planwithzen is designed around a simple security principle: your financial information should remain protected and under your control. Information is stored on your device and securely synchronized with planwithzen’s hosted systems. Access requires an authenticated planwithzen account through supported planwithzen applications.
Protected storage and synchronization
Income, expenses, assets, debts, budgets, financial goals, and related account information may be stored in the app’s private storage and synchronized with planwithzen’s hosted systems. Synchronization allows you to access your information through supported mobile and web applications after signing in and completing any required verification.
Account access and verification
Access to planwithzen and synchronized information requires a planwithzen account. planwithzen collects your email address to create, authenticate, recover, and protect your account. Two-factor authentication is a feature of the planwithzen web application. If you enable it there, planwithzen also collects your U.S. mobile telephone number to provide it, and mobile-number authentication is currently available only for U.S. telephone numbers. The planwithzen iPhone app does not offer two-factor authentication and does not ask for a telephone number.
SMS verification
SMS verification applies to the planwithzen web application; the iPhone app sends no SMS messages. planwithzen uses Twilio Verify to deliver and validate time-limited, one-time security codes for account registration, login, account recovery, and multi-factor authentication. Verification attempts may be rate-limited and screened for suspected fraud. Never share a verification code. planwithzen employees will never ask you for one.
Your information is protected
Locally stored records are encrypted using AES-256-GCM with a device-bound key held in the iOS Keychain. Information transmitted between planwithzen applications and supporting services is protected using TLS 1.2 or higher. Synchronized information stored in planwithzen’s hosted environment is protected through encryption, authentication, database access controls, and restricted administrative access.
Connected accounts are optional and read-only
Momentum subscribers may connect eligible U.S. financial institutions through Plaid. planwithzen may retrieve account names and types, balances, the charges that look like they repeat, liability details, and limited account identifiers, such as the last four digits of an account number. It cannot transfer money, make payments, move funds, or place trades.
We do not receive bank credentials
Plaid or your financial institution handles authentication. planwithzen does not receive or store the username and password you use with your institution. Their screens may also ask for whatever your institution requires to authenticate you, which can include a telephone number and a one-time code sent to it. That exchange is between you, Plaid and your institution; planwithzen does not ask for a telephone number, does not receive one from Plaid, and does not store one.
We never see your card number
Apple processes subscription payments. RevenueCat records which plan is active, tied to your planwithzen account identifier. Neither service receives the financial records you enter in planwithzen.
Subscription and data access are separate
Apple may restore your Momentum subscription through your Apple ID. Access to synchronized financial information is provided separately through your planwithzen account. After signing in and completing any required verification, you may access synchronized information through supported mobile and web applications. A financial institution may require you to reconnect or reauthorize access for security or technical reasons.
Additional safeguards
Protected hosted storage
planwithzen uses Supabase to host information needed to operate accounts, synchronize financial information, and support connected financial institutions. This may include account identifiers, contact information, authentication status, SMS consent records from the web application, device-credential references, financial information entered by users, encrypted Plaid access tokens, and information received from connected financial institutions. Access is controlled through account authentication, database authorization rules, encryption, and restricted administrative permissions.
Restricted administrative access
Administrative access to production systems is limited to authorized personnel, uses named identities and multi-factor authentication, and is reviewed regularly. Administrative access is permitted only for legitimate operational, security, support, or legal purposes.
Disconnecting and deleting
You can disconnect a financial institution using the available planwithzen controls. planwithzen then instructs Plaid to revoke the connection and deletes the associated access token and connected-account information according to the Privacy Policy. You can delete your planwithzen account and synchronized information in the app, under Settings. Deleting runs straight away: it revokes any connected institutions at the institution as well as here, removes your records from the device and from planwithzen’s hosted systems, and removes the account itself. It cannot be undone. You may also contact hello@planwithzen.com.
Report a vulnerability
If you believe you have found a security vulnerability, email security@planwithzen.com. Please do not include financial account numbers, statements, passwords, or other institution credentials.
No application or transmission method can guarantee absolute security. For complete information about data handling, retention, and your choices, read the Privacy Policy.