Legal

Privacy Policy

Last updated August 16, 2026Rowan, Inc.

This policy explains what Rowan collects, how we use and protect it, who else sees it, and the choices you have — including how read-only bank data is accessed through Plaid, and what happens to a message you send to Second Look. We never move your money, and we never sell your information.

Overview

Rowan, Inc. (“Rowan,” “we,” “us,” or “our”) helps people watch over the bank accounts of family members they care about and alerts them when a transaction looks like a scam. This Privacy Policy explains what information we collect, how we use and share it, and the choices you have. It applies to our mobile app, our website at joinrowan.com, the bank-connection flow we host for invited family members, Second Look — our free scam check, whether you use it in the app, on the web, by text, or by email — and related services (together, the “Services”).

Because our product is built around financial information, we hold ourselves to a simple promise: we have read-only access and can never move your money. We do not sell personal information.

Two kinds of people

Rowan involves two roles, and the information we hold differs for each:

  • The protector — the adult who installs the app, creates an account, and invites one or more loved ones to be watched.
  • The watched person (“loved one”) — the family member whose accounts are monitored. A loved one does not create an account or install anything. Everything on their side happens on one web page and by text message. They connect their bank from their own phone, and shortly after that we send one welcome text with our contact card, so they know the number is us.

After that we get in touch only when there is a reason to: if their bank asks them to sign in again, if they are the one paying and something needs doing about their payment method, or if they text us a message they want checked and we write back. They can reply STOP to any of it. It is an ongoing, occasional relationship rather than a one-time hand-off, and an earlier version of this policy described it as “exactly twice,” which was wrong.

If you are a loved one someone invited, the section Choices for the person being watched is written for you.

Information we collect

Information the protector provides

  • Account details — the protector's mobile phone number (used to sign in by one-time code) and name. An email address is optional; if you give us one we ask you to confirm it with a code, and we use it for the weekly digest and for billing receipts.
  • Details about each loved one — the name, relationship, approximate age, and mobile phone number the protector enters, plus the number the loved one confirms for themselves when they connect. The protector represents that they have permission to provide this information (see our Terms of Service).
  • Trusted contacts — if you nominate someone else to be texted about serious alerts, we store their name, how they're related to you, their phone number, an email address if you add one, whether their number has been confirmed, and whether they've asked us to stop texting them.
  • Monitoring preferences — the watch rules, thresholds, and merchant limits you configure, and the actions you take on alerts.
  • Contacts on your phone stay on your phone. The app can offer to read your address book to suggest who you might be watching over. That reading happens entirely on your device; the only thing that reaches us is the one name and number you pick.

Financial information (via Plaid)

When a loved one connects a bank account, we receive financial data through Plaid on a read-only basis. See Bank connections & Plaid for exactly what this includes and what it deliberately excludes.

What you send to Second Look

Second Look is our free scam check, and it works on whatever you hand it: a message you paste, a screenshot you upload, a text you forward to our number, or an email you forward to us. That content is the one thing we ask you for that we didn't write, so it gets its own section — see Second Look.

Payment information

Card details are entered directly with Stripe, our payment processor, and never reach our servers. What we hold is what Stripe tells us afterwards: which card brand and last four digits are on file, and whether the subscription is paid up.

Information we collect automatically

  • Device & push tokens — to deliver the alert notifications that are the core of the product, we store the push token for the protector's device.
  • Log & usage data — device type, app version, IP address, and diagnostic events, used to operate, secure, and improve the Services.
  • Measurement on our website — our marketing pages count page views and waitlist signups, and record which link or campaign brought you to us. This uses no cookies: what little we store is held in your browser tab and is gone when you close it, and we don't record your IP address with it. These counts go to our own servers first and are passed on to our analytics provider from there, so your network address is not attached to them and does not reach that provider at all. The bank-connection pages carry no analytics or advertising trackers at all.
  • Abuse-prevention records. Several of our pages are open to anyone with a link and no sign-in, so we count how often each source uses them. We never store the raw IP address or phone number for this: we store a keyed one-way hash of it, and the key is different for each feature, so the record kept for one can't be matched against the record kept for another. These become eligible for deletion after 48 hours, and a routine cleanup removes them once they do.
  • Your email address, if you join the waitlist — along with which page you joined from, and a keyed one-way hash of your IP address so one source can't flood the list.
  • Who invited you, if someone did. A Rowan user who has you as a trusted contact can send you an invitation link of their own. If you sign up through it, we record that your account came from theirs — the two accounts, the contact entry the link was made from, and the code it carried — so the invitation can be credited to whoever sent it. We keep that link between you on our own systems and do not send it to our analytics provider.
  • Cookies on our website. We set none of our own, for advertising or for measurement, and our site runs no advertising trackers. The Plaid and Stripe components embedded on the bank-connection and payment pages set their own cookies in order to work and to detect fraud.

