Your data
stays yours.
We use bank-level security and a privacy-first approach so you can plan your finances with peace of mind. Here are our key data protection measures.
Bank-level Security
We protect your data with AES-256 encryption and TLS 1.3 protocol — the same standards used by the world's leading financial institutions.
End-to-end Encryption
Your sensitive data is encrypted before it ever leaves your device. Even we cannot read it without your unique access key.
We don't sell your data
Your information is never shared or sold to third parties. Privacy is our top priority, not a commodity.
No access to card numbers
We never ask for or store your full credit card numbers. Your financial privacy remains under your complete control.
How it works, technically
Local IndexedDB storage
Your cards, balances, and payment history are stored in your browser's IndexedDB — a persistent local database that doesn't leave your device.
AES-GCM encryption
Before data is written to IndexedDB, it's encrypted using the Web Crypto API's AES-256-GCM — the same algorithm used by banks and government systems.
Content Security Policy
Strict CSP headers prevent cross-site scripting attacks and block any unauthorized third-party script from loading.
Dependency audits
Every dependency is audited on every CI build. We run automated security scans and review all third-party packages before including them.
Pro sync (encrypted blobs only)
If you use Pro cross-device sync, your data is encrypted client-side before leaving your device. Our servers store encrypted blobs they cannot read.
Export warnings
Before any export containing financial data, we display a clear warning and require explicit confirmation.
What we do collect
| What | Why | Stored where |
|---|---|---|
| Email (Pro only) | Billing, account recovery | Stripe + our database, encrypted |
| Subscription status | Feature gating | Stripe webhook, our database |
| Encrypted sync blobs (Pro only) | Cross-device sync | Our servers — unreadable without your key |
| Error logs (anonymized) | Bug fixing | Ephemeral, no PII, auto-deleted after 30 days |
Every month you wait costs you interest. Start your free payoff plan today.
Add your cards in 2 minutes, pick a strategy, and get a payoff plan built on the same daily-interest math your bank uses.