Security and privacy
TxnFlow never asks for your bank login: you upload the PDF statements your bank already gives you. This page lists every company that processes them, how long each piece is kept, and how to delete it.
Do you need my bank login?
No. TxnFlow works only from PDF statements you upload. It never connects to your bank, never asks for online-banking credentials, and holds none.
Where does my data go?
These companies process your data so that TxnFlow can run. No one else receives it.
| Company | What for | What it handles | Where |
|---|---|---|---|
| Supabase | Database, sign-in (including confirmation emails) and file storage | Your account email and sign-in records, uploaded PDFs, the statements and transactions read from them, and model usage records | United States (AWS us-east-2, Ohio) |
| Vercel | Hosting the site and app, and running the background worker | Every request, including each PDF held in memory while the worker sends it to Google for reading | United States (iad1, Washington, D.C.) |
| Google (Gemini API) | Reading each statement PDF to extract its transactions and balances | The PDF, sent with the request, and the rows the model returns | Google's infrastructure; the Gemini API offers no choice of region |
| Google Cloud Run (our decryption service) | Unlocking a password-protected PDF that the app's built-in decryptor cannot open (only for password-protected pdfs the built-in decryptor fails on) | That PDF and its password, held in memory for the request; the password is never logged | United States (us-east1, South Carolina) |
| Cloudflare (Email Routing) | Forwarding email sent to our support address to our inbox (only for email you send us) | Your message, your email address and anything you attach | Cloudflare's global network |
| Google (Gmail) | Our support inbox (only for email you send us) | Your message, your email address and anything you attach | Google's infrastructure |
TxnFlow takes no payments yet. When it does, the payment provider will be added to this list.
How are password-protected PDFs handled?
Your browser checks the password against the file first, so a mistyped password is normally caught before anything is uploaded. The password is then sent with the upload, used on our server to unlock the file in memory, and discarded: it is never stored or logged. The unlocked PDF replaces the encrypted copy.
If the built-in decryptor can't open a file for a reason other than the password, the file and password go to our own decryption service on Google Cloud Run, which holds both in memory for that one request and never logs the password.
How long is it kept?
| What | Where | Kept | Removed by |
|---|---|---|---|
| Uploaded PDF | Supabase Storage | Until you delete its upload | Deleting the upload. Deleting a statement or an account does not remove the PDF; delete the upload too. |
| Temporary copy of a password-protected PDF | Supabase Storage | Until the PDF is unlocked, moments after upload | Removed automatically once the file is unlocked. If an upload is abandoned partway, the copy can remain; ask us to remove it. |
| Statements and transactions | Supabase database | Until you delete the statement, its account or its upload | Deleting any of the three removes them |
| Accounts (bank name, currency, account type, the last four characters of the account number, latest balance) | Supabase database | Until you delete the account; deleting an upload or a statement leaves it | Deleting the account, or closing your account |
| Categories (yours, and the standard ones an import adds) | Supabase database | Until your account is closed; the app has no way to delete a category | Closing your account |
| Rules and budgets you set up | Supabase database | Until you delete them | Deleting them in the app, or closing your account |
| The model's raw output (every transaction, balance and account number it read) | Supabase database | Until you delete the upload | Stripped when the upload is deleted |
| Model usage records (tokens, cost, duration, model, error messages) | Supabase database | After the upload is deleted, with no expiry today; they no longer hold the extracted rows | Closing your account |
| PDF passwords | Nowhere | Never stored or logged | Not applicable |
| Account email and sign-in records | Supabase Auth | Until your account is closed | Email us to close your account; we do it by hand within 30 days, deleting everything above. A database copy taken before then keeps your data until that copy is deleted (see Database copies), and support emails follow their own row |
| Support emails | Our support inbox (Gmail) | 12 months after the conversation ends | Deleted after 12 months, or sooner if you ask, including when you close your account |
| Request and error logs | Vercel, Supabase and Google Cloud | Vercel: 1 hour. Supabase: 1 day. Our decryption service: Google Cloud's default of 30 days (method, path and status only) | Expire automatically |
| Database copies | The operator's own computer, on an encrypted disk | Supabase's current plan takes no automatic backups. Before each change to the database's structure, the operator takes one full copy of the database, which is deleted 30 days after the change is verified | Deleted on that schedule; closing your account does not remove you from a copy taken earlier |
How do I delete it?
- Delete an upload and its PDF, the statements and transactions read from it, and the model's raw output all go with it.
- Delete a statement or an account and its statements and transactions go, but the uploaded PDF stays in storage. Delete the upload too if you want the file gone.
- To close your account and have all of your data removed, email support@txnflow.app from the address you signed up with. We do it by hand within 30 days. A database copy taken before then is deleted 30 days after the change it was taken for is verified, and our emails with you are kept for 12 months unless you ask us to delete them too.
How is it protected?
- Every connection uses HTTPS, and browsers are told to insist on it (HSTS).
- Supabase encrypts the stored data at rest (AES-256).
- Every database query is scoped to your account.
- TxnFlow holds no bank credentials, because it never asks for them.
What reconciliation can and can't prove
The check proves that the rows TxnFlow extracted add up to the balances the statement prints. It can't catch a statement that is itself wrong, or two mistakes that cancel each other out exactly. Statement content is treated as untrusted: text inside a PDF can try to steer the model, and that risk is reduced, not removed, so an answer that is wrong but adds up would still pass. Check anything important against the original.
Certifications
TxnFlow itself holds no security certifications. Supabase and Vercel each hold a SOC 2 Type 2 attestation, and Vercel is ISO 27001 certified.
Reporting a vulnerability
Email support@txnflow.app with the details and the steps to reproduce. Please don't access other people's data or disrupt the service while testing.
Last reviewed