Data Retention & Disposal Policy

Last updated: 18 September 2026 · Outflow by STNC (outflow.stnc.com)

1. Purpose

This policy explains what personal and financial data Outflow stores, how long we keep it, and how you (or we) permanently dispose of it. It supports our security obligations to users and to partners such as bank-data aggregators (for example Plaid and TrueLayer).

2. Data we process

  • Account data: name, email, password hash, MFA secrets (encrypted), backup-code hashes.
  • Organization data: workspace name and membership.
  • Bank connection data: provider item IDs, institution names, encrypted access tokens, consent expiry metadata.
  • Financial records: accounts, transactions, categories, budgets, recurring-charge detections, import job metadata / review payloads.
  • Technical logs: application and hosting logs that may include IP address and request metadata.

3. Retention periods

DataRetentionDisposal trigger
Login & MFA credentialsWhile the account is activeAccount deletion
Bank access tokensWhile the connection is activeDisconnect, financial wipe, or account deletion
Transactions & derived insightsWhile the account is activeUser wipe request or account deletion
Uploaded statement contentProcessed in-request; review payloads only while an import needs reviewImport completion / wipe / account deletion
Application logsUp to 30 days (hosting provider defaults may apply)Automated log rotation
Backups (if enabled in production)Up to 30 days after primary deletionBackup expiry / purge job

We do not sell personal financial data. Aggregator partners (Plaid, TrueLayer) process bank data under their own terms and retention controls when you connect an institution through them.

4. Disposal methods

  • Logical deletion: records are permanently removed from the application database (not soft-deleted).
  • Token destruction: encrypted bank tokens are deleted with the connection; encryption keys are not reused to recover deleted ciphertext.
  • User-initiated disposal: from Settings → Data you may wipe all financial data or delete your entire account. Both actions require password confirmation and MFA when enabled.
  • Irreversibility: disposal is permanent. You will need to re-link banks and re-import statements to restore history.

5. Your controls

  1. Disconnect a bank connection to drop its tokens and stop sync.
  2. Wipe financial data — deletes transactions, accounts, budgets, recurring items, imports, and connections; keeps your login.
  3. Delete account — removes your user, MFA material, and organizations you solely own, including all financial data.

Open Data settings → · Privacy policy

6. Legal & operator holds

If we are required by law, regulation, or a binding request from a competent authority to retain specific records, we may preserve the minimum necessary data beyond the periods above until the hold is released. STNC will document any such holds for the outflow.stnc.com deployment.

7. Contact

For retention or disposal requests related to Outflow at outflow.stnc.com, contact STNC support:
support@stnc.com