How we handle bank data

Connecting a bank account is the part people think hardest about, and rightly. This page says exactly what kBooks receives, what it cannot do, and how to end it.

We never receive your bank login

Your online banking username and password are never typed into kBooks and never pass through our servers. You obtain a read-only access token from the bank-feed service directly, and that token is what kBooks holds. There is nothing in our database that could be used to sign in to your bank, because we were never given it.

One direction only

The connection reads transactions and balances. There is no payment instruction in it, no transfer, no bill pay. Money cannot move through a kBooks bank connection because the capability does not exist.

The token is encrypted at rest

It is sealed with AES-256-GCM under a key derived specifically for bank credentials, stored only in that sealed form, and unsealed for the seconds a sync is talking to the service.

The account is yours, with the service too

You pay the bank-feed service directly and hold the account with them. That is why it costs about fifteen dollars a year rather than being priced into a plan, and it is also why the connection is not ours to keep.

You can cut it at any moment

Disconnect inside kBooks and the token is deleted. Revoke it at the bank-feed service and the connection dies whatever we do. The transactions already imported stay in your books, because they are your records.

What actually arrives

Date, description, amount, and the account it belongs to - the same lines you would see on a statement. That is what a bank feed is: a faster, less error-prone way of typing in what already happened. Nothing is sent back.

Imported lines are staged for you to review before they touch the ledger. A feed never posts to your books by itself.

We do not sell it, and we do not mine it

Your transaction data is used to keep your books and to show you your own numbers. It is not sold, not shared with advertisers, not pooled into a data product, and not used to train anything.

If the feed service goes away

Bank feeds are a convenience layer over data you can always get another way. If the service stops, your books are unaffected: everything already imported is yours, statements can be uploaded and read directly, and every transaction can be entered or imported by file. A feed failing has never been able to take a customer's books with it, by design.

What we cannot do, stated plainly

Sign in to your bank
Move, send or withdraw money
Change anything at your bank
See accounts you did not connect