Skip to main content

Security through ownership

A financial record you can inspect, export, and keep.

Beancount.io keeps your ledger in human-readable plain text. That does not remove every security risk, but it gives you something closed financial systems cannot: a record you can audit and take with you.

plain textportable by designresponsible disclosure

Last updated: July 31, 2026

ledger.beancount
; Human-readable. Diffable. Yours.
2000-01-01 open Assets:Cash USD

2026-07-31 * "Coffee shop"
  Expenses:Meals       4.50 USD
  Assets:Cash
Readable today. Usable without us.

Your files, your future

Your data, in a format you can audit

Security starts with reducing dependency. A Beancount ledger is readable without a proprietary viewer, compatible with open-source tooling, and straightforward to archive or move.

Hands writing in a paper ledger beside a laptop showing abstract wordless charts, with a small brass padlock resting on the wooden desk

Readable by design

Open your ledger in a text editor, review it line by line, and compare changes with ordinary diff tools.

Portable, not trapped

Export your files and continue with Beancount-compatible tools. Your accounting record is not locked in a proprietary format.

Local-first on Android

The Android app stores financial data on your device by default. Cloud synchronization is an option, not a requirement.

See how the local-first Android app works

Protections on our side

Clear controls, without inflated labels

We focus this page on controls a reader can understand and claims we can support. We will add independent attestations here if and when they exist.

HTTPS in transit

HTTPS protects traffic between your browser and Beancount.io while it is in transit.

Authenticated access

Private ledger access requires authentication. Connected services use purpose-specific authorization instead of public ledger links.

Reviewable change history

Git-backed ledger history makes file changes inspectable and lets you restore earlier versions with standard tools.

Candid about limits

No service can promise perfect security. We publish our data practices and a path for responsible vulnerability reports.

Collection

What we collect — and what we do not

The honest answer depends on the feature you use. The public site measures visits; account, bank-sync, billing, and optional AI features have their own data paths.

Read the full Privacy Policy

Website measurement

We use Google Analytics and operational logs to understand site traffic, device and browser patterns, referrers, and reliability.

No data-selling business

We do not sell personal information or run an advertising business. The Privacy Policy explains the limited situations in which service providers or law may require disclosure.

Optional features are explicit

Bank sync, billing, and AI features involve separate providers only when those paths are relevant. Optional AI processing begins only when you choose an AI-powered feature.

Data paths

Service providers and what reaches them

These providers are in current site or product data paths. The Privacy Policy remains the source for complete legal disclosures and retention details.

ProviderData involvedPurpose
RenderWeb requests and operational server logs.Hosts the beancount.io web service.
CloudflareIP address, request metadata, and cached public assets.Edge delivery and DDoS protection.
StripeBilling and subscription details; payment data is handled in Stripe's flow.Payments and subscription management.
Google AnalyticsPage views, device and browser data, referrers, and cookie identifiers.Audience and site-usage measurement.
PlaidBank account and transaction data for accounts you choose to connect.Optional bank linking and transaction sync.
AnthropicPrompts and ledger or file content you choose to send through AI features.Optional AI processing with the Claude API.
BlockEdenThe same optional AI request payload while it is routed to the model provider.API proxy for optional AI requests.

Security FAQ

Is Beancount.io safe? Start with the specific questions.

Straight answers about access, portability, providers, and reporting.

Is Beancount.io safe?

No online service is risk-free. Beancount.io uses HTTPS and authenticated access, and its plain-text ledger format reduces lock-in by letting you inspect and export your records. This page documents the relevant data paths and how to report a problem.

Does Beancount.io see my bank password?

No. For optional bank sync, authentication happens in Plaid's account-linking flow; Beancount.io does not receive your bank login password. You can also enter plain-text transactions or import files without connecting a bank.

Can I export or delete my data?

You can export your ledger files in plain text. You can also request account-data deletion; legal, fraud-prevention, backup, and other limited retention obligations described in the Privacy Policy may still apply.

What happens to my data if Beancount.io shuts down?

A plain-text export remains readable and usable with the open-source Beancount toolchain. Keep current exports as part of your own continuity plan rather than depending on any hosted service forever.

Does Beancount.io sell my data?

No. Beancount.io does not sell personal information or provide it to third parties for their own marketing. The Privacy Policy lists service-provider, legal, and optional-feature disclosures.

Is the Beancount format open source?

Yes. Beancount's core tooling and plain-text syntax are open source, so your accounting records are not dependent on a proprietary file format or a single vendor's application.

How do I report a security issue?

Email [email protected] with reproduction steps, affected URLs, and the impact you observed. Follow the vulnerability disclosure policy on this page and avoid sending sensitive proof through public community channels.

Vulnerability disclosure

Report a security issue privately

Please send suspected vulnerabilities to the dedicated security address. Do not post sensitive details in Telegram, GitHub issues, or other public channels.

[email protected]

Use authorized accounts only

Test only accounts, systems, and data you own or are explicitly authorized to use. Do not access other users' data, disrupt the service, or use social engineering.

Send a useful report

Include reproduction steps, affected URLs or components, the observed impact, and a safe proof of concept. Minimize any personal or financial data in the report.

Good-faith safe harbor

If you act in good faith, follow this policy, avoid privacy violations and service disruption, and allow time for a fix before disclosure, we will not pursue legal action based solely on your research.

What to expect

We aim to acknowledge a report within three business days and share updates as we validate and address the issue. Resolution time depends on severity and complexity.

Have a general, non-sensitive security question?

Ask in the Beancount community

Keep control of your financial record

Start with plain-text accounting you can inspect, export, and keep.

Start your ledger