Bank connections & Plaid

We connect to financial institutions through Plaid Inc., the same technology used by apps like Venmo, Chime, and Robinhood. When a loved one taps their invitation link and chooses their bank:

Read-only, always

Bank credentials are entered directly with Plaid or the bank — Rowan never sees, receives, or stores bank usernames or passwords. Our access is read-only: we cannot move money, make payments, transfer funds, issue cards, or change anything about the account.

We ask Plaid for one capability and one only: the ability to read transactions. Through it, on a read-only basis, we receive:

  • Each transaction, as the bank describes it. The merchant, amount, date, and category are what our scam-pattern detection actually runs on — but we store the bank's complete record of the transaction, not just those fields, so that a better detection method we write later can be applied to charges that already happened. What that complete record contains varies by bank. It can include things like the name of the account holder as the bank has it, who was paid and how, and where the purchase happened. It becomes eligible for deletion 60 days after we receive it, leaving only the fields we use, and a routine cleanup removes it once it does — the same schedule described under Data retention & deletion.
  • Account information — account names, types, the masked last four digits, and balances.

Two things we deliberately do not ask Plaid for, and therefore never receive: the full account and routing numbers that would let money be moved, and the identity-verification products that return a date of birth, a Social Security number, or an address. An earlier version of this policy said we received account and routing numbers and identity information. We do not, and we have never held the access that would return them.

Plaid's collection and use of information is governed by Plaid's Privacy Policy and End User Privacy Policy. A loved one can disconnect at any time, which revokes our access through Plaid (see Choices for the person being watched).

Second Look: what happens to a message you send us

Second Look is our free scam check. You paste in a message, upload a screenshot, forward a text to our number, or forward an email to us, and we tell you plainly what we make of it. You don't need an account, and most people who use it don't have one.

What you send us is usually something a stranger wrote to you, and a screenshot taken in a hurry can carry far more of your screen than the part you meant to show us. So this section says exactly where it goes and how long it lasts.

Who reads it besides us

  • Anthropic. The message, or the image, is sent to Anthropic's Claude AI to be read and judged. This is the check — there is no version of Second Look that works without it. If you go on to share a screenshot, it is sent a second time, to look for personal information before that picture is published. Anthropic processes what you send on our behalf, under contract, to answer those questions. It is not permitted to use it to train its models or for any purpose of its own — only, as with any company running a service, to keep that service running, secure, and working correctly.
  • Google Web Risk. If the message contains links, we pull out the web addresses and ask Google Web Risk whether it already knows them to be dangerous. We send the addresses only — never the message they came from.
  • Telnyx, if you text it to us, and Resend, if you email it. These are the companies that carry our messages. When you forward something to us, they receive and hold their own copy on their own schedule, the same way your phone carrier holds your texts. For an emailed check, their copy is the one that lasts, not ours.

We do not use what you send to Second Look to train AI models. We don't use it to build a profile of you, and we make no attempt to identify, contact, or keep a record of whoever sent you the message in the first place.

What we keep, and for how long

The rule, in one sentence: we keep our read of your message, never your message.

  • The message and the image are discarded once the check is done. This is unconditional, and it applies to everyone — signed in or not, in the app or over text or email.
  • If you're signed in, we save the result to your history. That row holds the risk level, the names of the warning signs we spotted — chosen from a short fixed list we wrote, such as “Urgency” or “Gift cards” — whether it was a message or a screenshot, when you checked it, and your own answer to who you were checking it for. It holds no part of the message and no sentence written by the AI, because those sentences quote the message back.
  • If you text us, your message is held briefly while we answer it. A text has to be answered by a background job rather than on the spot, so your number, the text of your message, and the web address of any picture you sent are written down and then erased the moment the reply goes out — normally within seconds, and in every case within about six minutes. What's left afterwards is our provider's message id and some timestamps, deleted after 48 hours.
  • If you email us, we store nothing about the message at all — only an opaque id from our email provider so a retried delivery doesn't get answered twice, deleted after 48 hours. We read the body, the headers, and one attached image if there is one, and none of it is written down on our side.

When you tap Share

Sharing a result is the one deliberate exception, because the point of it is to publish. If you tap Share, we save a snapshot so the link renders a real page: the message you pasted, or the screenshot if you chose to include it, plus the assessment. Out of anything written on that page we strip email addresses, government ID numbers, and real card and account numbers — but not phone numbers or links, because in a scam message those belong to the scammer and are the evidence. Before publishing a screenshot we ask the AI to look for personal information belonging to you or your family, and if it finds any (or can't tell) we come back and ask you first.

A shared link is unguessable, carries an instruction telling search engines not to index it, and stays live for 90 days. When it expires we empty the content out of it, and the remaining record is deleted 30 days after that.

