Security
Updated October 8, 2026
Superworth is made by Cedar Dynamics LLC. This page explains how we protect your data, especially the bank, card and brokerage accounts you connect.
Encryption
- In transit. Everything between the app, the website, our servers and Plaid travels over HTTPS. The iPhone app reaches our servers only over HTTPS.
- At rest. Plaid access keys are encrypted in our database (AES-256-GCM) with a key unique to your household, and that key is itself encrypted with a master key kept only in our server environment. A copy of the database alone never yields a working access key. Your notes, home addresses, the names of assets you add, your private theses and credit report details are encrypted the same way.
How a connection works
- You tap Connect. Our server asks Plaid for a one-time Link token.
- Plaid's own screen opens and you sign in to your bank or brokerage there. Your username, password and security codes go to Plaid and your institution only. They never pass through the Superworth app or our servers.
- Plaid gives us an access key, which we encrypt and store as described above.
- Our server uses it to read your accounts, balances, transactions, holdings and loan details, and keeps them up to date.
- Disconnect in the app and we remove the connection at Plaid and delete its accounts and history from our servers. You can also revoke access at my.plaid.com.
Read-only
We only read. Superworth never asks Plaid for your full account or routing numbers, and it cannot move money or place trades.
Access and logging
- Every read or write of your household's money data is recorded in an audit log with ids only, never amounts or names.
- Our code does not log access keys, encryption keys or the contents of your accounts.
- There is no Superworth password to steal. You sign in with an emailed code, Apple or Google through our own sign-in service.
Your controls
- Disconnect any account in the app at any time.
- Delete your account in the app, under Settings. It deletes your data and disconnects every account at Plaid.
Reporting a vulnerability
If you find a security problem, email [email protected]. We acknowledge reports within three business days and will not take action against good-faith research. Details are in security.txt.
What we collect and who processes it is in the privacy policy.