How your financial data stays safe.
The short version
You connect banks, brokerages, and retirement accounts through Plaid. We never see your financial institution login, the connection can only read your data, and you can disconnect or delete your OpenBudget account whenever you want.
- We never store your financial institution login. Your username and password go to your institution through Plaid, never to us.
- Read-only access. Nothing here can move money or change anything at your bank, brokerage, or retirement plan provider.
- Encrypted and yours to control. Your data is encrypted in our database, and you can delete your OpenBudget account at any time, subject to required legal retention.
Your financial institution login never touches our servers
When you connect an account, you sign in to your financial institution inside Plaid's secure window, not on OpenBudget. Plaid returns a limited, revocable access token. Your institution username and password are never sent to, seen by, or stored on our servers.
Financial institution access is read-only
OpenBudget reads balances, transactions, liabilities, investment holdings, and investment activity. It cannot move money, make a payment, place a trade, transfer an asset, or change a record at your financial institution.
Investment accounts use the same protected connection
When you enable investments, Plaid supplies available account, holding, security, and activity data from supported brokerage and retirement accounts. OpenBudget stores that information so you can review positions, investment activity, allocation, and changes over time.
Powered by Plaid
Financial account connectivity is handled by Plaid, the connection network thousands of finance apps use to link to financial institutions, including banks, brokerages, and retirement plan providers. Plaid encrypts data in transit and uses each institution's supported connection method, including OAuth where available.
Encrypted connections
Every request to OpenBudget travels over TLS, the same HTTPS encryption financial institutions use on their own websites. Your connection to Plaid, and Plaid's connection to your institution, are encrypted in transit.
What we store, and what we don't
To make the app and your assistant useful, we store the financial data you connect: accounts, balances, transactions, liabilities, investment holdings and activity, security details, categories, and notes tied to your OpenBudget account. We also store assets and investment activity that you add through an authorized MCP connection. That data is encrypted at rest in our database. We do not store your financial institution login credentials; those stay with your institution and Plaid.
Your AI uses an authenticated connection
When you connect an AI assistant, it reaches OpenBudget through an authenticated MCP connection tied to your account. MCP tools can read financial data and, when you ask, change records stored in OpenBudget, such as categories, notes, rules, and manually tracked holdings or activity. They cannot move money, place trades, transfer assets, or modify records at a financial institution. You can disconnect the AI connection at any time.
We never sell your data
We do not sell, rent, or share your financial data with advertisers or data brokers. Your data is used to run OpenBudget and provide the features you request. The full detail is in our Privacy Policy.
You stay in control
You can disconnect any linked account at any time, which stops new data from syncing. You can also delete your account and the data we hold for you. If you ever want help with either, email support@openbudget.sh.