What Vault stores, what leaves your device, and what we can and cannot see.
Version 1.4 · Effective 18 September 2026 · Last updated 26 September 2026 · What changed
The short version. Your financial records live in a file on your own computer. Nothing is uploaded unless you turn on cloud sync, and if you do, everything is encrypted on your device first — we hold ciphertext we cannot read. Receipt photos stay on your machine unless you turn on receipt sync on a paid plan, and if you do, they are sealed on your device before they are uploaded — we hold the image as ciphertext and cannot open it. Your saved credentials never leave your machine at all. There is no analytics, no tracking, no telemetry and no advertising in this app.
The rest of this page is the long version, including the parts that are less flattering: the handful of things we can see, and the limits of what encryption protects you from.
Vault is an Australian personal finance application. In this policy, “Vault”, “we”, “us” and “our” mean that company; “you” means the person using the app.
Privacy questions, requests and complaints all go to one address: hello@pfmvault.com. There is no phone queue and no ticket system — a person reads it.
We handle personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth). We do this as a commitment rather than because our current turnover obliges us to, and we would rather say so plainly than rely on an exemption.
Vault is built for Australian residents and is offered in Australia only. Its tax
features assume Australian residency, ATO rules and Australian financial years.
This policy covers the Vault desktop application, our optional cloud sync service,
and this website at pfmvault.com.
Vault is unusual for a finance app, so it helps to be concrete. Your information sits in one of three places, and which one it is determines who can read it.
This is where the substance of your financial life lives, and it is the default for everything. It is stored in an application-private folder on your computer:
Vault does not ask for and does not store your tax file number, Medicare number, date of birth, BSB or full account numbers. There is no field for any of them.
If you create an account and turn on cloud sync, the contents of your records are encrypted on your device before upload, using AES-256-GCM under a key derived from your password with PBKDF2-SHA256 at 310,000 iterations.
The key never reaches us. What we store is a wrapped copy of it that can only be unwrapped with your password, which we do not have — we never receive your password, only a value derived from it that is useless for decryption. This is what “end-to-end encrypted” means here, and it has a hard consequence you should understand before relying on it: if you forget your password, your synced data cannot be recovered. Not by you, and not by us. There is no reset that preserves it.
Sync cannot work on ciphertext alone; something has to be readable for one device to know which record is newer. This is that something, and it is the complete list — see the next section.
Most privacy policies are vaguest exactly here. Ours is a table.
| We hold, readable | Why |
|---|---|
| Your email address and sign-in metadata | You need an account to sync at all |
| Each record’s id, its type (transaction, account, holding, savings, loan, pledge), and when it was created, changed or deleted | The merge runs on these; without them two devices cannot agree on which copy wins |
| How many records of each type you hold, and how that grows over time | An unavoidable consequence of the row above |
| That you have a bank feed connected, which provider it is, and when it last delivered | To route a feed to the right account and show you sync status |
| A record of each open‑banking event: reference numbers the provider uses for your enrolment, your consent, the sign‑in session and any error, plus what happened and when | Open banking rules require these reference numbers to be logged. They are identifiers only — they carry no amount, merchant or account detail — and you can read your own |
| Your subscription state — plan, status, renewal date, and the payment provider’s customer and subscription identifiers | To know what you have paid for |
| A count of API calls you make, per endpoint | Rate limiting, so one account cannot exhaust a shared quota |
| How many bytes of receipt images you have synced — a single number, not a list | To enforce a per-account storage limit. Two devices uploading at once can only be stopped by a counter the server owns |
| How many synced records you have and their total size in bytes — two numbers, not the records | To enforce a per-account sync limit, so one account cannot fill the storage every account shares |
| For each synced receipt: which transaction it belongs to, its size, and when it was added | Unavoidable — the image has to be stored somewhere addressable, and it is the transaction that has to be able to find it. The transaction’s id is in the row above either way; what this adds is that the transaction has a photograph attached. The photograph itself is encrypted |
| Anything you type into our research survey, and an email address only if you volunteer one | It is a survey; the answers are the point. No account is needed and none is created — see the section below |
Read plainly: we can see that you use Vault, that you have a bank feed, roughly how much you track, when you last touched it, and the reference numbers your open‑banking connection was set up under. We cannot see a single amount, merchant, description, balance, category or account name. There is no server-side view of your finances and no way for us to produce one — not for ourselves, not for a marketer, and not on request.
Every one of these is off until you turn it on. Each says exactly what leaves.
Encrypted record contents, plus the readable fields in the table above. Covered in full in section 3.
On a paid plan this also carries your receipt images. Each one is encrypted on your device before it is sent, with the same key as your records, so we hold the picture but cannot open it. The originals stay on the device that took them; another device fetches a copy only when you open that receipt, one at a time. What we can read is the filename, its size and when it arrived.
