How your account is protected

Security, explained plainly.

PerkMind locks on every launch, verifies your identity through Sign in with Apple, and keeps your wallet and session in your device's Keychain. Here's exactly what that means.

1

App-lock by default

PerkMind starts locked on every launch. You sign in with Sign in with Apple, verified through Supabase Auth, and your session is required for every protected request.

2

Optional authenticator-app MFA

You can enroll a TOTP authenticator app for multi-factor authentication. Once enrolled, protected bank and account requests require that second factor.

3

Keychain-backed storage

Your session tokens, wallet cards, and cached financial data are stored as Keychain items with kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly accessibility — device-local, not exportable, and unreadable before first unlock.

Wallet cards

What PerkMind will — and won't — ever ask for

PerkMind's wallet is built around display-safe metadata, not payment credentials. It's designed so a data export or device compromise can't expose a usable card number.

✓
Card nickname, issuer, product, network, and reward metadata

Used to power recommendations and the card art display.

✓
Optional last four digits, cardholder name, expiration, and signup-offer terms

Stored only in your device's Keychain — used to match synced transactions and track offer progress.

✕
Full card number

Never requested. If you use card scan to fill the form, the full number is processed only in memory on-device and never persisted.

✕
CVV, PIN, or signature

Never requested, never stored, never transmitted.

Sign-in & MFA

Sign in with Apple, verified server-side

PerkMind uses Sign in with Apple for identity, and every session is verified through Supabase Auth rather than trusted from the device alone.

  • Apple's identity token and nonce are verified by our backend on every sign-in.
  • Session tokens live in the iOS Keychain, refresh automatically, and are required for every protected request.
  • Optional authenticator-app MFA raises your session to a higher assurance level; once enrolled, bank and account requests require it.
Financial sync

Your bank credentials never touch this app

When you connect an account, Plaid Link opens so you can sign in to your bank with Plaid — PerkMind never sees or stores your bank credentials.

  • Plaid gives our backend (a Supabase Edge Function) a token, which we exchange and store encrypted with AES-256-GCM behind per-user row-level security.
  • Accounts and transactions are fetched when you sync, passed to your device, and cached there in the Keychain — we do not intentionally persist your transactions on our servers.
  • You can disconnect any linked institution individually from Settings; we verify it's yours, remove it with Plaid, delete its stored token, and clear its cached data from your device.
  • All traffic between the app, our backend, and Plaid is encrypted with TLS.
In plain terms

What we want you to know

PerkMind's reward, benefit, and credit figures are estimates generated from catalog data and your synced transaction history — not a live feed from your card issuer. Always confirm reward terms, statement credit balances, and benefit eligibility directly with your issuer before relying on a number PerkMind shows you.

If you'd like more detail on any part of this page, want to report a vulnerability, or you're evaluating PerkMind for an organization and need a written security summary, reach out to security@perkmind.app or from the Support & Contact page. For how your data is collected and used, see our Privacy page and full Privacy Policy.

Get PerkMind

Know which card wins — download PerkMind.

Available for iPhone and iPad on the App Store. Sign in with Apple and add your first card in minutes.

Download on the App Store Coming Soon