Sign-in and reset requests
Email, password, and Google sign-in flows pass through the authentication gateway before a MoneyKai session is accepted.
Authentication requests have server-side safeguards and client-side attempt throttling.
Password reset responses avoid disclosing whether a specific account exists.
Google authentication is handled through the backend-owned flow before Firebase session completion.
Clear, conservative failure handling
MoneyKai uses bounded requests and user-facing errors so access issues can be resolved without revealing sensitive implementation details.
Authentication requests use timeouts instead of waiting indefinitely.
The app validates authentication responses before accepting a session.
Users should never send passwords or verification codes to support.
Need help with a security or privacy concern?
Do not include passwords, verification codes, full card numbers, or sensitive documents in your message.
Contact support
For general security and privacy questions, email support@moneykai.app.