Privacy policy
Last updated 19 September 2026
Prowl is a personal budgeting tool. It helps you import bank and card statements and see where
your money goes. This policy explains what we collect, how we use it, and the choices you have.
It covers the hosted app at prowl.money.
What we collect
- Your account. We keep your email address and the public half of the
passkey each of your devices registered. There is no password. Nothing we store can be
used to sign in as you.
- Financial data you import. We keep the transactions taken from the
statements you upload. That means their dates, descriptions, amounts, account names and
currencies. We also keep the categories, tags, budgets and renames you add to them.
- Technical basics. Prowl sets four essential cookies, and none of them
tracks you. One keeps you signed in for 14 days. One lasts five minutes while you use a
passkey. One lasts a day when you open the demo. One lasts a minute, to show a message
after an account is deleted. Our servers
also keep standard logs of the time, the page requested and your IP address. We use them
only to keep the service secure and to fix problems.
- Notes you send us. We keep what you write in the feedback box and which
screen you were on. We also keep your screen size, your browser and a picture of that
screen. You can switch the picture off before sending. Your own browser draws it, and
anything you tapped is greyed out. The picture is
removed after 30 days whether or not we have acted on the note.
It leaves the encrypted backups within 30 more days. Your
words and our reply stay until you delete your account or clear your data. If your free month or plan ends, they're deleted along with the rest of your data. Nothing in a note is shared with anyone.
What we do not do
- We never store your raw statement files. Uploaded PDFs, CSVs and
spreadsheets are read in memory to pull out the transactions. Then they are thrown
away. A file over 1 MB may pass through a temporary file while it uploads. That
temporary file is gone as soon as the upload finishes.
- We never ask for or store your bank login details. You upload statements yourself. If
you choose to link a bank, you sign in inside Plaid's own window. Your bank login never
touches Prowl.
- We do not sell or share your data. There is no advertising, and no tracking or analytics
from other companies.
- We never send marketing email. No newsletter, no product updates, no
"we miss you". You can't be subscribed to anything, because there is nothing to
subscribe to. Prowl only emails you about your own account. It sends your invitation,
with the link that signs you up. It sends the link you ask for when you have
lost every device. It warns you the moment a new device gains access to your account.
It tells you if your account is made free. It emails you before Prowl's terms or privacy
policy change. It tells you before your free month ends. And it emails you
once, a few days before your data is deleted.
Reading a statement from a bank we've never seen
This reading, and the shop-name suggestions described below, are part of how Prowl works.
They are not settings you turn on, so neither asks you first. Everything each one sends, and
everything it never sends, is listed here in full. These limits apply every time.
Prowl reads most statements entirely on its own. Sometimes a statement comes from a bank
whose layout Prowl doesn't know yet. Then Prowl sends that statement's text to Anthropic's API
to be read once. Prowl learns the layout from that reading. Every later statement from that
bank is read by Prowl itself, offline and for free. This happens about once per bank, not once
per statement.
- We remove what identifies you from the statement before sending.
Account and reference numbers, IBANs, email addresses, and the name and postal address
printed at the top are removed first.
- What is sent. We send the bank's own name, and the dates, amounts and
merchant descriptions as printed. Prowl needs these to learn the layout. A person's name
can appear inside a transaction's description, for example "Transfer from J Smith".
That name is sent with the description, because it can't be told apart from an
ordinary merchant name.
- What is not sent. We never send the statement file itself, anything
from your other statements, or anything from your Prowl account.
- Anthropic processes the text and sends back the reading. Under their commercial API
terms, this content is not used to train their models.
Suggesting a shop's real name
After an import, Prowl suggests a readable name and a category for shops it hasn't met
before. For example, "SQ *BLUE BOTTLE 0412" comes up as "Blue Bottle", with coffee as its
category.
To do this, Prowl sends the shop's description to Anthropic's API, with card numbers,
account numbers and dates taken out. It also sends your own category names, so a guess can only
land in a category you already made. It sends nothing else, and never an amount, a date, a
balance, an account, or how often you shop somewhere. A description that names a person is not
sent at all. Each shop is looked up about once ever. The answer is remembered in your own
account, so it isn't looked up again.
Category suggestions are shown to you, dimmed. They are applied only when you accept them.
The readable name is applied straight away, so your transactions read plainly. The bank's own
wording is always kept and shown beneath the name. One click brings it back. We tell you this
on purpose. A list of the shops a person uses is personal, even with no amounts attached.
