Built to hold statements
A bank statement is about as sensitive as a file gets. Here is how yours is handled.
- Encrypted at rest
- Every statement file you upload is encrypted with AES-256-GCM before it is stored.
- No full account numbers
- Only the last few digits are kept — enough to tell your accounts apart.
- Bank tokens stay on the server
- A linked bank's access token is encrypted and never leaves the server — not to your browser, not to your phone.
- Your bank login is never ours to keep
- Linking runs through Plaid's own sign-in page. DimeRoot never receives your bank username or password.
What's stored
- The statement files you upload
- Transactions read from them
- Your score, recommendations and progress
Never sold. Never shared.
Your controls
- Export everything as CSV or JSON.
- Delete everything. It is removed, not archived.