Read-only, always.

Almanac needs to see what you spent. It never needs to move money, so it never asks for the ability to.

Your bankAggregatorAlmanacRead-onlyMoney can't move back this way

Where your data goes

Your bank talks to a third-party data aggregator. The aggregator passes read-only transaction history to Almanac. Nothing travels in the other direction2.

Credentials are entered in the aggregator's own screen and are never stored by Almanac. Coverage varies by institution1.

What protects the data

Read-only access

Credentials are read-only and held by the aggregator. Almanac cannot initiate a transfer, payment, or withdrawal.2

Encrypted end to end

TLS 1.2 or higher in transit, AES-256 at rest. Access to production data is limited and logged.4

Never sold

Transaction data builds your plan and nothing else. There is no advertising product to sell it to.3

Disconnect anytime

Revoking takes two taps in settings. Stored transactions are deleted within 30 days.1

How to disconnect

  1. Open Settings, then Connections.
  2. Choose the account and select Disconnect.
  3. Confirm. The link is revoked immediately and stored transactions are queued for deletion.

Security questions

See it work without connecting anything.

The demo runs entirely on sample data in your browser.