Skip to content

Last reviewed

Privacy policy

This policy explains what TxnFlow collects when you use it, why, who processes it, how long it is kept, and the rights you have over it. TxnFlow is operated by Omer Zahid Bajwa, an individual based in the United Arab Emirates(“we”, “us”).

Who we are

Omer Zahid Bajwa operates TxnFlow and is responsible for your data. For anything in this policy, email support@txnflow.app.

What we collect

  • Your account: your email address and the sign-in records Supabase Auth keeps for it.
  • What you upload: your statement PDFs and everything read from them (accounts, balances and transactions), plus your categories, rules and budgets.
  • Model usage records: for each reading of a statement, the tokens used, the cost, the duration, the model and any error message.
  • Request logs: your IP address, browser, the pages you request and any errors, kept briefly by our hosting providers.
  • Emails you send us: your message, your address and any attachments.

We never ask for or hold your bank login. We take no payments yet, so we hold no payment details.

Why we collect it

  • To provide the service you asked for: reading your statements, checking that they reconcile, and showing your ledger and reports.
  • To keep accounts secure and the service working, and to prevent abuse.
  • To answer you when you contact us.

Where data protection law asks for a legal basis, ours is that the processing is needed to provide the service you signed up for, and, for security logs, our legitimate interest in keeping the service safe. We don't sell your data or use it for advertising.

Who processes it

A small number of companies process your data on our behalf so that TxnFlow can run. The security page lists each one, what it handles and where. We don't share your data with anyone else unless the law requires it.

Where it is processed

  • Supabase: United States (AWS us-east-2, Ohio)
  • Vercel: United States (iad1, Washington, D.C.)
  • Google (Gemini API): Google's infrastructure; the Gemini API offers no choice of region
  • Google Cloud Run (our decryption service): United States (us-east1, South Carolina)
  • Cloudflare (Email Routing): Cloudflare's global network
  • Google (Gmail): Google's infrastructure

If you live outside the United States, using TxnFlow means your data is transferred there.

How long it is kept

Your statements and everything read from them are kept until you delete them or close your account. Logs expire on their own within 30 days. Before each change to the database's structure we take one full copy of it, kept on an encrypted disk and deleted 30 days after the change is verified. Support emails are kept for 12 months after the conversation ends. The security page sets out each item, where it is kept, and what removes it.

Your rights

You can ask to access, correct, delete or take a copy of your data, or object to how we use it. Much of this you can do yourself: delete uploads, statements and accounts in the app, and export your ledger as CSV or Excel. To close your account, or for any other request, email support@txnflow.app from the address you signed up with. We handle requests within 30 days. You can also complain to the data protection authority where you live.

Cookies

  • Supabase sign-in cookies, which keep you signed in. They are strictly necessary.
  • Two preference cookies inside the app: whether the sidebar is collapsed (kept for 7 days) and how the accounts page is laid out (kept for a year).
  • Your light or dark theme choice, kept in your browser's local storage.

There are no analytics or advertising cookies.

Children

TxnFlow is not meant for anyone under 18, and we don't knowingly collect their data. If you think a child has given us data, email us and we'll delete it.

Changes to this policy

When this policy changes, we update the date at the top. For significant changes we tell account holders by email before they take effect.

Contact

Omer Zahid Bajwa, United Arab Emirates. support@txnflow.app