Skip to content

Crest — Business Requirements Document (BRD) ​

ProductCrest — Personal Finance App
Document version0.23 (Draft) — NFR-17 corrected: DNS is hosted at Biznet Gio, not Cloudflare. Crest is local-first: the app works for anyone on their own device with no login (local mode); sync, sharing, and server backup are for invited people (connected mode)
Date2026-10-06
StatusDraft — pending review
OwnerReizkian Y. Radityatama

Unresolved decisions are listed in §14 Open Questions.

Terminology — read this first. This document never uses the word "account" on its own.

  • User: a person who can log in to Crest (identity, email, password, status). Managed by the Super Admin.

  • Financial account: a place where money is held or owed: cash wallet, bank, e-wallet / online payment, or credit card.

  • Space: a container that holds financial accounts, categories, budgets, and savings goals, plus the list of users who can see it (its members). Every user has a private Personal space; users can also create and join shared spaces.

  • Local mode and connected mode: Crest works in two ways. In local mode anyone uses the app on their own device with no login, and the data stays on that device. In connected mode a user who has been given access logs in, and the data is also kept on Crest's server so it can sync between devices and be shared. See §8.0.

A user can be a member of many spaces, and a space can have many members. Every financial account belongs to exactly one space. See §8.4 and §15 Glossary.


1. Executive Summary ​

Crest is a personal finance app that helps individuals understand where their money goes, plan budgets, and build better financial habits. Users record income and expenses across all their financial accounts (cash wallet, bank, e-wallet, credit card), see clear spending insights, and set budgets and savings goals.

The first release (MVP) focuses on fast manual tracking, budgeting, and insights. Automatic bank syncing is planned for a later phase.

Crest is local-first. For users, Crest is an app that runs in the browser (a Progressive Web App, PWA): people open it from a link and can add it to their phone's home screen, so it looks and works like an app without any app store. It is built with Flutter, so the same code can later be published as Android and iPhone apps if there is demand.

Anyone can use the app on their own device with no sign-up (local mode): the data stays on the device and Crest's servers never see it, so this costs nothing to run no matter how many people use it. The cloud part of Crest (sync between devices, shared spaces, a server backup, and email) is for the owner and the people they know (friends, family, colleagues), not a mass-market service. Those people are invited and use the app in connected mode. Around the app are two small websites: a public site (what Crest is, the access-request form, activation, install guide, and the privacy policy) and the Super Admin portal. The portal and the connected features talk to one separate backend.

Money is often shared. A couple runs a joint bank account; a small business owner gives staff a fund for groceries or supplies. Crest supports this with Spaces: a shared space holds the financial accounts, categories, and budgets that a group uses together, and every member sees every transaction in it, including who added it. Everything outside a shared space stays private.

Crest is free. If the number of users grows, users may later be asked for a small yearly contribution that only covers running costs. Payment would happen outside Crest, and the Super Admin records it manually.

The cloud part of Crest is invite-only. People cannot register themselves for it. They submit an access request, and the Super Admin reviews it and approves or rejects it from a web-based Super Admin portal. The portal is also used to manage all users. Using the app on your own device needs no request and no approval.

2. Problem Statement ​

  • People keep money in many places (cash, several bank accounts, e-wallets, credit cards) and lack one consolidated view.
  • Spending is hard to track consistently; most users give up on spreadsheets or apps that are slow to log into.
  • Users don't know whether they are on track for their monthly budget until it is too late.
  • Existing apps are often cluttered, ad-heavy, or not tailored to users' local currency, language, and payment habits.
  • People who share money (couples, families, a boss and staff) can't easily see how the shared money is being used, and by whom, without also exposing their private finances.
  • Many people don't want to hand their money data, or their email, to yet another service just to start tracking.

3. Business Objectives ​

IDObjectiveMeasure of success
BO-1Help users build a consistent tracking habit≥ 40% of new users still log a transaction in week 4
BO-2Make recording a transaction effortlessMedian time to add a transaction ≤ 10 seconds
BO-3Give users confidence about their money≥ 50% of active users create at least one budget
BO-4Be trusted with real financial data by the people who use itZero data-breach incidents; ≥ 80% of activated users still active after 3 months
BO-5Keep Crest cheap to run and, if needed, self-fundingRunning costs stay within the target in NFR-13; once contributions start (Phase 4), they cover ≥ 100% of yearly running costs
BO-6Make getting started easy for invited people≥ 70% of approved users activate their login and connect within 7 days; ≥ 50% add Crest to their home screen
BO-7Let anyone start recording with no sign-upA new person can add their first transaction within 2 minutes of opening the app, with no login (checked by the owner with new people, since Crest uses no analytics)

4. Scope ​

4.1 In scope (MVP) ​

Local mode (Phase 1a, ships first and needs no server)

  • The Crest app as a Progressive Web App (PWA): opens in the browser on phones, tablets, and computers; can be added to the home screen; works fully without internet. Built with Flutter, one codebase
  • No login: a first-launch welcome (Privacy Policy, Terms of Use, 18+), then the person starts recording
  • Unlimited financial accounts of every type: cash wallet, bank, e-wallet / online payment, credit card
  • A Personal space on the device
  • Manual income, expense, and transfer transactions
  • Categories (default set plus custom)
  • Monthly budgets per category
  • Dashboard with balances and spending insights
  • Transaction search and filters
  • CSV export
  • Backup file: save all data to a file and restore it, on the same or another device
  • Optional app lock (PIN) on the device
  • Update notice when a new version is published
  • Public website: landing page, install instructions, Privacy Policy and Terms of Use (English and Bahasa Indonesia, published before the first release)

Connected mode (Phase 1b, invite-only)

  • Invite-only access: public access-request page (also linked from the app's Connect screen), admin approval, user activation
  • Connect to Crest: login, upload of the device's data, and sync between devices
  • Server backup of connected users' data
  • Spaces: shared spaces with invited members, Owner/Member roles, and transfers between spaces
  • Email: activation, password reset, invitations
  • Super Admin portal (a separate web app) for access requests and user management
  • Backend API used by the app, the portal, and the public site

4.2 Out of scope (MVP) ​

  • Native Android and iPhone apps and app-store distribution (later, from the same codebase, if there is demand)
  • Contributions / subscriptions (planned for Phase 4, recorded manually; see §8.14)
  • Payment processing of any kind: Crest never takes card or online payments
  • Self-service registration for connected mode (anyone can use local mode with no login, but sync and sharing need an invitation)
  • Cloud backup for people who use local mode only (they save a backup file instead)
  • Encrypting the data stored on the device, or the backup file, with a password (to be decided, see §14)
  • External authentication of any kind: Google, Apple, Facebook, other social login, OAuth, SSO
  • Different admin permission levels (there is one Super Admin role; several users can have it)
  • Admin access to users' financial data
  • Automatic bank/e-wallet syncing (Phase 3)
  • Investment portfolio tracking
  • In-app money requests between members (they happen outside Crest; Crest records the resulting transfer)
  • Moving an existing financial account from one space to another
  • Bill payment or money transfer (Crest never moves money)
  • Recurring transactions and CSV import (Phase 2)
  • Tax reporting
  • Financial advice

