Security at LumynFi
Security starts with collecting less. Because LumynFi never connects to your bank and never asks for your banking credentials, the most sensitive data simply isn't there to lose. On top of that, we protect what you do store with encryption, isolation and disciplined access.
Last updated: June 29, 2026
Less data, by design
LumynFi is a record-keeping organizer, not a bank connection. You enter your own balances and transactions, so we never receive your online-banking logins, account PINs, card numbers or CVV codes. This privacy-first model removes an entire class of risk that aggregator-style apps carry.
Encryption
All traffic between your device and LumynFi is encrypted in transit using HTTPS/TLS. Sensitive fields are encrypted at rest, and our database backups are encrypted as well. Passwords are never stored in plain text. They are stored using a strong one-way hash.
Data isolation
Every record is scoped to the account that created it. Our application enforces that you can only ever read and write your own data, so one user's information is never exposed to another.
What we will never ask for
To keep you safe from phishing and fraud, it helps to know what a legitimate LumynFi screen or message will never request:
- Your online-banking username or password
- A bank account PIN or card PIN
- A full card number, expiry date or CVV
- A one-time passcode or banking authentication code
If anything ever appears to ask for these in LumynFi's name, do not provide them. Report it to us instead.
Backups and resilience
We take regular, encrypted backups so your records are protected against hardware failure or accidental loss, and we monitor the service to keep it available and responsive.
Your part in security
- Use a strong, unique password for your LumynFi account.
- Keep your devices and browsers up to date.
- Be alert to phishing, because we will never ask for banking credentials.
- Sign out on shared devices and contact us if you notice anything unusual.
Responsible disclosure
We welcome reports from security researchers. If you believe you've found a vulnerability, please email security@lumynfi.com with the details so we can investigate and address it promptly. We ask that you give us a reasonable opportunity to fix an issue before disclosing it publicly.
Continuous improvement
Security is ongoing. We review our practices as the product grows and improve our safeguards over time. For privacy-specific details about what we collect and how we use it, see our Privacy Policy.
Questions about this document? Reach us at hello@lumynfi.com. LumynFi is a personal-finance organizer, not a bank, and it does not provide financial, investment, tax or legal advice.