Legal
Privacy Policy
Recurna is operated by a Canadian company and is subject to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).
What data we collect
Recurna Flow collects the data you enter into the app and a small amount of identity data required to operate your account:
- Financial data: accounts, transactions, recurring transactions, categories, and forecasts you create
- Identity: your name, email address, and profile picture are held by Clerk, our authentication provider. The account record in Recurna's own database is a single internal identifier mapped to your Clerk account, with no name, email address, or picture beside it. That identifier is what associates your financial data with you. A few features do store an email address in our own database, because something has to be sent: see Emails we store outside your account below.
- Session data: authentication tokens used to keep you signed in
- Billing data: if you subscribe to Recurna Flow Pro, your Stripe customer ID and subscription status are stored in our database. We do not store your card number or payment details. Those are held by Stripe.
We do not connect to your bank accounts. All financial data is manually entered by you.
Emails we store outside your account
A few things ask for an email address before there is an account to attach it to, or on behalf of someone who may never have one. Those addresses are stored in our own Neon database, on their own records, and none of them carries any financial data. Household invites are the one place a link exists at all: an invitation has to record whose forecast it grants access to, which is the point of it.
- Beta applications: when you apply for the founding beta, we store the email address you gave us together with your answers to the form: your province, whether your income is salaried, variable, self-employed, mixed, or other, your household size, which banks you use, the question you most want a forecast to answer, how you heard about Recurna, and the fact that you consented. We use this to decide who to invite, to size the beta, and to send you the outcome. We normally email ourselves a copy of your application at the same time so we can review it, and we send you a confirmation that we received it.
- Launch list: if the founding beta is full when you visit the apply page, you can leave an email address to be told when Recurna Flow opens to everyone. We store that address, the fact that it came from the apply page, and the date you joined, and nothing else. We will only use it for that one announcement.
- Household invites: when you invite someone to share your forecast, we store the email address you typed, so that we can send the invitation and match it to their account if they accept. The invitation link expires after 7 days. The address stays on the invitation record after the invite is accepted, revoked, or expires, because that record is what shows who was given access to your forecast and when.
- Administrative records: when someone at Recurna acts on a beta application, or invites a person directly, or sends a test email, we write a line to an internal log recording what changed and who it applied to, including the email address involved. This is how we can answer later questions about who was admitted and why. Being in this log does not mean you applied for anything: a direct invitation puts an address there too.
How long we keep them. These records are not covered by "Delete my account", because they can exist without an account. Beta applications are kept for as long as we are running the founding beta, because a pending application has to stay readable until it is reviewed, and an accepted one records why an invitation was sent. Launch-list addresses are kept until we have sent the launch announcement. The internal administrative log is kept indefinitely, because its purpose is to be able to account for past decisions. Household invitations are kept for as long as the account that sent them exists, and are deleted with it, including when that account is removed by the 12-month inactivity sweep described under Data retention below. Apart from that one case, we run no automatic purge on any of these today, and we would rather say so than name a window we are not yet enforcing. You can ask us to delete any of them at any time, and we will: see Your rights and how to exercise them below.
None of this is used for advertising, none of it is sold, and none of it is combined with your financial data. Applying for the beta or joining the launch list does not create a Recurna account.
Where your data is stored
Your financial data is stored in a PostgreSQL database hosted on Neon (serverless PostgreSQL, US region). The application backend runs on Cloudflare Workers and the frontend is served from Cloudflare Pages. All data is processed within Cloudflare's global network.
Your identity (email, name, profile picture) is stored by Clerk in the United States. The account record in our Neon database holds an internal account identifier linked to your Clerk account, and no name, email address, or profile picture. The email addresses described in Emails we store outside your account above are the exception: those are stored in the same Neon database, on their own records, carrying no financial data. Billing data is stored by Stripe in the United States.
Third-party processors
We use the following third-party services that may access your data:
- Clerk: handles authentication and identity management. Clerk stores your email address, name, and profile image. See Clerk's privacy policy.
- Stripe: handles payments and subscription management for Recurna Flow Pro. Stripe stores your customer ID, billing email, and payment method details. No card data passes through our servers. See Stripe's privacy policy.
- Sentry: error tracking to help us find and fix bugs. Error reports may include technical details about your browser, device, and the actions that led to an error. Error data is retained for 90 days. See Sentry's privacy policy.
- PostHog: product analytics to understand how the app is used (which features are popular, where users encounter friction). Analytics are only active when you accept browser storage consent. No financial data is ever included in analytics events. Data is processed on PostHog's EU cloud. See PostHog's privacy policy.
