Installing it
- Open the file you downloaded (
Cash-Kit-0.2.dmg). A window appears with Cash Kit and an Applications folder in it. - Drag Cash Kit onto Applications. That is the whole install.
- Open Cash Kit from Launchpad or Spotlight. macOS shows one standard question the first time:
Click Open. You will not see it again. (Apple checked this build; if you ever see “Apple could not verify…” instead, the download was altered in transit: delete it and download again from this page.)
Then eject the installer (drag the “Cash Kit” disk on your desktop to the Trash) and delete the .dmg if you like; the app lives in Applications now.
The first time it opens
A short assistant walks you from nothing to a drawn chart, about ten minutes, most of it waiting on your banks. You can stop at any step; the app's Setup page shows what is left.
1 · Apple's command-line tools
Only if this Mac has never had them. The app shows an Install button; Apple's own installer runs. About five minutes, free, nothing else changes.
2 · A SimpleFIN Bridge account
The one thing that costs money: $1.50 a month or $15 a year, paid to SimpleFIN. You connect your banks on their site; Cash Kit gets a read-only feed.
3 · Paste one setup token
Copy it from the Bridge, paste it in the assistant. It is used once, right now, and never stored.
4 · Name your accounts
“Checking”, “Savings”, “Visa”. Tick which one is checking, and the projection is drawn for it.
Where your data goes (and doesn't)
| What | Where it lives | Who can see it |
|---|---|---|
| Your bank logins | Typed by you into the bank-connection screen on the SimpleFIN site. | SimpleFIN and its bank aggregator only. Cash Kit never asks for them and never sees them. |
| Your SimpleFIN setup token | Pasted once into the app; spent the moment it is claimed. | Nobody after that. |
| The read-only access link | ~/.config/cash-kit, permissions 600. | You. The app never shows it and refuses redirects, so it cannot be forwarded elsewhere. |
| Balances, transactions, the pages it draws | ~/Library/Application Support/CashKit, written with permissions 600. | You. They never leave the disk. |
| Anything at all | Anywhere else | Nobody. No telemetry, no analytics, no phone-home, no account with the author. |
The app makes exactly two kinds of network calls, both over HTTPS to the SimpleFIN host: the one-time claim, and the daily pull. Numbers are hidden on screen by default; an eye in the toolbar shows them.
What it needs
- macOS 15 (Sequoia) or later. Apple silicon or Intel.
- Apple's command-line tools, which bring the Python the engine runs on. The app offers to install them if they are missing. Nothing to
pip install, ever. - A SimpleFIN Bridge subscription at beta-bridge.simplefin.org.
- Optional: “Start at login”, so the daily refresh happens without opening the app. macOS asks once, under Login Items.
Verify the download
In Terminal, after the download finishes:
shasum -a 256 ~/Downloads/Cash-Kit-0.2.dmg
It should print exactly:
5acdf8d7282311641e2ba0b5702d44695eadcdbf5569225ead095db0b30e4392
And to see what Gatekeeper sees (after dragging it to Applications):
spctl -a -vv -t exec "/Applications/Cash Kit.app"
A good answer ends with source=Notarized Developer ID.
Removing it
Drag Cash Kit from Applications to the Trash. Your data stays in ~/Library/Application Support/CashKit and the bank link in ~/.config/cash-kit; delete those two folders too if you want nothing left. If you turned on Start at login, macOS removes the login item with the app.