Security

Security & data

Recurna is built on a simple principle: collect less, not more. Here's what we store, where it lives, and what we never touch.

What we store

No bank connection

Recurna never connects to your bank account. No OAuth handshake, no read access, no Plaid. You enter your transactions manually. That's the whole model.

No identity beside your numbers

Your name and email stay with Clerk, our identity provider. The account record on our side is an internal id and nothing else, so nothing in your forecast is tied to a name or an email address: just the numbers you typed and the labels you wrote.

You control what we see

Every transaction in Recurna is one you chose to add. We have no background access, no inferred data, no behavioral profile. You decide what the forecast knows.

Where your data lives

Recurna Flow is operated by a Canadian company. Your financial data is stored in a PostgreSQL database hosted on Neon (serverless PostgreSQL). The application backend runs on Cloudflare Workers and the frontend is served from Cloudflare Pages.

Authentication is handled by Clerk. Your name, email, and profile picture stay with Clerk. The account record on our side is a single internal identifier mapped to your Clerk account, which is what associates your financial data with you.

Some things do ask for an email address, because something has to be sent: applying for the beta, asking to be told when we launch, and inviting someone to share your forecast. Those addresses are stored on our side, on their own records, carrying none of your financial data. An invitation is the one that necessarily records whose forecast it opens, because that is what an invitation is. The Privacy Policy says what we keep, why, and how to have it removed.

Portability

Recurna is manual-first by design. Because you enter your own transactions, your data is always yours to take with you: export a full CSV from the account page at any time.

Full details in our Privacy Policy.