Privacy policy

Who holds what, why they are allowed to, who else sees it, how long it stays, and what you can make us do about it. The data charter states the same promises in technical detail.

Last updated 2026-09-19

Who is responsible for your data

Where this policy says “we”, it means the operator of Moflow. Until you turn sync on there is a real sense in which nobody is responsible for your financial data but you: there is no server copy of your ledger for anyone to hold. What does reach us includes the bare ticker symbols you hold, sent so we can label what each holding is, with no identity and no amounts attached.

The short version

  • Until you turn sync on, there is no server copy of your ledger. Your browser writes it into your own storage and it stays there. The bare ticker symbols you hold do reach us — no identity, no amounts — so we can label what each holding is.
  • With sync on, we hold your ledger and we can read it. It is encrypted in transit and encrypted at rest, and we read it to run Moflow for you and for nothing else — never sold, never used for advertising, never made into a profile.
  • We measure traffic, and the cookie is yours to decide. Page views and five product actions, counted — and, once you have an account, which product moments it reached, so we can see whether people who sign up come back. Nothing from your accounts, holdings or figures is ever included, and the counting works without the cookie.
  • Your card never reaches us. Stripe takes the payment on their own page, and what comes back to our server is which plan you are on and whether it is paid up — never a card number, an amount or a billing name.

The claim-by-claim version, one line per thing that leaves your device, is the data charter.

What we process, why, and on what basis

Every category Moflow asks for, including the ones a privacy policy usually leaves out. Each row names the purpose we use it for, and we use it for nothing else.

WhatWhyLawful basis
Your ledger — while it is only on your deviceYour accounts, balances, transfers and figures live in your browser's storage. There is no server copy, so there is nothing there for us to process; the bare ticker symbols you hold have their own row below.No processing
Email address, or your Google account identityTo give you an account, so a subscription and a synced ledger can attach to someone rather than to a browser.Performance of a contract
Your ledger, once there is a server copy of it: accounts, balances, transfers, holdings, snapshots, goals, reasons and your ledger settingsTo sync your ledger between your devices and to run Moflow for you. We hold it as records on our server, encrypted in transit and encrypted at rest, and we can read it. We read it to serve you and for nothing else: it is never sold, never used for advertising, and never used to build a profile of you.Performance of a contract
Your subscription record: whether the account is entitled, which plan, where the subscription stands — including a payment that failed and is being retried — and Stripe's customer and subscription identifiersTo know what your account is entitled to, to keep your access and your cloud copy alive while a failed payment is retried, and to open your billing portal. What we hold is the state in one word from a fixed set, the plan it applies to, and when it last changed. No card number, no amount, no billing name.Performance of a contract
Three whole numbers: an age band, a net-worth band, a growth band — no longer collectedThey were sent under an opt-in comparison that was part of Moflow. It has been withdrawn: no device sends a band any more, and no part of Moflow reads the ones already sent. What was sent was banded on your device before it left — never an amount, never a balance.Consent — no longer collected
A push-notification token and your per-type on/off flagsTo deliver the notifications you switched on, and to tell you once if your plan no longer includes delivery to your phone — we record that we have told you, so it is said once rather than every month. Notification content never contains amounts, balances or account names.Consent — withdrawn by switching them off
Ticker symbols, symbol-search text, FX-rate requests, and reason-coverage checksTo price your holdings, resolve what you search for, convert currencies, and tell the app which of your holdings we already hold public reason records for. These reach our own server and go no further than the providers described below. On a paid plan the quote and symbol-search requests also carry your sign-in token, so we can confirm your plan includes what you asked for; it is checked and discarded, and nothing we keep links the symbols you track to your account. The FX-rate request carries no sign-in token on any plan, and neither does the coverage check, which returns only which symbols are covered. We write no search log of our own and keep no search history, and the text you type in the picker is not part of the address of the request, so our hosting provider's request logs do not carry it either — those lines record that a search was asked for, not what you were looking for.Performance of a contract
An anonymous per-ticker interest counterTo know which tickers the people using Moflow actually hold, so we can decide which ones to cover next. A bare symbol, never linked to you, never readable by any client, and nothing we keep records who asked.Legitimate interest — improving coverage, with no identity attached to anything we keep
Usage analytics: page addresses, a count of five product actions, and the device type and rough location our analytics provider derives from the requestTo see how the app is used. Sent to our analytics provider with no advertising or personalisation signal, and never carrying anything from your ledger; the device type and rough location are what that provider derives from the request itself. The counting itself stores nothing on your device; the cookie that recognises a repeat visit is separate and you decide about it.Consent for the cookies where we must ask first; legitimate interest — understanding how Moflow is used, with no identifier stored — for the cookieless counting
Which product moments your account reached, and when: creating your account, adding your first account, each snapshot you confirm, and, if you subscribe, starting a trial and starting to payTo see whether Moflow works: how many people who sign up come back for a second and a third month. Each record is the moment's name, your account and the time, and it has no fourth field — no amount, no balance, no account name, no ticker, nothing you wrote. Deleting your account deletes them.Legitimate interest — knowing whether the product works, from the smallest record that can answer it
Server request logs, including the IP address your browser connects fromTo keep the service running and to spot abuse of the shared endpoints. Every request your browser makes to us arrives with the IP address it came from, and our hosting provider records that in its request logs beside the address asked for, status codes, counts and timings. The text you type in the symbol picker is not part of the address it asked for, so it is not in those lines — they record that a search request was made, not what you were looking for. The symbols the app sends for you are not in those lines either. Nothing we keep links any of it to your account.Legitimate interest — security and operating the service

