Encrypted transport
API traffic uses TLS. Plaid Link and Plaid API communication also occur over HTTPS/TLS.
Last reviewed July 19, 2026
A plain-English summary of current controls, provider roles, limitations, and the choices available to you.
These controls are specific to the current implementation. They do not cover every field, ingestion path, or operational risk.
API traffic uses TLS. Plaid Link and Plaid API communication also occur over HTTPS/TLS.
New password hashes use Argon2id. Legacy bcrypt hashes are accepted during migration and marked for rehashing.
Application-layer encryption covers selected sensitive fields, with AWS KMS used to protect user master keys.
Clients do not access the application database directly. Storage access uses private buckets and signed URLs through backend-mediated flows.
The privacy policy provides routes to export data, correct records, and request account deletion.
The privacy policy states that personal or financial data is not sold to advertisers or used for targeted advertising.
These providers support specific tasks. Expense Atlas remains responsible for how their outputs are used inside the product.
Bank credentials are entered through Plaid Link, not Expense Atlas. Plaid Link handles institution sign-in.
Expense Atlas receives connection tokens, selected account details, transactions, and provider metadata needed to maintain and sync the connection.
Institution coverage, history, refresh timing, and data quality depend on Plaid and the financial institution. Imported activity still requires review.
Structured budget-analysis context does not add your login email or password. This is not a universal redaction layer, and it does not mean every personal or financial detail is hidden from AI processing.
Depending on the feature, AI or OCR services can process the financial details, vendor names, goals, receipt images, or statement text needed for that task.
Expense Atlas does not use personal data to train its own AI models. Provider processing is still subject to provider service terms and availability.
AI output can be incomplete or wrong. Review extracted data, categories, and budget assumptions before relying on them. AI output is not professional advice.
Review and change supported transactions, categories, and budget assumptions.
Use the available export tools to take a copy of supported account data and records.
Use in-app controls or the hosted privacy request form to request account deletion.
The Privacy Policy governs collected data, uses, providers, retention, and requests. The founder and support routes identify who is responsible and how to ask questions.