We earn this every day.
How Plumb keeps your data safe, what we promise about it, and how to verify those promises yourself.
Three commitments that don’t bend.
We don’t sell your data. Ever.
Not to brokers, not to advertisers, not to anyone, not for anything. The subscription is the business model, by design. If you ever read anything that contradicts this, it’s a mistake we owe you a correction on.
We collect the minimum.
If we don’t need it to give you a plan, we don’t ask for it. Every field in onboarding has a clear reason behind it. The Coach knows your finances; we don’t know your friends, your location history, or your political views.
Your data is yours.
Export everything in standard formats anytime. Delete your account in one tap; your data is gone within 30 days. No “are you sure” loops, no hidden retention. We’re stewarding it for the year — that’s all.
Bank-grade is the floor, not the ceiling.
Plumb takes security as seriously as a bank does — but we hold ourselves to higher standards because the stakes are personal, not just regulatory.
TLS 1.3 in transit. AES-256 at rest.
All data — banking, transactions, conversations — is encrypted at every layer. Database encryption keys rotate quarterly. Backup keys are stored in a separate KMS region.
Passwordless by design.
You sign in with a one-tap magic link sent to your email — no password to create, forget, or reuse, and nothing for phishing or credential-stuffing breaches to steal. On returning visits, your device biometric (Face ID, Touch ID, or the Android equivalent) keeps sign-in quick.
Two-person production access. Always logged.
Production database access requires approval from two engineers. Every read and write is logged to an immutable audit trail. We do not allow individual employees to read user data without an audit record.
AWS, US-only. No data crosses the border.
Hosted on AWS US-East and US-West with VPC isolation. No data is replicated outside US jurisdiction. Backups encrypted, 90-day retention, restore tested quarterly.
Certified, audited, and honest about what’s still in progress.
SOC 2 Type II
Underway with our audit firm. We’ll publish reports here on issuance.
PCI DSS
Compliant via Stripe. We never see card numbers — full stop. Stripe is PCI Level 1 certified, the highest tier.
GLBA
Gramm-Leach-Bliley Act. We treat consumer financial information as covered data and follow the Safeguards Rule.
CCPA / CPRA
California Consumer Privacy Act and Privacy Rights Act. Data subject requests handled within 45 days, no fee.
CFPB §1033
Aligned with the CFPB’s 2024 final rule on consumer data rights. Open banking is a regulated right; we treat it that way.
State privacy laws
CO, VA, CT, UT, TX, IA, and others as applicable. Where they conflict, we default to the strictest standard.
Every third party with access to your data, listed.
We can’t run Plumb without some help. Here’s exactly which companies process your data on our behalf, what they do, and what data they touch. They are all contractually bound to confidentiality and to use your data only for the purposes below.
| Provider | Purpose | Data scope | Location |
|---|---|---|---|
| Amazon Web Services | Hosting and infrastructure | All operational data | US-East, US-West |
| Array | Bank account linking | Banking transactions and balances (read-only) | US |
| Stripe | Payment processing | Card numbers (we never see them) and billing | US |
| Mailgun | Transactional and marketing email | Email address, message content | US |
| AWS End User Messaging | SMS notifications | Phone number, message text | US |
| Anthropic | AI Coach inference | Conversation context (de-identified where possible) | US |
| Sentry | Error monitoring | Aggregated app errors, no PII | US |
We notify users by email at least 30 days before adding or changing a subprocessor.
Security researchers welcome.
If you’ve found a security issue with Plumb, we want to hear about it. We will not pursue legal action against good-faith research conducted under our Safe Harbor terms. Reach us at security@plumbfinance.com.
In scope: plumbfinance.com, *.plumbfinance.com, the Plumb iOS and Android apps. Out: third-party services (Array, Stripe, etc.), social engineering, physical attacks, denial-of-service.
Anything we haven’t covered?
Email support@plumbfinance.com. We’ll reply in plain English, by a real person.
Get in touch →