Security, in plain English
Last checked against the app: 30 September 2026
PathForward never holds your money and cannot move it. This page says exactly what we can see, who else can, and how it is protected — each line describes how the app works today.
- We never see your bank passwordYou sign in to your bank inside Plaid's window, not ours.
- Read-onlyWe only ever asked your bank for your transactions, so the app cannot move money.
- Nothing sold, no adsYour data is never sold or shared with advertisers, and never used to train AI.
- Yours to take or deleteDownload everything in one tap. Delete your account and it is gone.
Your bank connection
- Your bank username and password never reach us. When you connect a bank, you sign in inside Plaid's own window. Plaid is a bank-connection service used by many budgeting apps. Your login goes to Plaid and your bank; we could not store it if we wanted to.
- Read-only, by what we asked for. We ask your bank for one thing: your transaction history (your balances come with it). We have never asked for permission to make payments or transfers, so PathForward cannot move money — not "won't", cannot.
- The key to your account is locked away. Plaid gives us a key for reading your account. We encrypt it (AES-256) with a separate key kept in Google Cloud's Secret Manager, and it never goes to a browser — not even yours.
- Two-step verification before any bank is connected. Connecting a bank needs a 6-digit code from an authenticator app on your phone, on top of your password or Google sign-in.
- Disconnect any time. Settings → Connected Banks → Remove. We tell Plaid to cancel our access first, then delete our record of the connection.
- You hear about it when a connection breaks. If your bank needs you to sign in again, Home says so beside your balance with a Reconnect button, so your transactions never silently stop.
Who can see your data
- You.
- People you invite to your household. They see and edit the same budget and transactions as you. A member can leave at any time.
- Our support team sees your account, not your money. Our support tools show your name, email address and plan. They do not show your budget, transactions, balances or notes.
- The support assistant sees only what you type to it. It runs on Anthropic's Claude and receives your questions, never your budget or transactions.
- Receipt photos are private to the person who added them.
- Automatic jobs use your data only to work for you: syncing your bank, and the weekly recap and monthly report emails (turn those off in Settings → Emails).
What we never do
- Sell your personal or financial data, or share it with advertisers.
- Show ads, or use advertising cookies or tracking pixels.
- Use your financial data to train AI models.
- See or store your full card number. Payments go through Stripe.
How it is stored
- Encrypted on the way and at rest. Everything travels over HTTPS, and it is stored on Google Cloud (Firebase), which encrypts stored data.
- Your password is not ours to see. Sign-in is handled by Google's sign-in service for apps (Firebase Authentication).
- Every read and write is checked. Rules on the database tie your budget and transactions to your account, so no other account can read them. Household access is granted only by an invite you create.
Your data is yours
- Download everything in one tap. Settings → Profile → Download everything gives you one ZIP: spreadsheets of your transactions, every month of your budget, net worth, linked accounts, savings goals and filing rules, plus your whole account as a data file. On the free plan too.
- Delete means delete. Settings → Account permanently deletes your budget, transactions, receipt photos, goals and profile, disconnects every bank at Plaid, and cancels any subscription. It cannot be undone.
- Cancel yourself. Settings → Billing, no phone call. You keep Pro until the time you paid for runs out.
For the technically minded
- Plaid access tokens: AES-256-GCM with a fresh IV per token and an enforced 16-byte authentication tag; the key lives in Google Secret Manager. Tokens sit in a collection with no client access at all.
- Plaid webhooks are verified before they are acted on: ES256 signature, a SHA-256 hash binding the signature to the body, and a five-minute freshness limit.
- Firestore and Cloud Storage security rules scope budgets, transactions and files to their owner and household; household access exists only through a server-side invite. Staff tools can read the account record itself, never the budget, transactions or files under it.
- Authenticator-app (TOTP) two-step verification through Google Identity Platform, required before a bank can be linked.
- Content Security Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy headers on every page.
- Static analysis (Semgrep) and a dependency vulnerability audit run on every change to the code and weekly; a finding fails the check.
Found a problem?
If something looks wrong — a charge you do not recognise in the app, a bug, or a security issue — email pathforward.financial.2026@gmail.com. Security reports are read first. If you are testing, please use your own account and never anyone else's.
Related: our Privacy Policy covers what we collect and why, and Plaid's End User Privacy Policy covers Plaid.