No bank feed means no bank password in our database
Open-banking connections look convenient until you change country, change bank, or the aggregator drops the institution you actually use. They also mean a third party — and then us — sitting in the path of a credential that can empty an account. Rasa Money does not take that path. You type transactions or you import a file you already downloaded from your bank. There is no 'link account' OAuth into a retail bank, so there is no vault of bank logins to protect, leak, or subpoena.
That is a product decision as much as a security one. Expats and anyone who banks in more than one country already know how fragile aggregators are. A finance manager that only works in the markets Plaid likes is not a multi-currency app. File import and manual entry behave the same in every country we can sell into.
The trade-off is honest: we will not auto-pull last night's card spend. You keep the relationship with the bank. We keep a ledger you can explain. If a competitor's homepage boasts 'automatic bank sync in 12 countries', that is a different architecture with a different blast radius. Ours is smaller on purpose.
What sits in the account, and what does not
We store the financial records you create or import: accounts, transactions, budgets, categories, debts, and the exchange-rate snapshot that belonged to each posting. We store the identity data needed to log you in — email, a bcrypt password hash, optional profile fields, optional Google OAuth identifiers. We do not store a raw password. We cannot read it back to you.
Optional card numbers, if you type them, are a reference field, not a payment instrument. We recommend last-four only. They are encrypted at rest and are not returned in ordinary API responses. We do not process or validate PAN data, and we do not charge a card from that field. Checkout for Pro goes through the payment provider, not through a card number sitting on a transaction.
Session refresh tokens and short-lived OTPs exist so you can stay logged in and reset a password. IP addresses and error logs exist so we can see abuse and crashes. Diagnostic logs are not a second copy of your ledger. The Privacy Policy lists each of these with the reason it exists. This page is the 'why we designed it this way' layer, not a substitute for that list.
Irreversible actions ask you twice
Exporting your data, resetting your finances, deleting the account, or revealing a stored card number all require you to re-enter your password in the moment. Reset and deletion also make you type a confirmation word. That is not theatre. It is how we stop a stolen session or a shared laptop from emptying the workspace because someone clicked the wrong menu.
A financial reset is not the same as deleting the login. Reset clears the ledger you asked us to forget; deletion removes the account. Both are serious, both are in Settings, and both are gated. If you are trying to do either and the app is blocking you, that is the control working. Contact privacy@ if you need a rights request rather than the in-product button.
Downloads expire. Card digits stay put.
When Pro produces an export, the download link is HTTPS-only and the file is removed from disk after you take it. We are not keeping a zip of your life in an S3 bucket 'just in case you click again next year'. If you need another archive, you run export again, with the password challenge again.
That is also why we tell you, on pricing, to export while the subscription is active. Basic cannot mint the archive. Downgrade keeps the records in the product; it does not hand you the zip. Plan the exit the same week you cancel, not the week after you are surprised.
Rasa AI can read a snapshot. It cannot write the ledger.
The assistant sees a snapshot of accounts, balances, budgets, categories, and recent transactions so it can answer questions about your money and about the product. Chat history stays in the browser rather than being filed onto the account as a second database of secrets. There is no tool path for the model to create, edit, or delete a transaction.
Read-only is a security property, not a missing feature we will 'open up later' because demos look cooler when the bot books a bill. If an answer looks wrong, you still own the row. Import suggestions are suggestions until you confirm. Treat the model as a reader with a good memory of this product, not as a bookkeeper with signing authority.
You should be able to leave with the file
Data ownership is only real if leaving is possible. Pro's export is the structured archive: accounts, transactions, budgets, categories, debts. It is your copy, not a courtesy PDF of last month's dashboard. Use it to migrate, to keep an offline backup, or to satisfy your own record-keeping.
Deletion is the other half. When you delete, the account is deactivated, sessions die, and identifiers are obfuscated so you can register again later if you choose. The Privacy Policy is the document to cite if you are making a formal request rather than clicking the button. Email privacy@; do not send the ledger to sales@ as an attachment 'for safekeeping'.
Who is accountable for this
The operator is Rasa Corp, registered in Turkey, with a public office address in Şişli, Istanbul. That is the same entity named in the Terms. We are not a bank. We do not hold client money. A security page that will not name the company is a brochure; this one does.
Questions about an incident, a processor, or a rights request belong on the contact page — privacy@ for data, legal@ for notices. The About page is where we say what the company is for. This page is where we say what we refuse to hold so that a finance app stays a finance app.
Related pages
- Política de Privacidade — Legal detail on collection, processors, and your rights.
- Sobre — Rasa Corp operates the service. Registered in Turkey.
- Contato — privacy@ for access, export, and deletion requests.
- Preços — Data export is a Pro capability — plan for that before you cancel.
- FAQ — Bank connection, export, trial, and plan caps — the full list.