Security · privacy
Read-only by design.
Audit by default.
We never move money on your behalf. Bank access is read-only, OAuth-scoped and re-consented every 90 days. Every change, by you or by the assistant, lands on an append-only audit log with its trace id.
All systems normal
What is actually in place.
Bank connections are read-only. Your bank runs the sign-in itself and hands vokse a key that can only read; your bank password never reaches us, you renew the permission every 90 days with a reminder a week ahead, and the key is stored encrypted.
Your account is yours to lock down. Passkeys and two-step sign-in are there in Settings, repeated sign-in attempts slow down and then lock for up to an hour, and any key you create for another app gets exactly the permissions you choose and is shown to you once.
Every change is on the record. The log only ever grows: who did what, from where, and what changed, kept for two years. The assistant works through the same doors as the app and waits for your confirmation before anything it cannot undo. When you want out, you export everything as one file and deletion wipes your data after 30 days.
- Passkeys and authenticator codes
- Only ever grows, two years
- Read only, your bank signs you in
- Stored encrypted
- Everything, as one file, any time
- Wiped 30 days after you ask
Every change, on the record.
Every write, by you or by the assistant, is recorded with the request that caused it and the actor behind it. The whole log travels inside your data export.
- AI
ai.categorize09:41:07payee: Supermarket → cat: Groceries · confidence: 0.94
- You
budgets.move09:58:12you approved · $40.00 Groceries → Eating out
rules.apply10:14:03FNAC → Books · rule matched 4 transactions
transactions.import10:22:47Bank sync · 38 new, 0 duplicated
transactions.update11:05:19A connected app · tagged 12 transactions
trace: 01H8T1-Z078H · role: editor
Every line says where it came from
Each entry carries the request that produced it, so a change can be followed from the click to the row.
Who or what, never ambiguous
You, the assistant, a rule, an import or an API key. The log records the actor, not just the change.
Yours to take
The complete log travels inside your data export, in a format you can open.
Nothing rewrites it
Entries are only ever appended. The product has no path to edit one, and a scheduled prune is the only thing that ever removes one.
The documents behind the claims.
Privacy, self-serve
Export everything as a ZIP of JSON, review the consents you have given and delete your account with a 30-day purge, all from Settings. The policy spells out what we collect and what we never do.
Read the privacy policy
Data Processing Agreement
Our standard GDPR Article 28 contract, pre-signed on our side and incorporated into the Terms. Read it before you sign up, not after.
Read the DPASub-processors
Every vendor that ever sees customer data and what it does: storage, payments, AI providers, email, error tracking and analytics. At least 14 days' notice before we add or replace one.
See the listCommon worries · honest answers.
Responsible disclosure
Found a bug? We'll buy you dinner.
We reward serious security findings, scaled to severity, plus a thank-you on this page. We acknowledge within 24h, fix or workaround within 5 business days.
Read-only is the whole point.
Connect a bank in read-only mode, see every action in the audit log, and export everything whenever you want.