FlowFin
PrivacyTerms

Legal

Privacy Policy

Effective September 14, 2026 · Version 2026-09-14.4-sandbox

Your financial data is personal. This policy explains what FlowFin collects, why, who we share it with, and the control you have over it. The short version: bank connections use demo data only, we use your data to run FlowFin, and we never sell your information.

On this page

  1. Who we are
  2. Information we collect
  3. Cookies and local storage
  4. How we use information
  5. Legal bases (EEA, UK and similar laws)
  6. How information is shared
  7. How long we keep information
  8. Security
  9. Your choices and rights
  10. International transfers of personal information
  11. Children
  12. Changes to this policy
  13. Contact us

1. Who we are

FlowFin is a free, non-commercial personal project run by Kishore Muchintala (“FlowFin”, “we”, “us”), open to anyone while it runs on demo bank data. It is not a company. This policy covers the FlowFin website and web application and any FlowFin mobile app that links to it (together, the “Service”). Bank linking uses demo data only: FlowFin connects to Plaid’s test environment and never to real financial institutions. We are responsible for the personal information described here.

2. Information we collect

Information you give us

  • Account details: username, email address, display name, optional phone number, and your password (stored only as a salted Argon2 hash — we cannot read it).
  • Security settings: the secret for two-step verification if you turn it on, stored so we can check your codes.
  • Shared-expense content: expenses, groups, split rules, item lists, receipts, comments and settlement records you create, and the friends you invite by username or email.
  • Preferences: notification, weekly summary, and display settings.
  • Bug reports: the title, description, steps and impact you enter, plus the page you were on.

Registration acceptance records

When you register, we record the versions of the Terms of Service and Privacy Policy presented to you and the time our server records your acceptance of the terms and acknowledgement of the privacy notice. This record is separate from your permission to link demo accounts through Plaid.

Demo bank data from Plaid Sandbox

FlowFin does not connect to real banks and does not collect real bank data. Bank linking uses the Sandbox test environment of Plaid Inc. (“Plaid”), which serves simulated institutions and sample data. Sign in with the test credentials shown in the app — never enter your real bank username or password. We never receive or store bank login credentials. When you link a demo account, Plaid gives us simulated:

  • account names, types, masked account numbers (last four digits) and institution;
  • current and available balances and credit limits;
  • transactions — amount, date, merchant name and category;
  • for credit cards, student loans and mortgages: statement balances, minimum payments, payment due dates, and related loan details.

Plaid gives us an access token for each connection. We encrypt it with AES-GCM before storing it. Plaid’s handling of your data is described in the Plaid End User Privacy Policy.

Information collected automatically

  • Session data: a short device label derived from your browser (for example “Chrome on macOS”) so you can review and sign out active sessions. We do not store your raw user-agent string or IP address with your sessions.
  • Service logs: request and error logs kept to run and secure the Service. Our logger removes tokens, passwords and other secrets before a line is written. Sign-in attempts are rate-limited using a hashed copy of the username or email entered. Like any website, our hosting providers process your IP address to deliver requests.

3. Cookies and local storage

We use one strictly necessary cookie: an httpOnly, Secure, SameSite=Strict refresh-token cookie that keeps you signed in. It cannot be read by page scripts, and it is rotated each time it is used. Your short-lived access token is held in memory only and is never written to local storage.

We do not use advertising cookies, cross-site tracking, or third-party analytics. Because the Service does not require consent for strictly necessary cookies, we do not show a cookie banner. If we ever add optional cookies, we will ask first.

4. How we use information

  • To provide the Service — show your accounts and transactions, calculate splits and balances, record settlements, generate exports, and send the notifications you have turned on (including payment due reminders and weekly summaries).
  • To keep accounts secure — authenticate you, enforce two-step verification, detect reuse of stolen refresh tokens, rate-limit sign-in and prevent fraud or abuse.
  • To support you and fix problems — respond to requests and investigate bug reports and errors.
  • To meet legal obligations — keep records where the law requires and respond to lawful requests.

5. Legal bases (EEA, UK and similar laws)

Where these laws apply, we process your information because it is necessary to perform our contract with you (providing the Service), for our legitimate interests in keeping the Service secure and working (balanced against your rights), to comply with legal obligations, and — for linking demo bank accounts and optional notifications — with your consent, which you can withdraw at any time by unlinking the account or changing your settings.

6. How information is shared

We do not sell or rent your personal information, and we do not share it for cross-context behavioural advertising. We share it only as follows:

  • Finding and connecting with other users. Other signed-in users can search for you using all or part of your username or email address. Matching search results show your username and email address, even if you are not yet friends. Your username and email address are also visible to your friends and to people who receive a friend invitation from you.
  • People you split with. Your username, display name, and the expenses, comments, receipts and settlements you add to a shared expense or group are visible to its other members. Your linked bank accounts, balances and other transactions are not.
  • Plaid provides the demo bank connections. Plaid processes information under its own End User Privacy Policy and, for the bank-connection services we use, acts as an independent controller where applicable data protection law uses that term.
  • Service providers who process data on our instructions: Resend (transactional email), Atlassian Jira (bug reports, together with your account ID), and our hosting and database providers.
  • Legal and safety reasons — to comply with law or legal process, enforce our Terms of Service, or protect the rights, property or safety of our users or others.
  • If FlowFin becomes a business — we will tell you first and ask you to accept an updated policy before your information is used under it.

7. How long we keep information

We keep your information while your account is open. When you delete your account from Profile & Settings → Danger Zone, we sign out every session, unlink your bank connections at Plaid and delete the accounts and transactions imported from them, delete your notifications and preferences, and clear the bug-report text stored in FlowFin’s database. We replace your username and email with generated placeholders, change your display name to “Deleted user”, clear your phone number, and replace your password hash so the previous password cannot be used.

Shared expenses, comments and settlements stay visible to the other people in them — attributed to “Deleted user” — because removing them would change balances those people rely on. Financial records are append-only for accuracy, so some records may be retained where needed for that purpose, for security, or to meet legal obligations. Your internal account identifier remains linked to those records, and content you previously shared may still identify you. We also retain your registration acceptance record linked to your internal account identifier as evidence of the agreement. Deleting your account does not make all retained records anonymous.

Account deletion does not automatically remove copies of bug reports in Atlassian Jira. Those copies may include the content you submitted and your internal account identifier. To request deletion of personal information in a support report, contact support@flowfin.us.

Transaction retention settings offer 90 days, one year, or indefinite retention of imported activity. The cleanup rule excludes transactions linked to expenses, splits, or ledger records. These settings do not delete shared financial history, support reports, service logs, or backups.

Service logs are kept for 30 days and database backups for 14 days, then deleted automatically. They are separate from your active account data and are not erased early when you delete your account, so earlier versions of your records may remain in them until those periods end. Contact support@flowfin.us for questions or requests concerning retained information.

8. Security

We protect information with encryption in transit (TLS), encrypted Plaid access tokens, hashed passwords, rotating refresh tokens with reuse detection, optional two-step verification, and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Please use a strong, unique password and turn on two-step verification.

9. Your choices and rights

  • Update your profile and preferences in Profile & Settings.
  • Unlink a demo bank account at any time from Linked Accounts.
  • Export your shared-expense data as CSV or PDF.
  • Review and sign out active sessions, or delete your account.

Depending on where you live (for example under the GDPR, UK GDPR, or the California Consumer Privacy Act), you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. We will not discriminate against you for exercising these rights. To make a request, contact us at support@flowfin.us. We may need to verify your identity first. You may also complain to your local data protection authority.

10. International transfers of personal information

This section concerns personal information processed across national borders. FlowFin does not transfer money or issue checks. We and our service providers may process information in the United States and other countries whose laws may differ from yours. Where required, we use appropriate safeguards such as standard contractual clauses.

11. Children

The Service is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has given us information, contact us and we will delete it.

12. Changes to this policy

We may update this policy. We will change the effective date above and, for material changes, notify you in the app or by email before they take effect.

13. Contact us

Questions or requests about privacy: support@flowfin.us.

© 2026 FlowFin
HomePrivacy PolicyTerms of Service