Your Security is Our Priority

We use bank-level security to protect your financial data. Here's how we keep your information safe.

Encryption

All data is encrypted using industry-standard encryption at rest and TLS in transit.

Secure Infrastructure

Hosted on Google Cloud Platform (Firebase) with built-in security and monitoring.

Privacy by Design

We collect only what we need, never sell your data, and never use it for AI training.

Authentication

Support for biometric login and secure password policies.

Data Protection

Encryption Standards

  • At Rest: Industry-standard encryption for all stored data
  • In Transit: TLS encryption for all data transmission
  • Passwords: Secure hashing (Firebase Authentication)
  • Backups: Automatic encrypted backups via Firebase

Infrastructure Security

  • Hosted on Google Cloud Platform (Firebase)
  • Built-in DDoS protection via Google Cloud
  • Firebase Security Rules for data access control

Authentication & Access

User Authentication

  • Secure password requirements (minimum 8 characters, complexity rules)
  • Biometric authentication (Face ID, Touch ID, fingerprint)
  • Optional PIN code for additional security
  • Session management with automatic timeouts
  • Login attempt monitoring and lockout protection

Third-Party Access

  • OAuth 2.0 for social login (Google, Apple)
  • Polar.sh for payment processing (Merchant of Record)

Privacy Practices

  • We never sell your personal data
  • We never share your data with third parties for marketing
  • We never use your data for AI training
  • Voice recordings are processed and immediately deleted
  • Minimal data collection - only what's needed for the service
  • Full data export and deletion available on request
  • GDPR and CCPA compliant

Incident Response

  • Security monitoring via Firebase and Google Cloud
  • User notification of any data breaches as required by law

Compliance

  • GDPR (General Data Protection Regulation) - we respect EU user rights
  • CCPA (California Consumer Privacy Act) - we respect California user rights
  • PCI DSS compliance via Polar.sh (Merchant of Record) for payment processing

Found a Security Issue?

We appreciate responsible disclosure. If you've found a security vulnerability, please report it to us privately.

Email: support@slashcommit.com

Your Data is Safe With Us

Start tracking your expenses with confidence.