Security and trust
What we collect, and why
| Data | Why | Where it lives |
|---|---|---|
| First name and email (waitlist) | To hold your founding spot and email you when the scan is ready | Supabase database, Canada (ca-central-1, Montreal region) |
| Referral code and who referred you | So shared links move people up the list | Same database |
| Anonymous site analytics | To see which guides people read | Google Analytics, with consent mode on; our own visits are filtered out |
| Your bank statement in the scan | To show you a Leak Receipt | Your browser only. It is never uploaded. See below. |
The statement scan never leaves your device
The free scan at loonifinancial.com/scan reads your CSV with your browser's own file reader and does the maths on your device. The page makes no network request with your file. You can confirm this yourself: open your browser's developer tools, watch the Network tab, and run the scan. Close the tab and the file is gone.
How the waitlist is protected
- Encrypted in transit. The site and every form use HTTPS only.
- Encrypted at rest. Our database provider (Supabase) encrypts stored data on disk.
- Stored in Canada. The database runs in the Canada (Montreal) region.
- Locked tables. Row level security is switched on for every table. Public visitors can submit to the waitlist and nothing else. Reading the list needs an operator login held by the founders.
- Secrets in a vault. API keys and tokens live in an encrypted vault, not in code.
- Confirmed emails only. You are not on the list until you click the link we email you. We also block throwaway domains and obvious bot entries.
- No selling, no sharing for marketing. Your email goes to one email provider (Resend) to send you our messages, and nowhere else.
What you can ask us to do
Email hello@loonifinancial.com from the address you signed up with and we will, within 10 business days: show you what we hold about you, correct it, or delete it entirely. Unsubscribing is one reply. This is how we meet our obligations under PIPEDA, Canada's federal privacy law. Full details are in our privacy policy.
What is not built yet (honest list)
| Item | Status |
|---|---|
| Bank account connections (read-only, through a licensed aggregator) | Planned. Not live. Nothing connects to a bank today. |
| User accounts and two-factor login | Planned, with the app launch. |
| One-tap data deletion inside the app | Planned. Today it is by email, within 10 business days. |
| Independent security audit or penetration test | Not done yet. Planned before any bank connection goes live. |
| SOC 2 or similar certification | Not started. |
| Public bug bounty | Not yet. Responsible disclosure is open now, see below. |
We will update this page when each item ships. We will not say a thing is done until it is.
Found a security problem?
Email hello@loonifinancial.com with "Security report" in the subject. We read every one, reply within 3 business days, and will credit you here if you want. Please do not access other people's data or disrupt the service while testing.
Who runs Looni
Looni is built in Ottawa, Ontario by a small founding team. The founder worked in Canadian banking and started Looni because fees and leaks hide in plain sight on statements. Questions about anything on this page: hello@loonifinancial.com.