How we protect you
- Your ledger on your phone: SQLCipher-encrypted database; random 256-bit key held in iOS Keychain / Android Keystore; app lock with PIN or biometrics; excluded from cloud OS backups; screen privacy on sensitive screens.
- Family sync: end-to-end encrypted. Our servers store only envelopes they cannot read.
- Our servers: encryption in transit (TLS) and at rest; managed sign-in (AWS Cognito); least-privilege access; rate limiting; tamper-evident audit logs; a sensitive-field deny-list enforced in the app, server and build pipeline so financial values cannot be logged.
- No ads, no third-party trackers in the app or website.
Breaches
If a personal data breach occurs, we will inform affected users without delay and report to the Data Protection Board of India (detailed report within 72 hours) and to CERT-In within 6 hours of noticing a reportable incident, as Indian law requires.
Reporting a vulnerability
Found a security issue? Please tell us privately.
- Email: shivhari.lokhande06@gmail.com, subject "Security". Include steps to reproduce, impact, and your contact.
- We acknowledge within 48 hours, give an initial assessment within 7 days, and keep you updated until fixed.
- We will not take legal action against good-faith research that follows these rules.
Please do: test only with your own accounts; stop and report as soon as you find an issue; give us reasonable time to fix before disclosure.
Please don't: access or change other people's data; run denial-of-service, spam or social-engineering tests; use automated scanners that degrade service; demand payment.
We do not run a paid bug bounty at present, but we are glad to credit you (with your permission).