OweFlowOweFlow

Security & data handling

Last updated: August 7, 2026

The short version

OweFlow exists to track money between people you already trust, so we collect as little as we can, keep it inside your group, and let you take it with you or delete it at any time. This page explains the specifics in plain English. For the formal document, read our Privacy Policy.

Encrypted in transit and at rest

Every request runs over HTTPS/TLS, and the database and file storage behind OweFlow are encrypted at rest by our hosting provider.

Group data stays inside the group

Expenses, balances and receipts are readable only by members of that group. Access rules are enforced on the server, not just hidden in the interface.

We never see your password

Sign-in is handled by our authentication provider. Passwords are hashed, and you can use Google sign-in instead if you prefer.

No bank logins, no card numbers

OweFlow does not connect to your bank and never stores card details. Subscription payments are processed by Paddle, our merchant of record.

What we store

  • Account details — your display name, email address, optional profile photo and preferred currency.
  • Group content — group names, members, expenses, amounts, categories, notes, settlements and any receipt images you upload.
  • Activity records — membership changes are written to an immutable audit log so a group can always see who joined, left or changed role, and when.
  • Subscription status — plan, billing period and renewal state supplied by Paddle.

What we never store

  • Bank credentials or read access to any bank account.
  • Full card numbers, CVVs or bank account numbers — Paddle handles all payment data.
  • Your password in readable form.
  • Your contacts, your location, or the contents of your device.

Who can see what

Access is enforced by row-level security rules in the database, which means the server refuses to return data you are not entitled to even if a request is crafted by hand.

  • Only members of a group can read that group's expenses, balances and receipts.
  • Only the person who created an expense — or the group owner — can change or delete it.
  • Profile emails are visible only to people who share a group with you, never to the public.
  • Invite links show a limited preview (group name, emoji and member count) before someone signs in, and nothing more.

Receipts and uploads

Receipt images live in private storage. They are never publicly listable, and are served through short-lived signed links to members of the group the receipt belongs to. Delete the expense and the associated file is removed with it.

AI features

When you use receipt scanning or the spending coach, the relevant expense text or image is sent to our AI provider to produce that single result. It is not used to train third-party models, and AI features are optional — the rest of OweFlow works without them.

Your data, your call

  • Export — download any group as a CSV file from the group menu.
  • Correct — edit your profile and any expense you created at any time.
  • Delete — email privacy@getoweflow.com and we will delete your account and personal data. Shared expense history may be retained in an anonymised form so your groups' balances stay accurate.

Reporting a vulnerability

Found something that looks wrong? Email support@getoweflow.com with the details and steps to reproduce. We investigate every report, we will not take legal action against good-faith research, and we will tell you when it is fixed.

Honest limits

OweFlow is a small independent product, not a bank. We hold no security certifications such as SOC 2 or ISO 27001, and we do not claim end-to-end encryption: our servers can read group data in order to compute balances. We would rather tell you that plainly than imply protection we do not have.