5. Stakeholders ​

StakeholderRole / interest
Product ownerDefines vision and priorities; approves scope
Super AdminProduct owner acting as operator, plus any other users given the Super Admin role; approves access requests and manages users
Engineering & designCurrently the owner; builds, designs, and runs Crest, including maintaining the server
End usersAnyone, on their own device (local mode); the owner and people they know for sync and shared spaces (connected mode)
Legal / complianceData protection laws of the countries where users live (e.g. Indonesia's PDP Law — UU No. 27/2022, EU/UK GDPR)

6. Target Users & Personas ​

Crest's local-mode users can be anyone. Its connected users are the owner and people they know personally. They may live in different countries and use different currencies. The personas below are typical examples. Each of them can start in local mode; Andi and Rina, and Boss with Jojo and Maria, need connected mode for shared spaces.

Persona 1 — Young professional ("Dina", 26) First job, salary into a bank account, pays daily with e-wallets. Wants to know why money runs out before payday and to start saving for a goal.

Persona 2 — Family manager ("Budi", 38) Handles household spending across cash and several financial accounts. Wants monthly budgets per category and to spot overspending early.

Persona 3 — Freelancer ("Sari", 30) Irregular income. Wants to separate income sources, track expenses, and see month-over-month trends.

Persona 4 — Couple ("Andi", 34, and "Rina", 32) Share a joint bank account for household costs, and each keeps private financial accounts. Both add and use money from the joint account and want to see how the other uses it, without seeing each other's private finances.

Persona 5 — Small business owner ("Boss", 45) and staff ("Jojo" and "Maria") Boss gives each staff member a fund to manage. Jojo buys groceries, office food, and cooking ingredients from the kitchen fund. Maria pays for equipment, tools, couriers, and packaging from the operations fund. When a fund runs low, staff ask Boss in person or by chat; if Boss agrees, Boss tops up the fund. Jojo can't see Maria's fund and Maria can't see Jojo's; Boss sees both.

Persona 6 — Super Admin (the app owner) Controls who can use Crest. Also uses Crest as a normal user, with their own spaces. Reviews access requests, approves or rejects them, manages users (deactivate, reactivate, delete), and later records yearly contributions, all from the Super Admin portal. Does not need to, and should not, see users' financial data.

7. User Access Flow ​

Anyone can use Crest in local mode with no login. Connected mode (sync, shared spaces, server backup) is for invited people, who cannot sign up themselves. Access to connected mode works like this:

User statuses

StatusMeaningCan log in?
PendingAccess request submitted, awaiting reviewNo
RejectedRequest declined by Super AdminNo
InvitedApproved; activation link sent, password not yet setNo
ActiveUser activated their loginYes
DeactivatedAccess suspended by Super Admin; data retainedNo
DeletedUser and all their data permanently removedNo

8. Functional Requirements ​

Priority uses MoSCoW: M = Must, S = Should, C = Could, W = Won't (this release).

8.0 Local mode and connected mode ​

Crest has two ways of being used, in the same app:

Local modeConnected mode
WhoAnyoneA user who has been given access
LoginNoneEmail and password
Where the data livesOnly on the deviceOn the device and on Crest's server
Shared spaces, several devices, server backup, emailNoYes
Costs the server anythingNo (only the download of the app's files)Yes

In local mode Crest has no copy of the person's data and cannot recover it. Phase 1a delivers local mode; Phase 1b adds connected mode.

IDRequirementPriority
FR-MOD-1Anyone can open the Crest app and use it without a login or any personal details (local mode)M
FR-MOD-2In local mode all data (financial accounts, transactions, categories, budgets, settings) is stored on the device and never sent to Crest's servers. The app contacts Crest only to download its own files and to check for a new version (FR-APP-5)M
FR-MOD-3Local mode has one Personal space, on the device. It has no shared spaces, invitations, or members. Everything else in §8.5 to §8.12 that does not need a server works the same as in connected modeM
FR-MOD-4On first launch the app shows a short welcome. The person accepts the Privacy Policy and Terms of Use and confirms they are 18 or older (BR-44). The answer is kept on the deviceM
FR-MOD-5Backup file. The person can save all their data to a backup file, and restore from one, on the same or another device. Restoring replaces the data on the device only after a clear warning and a chance to save the current data firstM
FR-MOD-6Before the person enters data, and later in Settings, the app says plainly that in local mode the data lives only on this device and can be lost if the browser clears it, the device is lost, or the app is removed. On iPhone and iPad it first asks the person to add Crest to the home screen (UJ-38), because Safari can clear the storage of sites it was not used on for about a week, and the home-screen app keeps its data separately from SafariM
FR-MOD-7The app asks the browser to keep its data (persistent storage) and shows whether the browser agreedS
FR-MOD-8The app reminds the person to save a backup file when the last one is more than 30 days old and data has changed sinceS
FR-MOD-9Connect. A person who has been given access (an Active user) can connect from the app (More → Connect to Crest) by logging in. Connecting turns on sync and the features that need a server: shared spaces, use on several devices, server backup, and email. People without access see Request access on the same screenM
FR-MOD-10When connecting on a device that has local data, the app asks Upload this device's data (the default) or Start fresh. Upload is allowed only if the user's Personal space on the server is empty (BR-47). Otherwise the app offers Use my Crest data (the local data is first offered as a backup file) or Keep this device's data local onlyM
FR-MOD-11Log out asks whether to keep a local copy of their Personal space on the device (Crest continues in local mode and no longer syncs; shared spaces are never kept) or to remove the data from the device. After a forced logout, the synced data is removed from the device (BR-50)M
FR-MOD-12In connected mode the server is the source of truth. The device keeps a local copy so Crest works offline, and changes made on one device appear on the user's other devices after they syncM

8.1 Access Requests ​

IDRequirementPriority
FR-REQ-1Anyone can submit an access request with full name, email, country, and optional reason/messageM
FR-REQ-1aThe request form is a page on the public website with its own link (to share with friends), also reachable from the app's Connect screen (More → Connect to Crest)M
FR-REQ-2The request form is protected against spam (rate limiting and bot protection)M
FR-REQ-3The requester sees a confirmation that the request was received; no user is created at this pointM
FR-REQ-4A duplicate request for an email that is already pending or active is not created; the requester sees a neutral message that does not reveal whether the email existsM
FR-REQ-5The requester receives an email when their request is approved (with activation link). If it is rejected, they receive a short, polite email saying it wasn't approved, without a reasonS
FR-REQ-6The request form links to the Privacy Policy and Terms of Use (in the visitor's language); submitting requires accepting both and confirming the visitor is 18 or olderM