We do not use advertising networks or sell your data.
Canadian privacy law (PIPEDA)
Recurna Flow is operated by a Canadian company and is subject to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). Under PIPEDA, you have the right to:
- Know what personal information we hold about you and how we use it
- Request access to your personal information
- Request correction of inaccurate information
- Withdraw consent for non-essential data processing
- Lodge a complaint with the Office of the Privacy Commissioner of Canada (OPC) if you believe your rights have been violated
Our privacy practices are designed to meet PIPEDA's accountability, openness, and consent principles.
EU and international users (GDPR)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) or equivalent laws:
- Right of access: request a copy of the personal data we hold about you
- Right to rectification: request correction of inaccurate data
- Right to erasure: request deletion of your data (see "Deletion" below)
- Right to restriction: request that we limit processing of your data
- Right to data portability: receive your data in a structured, machine-readable format
- Right to object: object to processing based on legitimate interests
Our legal basis for processing your data is the performance of a contract (providing the Recurna Flow service you signed up for) and, for analytics, your explicit consent.
Local storage and cookies
Recurna Flow uses your browser's local storage to remember UI preferences such as your selected accounts and forecast view settings. When you accept browser storage consent, Recurna Flow also uses PostHog to collect anonymous product analytics (which features you use, where you encounter errors). No financial data is ever sent to PostHog. You can change or withdraw this consent at any time through the app's consent banner.
Clerk (our authentication provider) sets cookies required for sign-in sessions. These are strictly necessary and cannot be disabled while you are signed in.
This site uses a cookie consent banner to manage optional analytics storage. You can accept, reject, or customize your preferences at any time from the banner, and change your choice later by clearing your browser's local storage.
Your consent choice on recurna.ca is stored separately from your consent choice on flow.recurna.app. Each site remembers your preference independently.
Data retention
Your data is kept for as long as your account is active. Recurna Flow and Recurna Pantry share one account: "Delete my account" on either app's account page permanently removes everything tied to it: all Flow financial data, all Pantry data, your internal account record, the household invitations you sent, and your Clerk identity (which holds your email, name, and profile picture), in a single, irreversible operation. After deletion you cannot sign back in.
In line with the principle of storage limitation, we also remove data from accounts that have gone unused for a long time. If you do not sign in for 12 months, we treat the account as inactive: we email you a warning 30 days before deletion and a final reminder 7 days before. Signing in at any point during that window keeps your account and resets the clock. If you take no action, the account, and its Flow and Pantry data alike, is then permanently deleted, the same irreversible operation as "Delete my account" above.
Beta applications, launch-list sign-ups, and our internal administrative records sit outside this: they can exist without an account, so deleting an account does not reach them. Household invitations are different. The ones you sent go when your account goes, by either route above; but an invitation sent to an address that never signed up outlives the person it names, because there is no account of theirs to delete. What we keep and for how long is set out in Emails we store outside your account above.
Your rights and how to exercise them
- Access: all your financial data is visible in the app at all times; what you see is what we store. Your identity details (name, email, profile picture) are held by Clerk. View or update them by signing in to your Clerk account.
- Export: download a complete JSON export of all your data from the account page.
- Deletion: "Delete my account" on the account page permanently deletes your Flow and Pantry data, your internal account record, the household invitations you sent, and your Clerk identity (which holds your email, name, and profile picture). It also removes any accepted household invitation naming you. This is immediate, complete, and irreversible: no separate request needed. A beta application, a launch-list sign-up, or an invitation still pending to an address of yours is a separate record that outlives it; use the next bullet to have those removed.
- If you do not have an account: you can exercise every right on this page without one. If you applied for the founding beta, joined the launch list, or were invited to someone's household and never signed up, email us at [email protected] from the address you gave us, or name that address in the message. Tell us whether you want to know what we hold, correct it, or delete it. We will action it and confirm to you in writing, within 30 days at the latest. Deletion here means the record is removed, not marked inactive.
Data isolation
All data is scoped to your user account. You cannot see other users' data and they cannot see yours. Every database query is filtered by your authenticated user ID.
Breach notification
In the event of a data breach that affects your personal information, we will notify you by email within 72 hours of becoming aware of the breach, in accordance with PIPEDA breach reporting requirements.
Changes to this policy
We may update this privacy policy from time to time. If we make material changes, we will notify you through the app or by email. Continued use of the service after changes take effect constitutes acceptance of the updated policy.
Contact
If you have questions about this privacy policy, your data, or to exercise any of your rights under PIPEDA or GDPR, contact us at [email protected].