Key takeaways
- Vault defines the privacy-first direction in this comparison: a local manual core, on-device statement or receipt import, local coaching, and an explicitly optional Plaid path.
- A bank connection is a separate permissioned data path involving the app, an aggregator or direct OAuth connection, and the financial institution.
- Vault remains pre-release, so final Plaid scopes, production storage, deletion, pricing, compatibility, and connection behavior still require release verification.
Start with the data path, not the lock icon
Vault is the privacy-first design in this comparison. It is being built so manual budgeting, statement or receipt import, categorization, forecasting, and coaching can work through a local core, with Plaid disclosed as a separate optional path rather than a requirement. Vault remains pre-release. Actual shifts sync responsibility toward self-hosting, YNAB remains an account-based service even when banks are unlinked, and Copilot and Monarch center cloud aggregation. The deciding question is which fields, providers, retention, export, and deletion behavior a person is willing to accept.
Budgeting apps handle unusually revealing context: merchants, medical purchases, travel, income, balances, debt, investments, notes, locations, and household relationships. Convenience can be worth sharing some of that information, but the choice should be explicit. A good privacy review separates five actors: the device, app developer, bank-data provider, financial institution, and any analytics or AI processor. It then asks which one sees credentials, tokens, transactions, derived categories, questions, and forecasts.
| App | Manual or local path | Connected path and important limit |
|---|---|---|
| Vault | Planned manual tracking, on-device statement or receipt import, budgets, categorization, forecasts, and coaching. | Optional Plaid is planned, not released; final scopes, diagnostics, storage, deletion, price, and connection behavior remain provisional. |
| Actual Budget | Local-first database, local accounts, manual entry, and CSV, QIF, OFX, QFX, or CAMT file import. | Optional sync server and bank providers require configuration; bank-sync tokens are not covered by Actual’s budget-data end-to-end encryption. |
| YNAB | Unlinked accounts, manual entry, scheduled transactions, reconciliation, and file import without a bank link. | Optional Direct Import uses supported providers such as Plaid or MX; YNAB remains an account-based cloud product. |
| Copilot Money | Manual accounts and transactions are available for several account types, with stated limits on historic balances and imports. | Connected accounts use aggregators or direct OAuth; Copilot stores service data in cloud infrastructure and documents export and deletion controls. |
| Monarch Money | Manual records may supplement the dashboard, but the product’s central proposition is an aggregated financial home base. | Unlimited connected accounts, integrations, household collaboration, and reporting are included in the subscription service. |
Scroll horizontally to read the complete comparison on smaller screens.
1. Vault: a pre-release local-first path with optional Plaid planned
Vault is being designed for manual expense tracking, budgets, categorization, cash-flow forecasts, and coaching on iPhone and iPad, with on-device statement or receipt import. Optional Plaid is planned for people who decide automatic updates are worth the connected path. In the intended flow, authentication appears in Plaid rather than an Obsidian Ridge Labs password form. Plaid explains that it may use OAuth at supported institutions or collect login data when required by the institution, then share selected financial data with the chosen app. “Vault never sees your password” does not mean “no third party handles authentication.”
2. Actual Budget: local-first control with self-hosted responsibility
Actual Budget is an open-source envelope-budgeting system whose official documentation calls it local-first: the primary database lives on the local device. A user can create a local account, enter transactions, and import financial files without bank sync. Optional sync uses an Actual server, and end-to-end encryption can protect budget data from that server. This architecture offers unusual control, but it also gives the user responsibility for hosting, updates, backups, passwords, and recovery. The official native mobile apps are deprecated; the responsive web app can be installed as a PWA.
Actual’s bank-sync documentation makes an important caveat visible: providers such as SimpleFIN, GoCardless, Pluggy, or regional alternatives require an Actual server and user-supplied credentials, and the server stores bank-sync API secrets or tokens outside the budget file’s end-to-end encryption. That does not make the feature inherently unsafe; it means “the budget is encrypted” is not a complete description of the connected path. Self-hosters should understand server access, token storage, provider scopes, and backup before enabling it.
3. YNAB: manual budgeting inside an account service
YNAB supports unlinked accounts, manual transactions, scheduled entries, reconciliation, and file-based import. Its current help center explicitly describes Direct Import as optional and lets a person create an unlinked account instead. File import can bring QFX, OFX, and other supported bank exports into the web app or iPad without maintaining a bank connection. Those options avoid continuous aggregation, but the budget records still live inside YNAB’s account-based cloud service.