Who else sees it

Moflow relies on three kinds of outside service, and on one more only if you choose to connect an assistant. Only one of them holds your ledger — the provider that hosts our database. What any of the others gets from your ledger is in its own bullet below: the bare ticker symbols you hold, and what an assistant you connected asks for. Only two of them, the one that signs you in and the one that takes your payment, are told who you are.

  • Our hosting and database provider — hosting, sign-in, the database that stores your synced ledger, the server code, push delivery, and the usage analytics described under Cookies. It holds your ledger records, your sign-in identity, and the request logs described above — which carry the IP address your browser connects from. Its storage is encrypted at rest, and our server's rules put your records out of reach of every other account.
  • Our payment processor, Stripe — payments and the billing portal. Stripe receives your card details, your name and your billing address directly from your browser on their own hosted page, and is the one recipient here that is paid to know who you are; their own privacy notice governs what they do with it.
  • Market-data and exchange-rate providers — reached by our server only, never by your browser. They see a ticker symbol or a rate request arriving from our infrastructure, and they do not see your IP address, your identity, your holdings or your amounts.
  • An AI assistant you connect — only if you connect one yourself. What it asks for is read from your ledger and sent to the assistant you chose, and from there its own provider's privacy notice governs what it keeps. Disconnecting it in Settings ends its access.

Where it goes

Our hosting and database provider and our payment processor are both United States companies, so what reaches them is processed outside the EEA and the UK. What crosses a border includes: the IP address your browser connects from, your sign-in identity, your ledger itself once sync is on, your payment details entered on the processor's own page, the bare ticker symbols you hold and the text you type into the picker's search box, the three band indices sent under the withdrawn opt-in, and the page addresses and event counts above, together with the device type and rough location our analytics provider derives from the request itself. Until you turn sync on your balances, transfers, income and account names do not cross any border, because they do not leave your device at all. If you connect an assistant, what it reads from your ledger goes to the company that runs it, which is usually outside the EEA and the UK as well.

What crosses is minimised before it goes and bounded once it arrives: your ledger crosses encrypted in transit to the one provider that hosts our database, and nothing in the analytics stream comes from your accounts, holdings or figures.

How long we keep it

  • On-device data — as long as you keep it. It is in your browser's storage. Erasing it in Settings, or clearing your browser storage, removes it immediately and completely. We never had a copy.
  • Your synced ledger — until you delete it, or 30 days after your subscription lapses. Turning sync off and deleting the cloud copy in Settings removes it at once, and so does deleting your account. If your subscription lapses and you do nothing, a daily scheduled job deletes the copy 30 days after the lapse was recorded — a failed payment Stripe is still retrying does not start that clock, and we notify you about a week before the deadline. Re-subscribing inside the window clears the clock and resumes sync with nothing lost. Only the server-side copy is affected: your on-device data is untouched.
  • Band indices — no longer collected, and still here. The opt-in they were sent under has been withdrawn from Moflow, no device sends a band any more, and no part of Moflow reads the ones already sent. Deleting your account no longer reaches them: ask, and we delete yours.
  • Billing records — ours, until your account is gone; Stripe's, as long as tax law requires. Two records, two keepers. Stripe keeps the transaction record — the invoice, the amount, the date — as its own controller, for the period tax law sets for it. Ours is the subscription record described above: entitlement, plan, state, Stripe's identifiers and the date it last changed, with no amount, no invoice number and no card number in it. That makes it a mirror of what your account is entitled to rather than an accounting record, and no tax duty of ours needs it — so it does not outlive the account. Deleting your account takes the paid-plan flag off your sign-in identity, and a nightly job removes the mirror itself once the account is gone.
  • Analytics cookies — two years, or until you switch them off. Switching them off in Settings clears the ones already set and stops new ones. The counting itself keeps nothing on your device at all.
  • Product moments — while your account exists. One row per moment, kept so we can see whether people who sign up come back for a second and a third month. Deleting your account removes them: a nightly job clears every row belonging to an account that is gone.
  • Server request logs — short-lived operational retention. Our hosting provider's default log retention applies. The lines carry the IP address your browser connected from, the address it asked for, statuses, counts and timings — never your accounts, balances or figures, which travel in request bodies those lines do not record.

