Effective date: October 7, 2026 · Last updated: October 7, 2026
Security
In transit and at rest
The site uses TLS 1.2 or newer and HSTS with a two-year max-age, including subdomains, and is eligible for preload.
Account data is stored with Supabase on AWS. Mobile builds are planned to use an encrypted on-device database.
Who can read a row
Row-level security limits each account to its own rows. Sign-in is email and password, Google, or Apple when that provider is connected.
We never ask for a bank password. Card numbers are handled by Stripe. We do not see the full card number.
Report a problem
Email support@piximoney.com. The policy file is at /.well-known/security.txt.
If we confirm an incident that affects your account, we will email the address on the account.