Privacy choices
Necessary onNecessary cookies are active. Optional analytics stays off unless you choose otherwise.
Voyager on iOS and Android uses the same versioned API contract as the web app. Same read-only guarantee, same audit trail, same as_of on every balance. Deep links open the same account, transaction, and budget views — no divergent logic.
Native Apple Silicon & iOS 17+
Supabase Auth with secure Keychain token storage, Face ID / Touch ID / passcode gate, and a typed API client generated from the versioned OpenAPI contract. No raw provider credentials on device.
App Store — coming soon
Internal TestFlight distribution is available today. Public listing follows store review. Set IOS_STORE_URL to enable the badge.
voyager://accounts/{id}Material 3 & Android 8+ (API 26)
Supabase Auth with EncryptedSharedPreferences, BiometricPrompt gate, and a typed Ktor + Kotlinx Serialization client from the same OpenAPI contract. Identical authorization boundaries to web and iOS.
Google Play — coming soon
Internal track distribution is available today. Public listing follows Play review. Set ANDROID_STORE_URL to enable the badge.
voyager://budgets/{id}All three clients are generated from src/mobile/api-contracts/Voyager.Api.json. No hand-copied DTOs. Contract drift fails CI via pnpm generate:contracts.
The API authorizes every request. Client guards are UX only. Bearer JWT is validated (issuer, audience, JWKS, expiry, claims) before any data is touched.
No client can move money or place trades. Providers are read-only adapters (Plaid: bank/credit/loan; Plaid: brokerage). Freshness shows last_successful_sync_at vs last_financial_data_change_at.
Device & privacy posture
Biometrics gate the app, tokens are hardware-backed, pushes are permission-gated and deep-link to the same authorized API, offline cache is per-user encrypted and shows staleness explicitly, and background use is bounded. Full policies: docs/plans/tasks/phase-8-client-apps/POLICIES.md and MOBILE_DISTRIBUTION.md.