Skip to content

Privacy policy

Last updated: 2 October 2026

This policy explains how Rowzly handles personal information. Rowzly is run from Australia. We aim to follow the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). If you live outside Australia, you may also have rights under your local privacy law.

The short version

Rowzly is free. Statement contents are processed in your browser and are not uploaded or persisted by the app. The app sends anonymous usage counts and failure codes to our own domain, never filenames or file contents. Site delivery involves hosting requests; support email involves your email provider and ours. Those services may retain logs and messages.

Your statement files are never uploaded

Rowzly reads and cleans bank and payment statement files in your browser, on your device. Files are never uploaded to us or to anyone else. We cannot see your files, the transactions in them or the cleaned output. Files are held in memory and are gone when you close the tab.

Browser memory, caching and downloads

The app does not deliberately save statement contents in cookies, local storage, session storage or IndexedDB. Column choices and theme last only while the page is open. Your browser may cache scripts, fonts, images and other site assets. Downloaded output is saved to the location you choose and remains there until you remove it. Device backups and browser behaviour are outside the app's control. No account is needed to use the free tool. An optional Pro email waitlist is available.

No cookies, tracking scripts or third parties

Anonymous usage counts

To see how many files are converted and how often they fail, the app sends a short record to our own domain when a file is processed, when you download an export and when you choose a built-in sample. We store each record with a server timestamp in Cloudflare D1. A record holds only fixed labels:

The session ID is a random ID your browser creates when the app first sends a record. It is held in memory for that tab only, never saved on your device, and gone when you close or reload the tab. It lets us count files per session. We count sessions, not people: one person may appear as several sessions.

We never collect filenames, file contents, transactions, amounts, dates, descriptions, payees, passwords, exact file sizes, exact row counts, error messages, IP addresses or browser identifiers in these records. Records remain until we delete them. Because a record holds nothing that identifies you, we cannot find or delete your records on request. Records are capped per day and may be missing or submitted by others, so they are approximate.

Pro email waitlist

If you join the waitlist, we store your normalised email address, consent version and sign-up time in Cloudflare D1. Clicking Join submits your address and gives permission to send Rowzly Pro launch updates. The consent notice is shown beside the form. This is not a purchase or a guarantee of release. We do not verify ownership by email at sign-up or send an automatic confirmation. We retain the entry until you ask us to remove it or we delete the list. Email [email protected] to leave the list, correct your address or request deletion. No statement data is collected by this form.

Anonymous error diagnostics

When an import fails, the app may send fixed error codes, file type, a coarse size range and app version to our own domain. Unhandled application errors send a generic app-error code with no file details. We record these with a server timestamp in Cloudflare D1 to investigate reliability. We do not include filenames, file contents, transactions, passwords, error messages, stacks, IP addresses or browser identifiers in these records. Reports are limited and may be missing, duplicated across tabs or submitted by third parties, so they are not an exact count of affected users. These technical records remain until we delete them. Hosting request logs are separate and may include network details as described below.

Hosting

Our hosting provider may retain technical logs, such as IP address, request URL and browser type, for security and reliability. Statement contents are not included in app requests. Retention and processing locations depend on the hosting service (Cloudflare) and may change if we change hosting provider.

If you email us

If you choose to email us at [email protected], we receive your email address and what you write, and keep it only so we can reply. Our email provider stores those emails and may process them outside Australia. Please do not send us your bank statements. You can ask us to delete your emails at any time.

Access and correction

You can ask for a copy of any personal information we hold about you (such as waitlist details or emails you have sent us), or ask us to correct or delete it, by emailing [email protected]. We will respond within 30 days and will not charge you.

Complaints

If you have a privacy concern, email [email protected] first. We will respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Contact

Rowzly, Australia. Email: [email protected].

Changes to this policy

If Rowzly changes how statement contents or service information are handled, this policy must be reviewed and updated before those changes are released.

See also our privacy policy and terms of use.