If you were signed in when you shared it, you can revoke the link before then — that empties it straight away. If you shared without an account, we have no way to tell the link is yours: nothing about it is connected to you, which is also why nobody else can claim it. There is no way for us to take it down on request, and it runs its 90 days.

If a family member is watching over you

When someone forwards us a text and we judge it a likely scam, and that person is being watched over by a family member through Rowan, we let that family member know: that a message was flagged, how serious it looked, and when. Never the message, never a screenshot, and never anything the AI wrote about it. Checks that come back safe, or merely suspicious, tell nobody anything — we don't report that a check happened at all. Everyone else who forwards us something — a friend, a spouse, someone who found our number on a card — has nobody to notify, and we say so in the reply.

How we use information

We use the information we collect to:

  • Provide the core service — monitor connected accounts and match transactions against known scam patterns and the watch rules you set.
  • Check a message you send to Second Look and write back with what we make of it — see Second Look.
  • Send alerts and notifications — deliver push notifications to the protector when something needs attention, text a trusted contact about a serious alert, and email a weekly digest.
  • Send security codes and the occasional message about a connection — the one-time codes used to sign in, the welcome text to a loved one who has just connected, a nudge when a bank asks them to sign in again, and a payment-method link if they're the one paying. We do not text the invitation itself: the protector hands that link over themselves, and nothing in that flow contacts a loved one who hasn't connected yet.
  • Take payment for the subscription, through Stripe.
  • Keep the Services secure — detect abuse, prevent fraud against the Services, and protect accounts.
  • Improve the Services — understand which detections are accurate, reduce false alarms, and develop new protections. For Second Look this means counts and totals worked out from checks whose content we already discarded; we don't keep what you sent in order to improve anything.
  • Comply with law and enforce our Terms of Service.

We do not use your financial information for advertising, we do not sell it, and we do not use anything you send us to train AI models.

How we share information

We share information only as described here. We do not sell personal information, and we do not share it for cross-context behavioral advertising.

  • With the protector who invited a loved one. The whole purpose of the Services is to show the protector the watched person's account activity and alerts.
  • Service providers that operate the Services under contract. Each one is named below with what it actually receives, because “service providers” on its own tells you nothing. They may use what they receive only to provide their service to us.
  • For legal reasons — to comply with law, valid legal process, or to protect the rights, safety, and property of users, the public, or Rowan.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
  • With your direction — for example, when you choose to share an alert or loop in another family member.

The companies we rely on, and what each one gets

  • Plaid — bank connectivity. The bank sign-in happens with Plaid, and the transaction and account data described in Bank connections & Plaid comes back through them.
  • Anthropic — the AI that reads a message or screenshot sent to Second Look and judges whether it looks like a scam, and that checks a screenshot you choose to share for personal information before it is published. It receives that content, and nothing else about you.
  • Google Web Risk — receives the web addresses found inside a message sent to Second Look, to tell us whether any are already known to be dangerous. It receives the addresses only.
  • Telnyx — our text-message provider, in both directions. Outbound, it carries our sign-in codes, the welcome message, connection nudges, payment links, and the sparse alert text we send a trusted contact, so it sees those messages and the numbers they go to. Inbound, when someone forwards a message to our scam-check number, Telnyx receives that message and holds any attached picture on its own servers for about a month.
  • Resend — our email provider, also in both directions. Outbound, it carries confirmation codes and the weekly digest, which names the person being watched and the merchants and amounts we're flagging. Inbound, when you forward an email to our scam-check address, Resend receives and stores that email, its headers, and its attachments, and hands them back to us when we go to answer it. For an emailed check their copy is the durable one, kept on their retention schedule, not ours.
  • Your browser’s push service — if you turn on alerts in a web browser, each notification travels through the push service that browser is built on: Google for Chrome and Edge, Apple for Safari, Mozilla for Firefox. What we send them is encrypted for your browser specifically, so unlike the app’s notifications the wording is not readable by the service carrying it. What they can see is that a message was sent to your particular subscription, and when. We never send them anything on a schedule, so the timing reflects real findings on your account.
  • Expo — push-notification delivery and app updates. Each notification carries its full title and text, which typically name the merchant and the amount, so Expo and then Apple or Google handle that wording on the way to your phone. The app also checks Expo for a new version of itself. That request tells them which platform and app version you are running, which update your copy is on and any it recently failed to start, a lasting identifier for your installation of the app, and — as with any request to any server — the network address it came from. If the app crashed on launch, the next check also carries the text of that error, which is written by the code that failed rather than chosen by us.
  • Stripe — payments. Card details go straight to Stripe and never reach us; Stripe also receives your email address, your phone number if you're paying for yourself, and an internal Rowan account reference.
  • Amplitude — product analytics, in the app and on this website. In the app, it receives events about how the app and the connect flow are used, tied to your Rowan account id or, before you sign in, to a device-scoped id. On the website it receives two events only — that a page was viewed, and that the waitlist form was submitted. A page view carries which page; a waitlist submission carries where on the site you submitted from and whether it succeeded. Both carry whichever campaign link brought you here, the time, a pair of tab-scoped ids that group one visit together, and the browser, operating system and language your device reports. Those website events go to our own servers first and are passed on from there, so your network address never reaches Amplitude at all. The website measurement uses no cookies and keeps nothing on your machine after you close the tab, so it cannot follow you between visits or to any other site. Events carry what happened, not what was in it: no transaction data, no bank details, and nothing you sent to Second Look. When you delete your account we ask Amplitude to delete your profile too.
  • Sentry — error reporting, in the app, on the website, and on our servers. Receives crash and error reports. We turn off its collection of personal detail and strip phone numbers and the tokens in our private links out of every report before it is sent.
  • Detour — invite links. Used when someone opens an invite from a friend or family member and doesn't have the app yet. Tapping Get the app records the click and the invite's reference code, along with the network address, browser, device type, screen size, language and time zone of the device that tapped it. The first time the app is opened after being installed it sends those same details once, to work out which invite the install came from so the person who invited you gets the credit — that one check happens on any new installation, not only on invited ones, and it does not repeat on later openings. On iPhone the check can also read the clipboard, which is why iOS may tell you the app pasted from Safari. We have turned off the automatic app-open and retention tracking this tool offers. None of it is used for advertising.
  • Our cloud hosting and database providers — where the Services run and where the information described in this policy is stored.

