This policy covers Flowney: the iOS app, its Telegram bot and this website. It says what we collect, why, who else handles it, how long we keep it and what you can ask of us.
1. Who we are
Flowney is run by private entrepreneur Bohdan Bunchuk (ФОП Бунчук Богдан), Ukraine, who is the controller of your personal data. “We” in this policy means the operator.
Write to support@flowney.app about anything in this policy.
2. What we collect
Your account
- Your phone number, which is how you sign in. Accounts made before sign-in by phone may have an email address and a password instead. The password is stored only as a hash.
- The name you give.
- Your four-digit PIN, stored only as a hash, and a count of wrong attempts.
- If you link Telegram: your Telegram user ID, username and first name.
- The devices you are signed in on: the device name set in iOS, which often includes your own name, and when each session was last used.
Your ledger
Everything you keep in Flowney: accounts and balances; operations with their amounts, currencies, dates, categories, descriptions and notes; payees, budgets, debts, loans, instalment plans, recurring payments and the rules that sort your operations.
Receipts you attach to operations: the photo or PDF itself, its type and size, who attached it and when. In a shared ledger, everyone who can see an operation can see its receipts.
In a shared ledger we also keep who belongs to it, what each member may see and who wrote each entry.
If you set up the Apple Pay automation in Shortcuts, every payment you tap sends us its amount, the merchant, the card’s name and the time.
A bank you connect
To connect monobank you give us your personal monobank token. With it we read your accounts and jars, including the masked card number and IBAN, your statement for up to 92 days back, and every new operation the bank sends from then on. An operation from the bank can include the other party’s name, IBAN and EDRPOU code. We keep what the bank sends as it sent it, beside the operations made from it.
The personal token only lets us read. Nobody can make a payment or move money with it.
Other people in your ledger
Your ledger can hold data about other people: the name of someone you lent money to, the phone number of someone you invite to a shared ledger, the other party of a bank transfer. Add it only if you are entitled to. We use it only to keep your ledger and, for an invitation, to let that person join.
Problem reports
A problem report sent from the app carries the text you wrote, the app’s version and build, the iOS version, the device model and the app’s language. We keep it with your contacts, so that we can answer.
What we do not collect
- No analytics, advertising or tracking in the app, and no advertising identifier.
- No crash-reporting service.
- No location, contacts or microphone. The camera and your photos are used only when you attach a receipt, and then only the one picture you take or pick, or the one file you choose, is sent. The app saves every picture anew as a JPEG before sending it, without its location or anything else the camera recorded about it; a PDF is sent as it is.
- Nothing from Face ID: iOS checks your face on the device and never tells us anything about it.
- No IP addresses stored by our server. Cloudflare, which carries the traffic to it, does see them (section 4).
- No cookies and no analytics on this website.
3. Why we use it
- To provide Flowney: your account, your ledger, bank sync, shared ledgers and the bot. This is the performance of our contract with you (GDPR, Art. 6(1)(b)).
- To keep accounts safe: sign-in codes, the PIN, limits on attempts, the list of your sessions. This is our legitimate interest in security (Art. 6(1)(f)).
- To answer you when you write or send a problem report: our contract with you, and our legitimate interest in running the service.
- To comply with the law when it requires us to keep or disclose something (Art. 6(1)(c)).
The same grounds apply under the Law of Ukraine “On Personal Data Protection”.
We do not sell your data, show you ads, build a credit profile of you or hand your ledger to anyone for their own purposes. Operations are sorted into categories by rules on our server. No AI service sees your data.
4. Who else handles it
A few services help us run Flowney, and each gets only what its job needs:
- Cloudflare, Inc. (USA) carries all traffic between the app and our server, and hosts this website. It sees the traffic in transit, including your IP address. It also stores the receipts you attach, in Cloudflare R2 in the European Union: the storage is closed to everyone but our server, which hands a receipt out only after the same check that decides who may see its operation.
- Telegram (Telegram Messenger Inc.) delivers sign-in codes through Telegram Gateway, and gets your phone number and the code for that. If you link Telegram, it also carries the bot’s messages, which include amounts, payees and balances. Problem reports reach us through Telegram too.