YNAB is still an online account service, not a local-only database. Its privacy notices describe account, product, device, support, and financial data practices, along with service providers and user rights. Direct Import can involve providers including Plaid or MX, depending on location and institution. Compare the manual workflow to the convenience of automatic updates, then read the current policy and import documentation rather than assuming that an unlinked bank also means no financial records are stored by YNAB.
4. Copilot Money: connected intelligence plus newer manual accounts
Copilot Money is available in the United States across iPhone, iPad, Mac, and web. Its help center now documents manual checking, savings, cash, credit card, investment, loan, and real-estate accounts, with manual transactions on selected types. It also explains limitations: historic balances begin when the manual account is created, some account types cannot carry negative balances, and historic balance imports are not supported. That makes manual use possible without pretending it duplicates the history and automation of a connected account.
For connections, Copilot names Plaid, Mastercard Data Connect, and direct OAuth integrations. Its privacy-and-security page says Copilot does not see or store bank login credentials, uses encryption at rest and in transit, offers transactional-data export, and removes integrated financial information after account deletion subject to stated legal exceptions. It also explains that the service runs on Google Cloud and that the cloud provider’s certifications are not Copilot certifications. Those details reveal the remote service boundary more clearly than a generic “bank-grade” claim.
5. Monarch Money: a paid connected household dashboard
Monarch’s value proposition is aggregation: unlimited connected accounts, budgets, cash-flow views, goals, investment performance, reports, integrations, and household collaboration across web, mobile, and iPad. Its official pricing page showed $99.99 billed yearly when checked and states that the subscription is ad-free and the company does not resell financial data. Those claims describe a business model and service commitment; they do not turn a connected dashboard into a local app. A household should still review providers, access scopes, collaboration permissions, retention, export, and deletion.
The privacy checklist to use before any bank connection
- CAN I USE IT UNLINKED? Check manual entry, local accounts, file import, budgets, forecasts, and exports before granting ongoing access.
- WHO HANDLES AUTHENTICATION? Name the aggregator or OAuth institution and determine whether the app developer ever receives the bank password.
- WHAT FIELDS ARE REQUESTED? Balances, transactions, account numbers, identity, investments, loans, and location are different permission scopes.
- WHAT DERIVED DATA LEAVES? Merchant categories, notes, goals, budget questions, support logs, and AI prompts can reveal more than the original transaction.
- HOW DO I DISCONNECT AND DELETE? Revoking bank access, deleting an app account, deleting local records, and cancelling a subscription are separate actions.
- CAN I LEAVE WITH A USEFUL EXPORT? Verify formats, fields, attachments, category history, and whether the export can be restored elsewhere.
Questions, answered plainly
What budgeting app works without linking a bank?
Vault is being designed around manual local use without a required bank connection, including budgets, forecasts, and on-device statement or receipt import. It remains pre-release. Actual Budget, YNAB, and Copilot also document unlinked or manual paths, but each uses a different storage, account, and sync model.
Does using Plaid mean the budgeting app gets my bank password?
Plaid says it does not share the login and password with the connected app. Depending on the institution, authentication may use bank OAuth or Plaid may collect login data needed to connect. Review the live Plaid consent screen and requested fields.
Is a local-first budget automatically safer?
No. Local-first can reduce vendor data movement, but device compromise, weak backups, misconfigured self-hosting, exports, and optional sync can still create risk. It also does not guarantee correct calculations or financial outcomes.
Can an AI budgeting app give financial advice?
Treat generated coaching and forecasts as educational estimates based on incomplete inputs, not personalized financial, tax, legal, credit, or investment advice. Verify important decisions with the relevant statements and qualified professionals.
Sources and further reading
Primary documentation is preferred. Product features and prices can change; verify details before deciding.
- Actual Budget: local-first FAQ
- Actual Budget: bank sync and token caveats
- Actual Budget: importing transactions
- YNAB: add linked or unlinked accounts
- YNAB: file-based import without linking a bank
- YNAB: how optional Direct Import works
- Copilot Money: manual accounts
- Copilot Money: privacy and security
- Monarch Money pricing and included features
- Plaid: how bank connections work
- Plaid privacy and security policies
Meet VAULT
Review Vault’s intended manual path, planned on-device imports and forecasts, optional Plaid boundary, and explicit pre-release limitations.