VeloFlowVeloFlow

Privacy Policy

Last updated: August 2, 2026

1. Information We Collect

When you create a VeloFlow account we collect your name and email address. When you link a bank account via Plaid, VeloFlow receives read-only access to your account balances, transactions, and investment holdings. We never receive your bank login credentials — those are handled entirely by Plaid.

We also collect:

  • Device and browser information for security and fraud prevention
  • Usage data (pages visited, features used) to improve the product
  • Passkey / biometric credential identifiers (not biometric data itself)

2. How We Use Your Information

  • To display your net worth, transactions, and investment portfolio
  • To generate AI-powered financial insights and recommendations
  • To process payments for Pro subscriptions via Stripe
  • To send account-related notifications (with your consent)
  • To improve VeloFlow's features and performance

3. Data Sharing

We do not sell your personal data. We share data only with:

  • Plaid — to retrieve bank account data on your behalf
  • Stripe — to process subscription payments
  • Google (Gemini) — to generate the AI insights you see in the app, we send a limited financial summary: balances, category spending totals, APRs, and the names of bills or holdings. We never send your name, email address, account numbers, or bank credentials. This data is used solely to produce your requested insight — it is not used for advertising, not sold, and not used to build user profiles. AI-generated insights are educational only and are not financial, investment, or tax advice.
  • Google Analytics — to understand which features are used and where people get stuck, so we know what to improve. We send screen names and interaction events only. Page addresses are stripped of any query string before they are sent, and we never send your name, email address, account numbers, balances, or transaction data. Advertising features and Google Signals are switched off, so this data is not used to build an advertising profile of you. You can turn this off entirely in Settings → Privacy, in which case nothing is sent and no analytics cookie is set.
  • Sentry — to receive crash and error reports so we can fix faults we would otherwise never hear about. Reports contain the error, the screen it happened on, and your user ID; request bodies, cookies and access tokens are stripped before sending. You can turn this off in Settings → Privacy.
  • Resend — to deliver transactional email: password resets, security notices, and a copy of any feedback you send us. We send your email address and the contents of that message, nothing else. Resend does not use it for its own purposes.
  • Google (Firebase Cloud Messaging) — to deliver push notifications, if you turn them on. We send a device registration token and the notification text. The token identifies your device, not you, and it is deleted when you turn notifications off or delete your account.
  • Vercel / Supabase — infrastructure providers that host and store your data under strict data processing agreements

4. Data Retention

We retain your data for as long as your account is active. When you delete your account, all personal data, linked bank connections, transaction history, and financial data are permanently deleted within 30 days. Stripe billing records may be retained as required by law.

5. Security

We use industry-standard security practices including:

  • Encryption in transit: All data is transmitted over HTTPS/TLS
  • Encryption at rest: Plaid access tokens are encrypted using AES-256-GCM before being stored in our database. The encryption key is stored separately from the data.
  • Password security: Passwords are hashed using bcrypt and never stored in plaintext
  • Session security: Sessions use httpOnly, Secure, SameSite cookies
  • Security headers: Our web app enforces Content Security Policy, HSTS, X-Frame-Options, and other OWASP-recommended headers
  • Bank credentials: Never stored by VeloFlow — handled entirely by Plaid's secure infrastructure
  • Passkey authentication: Biometric credential identifiers use WebAuthn — your raw biometric data never leaves your device

6. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Delete your account and all associated data (via Settings → Privacy → Delete Account)
  • Unlink your bank accounts at any time (via Settings → Linked Accounts)
  • Opt out of analytics and crash reporting (via Settings → Privacy)

7. Mobile App Permissions

The VeloFlow mobile apps for Android and iOS request the following permissions. Both apps are shells around the same VeloFlow web app, so the data they handle is identical — only the platform names for each permission differ.

Android

  • Internet and network state — required to load the VeloFlow app and communicate with our servers
  • Biometric / Fingerprint — used only for local on-device authentication. Your biometric data is never transmitted to VeloFlow servers. Only a cryptographic credential identifier is stored.
  • Notifications — used to deliver the alerts you turn on in Settings. You can disable them at any time in Settings or in your device settings.
  • Vibration — used for haptic feedback within the app
  • Run at startup — used only to restore your scheduled notifications after the device restarts

iOS

  • Face ID / Touch ID — used only for local on-device authentication. Your biometric data is never transmitted to VeloFlow servers. Only a cryptographic credential identifier is stored.
  • Notifications — used to deliver the alerts you turn on in Settings, including while the app is in the background. You can disable them at any time in Settings or in your device settings.

Neither app requests access to your location, contacts, SMS messages, or call logs.

Microphone — used only by the optional voice-input feature on the Wearables screen. Your device asks for permission the first time you use it, the microphone is active only while that feature is running, and VeloFlow does not record or store any audio. Speech is transcribed by your browser or device's own speech-recognition service, which may process the audio on the vendor's servers; the resulting text is what VeloFlow receives.

8. Children's Privacy

VeloFlow is intended for users who are at least 18 years of age. We do not knowingly collect personal information from minors. If you are under 18, do not use VeloFlow.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notification. Continued use of VeloFlow after changes constitutes acceptance of the updated policy.

10. Contact

VeloFlow is operated by Obsidian & Ivory LLC, a limited liability company formed in Arizona, which is the data controller for the information described in this policy.

4539 N 22nd St, Ste NPhoenix, AZ 85016-4639United States

For privacy questions or data requests, contact us at support@velo-flow.io.