How we protect your money data
Financial information deserves more than a checkbox. Here's exactly what we do, in plain language.
- We never ask for your bank login. You choose what to share: a receipt, a voice note or a statement file you download yourself.
- Encrypted everywhere. All traffic uses HTTPS with HSTS; data is stored on Cloudflare's infrastructure, which encrypts it at rest. Sensitive secrets such as two-factor keys are additionally encrypted by us with AES-256-GCM.
- Strong sign-in. Passwords are hashed with PBKDF2-SHA256 and a server-side secret (never stored in plain text), checked against known data breaches, and protected by rate limits and automatic lockouts. Two-factor authentication with any authenticator app is built in.
- Your data is only yours. Every request is checked against your account; there is no way to view or reference another person's data. Even our admin tools show account details only, never your transactions.
- You can see who's signed in. Settings → Security lists every device with access and a log of security events. Sign out any device instantly.
- Hardened web app. Strict Content Security Policy, anti-clickjacking and anti-CSRF protections, secure host-only cookies, validated uploads and request size limits.
- Minimal data, minimal time. Raw voice transcripts and AI drafts are deleted once you've reviewed them; unreviewed captures expire after 30 days. Delete your account at any time and everything goes with it.
- Careful with AI. Receipts, statements and voice notes are sent to our AI provider only to extract transactions. They're not used to train AI models, and AI never changes your records without your confirmation.
- No selling, no ads. We make money from Premium subscriptions, never from your data.
Found a vulnerability?
Please email security@mywalletwise.com with details. We'll acknowledge within 72 hours and won't take legal action against good-faith research.