Security & privacy
Your giving history is personal financial data. Here's exactly how we treat it — no more, no less.
Sign-in without stored passwords
WriteOff Wallet authenticates through OAuth 2.0 — sign in with Apple, Google, or an email/password account managed by our identity provider (Auth0). We never store your password on our servers, because we never see it.
Encrypted in transit and at rest
All traffic between you and WriteOff Wallet runs over TLS (HTTPS, enforced with HSTS). Your data — donations, photos, receipts — is encrypted at rest in our cloud infrastructure.
You choose who sees your records
Donation records belong to a household, and only its members can see them: the owner and the people the owner has invited. Remove a member and their access ends immediately. There's no public profile and no social layer — your giving is nobody else's business.
Support without exposed mailboxes
Our support runs on a case system behind a contact form — you get a case number and threaded replies, and we don't scatter personal mailboxes across the internet for scrapers to find.
Your data is yours to take
Export your donation records as an itemized annual PDF summary anytime. If you stop subscribing, you keep read-only access through the end of that tax year — and you can still download your annual summaries after that.
Retention, honestly
We keep your records for as long as your account exists, so they're there when tax questions arrive years later. Want them gone? Contact us and we'll delete your account and its data. (In-app account deletion is on our near-term roadmap.)
No ads. No data sales. Ever.
We don't run ads, we don't sell or share your data for advertising, and we don't monetize your giving history in any form. You pay a simple yearly price (see pricing) and that's the entire business model.
Found a security issue? Please report it responsibly through our contact form — we read every report.