Back to home

Trust

Security

Practical information about how Recontraq treats account access, financial data, imports, security reporting, and user controls.

Last updated: 19 July 2026

Account Access

Recontraq requires authenticated access before user financial records are shown. The app supports email authentication and social sign-in paths in the product environment.

Transport and Hosting Security

Recontraq is served over HTTPS-facing infrastructure. The app server sets security headers including HSTS, X-Content-Type-Options, X-Frame-Options, and a strict referrer policy.

Bank and Import Data

Connected-bank and imported transaction data is used to provide account, cashflow, category, vendor, subscription, insurance, and reporting workflows. Recontraq should be treated as a sensitive financial-data environment even where the app is not moving money.

Data Controls

The app includes settings for connected banks, data sharing, export-my-data, categories, notifications, help, privacy, terms, and account deletion workflows. Some controls may depend on the app version and backend availability.

Incident Reporting

Report suspected unauthorised access, account misuse, data exposure, or security issues to [email protected]. Include the affected account email, a concise issue description, screenshots if safe to share, and the time you noticed the issue.

Responsible Disclosure

Do not access, change, copy, or destroy another user's data. Do not run intrusive tests against production systems. Send reproducible details to [email protected] so the issue can be triaged.