Security

Public overview of application and data protection

Service Operator

OPHIR is operated by:

Soavinjato Andrianarisoa
1203 Rue Normont
Laval, Québec H7G 3H3
Canada

Security concerns and support: support@joinophir.app
Privacy inquiries: privacy@joinophir.app
General and legal inquiries: contact@joinophir.app

At a Glance

TopicOPHIR's Approach
PurposeOPHIR helps users understand and organize personal and household finances.
Banking activityOPHIR is not a bank, does not hold user funds, and does not transfer money.
Account connectionSupported financial accounts may be connected through Plaid and the relevant financial institution's interface.
Online banking passwordUnless OPHIR expressly states otherwise, the application does not receive or store your online banking password.
Data protectionOPHIR uses administrative, organizational, contractual, technical, and physical safeguards appropriate to the sensitivity of the information and the risk.
Sale of dataOPHIR does not sell or rent personal or financial information.
Reporting a concernIf you suspect unauthorized access or a vulnerability, contact support@joinophir.app.

1. Purpose and Scope

This overview explains how OPHIR seeks to protect:

  • user accounts;
  • personal and financial information;
  • connected financial account data;
  • budgets, categories, goals, notes, and settings;
  • technical logs, tokens, and identifiers;
  • the mobile application, web pages, and support interfaces;
  • systems and service providers involved in delivering the Service.

Security is a shared responsibility among OPHIR, infrastructure providers, Plaid, financial institutions, Apple, Google, and the user. Each party protects the systems and information under its control.

This document supplements the OPHIR Privacy Policy, Terms of Service, and Application Technologies and Cookies Policy. If there is a conflict, the applicable legal document and mandatory law will govern.

2. OPHIR's Security Model

OPHIR treats financial information as sensitive. Safeguards are selected with regard to:

  • the nature and sensitivity of the information;
  • the volume and retention period;
  • how the information is used and transferred;
  • the likelihood of unauthorized access or disclosure;
  • the potential harm to a user;
  • the state of technology and emerging risks.

No single safeguard eliminates every risk. OPHIR therefore uses a layered approach in which organizational rules, access restrictions, infrastructure protection, secure development, monitoring, and incident response support one another.

3. Data and Function Limitation

Reducing the amount of data can reduce the potential consequences of an incident. OPHIR seeks to:

  • collect only information needed for selected features;
  • request through Plaid only the data categories needed for activated features;
  • not use connected financial account data for behavioural advertising;
  • not retain information longer than needed for stated purposes, security, and legal compliance;
  • delete or de-identify information in accordance with applicable retention rules;
  • limit financial content in diagnostic logs.

OPHIR is designed to analyze and organize financial information. Unless a separate feature is expressly implemented and disclosed, OPHIR does not:

  • open bank or investment accounts;
  • hold client funds;
  • issue payment cards;
  • execute payments, transfers, or securities trades;
  • request full account and routing numbers for moving money;
  • receive your full payment card number when a subscription is purchased through the Apple App Store or Google Play.

4. Account Protection

Depending on the features actually available, account protection may include:

  • authentication checks;
  • protected session tokens with limited validity;
  • session termination or revocation after sign-out, expiry, or detection of risk;
  • identity verification before a sensitive request is completed;
  • rate limits and other controls against automated abuse;
  • notices about material security events;
  • use of protected operating-system mechanisms for local secrets;
  • on-device biometric unlocking when enabled by the user and supported by the application.

A biometric template used by Face ID, Touch ID, or a similar Android feature is generally evaluated by the device operating system. Unless expressly stated otherwise, OPHIR receives the result of the check, not a copy of the biometric template.

5. Connecting Financial Accounts Through Plaid

When a user chooses to connect a financial account, OPHIR may open Plaid Link or a protected interface of the financial institution. The user selects the institution, completes the required verification, and authorizes access to specified data.

Depending on the financial institution:

  • authentication may occur directly on the institution's website or application;
  • Plaid may provide the protected connection and transfer authorized data;
  • the institution may require multi-factor or renewed authentication;
  • the user may be able to select available accounts and data categories;
  • the connection may require periodic consent renewal.

Unless OPHIR expressly states otherwise, the application does not receive or store your online banking password. Never send a banking password, PIN, one-time code, or full card number in notes, assistant messages, or support requests.

Plaid is an independent provider with its own technologies, policies, and responsibilities. Plaid publishes information about security, connection management, and data handling:

Disconnecting an account in OPHIR or Plaid stops or limits future data retrieval in accordance with available features, but it may not automatically delete information previously imported into OPHIR. Deletion of that information is governed by the Privacy Policy and the account and data deletion process.

6. Transmission, Storage, and Access

OPHIR uses safeguards appropriate to the sensitivity of financial information, including, where applicable:

  • encryption of data in transit;
  • protection of stored data through infrastructure controls;
  • separation of production, testing, and local environments;
  • management of secrets, tokens, and keys;
  • restricted administrative access;
  • multi-factor authentication for administrative access;
  • role-based and need-to-know access controls;
  • logging of significant security events;
  • backup and recovery measures;
  • secure deletion or de-identification at the end of the retention period.

Access to personal information should be granted only to people and providers who need it for a defined work purpose. Such access is limited by confidentiality obligations, contractual terms, and technical permissions.

OPHIR does not publish information about specific keys, backup locations, firewall rules, cloud configurations, or threat-detection mechanisms.

