Security

How we protect your data

Your financial data is the most sensitive thing you can hand a tool. This page explains where Walletguide runs and how we keep your data safe.

Hosted in Frankfurt

Walletguide runs on Google Cloud in Frankfurt, Germany (region europe-west3): the app, the background jobs and the PostgreSQL database on Cloud SQL. Uploaded files are stored in Google Cloud's EU multi-region.

Every request reaches Walletguide through Google Cloud's global load balancer, with Google Cloud Armor in front of the application. The database is backed up automatically, with point-in-time recovery.

Encrypted in transit and at rest

Every connection to Walletguide uses HTTPS. Plain HTTP is redirected, and browsers are told to only ever connect over HTTPS (HSTS).

Inside Google Cloud, our services reach the database only through Google's Cloud SQL connector, over mutually authenticated TLS with short-lived certificates. The database accepts no direct connections. Google Cloud encrypts the database, its backups and uploaded files at rest.

Your bank login never reaches us

Connecting a bank account is optional. You can also add accounts manually and import transactions from CSV files.

If you connect one, you sign in to your bank in the window of a licensed provider: finAPI, licensed by the German Federal Financial Supervisory Authority (BaFin), for banks in Europe, and Plaid for banks in the United States and Canada. Your online banking credentials go to the provider, never to Walletguide. If you let the provider save them for automatic updates, they stay with the provider.

The access is read-only. Walletguide retrieves balances, transactions and holdings, and has no function that initiates payments or transfers.

Signing in

You sign in with a passkey, your Google account, or email and password. Passwords are stored only as salted hashes. As a second factor, you can turn on authenticator codes, with one-time backup codes for when your phone is not at hand.

Attempts to sign in, sign up or reset a password are rate-limited, and a new account has to confirm its email address before it can use Walletguide.

Who can access a wallet

Every request to a wallet is checked: only its members and the API keys issued for it get in. Deleting a wallet or changing who has access always takes a signed-in owner, never an API key.

API keys belong to a single wallet. You see a key once, when you create it; we store only a salted hash of it, show when it was last used, and you can revoke it at any time.

AI assistants connect to Walletguide's MCP server with OAuth. You approve the access on a Walletguide consent screen, write access is a separate choice, and the assistant never gets your password.

AI that stays in the EU

Walletguide's AI features categorize and explain transactions, write the performance summary, read the documents you upload and suggest categories for merchants. They use Google's Gemini models through Vertex AI, on Google Cloud's EU endpoints: the same provider that hosts Walletguide.

No trackers, no data for sale

Our website counts page views with our own, self-hosted analytics: no cookies, no cookie banner, nothing shared with third parties. Neither the website nor the app contains advertising pixels or third-party tracking scripts, and the app only sets the strictly necessary cookies that keep you signed in.

Walletguide is paid for by its subscriptions. We don't sell your data. Payments are handled by Stripe, so your card details go to Stripe, not to us. Emails are sent through Amazon SES in the AWS European Sovereign Cloud, in Germany.

Your data, your decision

You can export a wallet at any time, as JSON or as a set of CSV files.

You can delete your account in the settings. Once you confirm by email, your account and the wallets you own are deleted with all their data. Wallets other people shared with you stay with their owners.

How we run it

Each of our services runs under its own Google Cloud service account with only the permissions it needs, and the credentials for the services we connect to are kept in Google Secret Manager, not in our code.

Changes go through pull requests with automated type checks, linting and tests. Every release of the app checks that it serves its security headers, including its Content Security Policy.

GDPR, in writing

Walletguide is built and operated in Germany. The documents that govern how we handle your data are public:

Reporting a vulnerability

If you believe you have found a security issue in Walletguide, email support@walletguide.com. Your report goes straight to the engineering team.