Security
How Bunse handles your financial data — and why there's less to secure than you'd think.
Our approach
Most finance apps ask you to trust a server with your account credentials and transaction history. Bunse takes a different approach: it doesn't run a server that holds your financial data at all, so there's nothing on our side to breach.
That trade-off means fewer features that depend on syncing between devices, in exchange for a much smaller attack surface — the data that matters lives on your device, under your control.
No bank connections
Bunse has no Open Banking integration, no third-party account aggregator, and no login flow for your bank. It never asks for your online banking credentials, and it couldn't do anything with them if it had them.
Where your data lives
Everything you enter — balances, transactions, goals, mortgage details — is stored locally on your device. Bunse does not operate a central database of user financial data, and nothing is uploaded automatically in the background.
When you import a statement (CSV, QIF, or OFX), the file is read entirely on your device. It is never sent to us or to any third party as part of that process.
Backups & exports
Because there's no cloud copy of your data, you are responsible for backing it up. Bunse lets you export a full copy of your data as a file whenever you like, and import it back in on this device or a new one.
An export file contains your full financial picture in plain form. Store it somewhere you'd store any other sensitive personal document — not somewhere publicly shared.
Third-party API keys
If you add a free Alpha Vantage API key to get live investment prices, that key is stored only on your device and is sent directly from your device to Alpha Vantage when you refresh prices — it never passes through Bunse's infrastructure, because Bunse doesn't have any infrastructure sitting in between.
Alpha Vantage's own handling of that request is governed by their terms and privacy policy, not ours.
Beta software
Bunse is currently in beta. That means occasional bugs are more likely than in a mature product — but it doesn't change the security model above: even in beta, your data stays local and there's no server-side account to compromise.
Reporting a vulnerability
If you believe you've found a security issue in Bunse, we'd genuinely like to hear about it before anyone else does. Email hello@bunse.uk with as much detail as you can — steps to reproduce, device and app version, and what you'd expect to happen instead.
We'll acknowledge reports and keep you updated as we look into them.
Questions this page didn't answer?
Check the FAQ