Transactions
| Date ↕ | Merchant | Category | Bank | Status | Amount ↕ |
|---|
Analytics
My Accounts
Security
When 2FA is enabled, you'll enter a 6-digit code from your authenticator app (Google Authenticator, Authy, 1Password, Microsoft Authenticator) every time you sign in.
Add a phone number and we'll text you a 6-digit code whenever you sign in. Useful as a fallback if you lose access to your authenticator app.
- 🔒 AES-256-GCM authenticated encryption (browser Web Crypto API)
- 🔑 Keys derived via PBKDF2-SHA-256 (100,000 iterations)
- 🏦 Plaid tokens, balances, transactions, and account metadata all encrypted
- 🛡️ Random 96-bit IV per record — ciphertext cannot be replayed
Exercising your data-portability rights under GDPR Art. 20 and CCPA §1798.100. The export includes your account profile, security configuration, connected accounts, transactions, balances, and preferences. Plaid access tokens are excluded for security.
This action is irreversible. Your profile, MFA enrollments, connected banks, transactions, balances, and preferences will be deleted. An audit log entry (hashed identifier only) is retained for compliance. Processing completes within 30 days per our Privacy Policy.
- 🔐 Bank credentials never touch our servers — all handled by Plaid
- 🔒 All traffic encrypted with TLS 1.3 in transit
- 🛡️ All Plaid data encrypted at rest with AES-256-GCM
- 📖 Read-only access to bank data — we can't move money
- 📱 2FA supports both TOTP (RFC 6238) authenticator apps and SMS codes
- 🗝️ Per-user keys derived with PBKDF2 (100k iterations)