Security

Keeping your data safe

Your transactions tell us how to optimize your wallet. Nothing else gets done with that data — not sold, not advertised against, not shared with card issuers. Here's exactly how we protect it.

Read-only Plaid

We connect to your banks through Plaid — the same regulated provider used by Venmo, Robinhood, Coinbase, and 12,000+ apps. Your login credentials go directly to Plaid; we never see them. Our access is read-only by construction. We can see transactions, never move money.

AES-256 at rest, TLS in transit

All connection tokens, points balances, and personal data are encrypted at rest using AES-256 — the standard banks use. Every byte between your browser and our servers travels over TLS. Nothing is stored or transmitted in plain text.

Multi-factor authentication

Sign-in requires SMS verification by default. We use the same one-time-code flow your bank does. Sessions auto-refresh every 60 minutes; idle sessions expire. If you lose access, password reset goes through your verified phone.

One account, no fragmentation

All your data lives in a single SavvX account. We don't sync to ad networks, push profiles to data brokers, or fragment your data across products you didn't ask for. Your spending pattern stays inside SavvX.

Fraud monitoring

Our Sentinel service monitors prod 24/7 for anomalous activity, suspicious sign-ins, and rate change events. We alert you on unrecognized devices and notify you of any data-impacting incident within 72 hours of detection.

Responsible disclosure

Security researchers: please send findings to security@savvx.com. We respond within 48 hours and don't pursue legal action against good-faith research that follows responsible disclosure norms (no destructive testing, no PII exfiltration, no public disclosure before fix).

The thing that's actually different

Most credit card optimization sites monetize your data — affiliate commissions when you sign up for a card they recommend, cross-sells to insurance/loan products, ad targeting against your spending patterns.

SavvX makes money from your subscription. That's the whole business model. No affiliate links. No card-issuer partnerships. No ads. No data sales. Ever.

What we store, what we don't

We store

  • • Email + phone number (login + alerts)
  • • Password as a one-way hash (we can't read it)
  • • Encrypted Plaid connection tokens
  • • Transaction history: merchant, amount, date, category
  • • Account names + types + last 4 digits
  • • Card balances + points balances
  • • Your SavvX preferences (mode, wallet size, etc.)

We never store

  • • Your bank login credentials (Plaid handles auth)
  • • Full account numbers
  • • Social Security number
  • • Government-issued ID
  • • Your full credit card numbers (only last 4)
  • • CVV codes (we don't process payments — Stripe does)
  • • Income tax info (separate from financial planning)

Your rights, your controls

You can manage everything from Account → Manage Your Data:

  • Download a JSON export of all your data, anytime
  • Delete your account and expunge all personal data — immediate and irreversible
  • Update marketing preferences — choose which categories of email/SMS we send
  • Review sign-in history — last 10 logins by device, time, and location
  • Disconnect a bank — revoke Plaid tokens for any account at any time

Read further

Questions about security or data handling? Email support@savvx.com. Security researchers: use security@savvx.com for responsible disclosure.