Security & privacy
Your money is your business.
Stead handles some of your most personal information. Here’s exactly how we look after it — in plain English, including the parts encryption can’t do.
How your data is protected.
Encrypted at rest
The database and the nightly backups are encrypted on disk at the storage layer.
Disk-level — it protects a stolen disk or backup file, not a running query.
Field-level encryption
Your email and display name are additionally encrypted with AES-256-GCM at the application layer, before they reach the database.
Not zero-knowledge — the running app holds the keys, so we can still read them to run the service.
Passwords are hashed
Never stored as text — hashed with bcrypt (cost 12).
Encrypted in transit
All traffic between your browser and our servers uses HTTPS (TLS 1.2 or higher).
The vault — what a breach of the database sees
Where your data lives.
Your primary data is in Australia. Some supporting services sit offshore — here they are, in full. We don’t claim your whole stack stays in Australia, because it doesn’t.
In Australia / in-region
- Database (Neon)
- Sydney, Australia
- Nightly backups (Cloudflare R2)
- Oceania
- Rate limiting (Upstash)
- Asia-Pacific
Offshore
- App compute (Vercel)
- Global edge
- Error monitoring (Sentry)
- European Union
- Product analytics (PostHog)
- European Union
- Email delivery (Resend)
- United States
What we never do.
- No ads.
- We never sell or rent your data — to anyone, ever.
- We don’t track you around the web.
You're in control.
Export, any time
Download your data from Settings → Export Data.
Delete on demand
Delete your account from Settings → Account. Your personal details are removed after a 30-day restore window — cancel any time before it ends.
Sharing is your call
Accounts start private; a partner sees one only if you choose to share it. Transactions and goals can be marked private too. Quick saves are the exception — they have no private marking, so a linked partner can see them.
Records follow your account
Your financial records (transactions, budgets, goals) live only as long as your account. Delete your account and they are permanently deleted with it once the 30-day restore window ends. Keeping tax records is on you, not us — the ATO expects you to keep your own (generally for at least 5 years) — so export your data before you go.
When we'd look at your data.
Only when running Stead requires it — investigating a problem you’ve reported, or keeping the service safe — and only as far as the job needs. Never for marketing, never out of curiosity, and never for sale. The rest of the time, your records sit behind the protections above.
The honest limit: the running app holds the encryption keys, so this isn’t zero-knowledge encryption — “we can’t see your data” would be an overclaim, and we’d rather be straight about it than imply otherwise.
Security questions.
Is my financial data safe with Stead?
Your database and its nightly backups are encrypted at rest; your email and display name are additionally encrypted at the application layer; passwords are hashed with bcrypt. Your data is never sold, and you can export or delete it whenever you like.
Do you connect to my bank?
No. You add your transactions and balances yourself, so your bank logins never touch Stead. Manual entry is a deliberate design choice.
Can you read my data?
To operate the service, yes — the running application holds the encryption keys, so this is not zero-knowledge encryption. In practice, your records are opened only when running Stead requires it: investigating a problem you’ve reported, or keeping the service safe. Never for marketing, and never for sale. Field-level encryption is there for the breach scenario — a leaked database snapshot or dumped table reads as ciphertext.
Who can see my data?
You do. A partner sees only what you choose to share: accounts start private, and transactions and goals can be marked private. Quick saves are the exception — they have no private marking and a linked partner can see them.
We checked this page against Stead’s own code on 28 July 2026. Questions about your data? Contact us. The full legal detail is in our privacy policy.
Budgeting that respects you.
Early access — join the waitlist.