One shared book of shop-name patterns
Prowl keeps one shared book of shop-name patterns, learned across all accounts. Once a
shop's messy bank wording is cleaned up, it reads cleanly for everyone after that. The book
holds patterns only. It never holds transactions, amounts, dates or balances. People's names
are always left out. When more than one account agrees on a pattern, the book notes how many
agreed, never which ones. It never records whose transactions taught it anything.
Linking a bank (optional)
If you prefer not to upload statements, you can connect a US bank so transactions arrive on
their own. The connection is made through Plaid, a bank-connection service. You sign
in to your bank inside Plaid's own window. Prowl never sees or stores your bank username or
password. Prowl receives the same information a statement carries, and nothing more. That
means transactions, balances, and account and bank names.
- Linking is always optional. Uploading statements works the same without it.
- The access key that keeps a connection working is stored encrypted, in your account's
own isolated area.
- You can disconnect a bank at any time from settings. Disconnecting deletes that access
key and tells Plaid to end its access. The transactions already in Prowl stay yours.
- Plaid's own handling of your data is described in
Plaid's End User Privacy
Policy.
How we use your data
We use it only to run the app for you. That means importing and cleaning statements,
categorizing your spending, and showing you reports. That's it.
Where it's stored and who processes it
- Hosting and storage. The app and your data run on Render's servers in
the United States. Each account's data is kept in its own isolated area.
- Backups. Cloudflare keeps an encrypted copy of the data, as the
security page describes. It cannot read that copy.
- Email. We use Resend to send the account emails listed above. Only your
email address and that message are shared with Resend.
- Reading new statement layouts and suggesting shop names. Anthropic does
both, as described above.
- Currency conversion. To convert amounts into your home currency, Prowl
asks public exchange-rate services for rates. It sends them currency codes only, never
your personal or transaction data.
- Bank connections. Plaid does this, as described above, and only when
you choose to link a bank.
- Payments. Prowl's plans are sold through Link, a service of Stripe.
When you subscribe, you pay on Stripe's own pages. Link collects your name, your billing
address and your card details there. It uses the address to work out the tax. Link sends
you your receipts, and a reminder before a yearly plan renews. Your card details go to Stripe and are
never seen or stored by Prowl. Prowl keeps only your plan, its status and a record of any
payment that was sent back.
Security
You open Prowl with a passkey instead of a password. Your device keeps the private key, and
Prowl stores only the public one. So there is no shared secret here to leak, and nothing a fake
site could collect from you. The site is served over HTTPS. Session cookies are HttpOnly, so
scripts on a page can't read them. Each account's data is kept apart from every other. No
system is perfectly secure, but we take reasonable measures to protect your information. More
detail is on the security page.
Keeping and deleting your data
Prowl keeps your data for the shortest time it can. While you use Prowl, your
data stays until you delete it. When your free month or plan ends, it stays for as long as you chose
in settings. Then Prowl deletes it for good. You can choose none, 3 months, 1 year or 2 years. If you
don't choose, it's 3 months. A few days before Prowl deletes it, we email you once, with a link to
keep it longer. Your account itself stays, so you can come back.
You can export your data as a spreadsheet, or as a full archive. The archive says in plain
words what it contains and what it leaves out. You can edit or remove individual items, or
delete your entire account and everything in it. You can do all of this at any time, from
inside Prowl, without asking us.
Encrypted server backups are kept for 30 days. How they are protected is on the
security page. So deleted data is fully gone from the backups only after
those 30 days. The law requires one exception. Records of payments you have made are kept for
accounting even after your account is gone. These are invoices and receipts, held at Stripe.
They hold your payment history, never your transactions or budgets.
What's planned (nothing here is live yet)
Prowl is honest about the future as well as the present. These features are being built,
and they will touch data when they arrive. Before any of them handles anyone's data, this
policy will be updated and the date at the top will change.
- Visit counting. Prowl may add privacy-respecting analytics that count
visits in total, never per person. They would use no cookies and no profiles, and would
never follow you across the web. Prowl will never add advertising trackers.
Children
Prowl isn't intended for anyone under 16, and we don't knowingly collect their data.
Changes
We may update this policy. The date at the top shows when we last did. If a change affects
you, we email you before it applies. The email says what changes and how to stop using Prowl.
Contact
Questions about your privacy? Email support@prowl.money.