Data Retention & Disposal Policy
Last updated: 18 September 2026 · Outflow by STNC (outflow.stnc.com)
1. Purpose
This policy explains what personal and financial data Outflow stores, how long we keep it, and how you (or we) permanently dispose of it. It supports our security obligations to users and to partners such as bank-data aggregators (for example Plaid and TrueLayer).
2. Data we process
- Account data: name, email, password hash, MFA secrets (encrypted), backup-code hashes.
- Organization data: workspace name and membership.
- Bank connection data: provider item IDs, institution names, encrypted access tokens, consent expiry metadata.
- Financial records: accounts, transactions, categories, budgets, recurring-charge detections, import job metadata / review payloads.
- Technical logs: application and hosting logs that may include IP address and request metadata.
3. Retention periods
| Data | Retention | Disposal trigger |
|---|---|---|
| Login & MFA credentials | While the account is active | Account deletion |
| Bank access tokens | While the connection is active | Disconnect, financial wipe, or account deletion |
| Transactions & derived insights | While the account is active | User wipe request or account deletion |
| Uploaded statement content | Processed in-request; review payloads only while an import needs review | Import completion / wipe / account deletion |
| Application logs | Up to 30 days (hosting provider defaults may apply) | Automated log rotation |
| Backups (if enabled in production) | Up to 30 days after primary deletion | Backup expiry / purge job |
We do not sell personal financial data. Aggregator partners (Plaid, TrueLayer) process bank data under their own terms and retention controls when you connect an institution through them.
4. Disposal methods
- Logical deletion: records are permanently removed from the application database (not soft-deleted).
- Token destruction: encrypted bank tokens are deleted with the connection; encryption keys are not reused to recover deleted ciphertext.
- User-initiated disposal: from Settings → Data you may wipe all financial data or delete your entire account. Both actions require password confirmation and MFA when enabled.
- Irreversibility: disposal is permanent. You will need to re-link banks and re-import statements to restore history.
5. Your controls
- Disconnect a bank connection to drop its tokens and stop sync.
- Wipe financial data — deletes transactions, accounts, budgets, recurring items, imports, and connections; keeps your login.
- Delete account — removes your user, MFA material, and organizations you solely own, including all financial data.
6. Legal & operator holds
If we are required by law, regulation, or a binding request from a competent authority to retain specific records, we may preserve the minimum necessary data beyond the periods above until the hold is released. STNC will document any such holds for the outflow.stnc.com deployment.
7. Contact
For retention or disposal requests related to Outflow at outflow.stnc.com, contact STNC support:
support@stnc.com