CLEARFLOW
Sign in Get started
Legal

Privacy Policy

Effective date: January 1, 2025  •  Last updated: January 1, 2025

The short version: ClearFlow collects only what's necessary to run the service. We do not sell your data, show ads, or share your financial information with third parties for marketing. Your bank credentials are never stored by us.

1. Who We Are

ClearFlow ("we," "us," "our") operates the ClearFlow budgeting application at clearflow.app. We are the data controller for personal information described here. Questions: privacy@clearflow.app or our Contact page.

2. Information We Collect

Information you provide directly

Data TypeWhat It IncludesWhy We Collect It
Account informationName, email address, password (hashed with bcrypt)To create and authenticate your account
Household informationHousehold name, member names and emailsTo enable shared budgeting
Budget dataIncome, spending categories, amountsTo calculate and display your budget
Expense dataAmounts, dates, merchant names, categoriesTo track and report your spending

Information from bank connections

When you connect a bank through Teller.io or Plaid, we receive read-only transaction data: amounts, dates, merchant names, account names, types, and last four digits. We never receive or store your bank login credentials, full account numbers, or Social Security numbers.

Technical information

Log data (IP addresses, browser type, timestamps) for security; session tokens in httpOnly cookies; activity logs (sign-in events, password changes) for account security.

3. How We Use Your Information

4. Third-Party Services

ServicePurposeData Shared
Teller.ioBank connectivity and transaction importEnrollment tokens; transaction data received in return
PlaidAlternative bank connectivity (inactive by default)Public tokens exchanged for access tokens
BrevoTransactional email deliveryEmail addresses, names, email content
Cloud hostingInfrastructureAll application data, stored in the United States

We do not use advertising networks, social media tracking pixels, or third-party analytics. We do not sell your data.

5. Data Retention

6. Security

Passwords are hashed with bcrypt (cost 12). All connections use HTTPS/TLS. Bank connections use mutual TLS in production. Sessions are stored in httpOnly, Secure, SameSite=Lax cookies. Two-factor authentication is required at every sign-in. See our Security page for full details.

7. Your Rights

Contact privacy@clearflow.app to exercise any of these rights.

8. California Privacy Rights (CCPA)

ClearFlow does not sell personal information. California residents may request to know, correct, or delete their personal information by contacting privacy@clearflow.app.

9. Children's Privacy

ClearFlow is not directed to anyone under 18. If you believe a minor has provided us information, contact privacy@clearflow.app and we will delete it immediately.

10. Cookies

We use one essential cookie: cf_token — an httpOnly authentication cookie required to keep you signed in, expiring after 30 days. We do not use advertising cookies, analytics cookies, or any third-party tracking technology.

11. Changes

Material changes will be communicated by email before they take effect. Continued use of ClearFlow after changes are posted constitutes acceptance.

12. Contact

privacy@clearflow.app  •  Contact form