Cipher
Your bank texts, turned into a clean ledger. Nothing leaves your phone.
Local-first finance app that reads bank SMS and notifications and builds your ledger on-device.
- Platform
- Android 8.0+ (min SDK 26)
- Distribution
- Google Play
- Architecture
- MVI with a UseCase layer
- License
- GPL-3.0, open source
- 420+
- automated tests
- 8
- regions with parser rules
- 6
- home-screen widgets
- 8
- languages
In the app
What it is
Cipher reads the bank SMS and notification alerts already landing on your phone and turns them into a searchable ledger of transactions, accounts, budgets and savings goals. Parsing, categorising and storage all happen on the device. The only network call is an optional licence check for the Pro plan, and there's no telemetry, analytics, ads or crash reporter.
- 01
A bank text arrives
Cipher listens for bank SMS and for alerts from the finance apps you choose, using a broadcast receiver and a notification listener.
- 02
The parser reads it
It pulls out the amount, whether money went in or out, and the merchant, and quietly drops OTPs, promos and other messages that aren't transactions.
- 03
It gets a category
A categoriser files it under Food, Travel, UPI and so on, and rules you define can override it.
- 04
It's locked away
The transaction lands in a SQLCipher AES-256 database with keys bound to the Android Keystore, behind an optional biometric lock.
What it does
Accounts and transfers
Track several accounts, cards and cash. Money moved between your own accounts is excluded from income and expenses, so budgets reflect real spending.
Savings goals
Dedicated goal pots with circular progress. Add or withdraw funds without touching your daily spending numbers.
Split expenses
Split a bill equally, by exact amounts or by percentage, then share the breakdown over WhatsApp or text.
Insights
Cash-flow curves, a calendar heatmap, budgets that can adjust to income, and a subscriptions hub that spots recurring bills.
Six widgets
Budget, daily stats, accounts, passbook, daily allowance and a one-tap quick logger, all built with Glance.
Your data, portable
CSV and PDF exports, password-protected backups, scheduled auto-backup, and a restore option on the very first screen of a new phone.
How it works
- 1
Bank SMS
or app notification
- 2
SmsReceiver
and notification listener
- 3
SmsParser
amount, direction, merchant
- 4
CategorizerEngine
Food, Travel, UPI...
- 5
TransactionRepository
- 6
Room + SQLCipher
AES-256
- 7
ViewModel
MVI state
- 8
Compose UI
Questions
- What is Cipher?
- Cipher is a local-first Android finance app. It reads the bank SMS and notification alerts already on your phone and turns them into a searchable ledger of transactions, accounts, budgets and savings goals.
- Does Cipher send my financial data anywhere?
- No. Parsing, categorising and storage all happen on the device. The only network call is an optional licence check for the Pro plan, and there is no telemetry, analytics, ads or crash reporter.
- How is the data protected?
- The database uses SQLCipher with AES-256, with keys bound to the Android Keystore and an optional biometric lock. Backups are password-protected with PBKDF2.
- Which banks and regions does Cipher support?
- Parser rules cover 8 regions: India, the UK, the US, the UAE, Singapore, Australia, Canada and the Euro area, with a global fallback. Over 420 automated tests guard the parsing.
- Which Android versions does Cipher run on, and is it open source?
- Cipher runs on Android 8.0 and up (min SDK 26). It is open source under GPL-3.0 and available on Google Play.
Under the hood
Parse locally, and drop what isn't money
Every message goes through a parser that extracts an amount, a direction and a merchant, and returns nothing for anything that isn't a transaction. Rules are split by region (India, UK, US, UAE, Singapore, Australia, Canada and the Euro area) with a global fallback, and the patterns and brand dictionaries live in one place so supporting a new bank format is a small change with a test beside it.
Finish the work before Android kills the receiver
A broadcast receiver is only guaranteed a few seconds. Cipher calls goAsync() so the parse and the database write can finish off the main thread before the system tears the receiver down. Messages that arrive late are stored with the time they were actually sent.
Encrypted at rest, honest about recovery
The Room database sits inside SQLCipher with AES-256, and the key is bound to the Android Keystore. Because that key can't leave the device, app data is excluded from phone-to-phone transfer and you move with a backup file instead. If secure storage ever can't be unlocked, Cipher explains what happened and offers recovery, rather than crashing or quietly replacing your key. Backups are password-protected with PBKDF2.
A ledger that survives bad days
Transfers between your accounts are saved all-or-nothing, so one can never end up half done. Account balances are computed by the database, which keeps the main screen quick even with years of history.
MVI keeps every screen predictable
Each screen has a contract: intents go into the ViewModel, a single state comes out. A UseCase layer sits between ViewModels and repositories, so screens stay thin and the logic stays testable.
Small enough to forget about
A transaction is roughly 200 bytes. Ten thousand of them come to about 2 MB, so logging five a day for years barely registers.
Stack
- Language
- Kotlin 2.4
- UI
- Jetpack Compose, Material 3
- Architecture
- MVI (MviBase), UseCase layer
- Dependency injection
- Hilt
- Database
- Room, SQLCipher (AES-256)
- Preferences
- DataStore
- Security
- BiometricPrompt, Android Keystore
- Widgets
- Glance
- Background work
- WorkManager
- SDK range
- Min 26, target 37
Written about
More from the same desk