8.2 Authentication & Security ​

IDRequirementPriority
FR-AUTH-1There is no public sign-up for connected mode. Only users approved by the Super Admin can log in. Local mode needs no login (FR-MOD-1)M
FR-AUTH-2An approved user activates their login through a single-use activation link and sets a passwordM
FR-AUTH-3Activation links expire after 72 hours; the Super Admin can resend a new linkM
FR-AUTH-4Users log in with email and passwordM
FR-AUTH-5No external authentication. Users log in only with their Crest email and password. There is no sign-in with Google, Apple, Facebook, or any other identity provider (no OAuth / SSO / social login)M
FR-AUTH-6Users can lock Crest with a PIN. In connected mode the PIN is one per user and works on all their devices. In local mode the PIN is stored on the device only and is optional; a wrong PIN there only slows down further attempts and never erases data (BR-49). When native Android and iPhone apps exist, the device's biometrics (Face ID or fingerprint) can unlock them as well; biometrics never leave the device and are not external authenticationM
FR-AUTH-7Users can reset their passwordM
FR-AUTH-8Users can delete themselves (their login) and all their data. Their Personal space is deleted; transactions they added in shared spaces stay there, labelled "Former member" (BR-34)M
FR-AUTH-9A deactivated or deleted user is logged out of all devices immediatelyM

8.3 Super Admin Portal ​

A separate web app at its own address, used only by Super Admins. It is designed for desktop but usable on a phone.

IDRequirementPriority
FR-ADM-1Only users with the Super Admin role can access the portalM
FR-ADM-2Super Admin login requires two-factor authentication (authenticator app)M
FR-ADM-2aWhen setting up 2FA, the Super Admin receives one-time backup codes to log in if the authenticator device is lostM
FR-ADM-3The first Super Admin is created during setup (seed script), not through the appM
FR-ADM-3aAs a last resort, the setup script can reset a Super Admin's 2FA (requires server access); the reset is recorded in the audit logM
FR-ADM-4Super Admin sees a list of access requests, filterable by status (Pending, Approved, Rejected)M
FR-ADM-5Super Admin can approve a request, which creates the user and sends the activation linkM
FR-ADM-6Super Admin can reject a request, with an optional reasonM
FR-ADM-6aSuper Admin can approve a request that was previously rejected (to reverse a rejection); this works like a normal approvalM
FR-ADM-7Super Admin can create a user directly (without a request), which sends an activation linkM
FR-ADM-7aIf the email in FR-ADM-7 already has a Pending request, that request is approved instead of creating a separate userM
FR-ADM-8Super Admin sees a list of all users with name, email, status, created date, and last login; searchable and sortableM
FR-ADM-9Super Admin can deactivate and reactivate a userM
FR-ADM-10Super Admin can resend an activation link or trigger a password-reset email for a userM
FR-ADM-11Super Admin can permanently delete a user and all their data, after typed confirmation. Shared spaces follow the same rules as FR-AUTH-8M
FR-ADM-12Super Admin can edit a user's name and email. An email change notifies both the old and the new address, and takes effect only after the user confirms it from a link sent to the new addressS
FR-ADM-13Super Admin is notified (email) when a new access request arrivesS
FR-ADM-14Every admin action is recorded in an audit log (who, what, which user, when), viewable in the portalM
FR-ADM-15Overview page shows counts: pending requests, active users, deactivated users, new users this monthS
FR-ADM-16Super Admin can give the Super Admin role to any Active user, or remove it (never from the last Super Admin). A user who receives the role must set up 2FA before opening the portalS
FR-ADM-17Super Admin cannot view users' financial data (financial accounts, transactions, budgets) or anything about their spaces, including space names and member listsM
FR-ADM-18Super Admin can select several access requests and approve or reject them togetherC

8.4 Spaces & Sharing ​

A space holds financial accounts, categories, budgets, and savings goals, plus its members. Everything inside a space is visible to all its members; nothing outside it is.

Example

Each green box is a shared space, and the people with an arrow into it are its members. Everyone also has a private Personal space that only they can see (not drawn here).

Roles and permissions

ActionOwnerMember
See all financial accounts, transactions, categories, budgets, goals, and members in the space✓✓
Add expenses, income, refunds, and transfers✓✓
Edit or delete transactions they added✓✓
Edit or delete transactions added by others✓—
Add, edit, archive, or delete financial accounts✓—
Manage categories✓—
Set budgets and savings goals✓—
Invite and remove members, change roles✓—
Rename or delete the space, change its currency or budget start day✓—
Leave the space✓ (not the last Owner)✓

In a Personal space the user is the only member and is its Owner.

IDRequirementPriority
FR-SPC-1Every user gets a Personal space automatically when their login is activated (connected mode; in local mode the Personal space is created on the device, FR-MOD-3, and is uploaded into this one, FR-MOD-10). Only they can see it. It can't be shared, and it can't be deleted except by deleting the userM
FR-SPC-2Any Active user can create a shared space with a name, currency, and budget start day, and becomes its OwnerM
FR-SPC-3Every financial account, category, budget, and savings goal belongs to exactly one space. A new space starts with the default categoriesM
FR-SPC-4Owners can invite other people by email. If the email belongs to an Active user, the invitation appears in Crest and by email; the person accepts or declines. The Owner always sees the same neutral message: "If this email belongs to a Crest user, they'll receive an invitation"M
FR-SPC-5Invitations expire after 14 days. Owners can see and cancel pending invitationsM
FR-SPC-6Members have the role Owner or Member, with the permissions in the table above. Any Owner can change the role of, or remove, any other member, including other Owners, as long as at least one Owner remains. A shared space can have several Owners (e.g. both partners of a couple)M
FR-SPC-7Every transaction shows who added it and, if changed, who last edited itM
FR-SPC-8A member can leave a shared space, and Owners can remove members (including other Owners, FR-SPC-6). Access ends immediately. Transactions they added stay and keep their nameM
FR-SPC-9The last Owner can't leave until they make someone else Owner or delete the spaceM
FR-SPC-10Owners can delete a shared space after typed confirmation. All its financial accounts, transactions, categories, budgets, and goals are deleted, and members are notifiedM
FR-SPC-11A space switcher at the top of Crest moves between spaces. Each space has its own dashboard, financial accounts, transactions, categories, and budgets. The switcher is hidden while a user has only their Personal spaceM
FR-SPC-12Each space has a currency used for its budgets and reports. For a Personal space it is the user's base currency; for a shared space an Owner sets itM
FR-SPC-13Each member has an Include in my totals setting per shared space: on by default for Owners, off by default for Members. The Personal dashboard's net worth adds up the Personal space and every included shared space, converted into the user's base currency with their own saved ratesS
FR-SPC-14A user can transfer money between financial accounts in any spaces they belong to (e.g. Boss's BCA in Personal → Kitchen fund in Kitchen). Each side of the transfer is visible only to the members of its own space, and shows the person who made it instead of the other financial account, e.g. "+500,000 from Boss"M
FR-SPC-15A shared space's dashboard can show spending by member as well as by categoryS
FR-SPC-16Each member can turn on Notify me when someone adds a transaction for a shared space (off by default). Invitations always notifyC
FR-SPC-17Financial accounts can't be moved between spaces. To share money that is in a private financial account, the Owner creates a new financial account in the shared space with an opening balanceM

