Trust Center

Security, privacy, and accessibility — in one place.

How Vision handles your data, how we protect it, and how we make sure everyone can use the product. The short version of each policy is below; the full legal text lives on the app at visionfinance.app.

·  ·  Pick a topic

Three policies, three clicks.

SECURITY How we protect your data +

Bank credentials never touch our servers

Account linking goes through Plaid — the same connection layer that powers Venmo, Robinhood, Wealthfront, and most major fintech apps. Your bank username and password are entered into Plaid's flow, not ours, and we never see them. Vision only ever holds the read-only access token Plaid hands back.

Encryption everywhere

  • In transit: every request is HTTPS / TLS 1.3. No plaintext anywhere.
  • At rest: Plaid access tokens are encrypted with AES-256-GCM before being stored in Upstash Redis. The encryption key lives in Vercel's secrets manager and is rotated quarterly.
  • Backups: automated daily backups are encrypted with the same key, retained for 30 days, and stored in a separate availability zone.

Auth

Sign in with Apple, Google, or email + password. Sessions use Firebase Authentication; tokens rotate hourly. We support biometric unlock (Face ID / Touch ID) on iOS.

We don't sell your data

No ads, no lead-gen, no data brokers. Vision is funded entirely by user subscriptions ($4.99/mo or $39.99/yr). The full vendor list and what each one sees is enumerated in the Privacy Policy (next section).

Vulnerability disclosure

If you find a security issue, please report it to security@visionfinance.app. We acknowledge every report within 24 hours and patch high-severity issues within 7 days.

PRIVACY POLICY What we collect and why +

Short version

  • We collect what we need to run the app: your name, email, the accounts you connect, and the transactions inside them.
  • We do not sell, rent, share, or trade any of it. Period.
  • We use Plaid for bank linking, Stripe for billing, RevenueCat for iOS billing, Firebase for auth, PostHog for product analytics (opt-in), Sentry for crash reports (opt-in), and Cloudflare + Vercel for hosting.
  • You can export your data as CSV from Settings → Your Data at any time.
  • You can delete your account and everything associated with it from Settings → Delete Account.
  • Cookie + analytics consent is honored on first launch and can be changed any time from Settings → Cookie settings.

The full Privacy Policy — including every vendor, every data class, every legal basis, and your rights under CCPA, GDPR, and similar laws — lives on the app.

Read the full Privacy Policy →

ACCESSIBILITY STATEMENT How we make sure everyone can use Vision +

Short version

  • Vision targets WCAG 2.1 Level AA. Self-attested partial conformance — most of the app is verified clean, with documented gaps.
  • Every interactive element is keyboard-reachable. Screen-reader labels on every form input. Color contrast meets 4.5:1 (body) and 3:1 (large text + graphics).
  • Color is never the only indicator: gains and losses use a +/- sign in addition to color. Status badges include text, not just dots.
  • Tested against VoiceOver (macOS & iOS), TalkBack (Android), NVDA, and JAWS.
  • No accessibility-overlay widgets. We fix the source, not the symptom.

If you can't use something, please tell us: accessibility@visionfinance.app. We acknowledge every report within 5 business days.

Read the full Accessibility Statement →