When bank feeds are available and you connect one, your email address and your Vault account identifier are shared with our open banking provider so it can create your enrolment. You then authorise the connection on your bank’s own page — Vault never sees your banking username or password, and there is no key for you to handle. Your bank returns account details and transactions, which are passed through to your device and stored there.
We do not store your bank transactions on our servers. They are relayed and kept locally. The only thing recorded server-side is that an enrolment exists and when the feed last fired. See section 14 for your rights under the Consumer Data Right.
If you supply your own Up Bank personal access token, the app talks to Up directly from your computer. Only the token is sent. The transactions and balances that come back go straight into your local vault. Nothing about this route passes through us.
Vault suggests a category for each transaction with a keyword classifier covering roughly 250 Australian merchant patterns, plus the merchant cache on your device. It runs entirely on your device and makes no network request of any kind. Vault currently includes no AI features: nothing you enter or import is sent to an AI model.
To show current values, the app requests a price for each holding from a public market-data service. That request contains the ticker symbol and, necessarily, your IP address. It contains no quantity, no cost base and no personal identifier — but a party observing it could infer which securities you hold. If that matters to you, leave the price refresh alone; the app works from the figures you enter.
When you set or change a password, Vault can check it against a public database of known breached passwords. It does this without disclosing the password: the password is hashed on your device and only the first five characters of that hash are sent, which matches many thousands of possibilities. The service cannot determine your password from it.
Subscriptions are handled by Stripe. You enter card details on Stripe’s own page — card numbers never touch Vault’s systems, and we could not store them if we wanted to. Stripe receives your email address and your Vault account identifier so the payment can be matched to your account.
The app periodically asks pfmvault.com whether a newer version exists. It
sends nothing about you — no account, no email, no financial information. Like any
web request it reveals your IP address and the version you are running, which is
unavoidable in asking the question at all.
Versions released before 22 September 2026 asked GitHub directly instead, because that is where the installers are stored. Copies installed before then keep doing so until they update; newer ones ask us, and we fetch the file from GitHub ourselves. Either way nothing about your account or your finances is involved.
Vault currently uses no AI. One thing it does automatically: it suggests a category for a transaction, from a keyword list and a cache of merchants you have already named, running on your device with no network call at all.
Every category it suggests is a suggestion. You can change any of them, at any time, and the app records whether a category came from you or from the keyword list. Nothing is hidden and nothing is final. It is never used to decide anything about your access to Vault, your subscription, or what you pay.
We include this section because from 10 December 2026 the Privacy Act requires entities covered by it to disclose where a computer program makes, or substantially supports, decisions that significantly affect a person. We do not believe Vault's suggestions reach that threshold — you overrule every one of them — but we would rather describe what the software does than argue about whether we had to.
The survey at pfmvault.com/survey is separate from
the app and needs no account. When you press Send, your answers are stored in our
Supabase database in Sydney. We ask for no account numbers, no balances and no
login details, and there is no field for any of them.
An email address is optional. Leave it blank and the response carries nothing that identifies you; fill it in and we may contact you about what you wrote. It is stored separately from the answers so it can be removed on request without destroying the response. Email hello@pfmvault.com and we will delete it.
Responses are not sold, not shared, and not used for advertising. They exist to decide what gets built.
Vault contains no analytics SDK, no crash-reporting service, no advertising identifier and no telemetry. We do not know how many of our users open the app, which screens they visit, or what they do there.
This is the complete list of parties in the production path.
| Party | Role | What it receives | Optional? |
|---|---|---|---|
| Supabase | Accounts, database and server functions | Your email address; encrypted record contents; the readable fields in section 4 | Only if you use cloud sync |
| Fiskil | Open banking data provider | Your email address and Vault account identifier; your bank data in transit. When you disconnect, we ask Fiskil to delete your enrolment with them | Only if you connect a bank feed |
| Resend | Delivers the codes we email you: sign-up, password reset and account deletion | Your email address and the code in that message | Only if you create an account |
| Stripe | Payments | Your email address, Vault account identifier, and the card details you give it directly | Only if you subscribe |
| Up Bank | Direct bank API | The access token you supply | Only if you connect Up |
| Yahoo Finance | Market prices | Ticker symbols you hold | Only if you refresh prices |
| GitHub | Stores the installer and update files | Nothing from you. Since 22 September 2026 your browser and your app talk to pfmvault.com, and we fetch the file from GitHub ourselves, so GitHub does not see your address or that you downloaded anything. Copies installed before then still check GitHub for updates until they update once | No — this is how you get the app |
| Cloudflare | Hosts this website | Standard web request data for pfmvault.com | No — but the website holds no user data |
We do not sell, rent, broker or trade your personal information. We do not disclose it for advertising, and we do not use it to train AI models. We have no advertising business, which is the most reliable reason to believe that.