8.5 Financial Accounts ​

A financial account is any place where money is held or owed. It belongs to one space (§8.4); in a shared space, only Owners manage financial accounts, and all members can use them. A user can have any number of financial accounts of every type, for example 3 banks, GoPay, OVO, and PayPal, 2 credit cards, and a cash wallet, all tracked side by side.

Financial account typeExamplesBalance meaning
CashWallet, piggy bank, petty cashMoney on hand (asset)
BankBCA, Mandiri, Chase, WiseMoney in the bank (asset)
E-wallet / online paymentGoPay, OVO, DANA, ShopeePay, PayPalStored balance (asset)
Credit cardVisa, Mastercard, JCB cardsAmount owed (liability)
IDRequirementPriority
FR-FIN-1Users can create any number of financial accounts, each with a name, type (cash, bank, e-wallet / online payment, credit card), currency, and opening balanceM
FR-FIN-2Users can edit, archive, and reorder financial accountsM
FR-FIN-3The app shows each financial account's current balance, derived from its transactionsM
FR-FIN-4Each space shows its net worth: assets (cash, bank, e-wallet) minus liabilities (credit cards). The Personal dashboard also shows the user's total net worth across spaces (FR-SPC-13)S
FR-FIN-5Users can hold financial accounts in different currenciesS
FR-FIN-6Users can maintain their own exchange rates (one rate per currency to their base currency) in settings, with the date each rate was last updated. A user's rates are private and are used for every space they viewC
FR-FIN-7Totals across currencies (net worth, dashboard) are converted into the base currency using the user's saved rates; the app shows the rate date and prompts for a rate if one is missingC
FR-FIN-8Users can optionally add the provider name (e.g. "BCA", "GoPay"), a color/icon, and the last 4 digits of a card or bank account number to tell similar financial accounts apartS
FR-FIN-9Financial accounts are grouped by type on the Financial Accounts screen, with a subtotal per groupS
FR-FIN-10Credit card financial accounts show the amount owed; users can optionally set a credit limit and see available creditS
FR-FIN-10aUnusual balances are allowed but highlighted: a cash / bank / e-wallet balance below zero, a credit card over its limit, and a credit card paid more than owed (shown as a "credit balance")S
FR-FIN-11Credit card financial accounts can optionally have a statement day and payment due day, with a reminder to the space's Owners before the due dateC
FR-FIN-12Paying a credit card bill is recorded as a transfer from a bank / e-wallet / cash financial account to the credit card financial accountM
FR-FIN-13A top-up (e.g. bank → GoPay) or a cash withdrawal (e.g. bank → cash wallet) is recorded as a transferM
FR-FIN-14A financial account's currency can be changed only while it has no transactions; after that the field is lockedM
FR-FIN-15Before a financial account is deleted, the warning lists the other financial accounts it has transfers with, and explains that those transfers become ordinary income or expense there (BR-6)M

8.6 Transactions ​

IDRequirementPriority
FR-TRX-1Users can add an expense or income with amount, financial account, category, date and time (defaults to now; can be set to a past date for entries logged late, or a future date for planned payments), and optional noteM
FR-TRX-2Users can record a transfer between financial accounts they can access, in the same space or in different spaces (FR-SPC-14). Transfers are not counted as income or expenseM
FR-TRX-2aUsers can transfer between financial accounts in different currencies (e.g. USD PayPal → IDR BCA) using a manually entered exchange rateS
FR-TRX-2bIn a cross-currency transfer the user enters the amount sent plus either the exchange rate or the amount received; the app calculates the missing valueS
FR-TRX-2cThe user can edit the calculated amount received to match what actually arrived (e.g. after fees or a different bank rate); the app then recalculates the effective rateS
FR-TRX-2dThe rate field is pre-filled with the user's saved rate for that currency pair (FR-FIN-6), if one exists; the user can override it for this transfer only, or choose to save it as the new rateC
FR-TRX-2eOn any transfer (same or different currency) the user can optionally record a fee, e.g. an e-wallet top-up admin fee. The fee is saved as a separate expense in the "Fees" category from the sending financial accountS
FR-TRX-3Users can edit and delete transactions, within their role in the space (§8.4): Members only their own, Owners anyM
FR-TRX-3aEditing a cross-currency transfer uses the same form as creating one: changing any of amount sent, rate, or amount received recalculates the third. Only that transfer changesS
FR-TRX-4Users can search and filter transactions in the current space by date, financial account, category, amount, and textM
FR-TRX-5Users can set up recurring transactions (daily, weekly, monthly, yearly)S
FR-TRX-5aWhen editing or deleting a transaction created by a recurrence, the user chooses Only this one or This and all future onesS
FR-TRX-5bRecurring transactions are created by the server on their due date in connected mode, so occurrences are never missed while the phone is off or offline. In local mode the app creates any missed occurrences, dated on their due dates, the next time it is openedS
FR-TRX-5cA recurring transaction in a shared space belongs to the member who set it up; it stops if that member leaves the spaceS
FR-TRX-6Users can attach a receipt photoC
FR-TRX-7Users can always add, edit, and delete transactions without internet. In connected mode the changes sync when the device is back onlineM
FR-TRX-8Users can record a refund: money returned for an earlier purchase, into any financial account, with an expense category (normally the one the original purchase used). It can optionally be linked to the original expenseM
FR-TRX-9Future-dated transactions are shown in an Upcoming section of the transaction list. Balances and net worth show the amount as of now, with a second figure "after upcoming". Future transactions count toward the budget of the period their date falls in, and become normal transactions automatically when their date arrivesS

Example: cross-currency transfer with manual rate

FieldValue
FromPayPal (USD)
ToBCA (IDR)
Amount sent100.00 USD
Exchange rate (entered by user)1 USD = 16,250 IDR
Amount received (calculated, editable)1,625,000 IDR

Result: PayPal balance −100.00 USD, BCA balance +1,625,000 IDR. The transfer stores both amounts and the rate. It is not counted as income or expense.

