Your will is end-to-end encrypted#

End-to-end encrypted

It is encrypted on your phone before anything is sent. What reaches our servers is a block of unreadable data — unreadable by us, by anyone we hand it to, and by anyone who compels us.

What is sealed

  • Your will

    Heirs, estate, bequests, funeral wishes, and who you appointed.

  • Every heir's share

    Worked out by the farāʾiḍ engine on your phone. A server that cannot read your heirs cannot divide your estate — so your phone does it.

How it works

  • AES-256-GCM

    Authenticated encryption, so altered data is refused rather than silently decrypted into something wrong.

  • A 256-bit key, made on your device

    Generated the first time you need one. It is never sent to us.

  • Sealed before it is sent

    Your phone encrypts, then uploads. The network carries ciphertext, and so does every backup and every log.

  • Read on a computer without handing over the key

    A one-time link carries the key after the #, the part of an address a browser never sends to a server. The will is decrypted in your browser.

Where the key lives

On your phone, and in your iCloud Keychain so it reaches your other devices — which Apple encrypts with a key Apple does not hold either.

We do not have a copy. That is the point, and it is also the risk: lose every device with iCloud Keychain off, and nobody can recover your will. Not even us.

Your income, expenses, savings and assets are encrypted in transit and at rest, but not end to end — see what we can and cannot see, below.

What we can and cannot see#

Encryption at rest protects your data against a stolen disk; it does not stop us reading it. So here is exactly where the line falls.

Stored with us, and readable by us

  • Your email address, or the identifier that comes with signing in through Apple or Google.
  • The income, expenses, savings, assets and settings you enter, so they sync across your devices.
  • A receipt photo — but only if you ticked “keep image” when you saved it.

Never sent to us, or unreadable to us

  • Your will. We hold ciphertext; the key stays in your iCloud Keychain.
  • Your bank logins. The app never asks for them.
  • Receipt photos you did not keep. They are read on the phone and stay there.
  • Your app passcode. It is held in the iOS Keychain on your device.
  • Your phone number, address, contacts, location or advertising identifier. The app does not ask for them.

How the app is built#

Your will is sealed before it leaves the phone

Wassiyah — your will, its heirs, what you own and who carries it out — is encrypted on your device with a key held in your iCloud Keychain. Rizq Trackr stores ciphertext it cannot read, and no employee, court order or database leak changes that. Reading it on a computer uses a one-time link whose key sits after the # — the part browsers never send to a server. The cost is real and worth stating: lose the key and the will is gone, because there is no copy to recover it from.

It never connects to your bank
There is no Plaid, no open-banking link, and no screen that asks for banking credentials. You enter figures yourself. That is slower, and it means a breach here cannot reach your accounts.
Receipts are read on your device
Scanning uses Apple’s Vision framework on the phone itself — the text is extracted locally and only the amount, date and merchant are saved. The photo is uploaded only if you tick "keep image"; leave it unticked and the picture never leaves the device.
A check before we email you a code
Asking for a sign-in code makes us send mail, so the web asks Cloudflare Turnstile to confirm a real browser made the request. It is usually invisible — it watches how the page behaves rather than asking you to identify traffic lights — and it stops a script having us post codes to strangers. The check is verified on our server, not just in the page, because a widget nobody verifies is decoration.
Passkeys, not passwords
Sign-in supports passkeys, Apple and Google — credentials that cannot be phished or reused, because there is no password to steal. Email codes are single-use and expire in minutes.
A separate lock on the app itself
An app passcode with Face ID or Touch ID, held in the iOS Keychain. Someone holding an unlocked phone still cannot open your figures.
Encrypted in transit and at rest
Every request is HTTPS. Data is stored on Convex, which encrypts at rest; the app adds no unencrypted side channel of its own.
It asks for very little
An email address, and the figures you choose to enter. No phone number, no address, no contacts, no location, no advertising identifier, and no third-party analytics watching what you do.

What you control#

Your data is yours, and leaving should be as easy as arriving.

Export everything
A full export of your records, from Profile, in a format you can open elsewhere.
Delete your account
Permanently, from inside the app. It removes your records rather than flagging them hidden.
See your devices
Sign out of other devices from Profile → Security whenever you want to.
Security email
You are told when a new device signs in, or when something looks wrong. These are never affected by marketing preferences.

What has not been done yet#

A security page that lists only strengths is a marketing page. These are real gaps, stated plainly, and each line stays here until it stops being true.

No third-party security audit
Nobody outside the project has reviewed the code or the infrastructure. There is no SOC 2 report and no ISO 27001 certification, and this page will not claim one before it exists.
No penetration test
The app has not been tested by a professional attacker. That is planned before wider release, not done.
No bug-bounty programme
There is no paid disclosure programme yet. Reports are still very welcome — see below — and will be answered by a person.

Questions about security#

No. It is encrypted on your phone with a key held in your iCloud Keychain, and we store only the ciphertext. That also means we cannot recover it for you: lose the key and the will is gone.

Found something?#

If you have found a vulnerability, please tell us before telling anyone else. Include what you did and what you saw; a proof of concept helps but is not required.

security@rizqtrackr.com

A person reads this address and will reply within a few days. We will not take legal action against anyone reporting a genuine issue in good faith.