Keeping your account secure.
BudgetR keeps public security statements tied to controls that are already present in the product.
Authentication
Sign in with a passkey using your device screen lock or security key. Add and manage passkeys in Account security after verifying your email. Passwords remain available for initial account access and are stored as hashes; resetting a password does not remove registered passkeys. You can also review and revoke browser sessions. The account page reports when verification or recovery email delivery is unavailable.
Access control
The server checks current account access and permissions. Administrators have separate privileges and must confirm with a passkey before sensitive changes. Household access is limited to explicitly shared cash accounts and the joint plan; removing a member revokes that shared access.
Abuse protection
Login, registration, and demo endpoints are rate-limited per network address, and demo sessions are blocked from all write operations at the API layer.
External credentials
Plaid handles bank credential collection. BudgetR receives the tokens and account data needed to sync supported accounts.
Security contact
Use the verified contact details below when available. A dedicated security-reporting channel has not been published. Do not include passwords, recovery codes or customer financial records in a report.