Privacy policy
Last updated: 2 October 2026
This policy explains how Rowzly handles personal information. Rowzly is run from Australia. We aim to follow the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). If you live outside Australia, you may also have rights under your local privacy law.
The short version
Rowzly is free. Statement contents are processed in your browser and are not uploaded or persisted by the app. The app sends anonymous usage counts and failure codes to our own domain, never filenames or file contents. Site delivery involves hosting requests; support email involves your email provider and ours. Those services may retain logs and messages.
Your statement files are never uploaded
Rowzly reads and cleans bank and payment statement files in your browser, on your device. Files are never uploaded to us or to anyone else. We cannot see your files, the transactions in them or the cleaned output. Files are held in memory and are gone when you close the tab.
Browser memory, caching and downloads
The app does not deliberately save statement contents in cookies, local storage, session storage or IndexedDB. Column choices and theme last only while the page is open. Your browser may cache scripts, fonts, images and other site assets. Downloaded output is saved to the location you choose and remains there until you remove it. Device backups and browser behaviour are outside the app's control. No account is needed to use the free tool. An optional Pro email waitlist is available.
No cookies, tracking scripts or third parties
- There are no cookies, no tracking scripts and no third-party analytics.
- Fonts, scripts and images are served from our own domain. The site loads nothing from other websites.
- Existing Cloudflare zone analytics measure hosting traffic and give an approximate visitor count. We do not add a browser analytics beacon.
- Anonymous usage counts and failure codes, described below, are sent to our own domain.
- The optional Pro waitlist sends your email address and consent to our own domain.
Anonymous usage counts
To see how many files are converted and how often they fail, the app sends a short record to our own domain when a file is processed, when you download an export and when you choose a built-in sample. We store each record with a server timestamp in Cloudflare D1. A record holds only fixed labels:
- File processed: the file type (PDF, CSV, Excel, text or other), success or failure, a fixed failure code, the recognised PDF layout (such as CommBank or General layout), a row count range (such as 100 to 1,000), a processing time range and the number of files picked together as a range.
- Export downloaded: the export target (Xero, QuickBooks Online or MYOB), the output format, the number of files as a range, and whether it was a single file or zip.
- Sample used: which built-in sample you chose.
- Every record: a session ID and the app version, plus the server timestamp.
The session ID is a random ID your browser creates when the app first sends a record. It is held in memory for that tab only, never saved on your device, and gone when you close or reload the tab. It lets us count files per session. We count sessions, not people: one person may appear as several sessions.
We never collect filenames, file contents, transactions, amounts, dates, descriptions, payees, passwords, exact file sizes, exact row counts, error messages, IP addresses or browser identifiers in these records. Records remain until we delete them. Because a record holds nothing that identifies you, we cannot find or delete your records on request. Records are capped per day and may be missing or submitted by others, so they are approximate.
Pro email waitlist
If you join the waitlist, we store your normalised email address, consent version and sign-up time in Cloudflare D1. Clicking Join submits your address and gives permission to send Rowzly Pro launch updates. The consent notice is shown beside the form. This is not a purchase or a guarantee of release. We do not verify ownership by email at sign-up or send an automatic confirmation. We retain the entry until you ask us to remove it or we delete the list. Email [email protected] to leave the list, correct your address or request deletion. No statement data is collected by this form.
Anonymous error diagnostics
When an import fails, the app may send fixed error codes, file type, a coarse size range and app version to our own domain. Unhandled application errors send a generic app-error code with no file details. We record these with a server timestamp in Cloudflare D1 to investigate reliability. We do not include filenames, file contents, transactions, passwords, error messages, stacks, IP addresses or browser identifiers in these records. Reports are limited and may be missing, duplicated across tabs or submitted by third parties, so they are not an exact count of affected users. These technical records remain until we delete them. Hosting request logs are separate and may include network details as described below.
Hosting
Our hosting provider may retain technical logs, such as IP address, request URL and browser type, for security and reliability. Statement contents are not included in app requests. Retention and processing locations depend on the hosting service (Cloudflare) and may change if we change hosting provider.
If you email us
If you choose to email us at [email protected], we receive your email address and what you write, and keep it only so we can reply. Our email provider stores those emails and may process them outside Australia. Please do not send us your bank statements. You can ask us to delete your emails at any time.
Access and correction
You can ask for a copy of any personal information we hold about you (such as waitlist details or emails you have sent us), or ask us to correct or delete it, by emailing [email protected]. We will respond within 30 days and will not charge you.
Complaints
If you have a privacy concern, email [email protected] first. We will respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Contact
Rowzly, Australia. Email: [email protected].
Changes to this policy
If Rowzly changes how statement contents or service information are handled, this policy must be reviewed and updated before those changes are released.
See also our privacy policy and terms of use.