← Back to prebalance.app

What we can see — and what we can't

We don't know who you are, and we can't read what you saved.

PreBalance is built so that a database breach, a stolen backup, or even one of our own engineers looking at the server has nothing to read but ciphertext — encrypted data that is unreadable without your key — and a short list of counts. This page lists, exhaustively, the small amount our server can see, and everything it can't.

What we can see

What we can't see

Everything else: account names, institutions, balances, transaction amounts, dates, descriptions, notes — all of it is encrypted on your device before it ever leaves, with a key we never have a copy of. We store only the encrypted version. That's it.

How

Your data is protected by a random encryption key generated on your own device the first time you use PreBalance. That key is locked behind your password using standard, publicly-documented cryptography built into every modern browser — nothing custom, nothing homegrown. We never see your password; we see only a scrambled version of it that can't be turned back into your password or used to unlock your data. Recovery codes, shown once at signup, are a second way to unlock the same key if you ever forget your password — they're yours to keep safe, and we don't have a copy of them either.

If you lose your password and every recovery code and every device that's ever been signed in — that's the one case nobody, including us, can undo. It's the same tradeoff every zero-knowledge system makes, and it's why we ask you to save your recovery codes somewhere safe when you get them.

Honest limits

Export, any time, every tier

You can download a full copy of your data — every account, transaction, statement, and recurring bill — at any time, free, on every tier, from the account menu. It's a plain file on your computer, readable by you, useful as a backup, and required by law for EU users under GDPR. Nothing about export is gated behind a subscription.