8.7 Categories ​

IDRequirementPriority
FR-CAT-1Every space starts with a default set of income and expense categories, named in the language of the person who created the space. Category names are normal text and are not translated for other membersM
FR-CAT-2The space's Owners can create, rename, recolor, and archive its categoriesM
FR-CAT-3Categories can have sub-categoriesC
FR-CAT-4A transaction's category always comes from the space of its financial account: when adding a transaction, the category picker shows that space's categoriesM

8.8 Budgets & Goals ​

IDRequirementPriority
FR-BUD-1The space's Owners can set a monthly budget per category, in the space's currency. All members see the budgetsM
FR-BUD-2Users see progress against each budget (spent / remaining)M
FR-BUD-3Members of the space get notified at 80% and 100% of a budgetS
FR-BUD-4The space's Owners can create savings goals with name, target amount, and target dateS
FR-BUD-5A savings goal is linked to one financial account in the same space (e.g. a savings bank); progress = that financial account's balance. Money moved there by transfer counts automaticallyS
FR-BUD-6If no financial account is linked, the user records contributions to the goal manuallyC
FR-BUD-7Expenses in currencies other than the space's currency count toward budgets after conversion with the viewing user's saved rate; if the rate is missing they are left out and the budget shows a warningC
FR-BUD-8A budget on a category with sub-categories includes the spending in its sub-categoriesC

8.9 Dashboard & Insights ​

IDRequirementPriority
FR-DSH-1Each space's dashboard shows its total balance, this month's income, expenses, and net. The Personal dashboard also shows total net worth across included spaces (FR-SPC-13)M
FR-DSH-2Spending breakdown by category (chart)M
FR-DSH-3Month-over-month spending trendS
FR-DSH-4Top merchants / largest expensesC
FR-DSH-5A Stats screen (its own tab) shows analytics for the current space. It shows one chart at a time, chosen with tabs: Categories, Calendar, Trend, and Accounts (in a shared space the last tab is Members, FR-SPC-15)M
FR-DSH-6A period selector (Week / Month / Year) applies to every Stats chart. Periods follow the space's budget start day (BR-4). The user can step back to earlier periodsM
FR-DSH-7Categories: a donut chart of spending by category, with the period total in the middle. Tapping a slice or its label selects that category and shows its amount and share of spendingM
FR-DSH-8Calendar: a month heatmap where each day's shade shows how much was spent that day. Tapping a day selects itS
FR-DSH-9Trend: a bar per period (e.g. the last 6 months). Tapping a bar selects that period and shows the change against the previous one (FR-DSH-3)S
FR-DSH-10Accounts: spending per financial account as bars; tapping one selects itC
FR-DSH-11Below the chart, Stats always lists the transactions behind the current selection (the category, day, period, account, or member), grouped by day, with a count and total. The list updates as soon as the selection changes. An Open in Activity link opens the transaction list with the same filter (FR-TRX-4). Refunds reduce the amounts (BR-24), transfers are left out (BR-2), and amounts in other currencies are converted with the viewer's saved rates, marked as estimates (FR-FIN-7)M

8.9a App Navigation ​

IDRequirementPriority
FR-NAV-1On phones the main screens sit in a bottom tab bar: Home, Activity (transactions), Budgets, Stats, More (financial accounts, categories, recurring, goals, spaces, settings). A + button on the main screens opens the add-transaction sheet (NFR-7). The space switcher sits at the top of every main screen (FR-SPC-11)M

8.10 Data Import & Export ​

IDRequirementPriority
FR-DAT-1Users can export to CSV the transactions of any space they belong to (one space or all), shared through the device's share menu or downloaded. The export includes who added each transactionM
FR-DAT-2Users can import transactions from CSV with column mappingS

8.11 Notifications ​

IDRequirementPriority
FR-NOT-1Optional daily reminder to log transactionsS
FR-NOT-2Budget threshold alerts (see FR-BUD-3)S
FR-NOT-3Notifications need connected mode. At launch they appear in a notification list inside Crest and, where it matters, by email; in local mode the app shows reminders only while it is open. Browser push notifications (Phase 2) need the user's permission and, on iPhone and iPad, Crest added to the home screenS
FR-NOT-4Users are notified of invitations to a shared space, of being removed from one, and of a shared space being deletedM

8.12 Settings ​

IDRequirementPriority
FR-SET-1Users can choose their base currency (any ISO 4217 currency; also the currency of their Personal space) and language (English, Bahasa Indonesia at launch)M
FR-SET-2Users can choose light/dark themeS
FR-SET-3Users can set the start day of the budget month for their Personal space (e.g. payday); Owners set it for a shared spaceS
FR-SET-4Changing the base currency (or a shared space's currency) shows a warning, then asks the user (or Owner) to review that space's budgets, pre-converted with saved rates where availableS

8.13 The Crest App and Websites ​

IDRequirementPriority
FR-APP-1Users use Crest through the Crest app, a Progressive Web App at its own web address. It works in the browser on phones, tablets, and computers. The first release is web onlyM
FR-APP-2The app can be added to the home screen and then opens full-screen with its own icon and name, like an app. The public website has an install page with the steps for the visitor's device (iPhone and iPad: Safari → Share → Add to Home Screen; Android and computers: the browser's Install option). The activation page and the activation email link to itM
FR-APP-3When browser push notifications are introduced, the app asks once for permission, explaining what they are forS
FR-APP-4Without internet, the app still opens, unlocks, and works fully in local mode. In connected mode it shows the data it last synced and accepts changes, with an Offline indicatorM
FR-APP-5When a new version is published, users get it automatically. The app finds out from a small public file on its own web address, so this works in local mode too. If the app is open, it shows "A new version is available" with a Reload button. If the open version is too old to work safely, it shows "Update required" and reloads before the user can continueM
FR-APP-6The app is designed for phones. On tablets and computers it keeps its phone-width layout. The Super Admin portal and the public website are designed for web browsersM
FR-APP-7Activating a login and resetting a password happen on the public website, so they work before the user has ever opened the appM
FR-APP-8Native Android and iPhone apps, built from the same code and distributed through Google Play and the App Store, may follow when there is demandW

8.14 Contributions (future — Phase 4) ​

Only built if running costs need to be shared, and announced to users at least 30 days before it starts (BR-45). Crest never processes payments: users pay the owner directly (e.g. bank transfer or e-wallet), and the Super Admin records it.

