Security
Your transactions, and what we do with them
How your data gets in
You add your transactions manually: by pasting them directly or uploading a CSV exported from your bank. Nothing is connected to your bank by default, and you can use Tellwise fully without ever connecting an external account.
If you choose to connect an account, the connection is read-only. Tellwise can read transactions to build your forecast. It cannot initiate payments, transfers or any other financial action. The connection can be revoked at any time from Settings, and no further data is pulled after that.
Encryption, in transit and at rest
All data transmitted between your browser and Tellwise's servers uses TLS 1.2 or better. Your transactions and account data are stored encrypted at rest by our database provider.
Your transaction data is never posted anywhere public, never shared with another user, and never sent to any third party other than the model provider that produces your plain-language explanation.
The model provider and training
Your forecast is computed entirely in code, not by a language model. The language model's only job is to write the plain-language explanation of what the numbers say. To do that, a structured summary of your forecast and the relevant patterns is sent to the model provider.
We use the model provider under its business API terms, which prohibit training on API traffic. We do not fine-tune any model on your transaction data, we do not use your data to improve prompts without asking, and we do not sell or license your data to anyone for any purpose.
The summary sent to the model provider does not include your bank account number or any identifier beyond what is needed to produce the explanation. Transaction descriptions may appear in that summary.
Who at Tellwise can see your data
Access to the production database is limited to the engineers who operate it, and it is used to fix problems, not to browse. We do not read customer transaction data for product research.
If you open a support ticket and describe a specific forecast or flag, we may look at the relevant records to answer your question. If you would rather we did not, say so in the ticket and we will work from your description instead.
How long we keep it
- Transactions and forecasts: until you delete them, or until 30 days after you close your account, whichever is sooner.
- Account records: for as long as the account is open, then 30 days.
- Form submissions from contact, help and careers forms: 24 months.
- Server logs, which record request paths and timings but not transaction content: 30 days.
- Backups: rolling 7 days. Once a record is deleted from the database and the next backup cycle runs, it is gone from backups too.
Exporting and deleting your data
From Settings you can export your transactions and forecast history as CSV at any time. You can also delete your account from Settings, which removes your transactions, your forecasts and your account record immediately.
Both export and deletion are immediate and neither requires a support ticket. The Your data page at /your-data walks through both in detail. If you want written confirmation of deletion for your own records, email us and we will send it.
Accounts and authentication
- Passwords are hashed with scrypt and a per-user salt. Nobody at Tellwise can see a password, and we never log one.
- Sessions are httpOnly, sameSite cookies signed with a server-side secret, expiring after 30 days.
- Every request for transaction or forecast data checks that the data belongs to the account making the request, in the database query itself rather than in the application layer.
- Two-factor authentication is available on all accounts and required for any account with administrative access to the service.
Our own security posture
- Two-factor authentication is required on every service Tellwise uses, with no shared logins and no exceptions.
- Production database access is limited to the engineers who operate it and is reviewed quarterly.
- Dependencies are updated on a weekly cadence and security advisories are addressed within 72 hours for anything reachable from production.
- We do not yet hold a SOC 2 report. We are a Pre-Seed company and would rather say that than imply otherwise. If you need a completed security questionnaire for procurement, email us and we will fill it in honestly.
Reporting a vulnerability
Email security@gettellwise.com. We acknowledge within two business days, we will not take legal action against you for reporting in good faith, and we will tell you when the issue is resolved. If you want to be credited, say so and we will credit you.
This page describes what Tellwise does today. The privacy policy is the legal version of the same thing, and the terms of service cover the rest. Your export and deletion controls are always reachable from /your-data. Last reviewed August 2026.