The thing we will never build
There is no bank connection. No login, no aggregator, no read access to any account you hold, on any plan, at any point.This is architectural rather than a setting. There is no facility to connect
a bank, so there is nothing to enable, nothing to misconfigure and nothing to
breach. A product that never asked for your banking credentials cannot leak
them.
Three layers
Privacy here is enforced in three independent layers, so that it never rests on a policy statement alone.1
Architecture: the capability does not exist
No bank integration, no aggregator relationship, no credential storage.
The first layer is the one that cannot fail, because there is nothing there
to fail.
2
The database: every row is scoped to its owner
Access rules are enforced by the database itself rather than by application
code remembering to filter. A query that forgot a condition returns
nothing, not somebody else’s book.
3
Policy: what we commit to in writing
The Privacy Policy states what is
collected, why, and for how long. It is the third layer because it is the
weakest one: a promise is only as good as the two mechanisms under it.
Document parsing
When document parsing ships, document content is stripped of identifying information before it is sent anywhere for processing: names, email addresses and account numbers are removed first, and what the model receives is amounts, dates and descriptions without knowing whose they are.What this means in practice
You choose what is recorded
Every entry is one you made or one you confirmed. Nothing arrives on its
own from an account we can see.
No session recording
We do not record your screen or replay your sessions.
Your IP is not stored
Product analytics runs without retaining it.
Deletion is real
No soft delete, no archived copy kept behind the scenes.
Next: what we collect
A plain-language inventory of every category of data.

