← Back to prebalance.appWhat we can see — and what we can't
We don't know who you are, and we can't read what you saved.
PreBalance is built so that a database breach, a stolen backup, or even one of our own engineers looking at the server has nothing to read but ciphertext — encrypted data that is unreadable without your key — and a short list of counts. This page lists, exhaustively, the small amount our server can see, and everything it can't.
What we can see
- That you have accounts, transactions, statements, and recurring bills — and how many of each. We can count the items of each kind, but see nothing about what's in them.
- When things changed. Every item records when it was last changed, so your devices can stay in sync. We can see that you edited something at 9:14pm, never what.
- Account type and archived/paused status. We can tell an account is a deposit account or a credit card, and whether it's active or archived — that's how the free tier's account-count limit is enforced. We can't see the name, balance, or institution.
- Which of two duplicate credit-card statements you meant to keep, when the same statement gets entered from two devices — resolved by an anonymous cryptographic fingerprint, never the statement's actual date or balance.
- Answers to "keep me on the free tier or archive this?" prompts, when a downgrade puts you over a limit.
- Session metadata and IP addresses, the way any web service needs to for basic operation and abuse prevention.
- Your email, if you gave us one. On the free tier it's always optional — we only ask when it unlocks something for you (a password-reset path, for example), never by default. Paid plans do need one, for billing.
- Billing details, if you subscribe. Paddle is our merchant of record and handles payment — we don't store card numbers.
- Institution names you look up while using the bank-logo autocomplete — inherent to that feature working at all (it's a request to our server). The name you typed isn't stored. What we keep is a tally against the institution, not against you: how many times each bank was looked up in a given month, so we know whose logo to go find next. If a lookup finds nothing, we record only what kind of miss it was — a near-match to a bank we already have, a name several banks share, or simply "none of the above" — never the text you entered.
- When a reminder is scheduled to fire — the timing of your bills clustering, never their content. If you turn on rich reminder text (an explicit, off-by-default toggle), the text you chose to upload is visible to us for exactly that purpose.
- Anything you send us on purpose. In-app feedback, and the optional "tell us about your bank" form (how your bank orders transactions, fee-waiver conditions, autopay timing) are readable by us by design — you're telling us something, not storing your finances, so there's nothing to encrypt.
What we can't see
Everything else: account names, institutions, balances, transaction amounts, dates, descriptions, notes — all of it is encrypted on your device before it ever leaves, with a key we never have a copy of. We store only the encrypted version. That's it.
How
Your data is protected by a random encryption key generated on your own device the first time you use PreBalance. That key is locked behind your password using standard, publicly-documented cryptography built into every modern browser — nothing custom, nothing homegrown. We never see your password; we see only a scrambled version of it that can't be turned back into your password or used to unlock your data. Recovery codes, shown once at signup, are a second way to unlock the same key if you ever forget your password — they're yours to keep safe, and we don't have a copy of them either.
If you lose your password and every recovery code and every device that's ever been signed in — that's the one case nobody, including us, can undo. It's the same tradeoff every zero-knowledge system makes, and it's why we ask you to save your recovery codes somewhere safe when you get them.
Honest limits
- We ship the app you're using. Because PreBalance runs in your browser, a compromised build of our own software could in theory misbehave. The defense here isn't a technical guarantee — it's that our protocol is documented (this page is part of that) and there's nothing to gain by cheating: we don't want your data, and encrypting it protects us from the liability of holding it as much as it protects you.
- We don't hide metadata. The list above — how many items you have, when they changed, account types — is visible by design, not an oversight. Hiding it entirely (disguising how much data you have and when you use the app) is a research-grade problem we're not attempting to solve.
- A weak password is still a weak password. Strong cryptography around a guessable password doesn't help much. Choose a real one.
Export, any time, every tier
You can download a full copy of your data — every account, transaction, statement, and recurring bill — at any time, free, on every tier, from the account menu. It's a plain file on your computer, readable by you, useful as a backup, and required by law for EU users under GDPR. Nothing about export is gated behind a subscription.