Security

What you earn, spend, and give is between you and God. We are only holding the ledger.

That ledger holds your balances, your transactions, and your giving history. Everything below is how we keep it yours.

Data Protection

AES-256 encryption at rest
Supabase hosts our database and encrypts the underlying disks with AES-256, the same standard banks use. That protects the storage itself, and the row-level rules below are what keep your records separate from everyone else’s.
TLS 1.3 in transit
Connections between your device and our servers are encrypted. Modern browsers negotiate TLS 1.3, and we accept nothing below TLS 1.2. Nothing is ever served over plain HTTP.
Your bank login never reaches us
You sign in to your bank through Stripe, and Stripe keeps that connection. What reaches us is the account name, the last four digits, and the balances. The access is read-only, so it cannot be used to move money.
Row-level security
The database checks who is asking before it returns a single row, so your transactions, goals, and giving history come back only for you. That check lives in the database rather than in our app code, so a bug on our side does not open your records to someone else.

Account Protection

A security code on every new device (default)
Sign in from a browser we have not seen and we email you a six-digit code. A stolen password on its own does not get in. Every account, no setting to turn it off.
Or a PIN, if you would rather not wait for email
Set a six-digit PIN in Settings, under Private PIN, and we ask for that instead of emailing you. Changing or removing it needs the current one, so nobody at your open laptop can take the lock off.
Sign out everywhere
One button in Settings ends every session and revokes remembered devices. A page open elsewhere keeps working until its token expires.
Your own security log
Settings shows your sign-ins, failed attempts, password changes, bank connections, and exports, with timestamps. You never have to ask us what happened.

Bank Connections via Stripe

Read-only access
Your bank connection runs through Stripe Financial Connections. The only permission we ask for is reading transactions and balances. We never request the ability to write, so nothing here can move, transfer, or alter your money. Stripe is a PCI DSS Level 1 service provider, which means an independent auditor reviews its security every year. Stripe does not sell personal data, and says bank data collected through Financial Connections is never shared with outside companies for marketing. Their terms are at stripe.com/privacy.
We never see your password
Stripe handles the authentication directly with your bank. Your banking credentials are never transmitted to or stored by Kingdom Cents.
You can disconnect anytime
Go to Banks in your dashboard sidebar and remove any connected institution instantly. Disconnecting unlinks the account immediately. No waiting period.

What We Will Never Do

Never sell your data
Your financial data, giving history, and prayer requests are never sold to third parties, data brokers, or advertisers. Ever.
Never run ads
Kingdom Cents does not serve ads and never will. There is no ad network, no tracking pixel, no behavioral targeting.
Never use your data to train AI
Your transactions, giving, and prayer requests are never used to train AI, and our AI provider is contractually barred from training on them. We do use AI in the moment to screen public posts for safety and suggest transaction categories, but that is a one-time check, never training. If that ever changes, we drop AI screening and rely on our human moderation queue.
Never share with insurers or lenders
Your financial information is never shared with insurance companies, credit bureaus, or lenders.

Your Data, Your Rights

Export everything
Download all your transactions, goals, and giving history anytime. Settings > Your Data. CSV and full JSON package, no friction.
Delete your account
One click in Settings > Danger Zone, and we confirm by email. Your live data is deleted within 30 days. Encrypted backups roll off within 90, the same window our Privacy Policy states, and nothing in a backup is readable by us in the ordinary course.
If we ever shut down
If we choose to close, you get 90 days notice and a full data export before anything stops working. If we are ever forced to close on someone else’s schedule, you get every day of notice we actually have, and the export is the last thing we switch off. Take one monthly anyway. That is the version of this promise that does not depend on us.

Your Money And Your Prayers Stay Apart

Giving is meant to be quiet
Scripture puts giving in secret rather than on display. Software can undo that without meaning to, by making generosity visible or comparable, so we designed it out rather than trusting ourselves to resist adding it later.
Nothing financial is ever attached to a post
Prayer requests and testimonies carry only what you typed. Your balances, transactions, giving history, and goals are never joined to anything you share, not in the post, not behind it, not in a feed ranking.
You choose the audience every time
A prayer can go to the public wall or only to a circle you belong to. There is no default that quietly makes something public.
A person reads every public post before it appears
The AI filter can remove abuse but it cannot publish. Every public prayer and testimony waits for human review first. The full pipeline, the reporting flow, and what we still lack are written out on Community Standards.

What We Have Not Done Yet

No independent security audit
Kingdom Cents has not been through a third-party penetration test. When one happens, the scope, the date, the findings, and the fixes get published on this page, including the parts that are unflattering.
No passkeys or authenticator apps
The second step today is an emailed code, or a PIN if you set one. Both are things you know or receive, not a hardware key. Passkeys are planned, with no date attached.
No outside appeal
If we take down something you posted, the appeal goes back to our own moderation team. We are both the referee and the party you are appealing against, so weigh our answer accordingly.

Legal Entity

Kingdom Cents is operated from California. See our Terms of Service for the operating entity.

Kingdom Cents is a personal finance tracking tool. It is not a registered investment advisor and does not provide investment advice. Financial projections are illustrative only.

Privacy PolicyTerms of Servicesupport@kingdomcents.com

Reporting A Vulnerability

Email support@kingdomcents.com with what you found and how to reproduce it. You will get a human reply within 2 business days, an assessment within 7, and we will tell you when it is fixed.

Research in good faith is welcome. If you stay within your own test account, avoid accessing or altering anyone else's data, do not degrade the service, and give us a reasonable window before going public, we will not pursue legal action against you and we will credit you if you want the credit. We do not run a paid bounty program yet.

Machine-readable contact details: /.well-known/security.txt

© 2026 Kingdom Cents · Home · Status