Security

How Deco protects your data

Deco uses one protected cloud-sync model for your financial data. Protection is built in, with encrypted storage, restricted account access and secure local caches. Optional usage analytics is a separate choice and is off by default.

In transit

Every connection between the app and Deco's servers uses TLS/HTTPS. Nothing is sent in the clear.

At rest

Your primary data is stored on Supabase-hosted PostgreSQL infrastructure in Ireland in the EU and protected by provider encryption at rest. Deco's service processes that data to provide the features you request. Authenticated access and row-level security restrict ordinary users to the records their account is allowed to access.

On your device

Sensitive local financial caches use authenticated encryption with a key held in secure device storage. If secure key storage is unavailable, new sensitive cache values stay in memory instead of being written in plaintext.

Account isolation

Authentication and row-level security bind financial records to the user who owns them. Server functions verify the signed-in user and connection entitlement before reading or changing connected-account data.

What Deco does not do

  • — Deco does not sell your data or share it with advertisers.
  • — Deco does not ask for your online-banking password. The current public app uses manual accounts and statement imports; live bank connections are not available.
  • — Deco does not use your financial data for advertising. Automatic contributions of readable categorization samples are disabled in the current app.
  • — Usage analytics are off by default. If you allow them, Deco removes financial details, merchants, names, emails and free text before an event can be sent.

Bank connection availability

Live bank connections and Deco Plus purchases are not available in the current public app. The following information applies only to existing, test or future connections where enabled.

With your permission, Deco retrieves account details, balances and transactions to build your budget, identify recurring costs and show your financial position. Connecting an account does not authorize Deco to move money or place trades.

You choose which accounts to share in the provider-hosted flow and review its permissions and terms before connecting. Deco does not receive or store your online-banking password. You can use manual accounts and statement imports without linking a bank.

Last synced shows when Deco last retrieved data from the connection provider. It is not a guarantee that the bank has updated its records at that moment. New transactions and balances can be delayed, and some connections require renewed consent.

Connection status and provider information

Reporting a vulnerability

If you believe you have found a security issue, email usedecoapp@outlook.com with what you found and how to reproduce it. Please give us a reasonable window to fix an issue before disclosing it publicly. This is a one-person team, so response times vary, but every report gets read.

For the full legal detail behind this page, see the Privacy Policy, including data protection, analytics, providers, retention and your rights.

Security · Deco