KeepUp shows you your complete financial picture. Because that picture is sensitive, we designed the product so that the worst case is always limited: your money never moves, and your bank logins never touch our servers. This page explains, in plain English, how that works. The legally authoritative detail lives in our Privacy Policy.
KeepUp never holds, moves, or manages your money. There is no transfer button, no payment rail, no trading integration – not hidden, not disabled: it doesn't exist. Every account connection is read-only. If a KeepUp account were ever compromised, the attacker could not move a cent, because KeepUp itself can't.
Bank and brokerage connections run through Plaid – the same connectivity infrastructure used by Venmo and American Express. When you link an account:
Plaid publishes its own security practices, certifications, and sub-processor list at security.plaid.com.
Crypto exchanges – Coinbase, Binance, and Kraken, for users in the United States for now – connect through SnapTrade, on the same read-only terms:
Linking a financial institution requires a passkey – a phishing-resistant check (Touch ID, Face ID, Windows Hello, or a hardware security key) under the FIDO2 / WebAuthn standard, completed moments before the link is created. No passkey enrolled yet? We walk you through it before your first connection. A stolen password or a hijacked session is not enough to connect a bank or expose new accounts on a KeepUp account – few financial apps, including most incumbents, enforce this.
You can download your complete data set as machine-readable JSON at any time ("Download my data" under Account Settings → Your Data). And you can delete your account at any time: your portfolio, snapshots, and connections are removed from our active systems immediately, with Plaid tokens and SnapTrade authorizations revoked first. Hosting-provider backups age out within 30 days. Details in Privacy Policy Section 10.
We want to hear about it, and we'll respond quickly. Email [email protected] with enough detail to reproduce the issue. Good-faith security research is welcome; we won't pursue action against researchers who report responsibly and give us reasonable time to fix. Our machine-readable contact record lives at /.well-known/security.txt.