Skip to content

Security and privacy

TxnFlow never asks for your bank login: you upload the PDF statements your bank already gives you. This page lists every company that processes them, how long each piece is kept, and how to delete it.

Do you need my bank login?

No. TxnFlow works only from PDF statements you upload. It never connects to your bank, never asks for online-banking credentials, and holds none.

Where does my data go?

These companies process your data so that TxnFlow can run. No one else receives it.

CompanyWhat forWhat it handlesWhere
SupabaseDatabase, sign-in (including confirmation emails) and file storageYour account email and sign-in records, uploaded PDFs, the statements and transactions read from them, and model usage recordsUnited States (AWS us-east-2, Ohio)
VercelHosting the site and app, and running the background workerEvery request, including each PDF held in memory while the worker sends it to Google for readingUnited States (iad1, Washington, D.C.)
Google (Gemini API)Reading each statement PDF to extract its transactions and balancesThe PDF, sent with the request, and the rows the model returnsGoogle's infrastructure; the Gemini API offers no choice of region
Google Cloud Run (our decryption service)Unlocking a password-protected PDF that the app's built-in decryptor cannot open (only for password-protected pdfs the built-in decryptor fails on)That PDF and its password, held in memory for the request; the password is never loggedUnited States (us-east1, South Carolina)
Cloudflare (Email Routing)Forwarding email sent to our support address to our inbox (only for email you send us)Your message, your email address and anything you attachCloudflare's global network
Google (Gmail)Our support inbox (only for email you send us)Your message, your email address and anything you attachGoogle's infrastructure

TxnFlow takes no payments yet. When it does, the payment provider will be added to this list.

How are password-protected PDFs handled?

Your browser checks the password against the file first, so a mistyped password is normally caught before anything is uploaded. The password is then sent with the upload, used on our server to unlock the file in memory, and discarded: it is never stored or logged. The unlocked PDF replaces the encrypted copy.

If the built-in decryptor can't open a file for a reason other than the password, the file and password go to our own decryption service on Google Cloud Run, which holds both in memory for that one request and never logs the password.

How long is it kept?

WhatWhereKeptRemoved by
Uploaded PDFSupabase StorageUntil you delete its uploadDeleting the upload. Deleting a statement or an account does not remove the PDF; delete the upload too.
Temporary copy of a password-protected PDFSupabase StorageUntil the PDF is unlocked, moments after uploadRemoved automatically once the file is unlocked. If an upload is abandoned partway, the copy can remain; ask us to remove it.
Statements and transactionsSupabase databaseUntil you delete the statement, its account or its uploadDeleting any of the three removes them
Accounts (bank name, currency, account type, the last four characters of the account number, latest balance)Supabase databaseUntil you delete the account; deleting an upload or a statement leaves itDeleting the account, or closing your account
Categories (yours, and the standard ones an import adds)Supabase databaseUntil your account is closed; the app has no way to delete a categoryClosing your account
Rules and budgets you set upSupabase databaseUntil you delete themDeleting them in the app, or closing your account
The model's raw output (every transaction, balance and account number it read)Supabase databaseUntil you delete the uploadStripped when the upload is deleted
Model usage records (tokens, cost, duration, model, error messages)Supabase databaseAfter the upload is deleted, with no expiry today; they no longer hold the extracted rowsClosing your account
PDF passwordsNowhereNever stored or loggedNot applicable
Account email and sign-in recordsSupabase AuthUntil your account is closedEmail us to close your account; we do it by hand within 30 days, deleting everything above. A database copy taken before then keeps your data until that copy is deleted (see Database copies), and support emails follow their own row
Support emailsOur support inbox (Gmail)12 months after the conversation endsDeleted after 12 months, or sooner if you ask, including when you close your account
Request and error logsVercel, Supabase and Google CloudVercel: 1 hour. Supabase: 1 day. Our decryption service: Google Cloud's default of 30 days (method, path and status only)Expire automatically
Database copiesThe operator's own computer, on an encrypted diskSupabase's current plan takes no automatic backups. Before each change to the database's structure, the operator takes one full copy of the database, which is deleted 30 days after the change is verifiedDeleted on that schedule; closing your account does not remove you from a copy taken earlier

How do I delete it?

  • Delete an upload and its PDF, the statements and transactions read from it, and the model's raw output all go with it.
  • Delete a statement or an account and its statements and transactions go, but the uploaded PDF stays in storage. Delete the upload too if you want the file gone.
  • To close your account and have all of your data removed, email support@txnflow.app from the address you signed up with. We do it by hand within 30 days. A database copy taken before then is deleted 30 days after the change it was taken for is verified, and our emails with you are kept for 12 months unless you ask us to delete them too.

How is it protected?

  • Every connection uses HTTPS, and browsers are told to insist on it (HSTS).
  • Supabase encrypts the stored data at rest (AES-256).
  • Every database query is scoped to your account.
  • TxnFlow holds no bank credentials, because it never asks for them.

What reconciliation can and can't prove

The check proves that the rows TxnFlow extracted add up to the balances the statement prints. It can't catch a statement that is itself wrong, or two mistakes that cancel each other out exactly. Statement content is treated as untrusted: text inside a PDF can try to steer the model, and that risk is reduced, not removed, so an answer that is wrong but adds up would still pass. Check anything important against the original.

Certifications

TxnFlow itself holds no security certifications. Supabase and Vercel each hold a SOC 2 Type 2 attestation, and Vercel is ISO 27001 certified.

Reporting a vulnerability

Email support@txnflow.app with the details and the steps to reproduce. Please don't access other people's data or disrupt the service while testing.

Last reviewed