TRUST CENTER

Security at CashWeeks

Updated September 11, 2026

CashWeeks is operated by Xmbroider LLC.

CashWeeks never receives your bank username or password. Plaid handles institution authentication and returns supported financial data and an access token. CashWeeks encrypts that token in server-only storage.

Account protection

Data boundaries

Provider verification

CashWeeks validates Plaid webhook signatures and request-body hashes before queuing synchronization. Stripe webhook signatures are checked against the original request body with a limited timestamp window. Subscription access is reconciled against Stripe’s current records; a browser return link cannot grant Premium access.

Payments and receipts

Stripe hosts payment entry and stores payment-card details. CashWeeks stores subscription identifiers and status rather than full card numbers. Receipt photos are available only to authenticated members of the household. Gemini processes submitted receipt images to return structured merchant, total, date, and item data.

What users can do

Use a unique password, protect your email and phone accounts, keep a backup verification phone, review household membership, disconnect old institutions, and never share verification codes. Review receipt extractions and forecasts before relying on them.

Report a security issue

Send suspected vulnerabilities or unauthorized access reports to security@cashshield.app. Include the affected page, what happened, and how we can reproduce it. Do not include passwords, verification codes, full bank account numbers, or sensitive receipt images.