When you connect financial accounts to a service, you have every right to ask exactly what they do with your data. This page tells you, specifically.
When you connect a brokerage or bank, you enter your credentials into Plaid — not into Cresara. Plaid is the same trusted infrastructure used by Robinhood, Venmo, Coinbase, and hundreds of other regulated financial apps.
Plaid returns to us only an access token — an opaque string that lets us request your balances, never your password. If you revoke access in Plaid's portal, our access ends immediately.
All Plaid access tokens and sensitive fields are encrypted with AES-256-GCM before being written to our database. The encryption key is stored separately in our server environment.
Every connection to Cresara is over HTTPS. The .app top-level domain enforces HTTPS at the browser level — the site won't even load without it.
We don't use passwords. Sign-in is via a one-time code sent to your verified email. Sessions expire after 30 days of inactivity. Compromised email means compromised account — so we recommend strong 2FA on your email provider.
If you discover a security vulnerability or have a security concern, email security@cresara.app. We'll acknowledge within 24 hours and work to resolve quickly. Cresara is operated by Cresara LLC, Delaware, United States.
We want to be transparent about what we're not (yet):
For these reasons, we recommend Cresara as a tracker and overview tool — not as your only record of important financial data. Always retain official statements from your financial institutions.