShield uses this permission only to decode a QR code you point it at.
Screen / screenshots
You choose the file each time
There is no background screen monitoring. OCR runs locally on the image you import.
Share sheet
Supported
Share text into FinShield and it opens straight in the message analyser.
Notifications
Enabled (local only)
Local, non-intrusive alerts for checks you run.
Security & language
Threat intelligence
Live scam-pattern intelligence
FinShield scores against 10 fraud playbooks (RBI, NPCI, CERT-In, I4C, FTC) plus a live feed of active phishing and malware hosts from OpenPhish and abuse.ch URLhaus. The newest feed entries are distilled by the AI layer into emerging lure signatures, so detection keeps learning as scams change.
No live feed snapshot on this device yet.
Threat-pattern catalog
Version: baseline · update available — 12 manipulation types, 10 patterns (0 live).
Served by the public patterns API at /api/public/threat-patterns, so the taxonomy and detection rules update without a new app build.
About
FinShield · version 1.0.0 (MVP)
AI model: Layer 1 is a deterministic rules and context-extraction engine that always runs in this app. Layer 2 is a real LLM pass (google/gemini-3.7-flash via the Lovable AI Gateway, called from a server function so no key is exposed) that reads intent and can add tactics the rules missed. Layer 3 fuses both into the score. If the AI layer fails, the result is labelled on-device only.
Architecture: local-first. QR decoding, screenshot OCR, rules, scoring and history all run on this device; only the interaction text is sent when the AI layer is enabled, and nothing is stored server-side.
Honesty note: FinShield cannot intercept SMS, WhatsApp or calls, and does not integrate with real banks. Demo scenarios are labelled as simulated.