Last reviewed July 19, 2026

How Expense Atlas handles your financial data

A plain-English summary of current controls, provider roles, limitations, and the choices available to you.

Controls in place today

These controls are specific to the current implementation. They do not cover every field, ingestion path, or operational risk.

Encrypted transport

API traffic uses TLS. Plaid Link and Plaid API communication also occur over HTTPS/TLS.

Password hashing

New password hashes use Argon2id. Legacy bcrypt hashes are accepted during migration and marked for rehashing.

Selected field encryption

Application-layer encryption covers selected sensitive fields, with AWS KMS used to protect user master keys.

Backend-mediated access

Clients do not access the application database directly. Storage access uses private buckets and signed URLs through backend-mediated flows.

Data choices

The privacy policy provides routes to export data, correct records, and request account deletion.

No sale for advertising

The privacy policy states that personal or financial data is not sold to advertisers or used for targeted advertising.

What Plaid and AI providers do

These providers support specific tasks. Expense Atlas remains responsible for how their outputs are used inside the product.

Plaid connects supported accounts

Bank credentials are entered through Plaid Link, not Expense Atlas. Plaid Link handles institution sign-in.

Expense Atlas receives connection tokens, selected account details, transactions, and provider metadata needed to maintain and sync the connection.

Institution coverage, history, refresh timing, and data quality depend on Plaid and the financial institution. Imported activity still requires review.

AI assists specific tasks

Structured budget-analysis context does not add your login email or password. This is not a universal redaction layer, and it does not mean every personal or financial detail is hidden from AI processing.

Depending on the feature, AI or OCR services can process the financial details, vendor names, goals, receipt images, or statement text needed for that task.

Expense Atlas does not use personal data to train its own AI models. Provider processing is still subject to provider service terms and availability.

AI output can be incomplete or wrong. Review extracted data, categories, and budget assumptions before relying on them. AI output is not professional advice.

Your data choices

Review and correct

Review and change supported transactions, categories, and budget assumptions.

Export

Use the available export tools to take a copy of supported account data and records.

Delete

Use in-app controls or the hosted privacy request form to request account deletion.

Policies and accountability

The Privacy Policy governs collected data, uses, providers, retention, and requests. The founder and support routes identify who is responsible and how to ask questions.