IDRequirementPriority
FR-SUB-1Super Admin can set a paid-until date for each user, and see who is paid, due soon, or lapsedW
FR-SUB-2Super Admin can mark a user as exempt (e.g. family), so they never need to contributeW
FR-SUB-3Users see their paid-until date and the payment instructions set by the Super Admin in SettingsW
FR-SUB-4Users get a reminder 30 days and 7 days before their paid-until dateW
FR-SUB-5After the paid-until date there is a 30-day grace period with full accessW
FR-SUB-6After the grace period the user is read-only in every space they belong to: they can view and export but cannot add or edit anything, until the Super Admin records a new payment. Other members of shared spaces are not affectedW
FR-SUB-7Every change to paid-until or exempt status is recorded in the audit logW

9. Non-Functional Requirements ​

IDCategoryRequirement
NFR-1AccuracyMoney is stored as exact integers in minor units (never floating point). Balances are always derived from transactions.
NFR-2SecurityData encrypted in transit (TLS 1.2+) and at rest. A user can access only the spaces they are a member of, and only with the permissions of their role; this is enforced by the database (row-level security), not only by the app. No financial data in logs. In local mode the data lives in the browser's private storage on the person's device; the PIN lock hides it in the app but does not encrypt it.
NFR-3PrivacyComplies with data protection laws of the markets served (GDPR, Indonesia PDP Law, etc.); consent captured on the first launch of the app and on the request form; in local mode Crest collects no personal data; clear Privacy Policy explaining what shared-space members can see, what stays after deletion, how long deleted data remains in backups (at most 90 days), and that the operator has technical access to the server but commits never to look at users' financial data except to fix a problem the user reports; user can export and delete their data. No selling of user data.
NFR-4PerformanceFirst visit: the app is usable within 5 s on a 4G connection (about 3 MB to download once). Later visits: ≤ 2 s (cached). Screens show data in ≤ 1 s; adding a transaction feels instant (optimistic update).
NFR-5AvailabilityBackend uptime ≥ 99.5%. Local mode does not depend on the backend, and core logging works offline in both modes.
NFR-6ScalabilitySupports at least 500 connected users, 10k transactions per user, and 20 members per shared space without slowing down. There is no limit on the number of financial accounts or spaces per user. Larger scale is not a goal, but the design should not prevent it. People using local mode only download the app's static files, so their number is not limited by the server; if that traffic ever grows, the files can move to free static hosting.
NFR-7UsabilityAdd a transaction in ≤ 3 taps from the Home screen. Accessible font scaling and contrast.
NFR-8LocalizationEnglish and Bahasa Indonesia at launch; architecture supports adding languages without code changes. Locale-aware number, date, and currency formatting. Correct minor units per currency (e.g. JPY 0, USD 2, KWD 3). All timestamps stored in UTC and shown in the user's time zone.
NFR-9PlatformsThe Crest app is a Progressive Web App built with Flutter. Supported: Safari on iPhone and iPad with iOS/iPadOS 16.4+, Chrome on Android 10+, and the latest two versions of Chrome, Safari, Edge, and Firefox on computers. The Super Admin portal and public website support the same browsers. The backend is a separate API used by all of them. Native Android and iPhone apps are not part of the first release (FR-APP-8).
NFR-10BackupDaily automated, encrypted database backups: the last 30 daily copies and 3 monthly copies, so deleted data is gone from all backups within 90 days. Stored outside the Crest server (e.g. Biznet Gio NEO Object Storage). A restore is tested at least every 3 months. Point-in-time recovery is not required.
NFR-11Admin securityAdmin portal enforces 2FA, session timeout after 30 minutes idle, and rate-limited login. Admin actions are authorized server-side, never only in the UI.
NFR-12AuditAdmin audit log entries cannot be edited or deleted and are kept for at least 1 year.
NFR-13Running costRunning costs stay very low: target ≤ IDR 150,000 per month for the server, backup storage, domain, and email, for up to 500 connected users. Local-mode users add no cost beyond downloading the app's static files. Free tiers are used wherever they are enough. There are no app-store fees at launch; if native apps are published later, Google Play (USD 25 once) and the Apple Developer Program (USD 99 per year) are added.
NFR-14Data durability on devicesIn connected mode the server is the source of truth: data the app keeps in the browser may be cleared by the browser at any time, or lost with the device, without losing anything already synced. In local mode the device holds the only copy, so it can be lost for the same reasons. The app reduces this risk by asking the browser to keep its data (FR-MOD-7), by asking iPhone users to install the app first (FR-MOD-6), and by backup files and reminders (FR-MOD-5, FR-MOD-8).
NFR-15HostingCrest runs on a self-managed VPS at Biznet Gio (NEO Lite) in Indonesia, so user data is stored in Indonesia. The server is hardened: automatic security updates, firewall open only for web traffic and key-based SSH, HTTPS certificates renewed automatically, database not reachable from the internet, and uptime monitoring with alerts to the owner.
NFR-16RecoverabilityThe whole server can be rebuilt from the repository and the latest backup by following a written runbook, within 4 hours.
NFR-17Web addressesThe public website is at crest.radityatama.web.id, the Crest app at app.crest.radityatama.web.id, the backend API at api.crest.radityatama.web.id, and the Super Admin portal at admin.crest.radityatama.web.id, all over HTTPS only. Emails are sent from no-reply@radityatama.web.id; the public contact address is contact@radityatama.web.id (forwarded to the owner). The domain is registered at Biznet Gio, and its DNS is hosted there too (Biznet NEO DNS, no proxy). The domain is a configuration setting, so it can change later without code changes.
NFR-18Data retentionRejected access requests are deleted after 6 months. Server logs are kept for 14 days. The admin audit log is kept for at least 1 year (NFR-12). Backups follow NFR-10.

