Security & trust

The trust doctrine isn't a marketing page bolted onto the product. It's how the product is built. Here's exactly what that means, in plain language.

🔒 Read-only, always 🔐 KMS-encrypted tokens 🚫 We never sell your data

🔐Read-only bank access

SaveGuard connects to your bank through Plaid with read-only permissions. That's not a setting we could change. It's the only kind of access we ever request. We can see transaction history and balances. We cannot initiate a transfer, make a payment, or modify anything in your account. There's no code path in SaveGuard that moves money, because we never built one.

🔑Encrypted bank connection tokens

The access token Plaid issues for your bank connection is encrypted before it's stored, using AWS Key Management Service (KMS). It's decrypted only at the moment a request needs it, and only by the specific backend function handling that request. Your bank login credentials are never seen by SaveGuard at all. Plaid handles authentication directly with your bank.

🚫We don't sell your data

Your transaction data is used to run the product you signed up for: detecting subscriptions, forecasting Safe-to-Spend, generating your bill roast, and nothing else. We don't sell it to advertisers, data brokers, or anyone else. We don't use it for credit decisions or scoring. Full detail in our Privacy Policy.

Delete anytime, actually deleted

You can clear your data or delete your account at any time, from inside the app or by requesting deletion here. Plaid access tokens are revoked immediately. Your transaction history, detected subscriptions, and account data are purged from our systems within 30 days. Not archived, not "anonymized and kept."

We detect and draft. We never act for you

SaveGuard doesn't cancel subscriptions, negotiate bills, or file disputes on your behalf. When it finds something worth acting on, it drafts the cancellation request, negotiation script, or dispute, and hands it to you to review and send. Nothing leaves your name without you reading it first.

💬Honest numbers, always

SaveGuard never tells you what you "would have saved" or projects a total based on what you might cancel. Every dollar figure the app shows you is a fact: the price you're actually paying, or an amount you've confirmed after taking an action. AI-generated copy (like your bill roast) is automatically screened to strip out any invented savings claim before you ever see it. If we don't know a number, we don't make one up.

🌐Infrastructure

SaveGuard runs on Amazon Web Services. Data is encrypted with AES-256 at rest and TLS 1.2+ in transit. Access to production systems follows least-privilege IAM policies, and secrets (API keys, encryption keys) are stored in AWS Secrets Manager with KMS encryption, never in source code. Authentication is handled by AWS Cognito with email verification.

Questions about any of this? Read the full Privacy Policy and Terms of Service, or email hello@usesaveguard.com.