Security & Privacy
Last updated: May 2026 · Lumara takes the security of your financial data seriously.
Encryption
All data transmitted between your device and our servers is encrypted using TLS 1.3. Data stored at rest is protected with AES-256-GCM encryption — the same standard used by major banks. Sensitive fields including Plaid access tokens are encrypted at the column level in our database.
Authentication
Every Lumara account is protected by strong password requirements, rate-limited login to prevent brute-force attacks, automatic idle session timeouts, and optional two-factor authentication (2FA) via authenticator apps like Google Authenticator or Authy.
Bank access
Lumara connects to your bank accounts via Plaid, a trusted financial data infrastructure provider used by thousands of apps including Venmo and Robinhood. Our integration is strictly read-only — we can view your transactions and balances, but we can never move, transfer, or access your funds. We never store your bank login credentials on our servers.
Data privacy
We do not sell your personal or financial data to third parties. We do not serve you ads based on your financial behavior. Your data is used exclusively to power your Lumara experience — insights, goals, and pack accountability.
Responsible disclosure
Found a vulnerability? Email support@wolfpackfinance.app with details. We take all security reports seriously and respond within 24 hours.