10. Business Rules ​

IDRule
BR-1Each financial account has exactly one currency; transactions inherit the financial account's currency.
BR-2Transfers between financial accounts, in the same space or across spaces, do not count as income or expense.
BR-3Financial account balance = opening balance + sum of all its transactions.
BR-4Budget periods start on the space's configured start day (default: 1st of month).
BR-5Deleting a category does not delete its transactions; they become "Uncategorized".
BR-6Deleting a financial account requires confirmation and deletes its transactions; archiving keeps them. Transfers to or from other financial accounts are not deleted on the other side: each becomes an ordinary expense or income there (e.g. "Transfer to deleted financial account"), so the other financial accounts' balances do not change.
BR-7Crest never initiates payments or moves money.
BR-8A user can only be created by the Super Admin, either by approving an access request or by creating it directly.
BR-9One email address maps to at most one user.
BR-10Activation links are single-use and expire after 72 hours.
BR-11Deactivating a user keeps their data; only deletion removes it. Deletion cannot be undone. The only data that remains after deletion is transactions they added in shared spaces (BR-34).
BR-12The Super Admin role manages access only; it grants no access to users' financial data.
BR-13There must always be at least one active Super Admin; the last one cannot be deactivated, deleted, or demoted.
BR-14A rejected requester may submit a new request after 30 days. Within those 30 days, a new request from that email gets the same neutral confirmation, and nothing is created or emailed.
BR-15Exchange rates are always entered manually by the user; Crest does not fetch rates from external services.
BR-16A cross-currency transfer stores the amount sent, the amount received, and the rate used. Later rate changes never alter past transactions.
BR-17Converted totals are estimates for display only; financial account balances always stay in that financial account's own currency.
BR-18Spending with a credit card is an expense when the purchase is made; paying the card bill is a transfer, so the same spending is not counted twice.
BR-19Crest stores at most the last 4 digits of any card or bank account number, never the full number, CVV, PIN, or login details.
BR-20Crest is its own and only identity provider. Users and the Super Admin authenticate only with Crest-managed credentials (email + password; a PIN for unlocking; 2FA for the Super Admin); no third-party identity provider is used.
BR-21Sync conflicts in connected mode: for each transaction, the last change received by the server wins, and a delete wins over an edit. Unsynced changes from a user who has been deactivated are discarded.
BR-22Budgets are always set in the space's currency.
BR-23Crest records what really happened: negative balances, spending over a credit limit, and overpaid credit cards are allowed, never blocked.
BR-24A refund reduces spending in its category (and the related budget). It is never counted as income.
BR-25A recurrence on day 29, 30, or 31 falls on the last day of shorter months.
BR-26A financial account's currency is fixed once it has any transaction.
BR-27Crest never processes payments. Contributions are paid outside Crest and recorded by the Super Admin.
BR-28A user whose contribution has lapsed always keeps read and export access to their own data and their spaces. Their data is never deleted because of non-payment.
BR-29The contribution amount is set only to cover Crest's running costs, not to make a profit.
BR-30Every financial account, category, budget, and savings goal belongs to exactly one space. A user can see and use them only if they are a member of that space.
BR-31A transaction's category must belong to the same space as its financial account.
BR-32A Personal space always has exactly one member, its user.
BR-33Every shared space has at least one Owner. If the last Owner is deleted, the longest-standing member becomes Owner; if there are no other members, the space and all its data are deleted.
BR-34When a member leaves or is removed, transactions they added stay in the space with their name. When a user is deleted, those transactions stay and are labelled "Former member".
BR-35In a transfer between spaces, members see only the side in their own space. The other side is shown as the person who made the transfer, never as the other financial account or its balance.
BR-36Members can edit or delete only transactions they added; Owners can edit or delete any transaction in their space.
BR-37Financial accounts can't be moved between spaces.
BR-38Requests for money between members (e.g. staff asking the Boss for more) happen outside Crest. Crest records only the resulting transfer.
BR-39Only Active users can join a shared space, and only by accepting an invitation, which expires after 14 days.
BR-40A recurring transaction in a shared space belongs to the member who set it up and stops when that member leaves the space.
BR-41Super Admin is a role held by a user. A Super Admin also uses Crest as a normal user, with their own Personal space and shared spaces; the role only adds access to the portal. There can be several Super Admins.
BR-42Balances and net worth are always shown as of now. A future-dated transaction affects them only once its date arrives, except in the "after upcoming" figure and in the budget of its own period.
BR-43Deactivating a user does not change their space memberships. Their shared spaces keep working for the other members. If they were a space's only Owner, nobody can manage that space until they are reactivated, or deleted (then BR-33 applies).
BR-44Crest users must be 18 or older, confirmed on the first launch of the app (local mode) and again on the access-request form.
BR-45Users are told in Crest and by email at least 14 days before important changes to the Privacy Policy or Terms of Use take effect, and at least 30 days before contributions start or Crest shuts down.
BR-46In local mode Crest receives no personal or financial data, has no copy of what the person records, and cannot recover or reset it.
BR-47A device's local data is uploaded into a user's Personal space only when that space is empty on the server. Otherwise the person chooses to use the server's data (after being offered a backup file of the local data) or to keep the device's data local only. Local data is never merged into existing server data automatically.
BR-48Every record is identified by an ID created on the device, so uploading or restoring the same record twice never creates a duplicate.
BR-49In local mode a wrong PIN only slows down further attempts; it never erases data, because the device holds the only copy. If the PIN is forgotten, the way back in is to erase the app's data on that device and restore a backup file. (In connected mode five wrong attempts log the user out and clear the local copy, because the server has the data.)
BR-50After a forced logout (the user was deactivated or deleted), the app removes the synced data from the device and continues in local mode with an empty start.

11. Release Roadmap ​

PhaseScopeTarget
Phase 1a — Local app (ships first, no server needed)The Crest app (PWA) in local mode: first-launch welcome, financial accounts, transactions, categories, budgets, Home and Stats, search, CSV export, backup file, optional PIN, update notice; public website (landing, install, privacy, terms)TBD
Phase 1b — ConnectedBackend API, Super Admin portal, access requests, login, connect and upload of local data, sync between devices, server backup, spaces and sharing, emailTBD
Phase 2 — EngagementRecurring transactions, savings goals, notifications, CSV import, cross-currency transfers, manual exchange rates (these work in both modes, except notifications)TBD
Phase 3 — AutomationAuto-categorization; bank/e-wallet sync via aggregator only if affordableTBD
Phase 4 — ContributionsManual yearly contributions (§8.14), only when running costs need to be sharedWhen needed
Phase 5 — ExpansionInvestments, more languagesTBD
Native appsAndroid and iPhone apps from the same Flutter code, with device biometrics and store distribution (FR-APP-8)When there is demand

12. Assumptions & Constraints ​

Assumptions

  • Local-mode users can be anyone and cost nothing to serve. Connected users are the owner and people they know; expected size is tens of users, possibly growing to a few hundred.
  • Users may live in different countries and choose their own base currency.
  • Users use Crest on their phones; the Super Admin mostly uses a computer.
  • All user data is hosted in Indonesia (Biznet Gio).
  • Users are comfortable entering transactions manually and adding a web app to their home screen with a short guide.
  • Crest is free now. A yearly contribution to cover running costs may be introduced later (Phase 4).
  • Access to connected mode is invite-only; connected user numbers grow at the pace the Super Admin approves requests.
  • A single person (the owner) acts as Super Admin at launch; other users may be given the role later.
  • People who share a space trust each other (couples, families, a boss and staff); every member of a space can see everything in it.

Constraints

  • Built and run by one person (the owner) on a single self-managed VPS; the stack must stay small and simple enough for one person to maintain, update, and restore.
  • Must comply with the data protection laws of the countries where users live before inviting them.
  • iPhone and iPad limits for web apps: no automatic install prompt, push notifications only after adding to the home screen, and stored data may be cleared if Crest is not used for a while. Safari clears the storage of websites it was not used on for about a week, and a home-screen app keeps its data separately from Safari, so local-mode data on iPhone is safe only in the home-screen app (UJ-38).
  • A Flutter web app downloads about 3 MB on the first visit, more than an ordinary website.
  • One person maintains four parts (backend, the Crest app, admin portal, public site), so each must stay small.
  • Bank syncing depends on third-party aggregator availability, cost, and licensing.