Your rights, and how to actually use them

If the GDPR or UK GDPR applies to you, you have the rights below. Erasure, and withdrawal of consent for push notifications and analytics cookies, are switches in Settings — you exercise them yourself, immediately, with no request to anyone. Every right here is free to exercise.

  • Access and portability. These rights cover the personal data we process, which the table above sets out. The ones tied to your identity are your sign-in identity, your subscription record — entitlement, plan, state and Stripe's identifiers beside it — the three band indices if you sent them, this device's notification registration, the product moments your account reached, and your ledger if sync is on. Ask us for a copy and we will send you one, machine-readable and free of charge. Until you turn sync on your ledger is not among them: it is written by your own browser into your own storage, and the bare ticker symbols that reach us are never attached to an identity. What is ours to hand back from the moment you have an account is the short list above.
  • Erasure. Settings → Delete account removes the account itself: it cancels any subscription first, then deletes the cloud copy of your ledger, this device's notification registration, and finally the sign-in identity — and the paid-plan flag goes with it, because that flag lives on the identity rather than beside it. That sequence needs no request and no waiting. The one thing deletion leaves alone is the ledger on your own device: it is your file, not our record, and Settings → Data → Erase is how you remove that. Narrower erasures still have their own switches — Sync → “Turn off & delete cloud copy” removes the cloud copy on its own. Not everything goes with it. The three band indices, if you ever sent them, are no longer on the list above — the step that deleted them went with the feature that asked for them, so ask and we delete yours. And if you ever paid, Stripe keeps its own invoice records for the period tax law requires; that one is not ours to delete. Nothing in either can sign you in.
  • Rectification and restriction. Your ledger is edited by you, in the app, directly: every figure in it is yours to change, and a correction syncs like any other edit — there is nothing to ask us for. The one record of yours we hold that you cannot edit is your subscription record, and it is a copy of what Stripe tells us: correcting it means correcting the subscription itself, which is what the billing portal is for, and our copy follows the next event. Restriction of the consent-based processing is the switch in Settings, and it takes effect at once.
  • Withdrawing consent. The consent-based features are push notifications and — where we ask before setting them — analytics cookies. Each is switched off in Settings, and switching one off is the withdrawal — no request, no delay. The opt-in comparison that asked for three band indices has been withdrawn from Moflow altogether: no device sends a band any more, and ask and we delete one you already sent.
  • Objection, and complaining about us. You can object to the legitimate-interest processing above, and you can complain to your national data-protection authority.

Cookies, storage, and tracking

Cookies for counting visits, and nothing else — never advertising, never sold, never a profile. Whether they are set before you are asked depends on the rules that apply where you are: where consent is required — the EEA, the UK and Switzerland — the banner asks first and nothing is stored until you press Accept; elsewhere they are set by default and switched off in Settings → Data & privacy. We work out which applies from your browser's own language and time-zone settings, and we lean towards asking.

Either way we measure traffic. Our analytics provider receives the pages you open and a count of five product actions: creating an account, opening upgrade, starting a checkout, confirming a snapshot, adding a reason. That provider also derives your device type and rough location from the request itself. Nothing from your accounts, holdings or figures is ever included, and no advertising or personalisation signal is sent. Declining — or leaving the banner unanswered — keeps that counting running without any cookie and without identifying you. Analytics cookies in Settings shows where the setting currently stands and changes it; off stores nothing and clears what was already set.

Moflow does use storage that lives in your browser, which is not the same thing and should not be dressed up as none:

  • Local storage holds your entire ledger, and until you turn sync on that is the only copy of it. That is the product, not tracking — we hold no server copy of it until then. The one part that does reach us is the bare ticker symbols we use to label what each holding is, with no identity and no amounts.
  • Signing in stores an authentication token in your browser so you stay signed in. It identifies you to our own server and to our sign-in provider, and signing out removes it.
  • A service worker caches the app so it loads offline and can install to your home screen. It caches application code, not your data.

Children

Moflow is not directed at children and we do not knowingly process children's data.

Changes to this policy

This page carries a “last updated” date that moves only when its content does. A change that widens what we process is announced in the app before it takes effect, not slipped into a diff.

Contact and complaints

Wherever you are, you may complain to the data-protection supervisory authority of the country you live in.

The terms of service cover the commercial side — plans, renewal, cancellation and refunds.