Trust · Your data, in safe hands

We earn this every day.

How Plumb keeps your data safe, what we promise about it, and how to verify those promises yourself.

All systems operational.99.99% uptime · last 90 days
Our principles

Three commitments that don’t bend.

01

We don’t sell your data. Ever.

Not to brokers, not to advertisers, not to anyone, not for anything. The subscription is the business model, by design. If you ever read anything that contradicts this, it’s a mistake we owe you a correction on.

02

We collect the minimum.

If we don’t need it to give you a plan, we don’t ask for it. Every field in onboarding has a clear reason behind it. The Coach knows your finances; we don’t know your friends, your location history, or your political views.

03

Your data is yours.

Export everything in standard formats anytime. Delete your account in one tap; your data is gone within 30 days. No “are you sure” loops, no hidden retention. We’re stewarding it for the year — that’s all.

Security

Bank-grade is the floor, not the ceiling.

Plumb takes security as seriously as a bank does — but we hold ourselves to higher standards because the stakes are personal, not just regulatory.

Encryption

TLS 1.3 in transit. AES-256 at rest.

All data — banking, transactions, conversations — is encrypted at every layer. Database encryption keys rotate quarterly. Backup keys are stored in a separate KMS region.

Authentication

Passwordless by design.

You sign in with a one-tap magic link sent to your email — no password to create, forget, or reuse, and nothing for phishing or credential-stuffing breaches to steal. On returning visits, your device biometric (Face ID, Touch ID, or the Android equivalent) keeps sign-in quick.

Access

Two-person production access. Always logged.

Production database access requires approval from two engineers. Every read and write is logged to an immutable audit trail. We do not allow individual employees to read user data without an audit record.

Infrastructure

AWS, US-only. No data crosses the border.

Hosted on AWS US-East and US-West with VPC isolation. No data is replicated outside US jurisdiction. Backups encrypted, 90-day retention, restore tested quarterly.

Compliance

Certified, audited, and honest about what’s still in progress.

In progress

SOC 2 Type II

Underway with our audit firm. We’ll publish reports here on issuance.

Compliant

PCI DSS

Compliant via Stripe. We never see card numbers — full stop. Stripe is PCI Level 1 certified, the highest tier.

Compliant

GLBA

Gramm-Leach-Bliley Act. We treat consumer financial information as covered data and follow the Safeguards Rule.

Compliant

CCPA / CPRA

California Consumer Privacy Act and Privacy Rights Act. Data subject requests handled within 45 days, no fee.

Compliant

CFPB §1033

Aligned with the CFPB’s 2024 final rule on consumer data rights. Open banking is a regulated right; we treat it that way.

Compliant

State privacy laws

CO, VA, CT, UT, TX, IA, and others as applicable. Where they conflict, we default to the strictest standard.

Subprocessors

Every third party with access to your data, listed.

We can’t run Plumb without some help. Here’s exactly which companies process your data on our behalf, what they do, and what data they touch. They are all contractually bound to confidentiality and to use your data only for the purposes below.

ProviderPurposeData scopeLocation
Amazon Web ServicesHosting and infrastructureAll operational dataUS-East, US-West
ArrayBank account linkingBanking transactions and balances (read-only)US
StripePayment processingCard numbers (we never see them) and billingUS
MailgunTransactional and marketing emailEmail address, message contentUS
AWS End User MessagingSMS notificationsPhone number, message textUS
AnthropicAI Coach inferenceConversation context (de-identified where possible)US
SentryError monitoringAggregated app errors, no PIIUS

We notify users by email at least 30 days before adding or changing a subprocessor.

Vulnerability disclosure

Security researchers welcome.

If you’ve found a security issue with Plumb, we want to hear about it. We will not pursue legal action against good-faith research conducted under our Safe Harbor terms. Reach us at security@plumbfinance.com.

In scope: plumbfinance.com, *.plumbfinance.com, the Plumb iOS and Android apps. Out: third-party services (Array, Stripe, etc.), social engineering, physical attacks, denial-of-service.

More questions?

Anything we haven’t covered?

Email support@plumbfinance.com. We’ll reply in plain English, by a real person.

Get in touch →