Security
How your budget stays yours.
The promise on the front page is that your budget is yours and nobody can read it. This page says how that is true, in plain words. The full details live in the Privacy Policy.
Effective 08/25/2026 · Version 1.4 · Own What’s Left LLC
Encrypted before it leaves
If you never turn on sync, your budget never leaves your computer and we hold nothing. If you do turn it on, your budget is encrypted on your device with AES-256-GCM before it travels anywhere. It leaves your computer already unreadable.
A passphrase we never receive
The encryption key comes from a passphrase you choose, and the passphrase never travels to us. This has a hard consequence: if you forget it, nobody can recover the budget it protects, including us. That is deliberate. The printed Recovery Kit exists so you do not have to rely on memory.
What our servers hold
Ciphertext they cannot decrypt, a random household identifier, license records if you buy something, and any budget or device names you choose to set. If you name your budget or your devices, those names are stored in plain text so your account page can show them. Choose names accordingly. No plaintext budgets, no names, no account numbers.
Our servers also keep a request log, which is how an attack gets noticed and traced: the address a request came from, the time, what was asked for and the result. The one-time codes in the links we email you are removed before a line is written, and passwords, sign-in cookies and the keys your devices use to authenticate are never recorded. Only the server account that writes the log can read it, and records are deleted after ninety days.
Your bank password never touches us
If you connect a bank, you sign in at your bank’s own site through a regulated aggregator. We never see, receive or store a banking password, and the access is read-only. OWL cannot move money, and never will.
What the software sends us
No analytics, no tracking, no advertising identifiers. During the beta the application sends crash reports: the error, a stack trace and the version. Never budget content, never account details, never transactions.
Found a hole? Tell us.
Good-faith security research is welcome here. If you find a vulnerability, write to the address below with what you found and how to reproduce it. We aim to acknowledge reports within 3 business days, and we do not answer good-faith research with legal threats.