- AlphaSMS (Ukraine) sends sign-in codes by SMS to Ukrainian numbers, and gets your phone number and the code.
- Backblaze, Inc. (a US company, storing in the EU) keeps our backups. They are encrypted before they leave our server, so Backblaze cannot read them.
Our server itself is in Ukraine and is run by us.
monobank, Telegram and Apple are also independent companies with their own privacy policies, and those apply to what you do with them directly: the token you issue in monobank, the chats you have with the bot, the App Store and Shortcuts.
As the operator, we can see account details — name, contacts, plan, number of accounts and operations — on an internal admin page, and we have access to the database and to the storage of receipts to keep the service running. We use that access only for support, maintenance and legal obligations.
We disclose data to authorities only when Ukrainian law obliges us to, and only what it obliges us to.
5. Data outside Ukraine and the EU
Cloudflare and Telegram work outside Ukraine and the European Union; the receipts Cloudflare stores for us stay in the EU. For Cloudflare we rely on its data processing terms, which include the European Commission’s standard contractual clauses. For Telegram, and wherever else a transfer needs a basis, it is our contract with you: without them we cannot carry your traffic or deliver your code.
6. How we protect it
- Traffic between the app and our server is encrypted.
- The bank token is encrypted on our server (AES-256-GCM) and never shown again, not even to you.
- Passwords and PINs are stored as argon2id hashes. Sessions use short-lived tokens that the app keeps in the iOS Keychain.
- You can lock the app with the PIN and Face ID.
- Backups are encrypted before they leave our server.
- Receipts are kept in private storage that hands nothing out by itself: only our server reads from it. Cloudflare encrypts them on disk (AES-256).
- The admin tools are reachable only from our private network.
Your ledger itself is not hidden from us: the server has to read it to show it to you, sort it and sync it with your bank. No system is perfectly secure. If a breach affects your data, we will tell you and the authorities as the law requires.
7. How long we keep it
- While your account exists, we keep what it holds.
- When you delete your account (Settings → Delete account), it is erased from the live database at once: the ledger you own, the bank token, what the bank sent, the Telegram link, your sign-in records and your problem reports. The files of your receipts are removed from storage right after.
- A receipt is kept as long as its operation. When you take it off, delete the operation or delete your account, its record leaves the database at once and its file leaves storage right after. If removing a file fails, or attaching one breaks off half-way, the file can stay in storage for a short while, with nothing pointing to it and nobody able to open it; a daily clean-up deletes such files automatically, within three days at most.
- Backups keep a copy for up to six months, until they are replaced by newer ones. Receipt files are not in the backups; they hold only the record that a receipt existed, with its type and size.
- Technical records such as sign-in attempts, used codes and records of recent requests are deleted automatically within 30 days.
- Out of our reach: messages the bot has already sent stay in your Telegram chat, and entries and receipts you added in someone else’s shared ledger stay in that ledger, without your name on them.
We do not delete an account for being inactive.
8. Your rights
You can:
- get a copy of your data: the app exports your operations to CSV at any time, on every plan; for anything else, write to us;
- correct it: almost all of it can be edited in the app;
- delete it: in the app, or by writing to us. If you own a shared ledger that others are still in, remove them first;
- withdraw access: disconnect the bank or unlink Telegram in the app at any time, and revoke the token in monobank itself;
- object to processing based on our legitimate interests, or ask us to restrict it;
- complain to a supervisory authority: in Ukraine, the Ukrainian Parliament Commissioner for Human Rights; in the EU, the authority of your country.
We answer within one month. We may ask you to confirm a request from the phone number of the account.
9. Children
Flowney is not meant for anyone under 16. If we learn that an account belongs to a child under 16, we delete it.
10. Changes to this policy
The date at the top is the date of this version. If a change affects what we collect or who receives it, we will let you know before it takes effect.
11. Contact
ФОП Бунчук Богдан, Ukraine — support@flowney.app.