7. Secure Development and Operations

OPHIR's development and operational approach includes, where appropriate:

  • considering privacy and security requirements when designing features;
  • reviewing changes before release;
  • managing dependencies, libraries, and SDKs;
  • limiting secrets in source code and logs;
  • remediating known vulnerabilities according to risk;
  • updating the application, server components, and infrastructure;
  • reviewing application permissions and the amount of data transferred;
  • assessing providers before giving them access to sensitive information;
  • testing recovery and incident-response procedures;
  • periodically reviewing safeguards as technology and threats change.

Application updates may contain important security fixes. Using an outdated application version or unsupported operating system may limit functionality or increase risk.

8. Monitoring and Abuse Prevention

To protect the Service, OPHIR may process limited technical information and security logs, such as:

  • sign-in time and the technical result of an attempt;
  • account, installation, or session identifiers;
  • device type, application version, and operating system version;
  • IP address and approximate region;
  • error codes and crash information;
  • token-revocation or reauthentication events;
  • indicators of unusual, automated, or prohibited activity.

This information is used to prevent abuse, investigate errors, protect infrastructure, and respond to incidents. OPHIR seeks to limit the volume of logs and does not use them to sell user profiles.

9. Service Providers and Third-Party Services

OPHIR may use providers for:

  • financial data connectivity;
  • cloud hosting and databases;
  • authentication and access management;
  • backups;
  • crash and performance diagnostics;
  • message and notification delivery;
  • subscription verification;
  • user support and abuse prevention.

Before granting access, OPHIR should assess the necessary data, purposes, risks, processing location, and available safeguards. Providers may process information only for agreed services and under applicable contractual, confidentiality, and security obligations, except where they independently determine processing under their own policies.

Apple, Google, Plaid, and financial institutions protect their own platforms and process certain information under their own terms and policies. Their safeguards should not be treated as certification or a guarantee of OPHIR's security.

10. Incident Response

OPHIR maintains a process for:

  • receiving and validating a report;
  • containing a suspected threat;
  • preserving necessary records;
  • identifying affected systems and data;
  • assessing information sensitivity and the likelihood of harm;
  • remediating the cause and restoring service safely;
  • documenting the incident and actions taken;
  • notifying users, regulators, or other organizations when required by law;
  • reviewing safeguards after the incident.

If an incident creates a legally defined risk of serious harm, OPHIR will provide required notices within the applicable time. A user notice may describe the event, the categories of information involved, OPHIR's response, and recommended actions.

OPHIR maintains incident records to the extent and for the period required by applicable law.

11. What Users Should Do

Users also influence the security of their information. We recommend that you:

  • protect your device with a passcode and available biometrics;
  • use a unique, strong password for OPHIR and your email account;
  • enable multi-factor authentication where available;
  • never share a password, PIN, or one-time code;
  • do not enter secret banking information in notes or support messages;
  • install application and operating-system updates;
  • download OPHIR only from an official store or official link;
  • verify the website address and message sender before following a link;
  • reject unexpected sign-in or multi-factor authentication requests;
  • sign out on a shared or third-party device;
  • review connected accounts and disconnect connections you no longer need;
  • immediately report a lost device or suspicious activity.

OPHIR should never ask you to email your full online banking password, full payment card number, PIN, or one-time authentication code.

12. Lost Device or Suspected Compromise

If your device is lost, your account is compromised, or you notice unusual activity:

  • secure the email account associated with OPHIR;
  • change your OPHIR password if that feature is available;
  • end active sessions or contact support;
  • disconnect financial connections you no longer need;
  • if necessary, change banking credentials through your financial institution;
  • review transactions and notify the financial institution of suspicious activity;
  • contact support@joinophir.app from the email address associated with the account.

Do not include a banking password, full card number, PIN, or one-time code. OPHIR may request reasonable identity verification before changing access or disclosing information.

13. Reporting a Vulnerability

If you believe you have found a vulnerability in OPHIR:

  • email support@joinophir.app;
  • provide a concise description and identify the affected feature;
  • include safe reproduction steps, application version, and device model where relevant;
  • do not include another user's personal or financial information;
  • do not use the vulnerability to access, change, or delete another person's information;
  • do not disrupt the Service or use social engineering;
  • allow OPHIR reasonable time to investigate and remediate the issue before public disclosure.

A report does not create a right to payment. If OPHIR introduces a separate vulnerability disclosure or reward program, its specific terms will be published separately.

14. Limitations

No digital system, encryption method, or provider can guarantee absolute security. The internet, mobile devices, financial institutions, and third-party platforms may experience outages, errors, and attacks.

This overview:

  • is not a guarantee that incidents will never occur;
  • does not replace the terms of Plaid, Apple, Google, or a financial institution;
  • does not mean OPHIR is certified under a standard that is not expressly identified here;
  • does not contain a complete list of internal safeguards;
  • may be updated as features, technologies, risks, or legal requirements change.

OPHIR will communicate material changes in a manner appropriate to their nature and applicable law.

15. Related Documents

For a complete understanding of how information is handled and protected, review:

OPHIR's approach takes account of applicable requirements and guidance, including:

  • Quebec's Act respecting the protection of personal information in the private sector - legisquebec.gouv.qc.ca;
  • guidance from the Office of the Privacy Commissioner of Canada on safeguards and breaches - priv.gc.ca;
  • guidance from the Canadian Centre for Cyber Security on account protection and multi-factor authentication - cyber.gc.ca.

16. Contact

Security concerns and suspicious activity: support@joinophir.app
Privacy and personal information requests: privacy@joinophir.app
General and legal inquiries: contact@joinophir.app

Mailing address: Soavinjato Andrianarisoa, 1203 Rue Normont, Laval, Québec H7G 3H3, Canada

Do not send your online banking password, full payment card number, PIN, one-time authentication code, secret key, or other confidential credentials.