Twiggybank

Chapter 03 · Security

What we hold, and how we hold it.

Every balance in Twiggybank is practice money, which keeps the security surface small. There are no funds to move and no card numbers to lose. The data we do hold is a small family record and the names attached to it, and we treat it with the care family records deserve.

We do hold

Family
A family name, a currency, a time zone, and your chosen configuration (allowance schedules and the saving growth rate).
People
An email address for each Adult. A display name, an optional birthday, and a chosen color for each kid.
Ledger
Every money event your family records: paydays, saving growth, spend requests, fixes. Once it happens it stays in the record as it was. Sized in whole cents of your family currency.
Auth metadata
Session tokens and password hashes managed by our auth provider. Standard browser cookies for keeping you signed in.

We do not hold

Card numbers
We never see or touch a card. No PCI scope.
Bank accounts
No ACH and no balances at any real institution.
Real money
Every figure is practice money. There are no real balances.
Behavioral data
We build no advertising profile and run no third-party trackers. We sell nothing we collect.
Photos of children
Only display names. No image uploads of kids in v1.

How we protect it

Boring is the goal.

Twiggybank runs on well-trodden infrastructure. We have not invented our own cryptography or our own authentication. The less novelty in the stack, the more the security guarantees come from the people who do this for a living.

Hosting
The web app is deployed on Vercel; the database is managed Postgres hosted by Supabase. Both encrypt data at rest by default and serve all traffic over TLS.
Isolation between families
Postgres row-level security policies tie every read and write to your family ID. There is no API path that can ask for another family's data. The database refuses before the app ever sees the request.
Authentication
Passwords are never stored in plaintext; auth is handled by Supabase Auth, which uses industry-standard hashing and short-lived session tokens.
Transport
HTTPS everywhere. Cookies are marked secure and HttpOnly. No mixed-content surfaces.
Ledger immutability
Posted records cannot be edited from any client. A correction adds a new, linked record that undoes the original, and both stay visible. Tampering would require database access we do not give to ourselves casually.
Least privilege
The service key that can bypass row-level security never ships to the browser or mobile app. It lives only on the server, scoped to specific operations.

Kids

The smaller set.

We collect the minimum from children: a display name, an optional birthday, a chosen color, and the money events an Adult or the kid posts to the family record. We hold no contact information for a kid and no advertising data.

Read our children’s privacy notice →

What we do not offer yet

We’ll get to it.

We are a small project. We do not yet offer two-factor authentication, hardware-key sign-in, audit-log export to Adults, or SOC 2 certification. Each is on the list, and none is shipped.

Reporting an issue

We want to hear it.

If you’ve found something that looks like a vulnerability, email security@twiggybank.com. Please give us a chance to look at it before publishing details. We’ll respond within a few days and credit you, if you’d like the credit.