Authentication
- Google is the initial sign-in provider.
- The app uses cookie-based session auth after sign-in.
- Household permissions are enforced by the app, not the background worker.
SafeSpend is designed to protect household financial data with a minimal-trust approach. This summary captures the current MVP security posture and the direction for the platform.