Security overview
What this page is (and isn’t)
This is a plain language security overview for visitors evaluating SmartStack. It is not a compliance certificate, audit report, or SOC 2 / ISO badge page. We do not display certifications we have not earned.
For full legal detail, read the Privacy Policy, Terms of Service, and Financial Disclaimer.
Account locked cloud + row level security
Your budgets, transactions, goals, and related data live in a secure cloud database tied to your account so phone and desktop stay in sync.
Row level security is designed so other customers cannot read your rows. Multi device sync is intentional. This is not a single device file product that never reaches the cloud.
Bank passwords never go into SmartStack
We do not ask for your bank username or password inside SmartStack forms.
Optional bank linking on paid plans uses an industry link flow (Plaid). Free includes 0 bank connections. Starter 1, Plus 4, Power 8. Limits match product configuration.
What we do not do
- Sell your personal financial data for advertising
- Browse your household budget as a product feature for staff entertainment
- Require bank linking to use Free-tier budgeting
- Put bank access tokens in marketing analytics events
Export and leave
You can export data from Settings without bank tokens or secrets.
Deletion and retention follow the Privacy Policy. Ownership includes a real exit path.
Infrastructure honesty
Like most modern SaaS, SmartStack relies on reputable cloud infrastructure (hosting, auth, database). No system is 100% secure; we use encrypted transport and access controls appropriate to the product.
Analytics on public pages may use Plausible (cookieless) for aggregate traffic. Never amounts, payees, or emails in event props.
Related pages
Privacy Policy. Data collection, subprocessors, retention.
Disclaimer. Educational tool only; not financial, tax, investment, or legal advice.
Contact. Privacy requests and product questions.