All of our own server-side data is hosted in Australia, in
Supabase’s Sydney region (ap-southeast-2). Your bank data is not
stored on our servers at all.
One of the optional services above is operated from overseas, principally the United States: the market-price lookup. It is off unless you switch it on, and it is described precisely in section 5. Resend, which delivers the codes we email you, is also operated from the United States. Stripe processes payments internationally. GitHub and Cloudflare operate global networks. The typeface on this site is served from our own domain, so loading a page here contacts nobody but our host.
| What | Kept for |
|---|---|
| Your ledger, accounts, investments and receipts on your device | Indefinitely, at your discretion. Tax substantiation generally requires five years from the date you lodge, so the app does not quietly age your records out — you delete what you want gone. |
| Encrypted record contents on our server | Until you delete the record or your account |
| Your account and email address | Until you ask us to delete the account |
| Subscription and billing records | As required by Australian tax and corporations law, generally seven years, after account deletion |
| Bank data on our servers | Not stored. Transactions are relayed to your device, not retained |
| Error logs | On your device only, capped and rotated. Never transmitted |
| Server operational logs | Our hosting provider’s default retention period |
You can read, edit and delete everything in the app directly — that is the normal way to correct your information, and it needs no request to us. You can also export your whole vault to a JSON file, and your transactions to CSV, at any time and on any plan.
In Vault, open Settings → Accounts → Delete account. Enter the email address and app password on the account, then the fresh code we email you. The final button deletes your sign‑in and every server-side row attached to it — encrypted records, settings, encryption metadata, bank enrolment, feed events, the open‑banking event log, subscription record and usage counters. Any paid subscription is cancelled first. If you have a bank feed, we also ask the provider to delete your enrolment.
If you cannot use the app, email hello@pfmvault.com from the address on the account. We will verify the request, complete it within 30 days, and tell you when it is done. Your local copy stays on your device after either route; deleting that is uninstalling the app, or deleting the vault from within it.
When you delete a single record while sync is on, its contents are destroyed locally and on our server, but a marker remains: the record’s id, its type, and the time it was deleted. That marker is what tells your other devices to delete it too — without it, the record would reappear on the next sync. It contains no amount, date, merchant, description, category or account. Those markers are removed when you delete your account.
You already hold your data, so an access request is usually unnecessary. If you want the readable fields we hold about you — section 4’s table, for your account — ask and we will send them within 30 days, free.
A limitation we would rather state than have you discover. The vault file on your own computer is not encrypted by Vault itself. It is protected by your operating system’s file permissions and by full-disk encryption if you have it on. Anyone with access to your unlocked computer, or to an unencrypted disk taken from it, can read it. Turning on full-disk encryption — BitLocker on Windows, FileVault on macOS — is the single most useful thing you can do about that.
No system is perfectly secure, and we will not claim otherwise. What we have done is limit how much a breach of our systems could expose, which is why the encryption boundary sits on your device rather than ours.
If a data breach occurs that is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988, and — where bank feed data is involved — as required by the Consumer Data Right rules. We will tell you what happened, what information was involved and what to do about it. We would rather tell you early and be imprecise than tell you late and be tidy.
Not yet in effect. Bank feeds through Australia’s Consumer Data Right are built into Vault but are not switched on, because the arrangement with an accredited provider is not in place. No Consumer Data Right data is being collected today.
When it is switched on, our provider Fiskil — which holds unrestricted accreditation as a data recipient — will act as the CDR principal and Vault will operate as its CDR representative under a written arrangement required by the CDR Rules. Under those rules, Fiskil’s CDR policy governs CDR data, not this one, and your rights sit with the accredited entity.
Vault is not itself accredited under the Consumer Data Right, and we do not represent otherwise. The details, including how consent works and how to complain, are on our Consumer Data Right page.
Vault is not intended for people under 18 and we do not knowingly collect information from them. If you believe a child has created an account, tell us and we will delete it.
Tell us first: hello@pfmvault.com. We will acknowledge within 7 days and give you a substantive answer within 30 days. Say what happened and what you would like done about it.
If you are not satisfied, you can take a privacy complaint to the Office of the Australian Information Commissioner — oaic.gov.au, or 1300 363 992. Once bank feeds are live, complaints about Consumer Data Right data can also go to the Australian Financial Complaints Authority; the Consumer Data Right page sets out that path.
If we change this policy in a way that materially affects you, we will tell you in the app or by email before it takes effect, and the version and date at the top will change. Older versions are available on request. We will not quietly widen what we collect and rely on you not re-reading the page.