13. Risks ​

RiskImpactLikelihoodMitigation
Users stop logging after a few daysHighHighVery fast entry, reminders, recurring transactions
Data breach erodes trustHighLowRow-level security, encryption, security review before launch
Bank aggregator cost or coverage is poorMediumMediumKeep bank sync out of MVP; design data model to support it later
Regulatory changeMediumLowLegal review; avoid moving money or giving advice
iPhone and iPad limits for web apps (manual install, push only after install, on-device data may be cleared)HighMediumInstall page (FR-APP-2); iPhone users install first (FR-MOD-6); server as source of truth for connected users (NFR-14); backup file and reminders for local users; in-app notification list and email
Local-mode users lose their only copy (browser clears data, device lost or reset)HighMediumPersistent-storage request (FR-MOD-7), plain warning before data is entered (FR-MOD-6), backup file with reminders (FR-MOD-5, FR-MOD-8), easy invitation to connect for people the owner knows
Data stored in local mode is not encrypted, so someone with access to the unlocked device's browser data could read itMediumLowThe PIN stops casual access; the phone's own screen lock is the real protection; say so in the Privacy Policy; consider encrypting with the PIN later (§14)
Money rules in the app and in the API differ, so uploaded local data is rejected or counted differentlyMediumLowBoth run the same test vectors (shared money-test-vectors); the API validates every uploaded record
The first visit feels slow because the app is a large downloadLowMediumLoading screen with the Crest logo, caching so later visits are fast (NFR-4), public pages kept separate and light
Maintaining four separate parts is too much for one personMediumMediumGenerated API clients from one contract, shared money test cases, small admin portal and static public site
The owner holds friends' and family's financial dataHighLowSuper Admin cannot see financial data, encryption, easy export and delete, clear privacy policy
Super Admin login is compromisedHighLowMandatory 2FA, audit log, no admin access to financial data
Access requests pile up and requesters lose interestMediumMediumNew-request email alerts, pending count on portal overview
Spam or bot access requestsLowMediumRate limiting and bot protection on request form
Users live in countries with different privacy lawsMediumMediumDesign to GDPR standard (strictest common baseline); check the rules of a new country before inviting people there
A user adds a private expense to a shared space by mistake, or members misunderstand what others can seeMediumMediumCurrent space always visible at the top; the entry form shows which space a financial account belongs to; clear explanation when joining a space; members can delete their own entries
Keeping a deleted user's shared-space transactions conflicts with "delete all my data"MediumLowOnly transactions they added in shared spaces stay, labelled "Former member"; explained in the privacy policy and in the delete warning
Running costs grow with no revenueMediumMediumLow fixed-cost stack (NFR-13); local mode costs nothing per user; invite-only access controls the part that costs money; optional yearly contribution (Phase 4)
The self-managed server is hacked or misconfiguredHighLowHardening and automatic updates (NFR-15), database not exposed to the internet, encryption, row-level security, off-server backups
The server fails or data is lostHighLowDaily off-server backups (NFR-10), tested restores, written rebuild runbook (NFR-16)
Server maintenance takes too much of the owner's timeMediumMediumSmall stack, automatic updates and certificate renewal, container-based deployment, monitoring with alerts

14. Open Questions ​

  1. Target launch date?
  2. Contribution amount, payment methods, and when to start (decide when running costs need sharing).
  3. Whether Crest will later be owned by an organisation instead of the owner personally.
  4. Whether the backup file should be protected with a password, and whether data on the device should be encrypted with the PIN (local mode).
  5. How a local user who is later invited and has data on several devices should merge them (for now: one device uploads, the others use the server's data, BR-47).

15. Glossary ​

TermDefinition
UserA person who can log in to Crest (connected mode). Has an email, password, and status (Pending, Invited, Active, …). Created and managed by the Super Admin. Never called an "account".
Financial accountAny place where money is held or owed: cash wallet, bank, e-wallet / online payment, or credit card. Belongs to one space and is managed by that space's Owners.
LiabilityMoney owed, such as a credit card balance. Subtracted when calculating net worth.
Access requestA person's request to be given access to connected mode and become a Crest user.
Super AdminA role that a user can have, allowing them to approve access requests and manage users through the admin portal. Several users can have it.
Activation linkSingle-use, time-limited link emailed to an approved user to set their password.
Audit logPermanent record of every admin action.
TransactionA single income, expense, refund, or transfer entry.
RefundMoney returned for an earlier purchase. Reduces spending in its category instead of counting as income.
TransferMovement of money between two financial accounts, in the same space or in different spaces.
SpaceA container for financial accounts, categories, budgets, and savings goals, with a list of members who can see it.
Personal spaceThe private space every user gets automatically. Only that user is a member.
Shared spaceA space with more than one possible member, created by a user, who becomes its first Owner.
OwnerA member of a space who can manage its setup (financial accounts, categories, budgets, members) and edit any of its transactions.
MemberA member of a space who can see everything in it and add transactions, but edit or delete only their own.
InvitationAn Owner's request for an Active user to join a shared space. Must be accepted; expires after 14 days.
BudgetA spending limit for a category in a space over a period.
Minor unitSmallest unit of a currency (e.g. cents for USD). The number of decimal places differs by currency (JPY and IDR 0, USD 2, KWD 3).
AggregatorThird-party service that connects to banks to retrieve transaction data.
Exchange rateHow much one unit of a currency is worth in another. In Crest, entered manually by the user.
Base currencyThe currency a user chooses for their Personal space and for their total net worth across spaces.
Crest appThe app people use. In the first release it is a Progressive Web App; the same Flutter code can later be published as Android and iPhone apps.
Local modeUsing the Crest app with no login. The data stays on the device and is never sent to Crest's servers. Open to anyone.
Connected modeUsing the Crest app while logged in as a user. The data syncs with Crest's server, which allows several devices, shared spaces, and a server backup. Only for people who have been given access.
ConnectLogging in from the app so that a device moves from local mode to connected mode (More → Connect to Crest).
Backup fileA file the person saves from the app that holds all their data, and that can be restored on the same or another device.
PWA (Progressive Web App)A web app that can be added to the home screen and then opens and works like an app, including without internet.
Public websiteThe pages at crest.radityatama.web.id: what Crest is, request access, activate, reset password, install, privacy, and terms.
APIThe backend that the Crest app, the Super Admin portal, and the public website all talk to.
App lockProtection that asks for the Crest PIN before showing any data.
ContributionA future, optional yearly payment from a user to cover Crest's running costs, paid outside Crest and recorded by the Super Admin.
Paid-until dateThe date a user's contribution covers them until.
VPS (Virtual Private Server)A rented virtual server. Crest runs on one at Biznet Gio, maintained by the owner.

16. Approval ​

NameRoleSignatureDate
Product owner
Engineering lead

Crest is a personal project by Reizkian Y. Radityatama.