RD$Budget
ES EN

Security

What we do to protect your data, and what we don't. No exaggeration.

The main thing: there's nothing to steal

The risk with a finance app is usually that it holds the keys to your bank. Here those keys don't exist: we don't ask for banking credentials, we have no access to your account, and anyone breaking into our server could not move your money. At worst they would see a list of purchases.

How we protect your account

How we protect the data

The limits of that encryption

The email bodies we keep are encrypted in the database, and the key lives in the server's configuration. That protects backups, database dumps and stolen disks. It does not protect against someone who gets into the server itself, because that's where the key is. We'd rather say it that way than call it end-to-end encryption, which it isn't.

What this project is not

This is a one-person project. I have no SOC 2 or ISO certification, no security team, and I'm not going to tell you we have "bank-level security" because that would be a lie.

What I can offer you is verifiable:

Report a vulnerability

Email me at [email protected]. I respond within 72 hours at most. There's no bug bounty, but there is credit if you want it. Please don't test against accounts that aren't yours.

security.txt · Privacy

Last updated: 2026-07-25