Your bank statements are nobody's business. Not your landlord's, not your employer's, and honestly, not ours either.
WonderFunds is built so that we ourselves can't figure out which financial data belongs to which person. Sounds odd for a finance app. That's exactly the point.
Two Vaults Instead of One
Imagine your financial data sitting inside a vault. Good start. But the key to that vault isn't just lying next to it. It's locked inside a second vault. And the second vault has its own key that only the system knows.
Even if someone breaks into the building (meaning: gets access to the database), they're standing in front of two locked vaults. Without both keys, they get nothing.
That's essentially what experts call AES-256-GCM, an encryption standard used by banks and governments. You don't need to know more than that. But if you do want the details, we've written a deeper technical article about it.
No Name on the Vault
With most finance apps, your spending sits right next to your profile. Name, email, transactions, all in one row.
WonderFunds works differently. Your financial data isn't linked to your name or email. Instead, we use a randomly generated code called a data token. This code has zero connection to your identity. It's just a long, random string of characters.
The link between your account and this code? Encrypted. Twice. See: the two vaults above.
What this means: even if someone copies the entire database, they see financial data without owners and user accounts without financial data. The connection only exists in encrypted form, and without the right keys, it can't be recovered.
What Happens When You Delete Your Account?
The key gets destroyed. Not archived, not deactivated. Deleted.
Without the key, the link between your account and your financial data can never be restored. This is called crypto-shredding and it's one of the most secure methods for permanently separating data.
On top of that, we delete all the financial data itself: transactions, categories, rules, everything. Not moved to a trash folder. Gone for good.
More about your deletion rights in our privacy policy.
No Bank Connection Needed
WonderFunds never connects to your bank. No access to your online banking, no third parties seeing your login credentials.
You upload your bank statements yourself, as CSV or PDF. WonderFunds reads the file, extracts the transactions, and deletes the original file immediately. No bank statement ever stays on our servers.
You decide what goes in. And you decide when it comes out.



