Security
Last updated 18 August 2026
Xfin handles bank data, so this page states what we actually do rather than reassurances. If something here stops being true, it gets corrected.
The architecture is the main control
Xfin runs from a database on your phone, and the most sensitive feed of all never touches us: transactions fetched from your bank through Plaid are passed straight back to your device and are never stored on our server. A server that never holds them cannot leak them.
Cloud backup is the exception, and it is on by default. With it on, a copy of what you create in Xfin, meaning your accounts and balances, the transactions you enter or import, your categories, goals and rules, is stored on our server so a reinstall or a new phone does not lose it. It is encrypted in transit and at rest and scoped to your account by row-level security. It is not encrypted with a key only you hold, so we are technically capable of reading it. We would rather say that than let "encrypted backup" imply something stronger. You can turn it off in Settings, under Cloud backup and sync.
Alongside it, our server holds your profile, your notification settings and messages, your bank access token, your subscription status, and rate-limit and audit records. The privacy policy lists all of it.
Four companies are involved in running that, and it is worth naming them: Supabase hosts the database and authentication, Plaid connects your bank, Anthropic generates Fin's replies, and Sentry receives crash reports. Apple handles Sign in with Apple, push delivery and billing. Nobody else receives anything, and there are no advertising or analytics vendors in the app today.
Bank credentials
We never see them. You enter them into Plaid's own interface. Xfin receives an access token, never a username or password, and that token is kept server-side and never sent to your device.
In transit and at rest
- All network traffic uses TLS. There is no unencrypted endpoint.
- Server data sits behind row-level security, so one account cannot read another's rows even if application code is wrong.
- Secrets and tokens are held in the iOS Keychain on device, not in plain preferences.
- Cloud backup is encrypted in transit and encrypted at rest on the server. It is not end-to-end encrypted, and we do not claim it is.
- Every request to our server is authenticated, rate limited per user, and written to an audit log kept for 90 days.
Getting into your account
- Sign in with Apple, which means no password for us to hold at all.
- Or email and a password, which our authentication provider stores as a salted hash. We never see the password itself.
- Optional Face ID or Touch ID lock, which re-locks when you leave the app.
- Rate limiting and audit logging on the account system to catch abuse.
The assistant
Questions to Fin are sent with a redacted summary rather than your raw history. Account nicknames and goal names are replaced with generic labels, balances are rounded off, your notes are not sent, and text that looks like an ID number, an email address, a phone number or a card number is replaced before the request leaves your device. What does go, including the bank a card belongs to and your last ten merchants with rounded amounts, is listed in full in the privacy policy.
Your financial data is not used to train any model, and we grant no permission for it to be. Chat history is stored on your phone only, is in no backup, and a conversation with no activity for 14 days is deleted automatically unless you star it. Fin cannot move money: it has no payment capability of any kind, and every change it proposes waits for you to confirm.
Xfin does not move money
This matters for more than reassurance, so it is worth being exact. Xfin never originates an ACH entry or any other payment. It has no payment capability at all, and no feature that could acquire one by accident.
We request read access only. We do not use Plaid Auth or Plaid Transfer, which means we never receive your account or routing numbers. Xfin reads a copy of transactions your bank has already posted.
Because we originate nothing, Xfin is not an ODFI, an Originator, a Third-Party Sender or a Third-Party Service Provider under the Nacha Operating Rules, and the 2026 ACH fraud-monitoring requirements do not apply to it. If that ever changes, this page changes first.
What we do not claim
We are a small team. We hold no SOC 2 report and no ISO 27001 certificate, and we would rather say so than imply otherwise. What we can say is that the app is built so that the most sensitive data never reaches us in the first place.
Reporting a vulnerability
Email security@getxfin.com with enough detail to reproduce it. We will acknowledge within three business days and keep you updated. Please give us a reasonable window to fix it before going public, and please do not access anyone else's data while testing.
We do not currently run a paid bounty, but we will credit you if you would like.