Effective date: June 1, 2025 · Last updated: June 7, 2025
Welcome to TCFlow ("we", "our", or "us"). TCFlow is a personal finance tracking application that helps you monitor income, expenses, budgets, and overall cashflow. This Privacy Policy explains how we collect, use, and protect your information when you use our service.
By using TCFlow, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the service.
When you sign in with Google, we receive the following from Google's OAuth 2.0 service:
We do not request or store OAuth access tokens, refresh tokens, or any Google Drive / Sheets scopes. Authentication is identity-only.
All financial data you enter — transactions, budgets, categories, accounts, and settings — is stored in a private Turso database (hosted on Turso's infrastructure) that is isolated to your account. No other user can access your data.
We store a short-lived, encrypted session cookie in your browser to keep you signed in. This cookie contains only your name, email, picture URL, and Google user ID — no tokens. It expires after 7 days and is deleted when you sign out.
Our hosting provider may collect standard server logs including IP addresses, browser type, pages visited, and timestamps. These are used for security and performance monitoring only.
We use the information we collect to:
We do not use your data for advertising, profiling, or any purpose other than providing the TCFlow service to you.
Your financial data is stored in a Turso libSQL database — a distributed, edge-hosted SQLite service. Each user's data is isolated by a unique user ID and is never commingled with other users' data. You can export or delete your data at any time from within the app.
Session cookies are encrypted using a server-side secret key, marked HttpOnly (inaccessible to JavaScript), and transmitted only over HTTPS in production.
Unlike earlier versions of TCFlow, we no longer store or use Google OAuth access or refresh tokens after the initial sign-in. Your Google account is used only to verify your identity. No Google APIs are called after login.
We do not sell, trade, rent, or share your personal information with any third parties, except as required by law or as necessary to provide the service (e.g., Turso for database hosting, Google for sign-in authentication).
TCFlow uses the following Google APIs:
TCFlow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We only request the minimum scopes necessary:
userinfo.email — to identify your accountuserinfo.profile — to display your name and picture We do not request spreadsheets, drive.file, or any other Google API scopes.
TCFlow is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the "Last updated" date at the top of this page. Continued use of TCFlow after changes constitutes acceptance of the updated policy.
If you have questions or concerns about this Privacy Policy or our data practices, please reach out:
TCFlow
Gemini Powered • Context-Aware Advice
I've analyzed your transaction registers and accounts. Ask me custom questions or try one of these suggestions: