Last updated: April 16, 2026 • Effective: January 1, 2025
MoneyFlow is built on a simple principle: your financial data belongs to you. We do not sell your data, share it with advertisers, or use it for any purpose other than providing you with the service you signed up for.
Account information. When you create an account, we collect your full name, username, email address, phone number, and a hashed (never plain-text) version of your password.
Financial data you upload. When you upload bank statements, we store the transaction data contained in those statements — including dates, amounts, descriptions, and account identifiers — in our database, associated only with your account.
Usage data. We log standard server access data (IP address, browser type, pages visited, timestamps) for security monitoring and debugging purposes.
Device information. When you enable the "trust this device" feature during two-factor authentication, we store a cryptographic hash of your device identifier to recognize your browser for 30 days. We never store your actual device hardware identifiers.
We do not use your financial data to serve you advertisements. We do not sell, rent, or trade your personal information to third parties.
Your data is stored on encrypted servers hosted on Amazon Web Services (AWS) in the United States. We use industry-standard security practices including:
Bank statement files you upload are stored in a private, access-controlled vault on our servers. They are not publicly accessible and are never shared with third parties.
We use the following third-party services to operate MoneyFlow:
We retain your account data for as long as your account is active. If you request account deletion, we will permanently delete your data within 30 days, except where we are required by law to retain certain records.
Audit logs (recording login attempts, security events) are retained for 90 days for security purposes.
You have the right to:
To exercise any of these rights, contact us at privacy@moneyflowinc.com.
We use two types of cookies:
session_id) — required for authentication. Expires after 30 days of inactivity.mf_did) — stores an encrypted device identifier to enable the "trust this device" feature. Expires after 30 days.We do not use advertising, tracking, or analytics cookies.
MoneyFlow is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us immediately.
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in the app at least 14 days before the change takes effect. Your continued use of MoneyFlow after that date constitutes acceptance of the updated policy.
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us: