Cookies & privacy

One essential cookie keeps you signed in — no third-party cookies, no ads. We use privacy-first analytics to improve the app; it carries no personal data and you can turn it off any time. Learn more

Skip to content

Security & privacy

Your money is your business.

Stead handles some of your most personal information. Here’s exactly how we look after it — in plain English, including the parts encryption can’t do.

How your data is protected.

  • Encrypted at rest

    The database and the nightly backups are encrypted on disk at the storage layer.

    Disk-level — it protects a stolen disk or backup file, not a running query.

  • Field-level encryption

    Your email and display name are additionally encrypted with AES-256-GCM at the application layer, before they reach the database.

    Not zero-knowledge — the running app holds the keys, so we can still read them to run the service.

  • Passwords are hashed

    Never stored as text — hashed with bcrypt (cost 12).

  • Encrypted in transit

    All traffic between your browser and our servers uses HTTPS (TLS 1.2 or higher).

The vault — what a breach of the database sees

What you seePriya
What the database storesv1:1:kQ4tR8Zw…:9fXb2wLq0M…
Display name — sealed with AES-256-GCM before it reaches the database (shortened)

Where your data lives.

Your primary data is in Australia. Some supporting services sit offshore — here they are, in full. We don’t claim your whole stack stays in Australia, because it doesn’t.

In Australia / in-region

Database (Neon)
Sydney, Australia
Nightly backups (Cloudflare R2)
Oceania
Rate limiting (Upstash)
Asia-Pacific

Offshore

App compute (Vercel)
Global edge
Error monitoring (Sentry)
European Union
Product analytics (PostHog)
European Union
Email delivery (Resend)
United States

What we never do.

  • No ads.
  • We never sell or rent your data — to anyone, ever.
  • We don’t track you around the web.

You're in control.

Export, any time

Download your data from Settings → Export Data.

Delete on demand

Delete your account from Settings → Account. Your personal details are removed after a 30-day restore window — cancel any time before it ends.

Sharing is your call

Accounts start private; a partner sees one only if you choose to share it. Transactions and goals can be marked private too. Quick saves are the exception — they have no private marking, so a linked partner can see them.

Records follow your account

Your financial records (transactions, budgets, goals) live only as long as your account. Delete your account and they are permanently deleted with it once the 30-day restore window ends. Keeping tax records is on you, not us — the ATO expects you to keep your own (generally for at least 5 years) — so export your data before you go.

When we'd look at your data.

Only when running Stead requires it — investigating a problem you’ve reported, or keeping the service safe — and only as far as the job needs. Never for marketing, never out of curiosity, and never for sale. The rest of the time, your records sit behind the protections above.

The honest limit: the running app holds the encryption keys, so this isn’t zero-knowledge encryption — “we can’t see your data” would be an overclaim, and we’d rather be straight about it than imply otherwise.

Security questions.

Is my financial data safe with Stead?

Your database and its nightly backups are encrypted at rest; your email and display name are additionally encrypted at the application layer; passwords are hashed with bcrypt. Your data is never sold, and you can export or delete it whenever you like.

Do you connect to my bank?

No. You add your transactions and balances yourself, so your bank logins never touch Stead. Manual entry is a deliberate design choice.

Can you read my data?

To operate the service, yes — the running application holds the encryption keys, so this is not zero-knowledge encryption. In practice, your records are opened only when running Stead requires it: investigating a problem you’ve reported, or keeping the service safe. Never for marketing, and never for sale. Field-level encryption is there for the breach scenario — a leaked database snapshot or dumped table reads as ciphertext.

Who can see my data?

You do. A partner sees only what you choose to share: accounts start private, and transactions and goals can be marked private. Quick saves are the exception — they have no private marking and a linked partner can see them.

We checked this page against Stead’s own code on 28 July 2026. Questions about your data? Contact us. The full legal detail is in our privacy policy.

Entries 01–06Settled
Carried forward →

Budgeting that respects you.

Start free

Early access — join the waitlist.