
Loading...
You have probably read a breach-notification letter before. So has the person who built PiggySize. So this page does not say “bank-level security” and hope you nod along. It tells you exactly what happens to your data, names every company that touches it, and points you at the response headers and settings you can check yourself. If a claim here cannot survive you actually looking, it does not belong on the page.
PiggySize never asks for your bank username or password, because there is no code in the product that could use them.
There is no account-aggregation layer here — no Plaid, MX, Finicity, Teller, or Yodlee, in the app or in its dependencies. Nothing connects to a bank, imports transactions, or stores a login to one. You type in the numbers you want to plan around, and that is all we hold.
A credential we never collect is a credential that cannot leak, cannot be phished, and cannot be sold. There is simply nothing there to steal.
Three groups can see your data, and no one else.
We never sell data — to anyone.
Every table in our database is covered by row-level security — the database itself enforces that a family can only read its own rows, even if application code has a bug.
Row-level security means the isolation rule lives inside the database, one layer below the application. So even if a bug in our code ever asked for the wrong family’s data, the database would refuse to hand it over. It is a backstop, not a slogan — the same backstop the self-serve export runs through.
59 tables, 158 policies as of July 2026.
We use the encryption you would expect, and we will not pretend it is more than it is.
Encrypted in transit: TLS everywhere, HSTS enforced. Encrypted at rest: by our infrastructure providers (Supabase-managed Postgres, Vercel). That is the industry baseline — we won’t dress it up as bank-level encryption, and you should be suspicious of anyone who does.
What we add on top is structural: your bank credentials are never asked for, so they can’t be lost.
The browser itself is told to deny this site your camera, microphone, and location — you don't have to take our word for it.
A Permissions-Policy response header sets camera=(), microphone=(), geolocation=() — an empty allow-list, which means “no one, not even us.” You can read it in your browser’s developer tools under the Network tab.
There are no push notifications — we’ll never ping you — and no advertising SDKs anywhere on the site.
Eight service providers help run PiggySize. Here is each one and exactly what it does.
Nobody else — and we don’t sell your data to any of them, or to anyone.
If you use Piggy, the Pro AI assistant, your question and the numbers behind it are sent to Anthropic's Claude to write the answer — and nowhere else.
Piggy runs on Anthropic’s Claude. When you ask a question, the relevant figures from your account — or, if you scan a paystub (available on every plan), that image, which is read once and never stored — are sent to Anthropic’s API to generate the reply. Anthropic’s commercial API terms prohibit training their models on this data.
You can turn the AI assistant off entirely in Settings. Your chats are stored with your account and are reviewable by our team so we can keep Piggy accurate. Piggy can answer questions and file a support ticket for you, but it can’t change your financial data.
The account owner can wipe the whole account for good, and any owner or spouse can download a full copy — no support ticket either way.
The account owner can permanently delete the entire account — every financial record, every member login — from Settings with a typed confirmation. No support ticket, no exit interview. Two honest footnotes: only the owner can do this (spouses and children can’t nuke the household), and billing identifiers are retained about 7 years because tax law requires it.
You can also take your data with you. Settings → Your Data has a self-serve export that downloads everything your family has entered as a .zip — a full JSON copy plus a CSV for each type of data, including a profit-and-loss sheet for each business. It’s available on the Free plan, for the owner or spouse; child accounts are blocked.
Tell us. There is a standard machine-readable policy file, and a simple way to reach a human.
We publish a /.well-known/security.txt with our disclosure contact. Found a security issue? Tell us through our contact form — start the subject with “Security.” We don’t run a security@ mailbox yet, so the contact form is the fastest path to the right person.
Here's exactly where sign-in security stands.
Two-factor authentication: available now in Settings → Security, free on every plan. It’s authenticator-app codes (TOTP) with one-time backup codes, not text-message codes, because SIM-swap attacks make SMS weak. You can also review your recent sign-in activity — when, roughly where, and how each sign-in happened. And if you sign in with Google or Apple, your sign-in also inherits that provider’s two-factor protection.
Passkeys: you can also sign in without a password at all. Add one from Settings → Security, then sign in with Touch ID, Windows Hello, or a security key — no password typed, no code to enter. A passkey works side by side with your password, so adding one doesn’t take the password option away. And because a passkey already proves who you are and that you hold the device, signing in with one skips the two-factor code step.
We also email you when something security-sensitive changes on your account — a sign-in from an unfamiliar device or location, a password change, or a change to your two-factor setup. And changing your password automatically signs out every other session, so a stolen session can’t outlive the password it stole.
Whichever way you sign in, password sign-up is rate-limited — five tries per fifteen minutes, per IP address — and disposable-email domains are blocked.
One more honest note: we don’t wave around a SOC 2 or ISO badge. We’re a small US team, and instead of a logo this page shows you the actual mechanisms and the settings you can check.
Every important claim on this page is something you can confirm in a few minutes.
Strict-Transport-Security (HSTS) and Permissions-Policy: camera=(), microphone=(), geolocation=().Last reviewed: July 2026
Plan your whole financial picture — income, bills, net worth, retirement — without connecting a single account.
Every account starts with 30 days of Pro free — no credit card.