Every dollarhas a source.
CanCan — as in, all your money sources, can.
Bank here, a card there, a wallet for the weekends — your money is spread across more platforms than anyone can track by hand. CanCan collects the statements those platforms already issue, reads them on your Mac with an AI provider you configure, and reconciles them into one ledger where every number cites its document.
Your money lives in more placesthan it did five years ago.
DBS, POSB, UOB, OCBC, HSBC, Standard Chartered, Citi, Wise, GrabPay, CPF, insurance, and brokerage — platforms a typical household juggles.
[ Platforms a typical household juggles — not a coverage claim ]
Nobody keeps a spending diary — and nobody should have to. The statements already exist. CanCan reads those.
The same dollar, seen twice.
Money moves between your own accounts constantly — salary in, card paid off, savings swept aside. Each move appears on two statements, once as money out and once as money in. Untracked, it inflates your spending. CanCan links the pair into a single event.
[ Wise appears as the goal, not as coverage — supported sources are listed below ]
Four steps, no surprises.
Collect
Add statement PDFs, CSVs, or images directly — or use the phone Share Shortcut to save them to your CanCan Inbox folder in iCloud Drive, and CanCan picks up new files for you. No bank credentials, no screen scraping.
Parse
CanCan extracts evidence locally, then asks the AI provider you configure to propose structured records — with the exact parser and runtime versions recorded next to every run.
Reconcile
Records wait in Review. Check details, edit, and link the same money seen on two statements — a card payment leaving DBS, arriving at your card — into one event.
Ledger
Accepted records become your ledger and Money Overview — every value traceable back to the document it came from, with typed Undo.
No account.
No sign-up, no sync service, nothing to breach on our side
No analytics.
Neither the app nor this site collects analytics or behavioral data
No silent network.
Gmail and AI go direct from your Mac, only with your consent
[ What "local" is built on ]
Your Mac is the whole stack.
[ No listener, no telemetry — updates verify signed metadata before anything runs ]
- At rest
- SQLCipher ledger database and XChaCha20-Poly1305 document envelopes — authenticated encryption, plaintext never touches disk.
- Keys
- Argon2id stretches your password into a wrapping key that seals the randomly generated master key; Vault keys, tokens, and statement passwords live in the macOS Keychain.
- Integrity
- Every document is SHA-256 hashed on the way in, every decryption is authenticated, and an integrity sweep re-checks stored bytes — tamper-evident, deduplicated, deterministic.
- Isolation
- The interface receives presentation-safe read models only — no raw bytes, paths, hashes, or database handles cross into it.
- Network
- Opt-in connections only: Gmail with read-only scope, your AI provider with a key you hold, update checks against signed metadata.
Engineering, not policy filler — read exactly how: Privacy · Security
Collected, reconciled,accounted for.
- 04.1
AI-assisted parsing, archived.
CanCan extracts evidence locally, then asks the AI provider you configure — with a key you hold — to propose structured records. The parser and runtime versions are recorded against every record, and the source document is filed in the encrypted Vault.
- 04.2
Reconciled, counted once.
Money moving between your own accounts appears on two statements — once out, once in. Link the pair during review and your own transfers stop posing as spending.
- 04.3
An overview that cites its sources.
One allocation view across accounts and currencies, drawn only from approved ledger records — every figure traceable back to the page it came from.
- 04.4
Analysis, on your terms.
Deeper AI analysis is being qualified before it ships. When it arrives: your provider, your key, your consent — each analysis individually approved. Skip AI entirely and nothing is sent anywhere.
Statement sources,honestly listed.
| Source | Status | Notes |
|---|---|---|
| DBS Bank | [ Current ] | Bank statements — parsed locally, review-first |
| DBS Card | [ Current ] | Credit-card statements — parsed locally, review-first |
| HSBC | [ Current ] | Bank statements — parsed locally, review-first |
| UOB | [ Coming ] | Targeted for the first public preview, gated on evidence |
| Gmail | [ Optional ] | Optional statement-attachment channel — ships independently after Google verification |
A source appears as [ Current ] only after a real parser profile exists for it. Rows marked [ Coming ] or [ Optional ] are planned or gated capabilities; they stay off the automatic-add path until their confidence or external gates are separately qualified. Password-protected eStatements are a first-class case: unlock once, and the password stays in your macOS Keychain.
Using POSB, OCBC, Standard Chartered, Citibank, or Wise? Tell us what you use.
The first preview,honestly scoped.
A pre-1.0 preview, not a stability promise.
It ships local file ingestion, the phone Share Shortcut into your CanCan Inbox folder in iCloud Drive, statement parsing with review-first control, and source-backed money views.
First-preview source coverage: DBS, HSBC, and UOB — some profiles start Review-only while their automatic-add confidence is calibrated against held-out evidence.
Gmail connection for statement attachments and separately consented transaction-notification emails is an optional, independently gated capability; public availability follows Google’s verification and is not a first-preview blocker.
Deeper AI analysis of your ledger is being qualified separately and ships only behind explicit consent — your provider, your key.
Follow along on GitHub — development, specs, and releases all happen in the open — or read the docs.
Prove it.
CanCan — as in, all your money sources, can.
GitHub Releases · Signed artifacts · No account