Readable by design
Open your ledger in a text editor, review it line by line, and compare changes with ordinary diff tools.
Security through ownership
Beancount.io keeps your ledger in human-readable plain text. That does not remove every security risk, but it gives you something closed financial systems cannot: a record you can audit and take with you.
Last updated: July 31, 2026
; Human-readable. Diffable. Yours.
2000-01-01 open Assets:Cash USD
2026-07-31 * "Coffee shop"
Expenses:Meals 4.50 USD
Assets:CashYour files, your future
Security starts with reducing dependency. A Beancount ledger is readable without a proprietary viewer, compatible with open-source tooling, and straightforward to archive or move.

Open your ledger in a text editor, review it line by line, and compare changes with ordinary diff tools.
Export your files and continue with Beancount-compatible tools. Your accounting record is not locked in a proprietary format.
The Android app stores financial data on your device by default. Cloud synchronization is an option, not a requirement.
Protections on our side
We focus this page on controls a reader can understand and claims we can support. We will add independent attestations here if and when they exist.
HTTPS protects traffic between your browser and Beancount.io while it is in transit.
Private ledger access requires authentication. Connected services use purpose-specific authorization instead of public ledger links.
Git-backed ledger history makes file changes inspectable and lets you restore earlier versions with standard tools.
No service can promise perfect security. We publish our data practices and a path for responsible vulnerability reports.
Collection
The honest answer depends on the feature you use. The public site measures visits; account, bank-sync, billing, and optional AI features have their own data paths.
Read the full Privacy PolicyWe use Google Analytics and operational logs to understand site traffic, device and browser patterns, referrers, and reliability.
We do not sell personal information or run an advertising business. The Privacy Policy explains the limited situations in which service providers or law may require disclosure.
Bank sync, billing, and AI features involve separate providers only when those paths are relevant. Optional AI processing begins only when you choose an AI-powered feature.
Data paths
These providers are in current site or product data paths. The Privacy Policy remains the source for complete legal disclosures and retention details.
| Provider | Data involved | Purpose |
|---|---|---|
| Render | Web requests and operational server logs. | Hosts the beancount.io web service. |
| Cloudflare | IP address, request metadata, and cached public assets. | Edge delivery and DDoS protection. |
| Stripe | Billing and subscription details; payment data is handled in Stripe's flow. | Payments and subscription management. |
| Google Analytics | Page views, device and browser data, referrers, and cookie identifiers. | Audience and site-usage measurement. |
| Plaid | Bank account and transaction data for accounts you choose to connect. | Optional bank linking and transaction sync. |
| Anthropic | Prompts and ledger or file content you choose to send through AI features. | Optional AI processing with the Claude API. |
| BlockEden | The same optional AI request payload while it is routed to the model provider. | API proxy for optional AI requests. |
Security FAQ
Straight answers about access, portability, providers, and reporting.
No online service is risk-free. Beancount.io uses HTTPS and authenticated access, and its plain-text ledger format reduces lock-in by letting you inspect and export your records. This page documents the relevant data paths and how to report a problem.
No. For optional bank sync, authentication happens in Plaid's account-linking flow; Beancount.io does not receive your bank login password. You can also enter plain-text transactions or import files without connecting a bank.
You can export your ledger files in plain text. You can also request account-data deletion; legal, fraud-prevention, backup, and other limited retention obligations described in the Privacy Policy may still apply.
A plain-text export remains readable and usable with the open-source Beancount toolchain. Keep current exports as part of your own continuity plan rather than depending on any hosted service forever.
No. Beancount.io does not sell personal information or provide it to third parties for their own marketing. The Privacy Policy lists service-provider, legal, and optional-feature disclosures.
Yes. Beancount's core tooling and plain-text syntax are open source, so your accounting records are not dependent on a proprietary file format or a single vendor's application.
Email [email protected] with reproduction steps, affected URLs, and the impact you observed. Follow the vulnerability disclosure policy on this page and avoid sending sensitive proof through public community channels.
Vulnerability disclosure
Please send suspected vulnerabilities to the dedicated security address. Do not post sensitive details in Telegram, GitHub issues, or other public channels.
[email protected]Test only accounts, systems, and data you own or are explicitly authorized to use. Do not access other users' data, disrupt the service, or use social engineering.
Include reproduction steps, affected URLs or components, the observed impact, and a safe proof of concept. Minimize any personal or financial data in the report.
If you act in good faith, follow this policy, avoid privacy violations and service disruption, and allow time for a fix before disclosure, we will not pursue legal action based solely on your research.
We aim to acknowledge a report within three business days and share updates as we validate and address the issue. Resolution time depends on severity and complexity.
Have a general, non-sensitive security question?
Ask in the Beancount communityStart with plain-text accounting you can inspect, export, and keep.