Choices for the person being watched

If a family member invited you to Rowan, you stay in control:

  • You choose whether to connect. Nothing is shared until you open the link your family member gave you and connect your bank yourself. Until then we hold only what they typed in — your name, how you're related, roughly your age, and a phone number — and we never contact you at it.
  • Your password stays yours. You sign in through Plaid or your bank — Rowan never receives your bank credentials.
  • You can stop at any time. Reply STOP to any text from us, or return to your personal link, to disconnect. When you disconnect, we revoke our access through Plaid and delete the connected financial data associated with you, except limited records we must keep for legal or security reasons. The protector is notified.
  • You can text us without any of that changing. If you forward us a message to check, we answer you and then discard it. Your family member is told only when a message looks like a scam, and only ever that it did and when — never what it said. See Second Look.

Data retention & deletion

We keep personal information for as long as needed to provide the Services and for legitimate business or legal purposes. When a loved one disconnects, or when a protector closes their account, we revoke bank access and delete the associated financial data, except where we must retain limited records (for example, to comply with law, resolve disputes, or prevent abuse). De-identified or aggregated data that can no longer be linked to you may be retained.

Beyond that, specific records become eligible for deletion on the schedule below, and a routine cleanup process removes them once they do:

  • What you send to Second Look. Discarded as soon as the check is done. A message you text us is held while we compose the reply and erased when it goes out — within about six minutes at the outside. See Second Look for the full picture, including what a signed-in history row does and doesn't hold.
  • Shared scam-check results. A link you share stays live for 90 days. Once it expires, the content you shared — the message text, any screenshot, and the assessment written about it — becomes eligible for deletion, and the remaining record becomes eligible 30 days after that.
  • Bank transaction records. Kept while the connection is active, and deleted when the loved one disconnects or the protector closes their account. The bank's complete record of each transaction becomes eligible for deletion 60 days after we receive it, leaving only the fields we use.
  • Sign-in codes. A code is valid for 10 minutes; the record of it becomes eligible for deletion after 48 hours.
  • Email confirmation codes. The record holds the address being confirmed alongside the code. The code is valid for 10 minutes; the record becomes eligible for deletion 30 days after that.
  • Abuse-prevention records — the keyed hashes described under Information we collect, and the message ids that keep a forwarded text or email from being answered twice. Eligible for deletion after 48 hours.
  • Trusted contacts. Kept for as long as the person who added them keeps them on the list, and deleted when they remove them or close their account. If a contact replies STOP we keep a note that they opted out, so we don't text them again.
  • Who invited whom. The referral record described under Information we collect is kept for as long as the invited account exists and is deleted with it. If the person who sent the invitation closes their account first, we clear them out of the record and keep the rest.
  • The weekly digest. We keep the summary we sent — the counts, merchants, and amounts for that week — so the app can show you the most recent one. It becomes eligible for deletion after 180 days, and we empty it sooner than that if the loved one it describes disconnects.
  • Waitlist emails. Kept until we launch to you or you ask us to remove you.
  • Sign-in sessions. A session expires after a period of inactivity (60 days by default), and in every case 180 days after you signed in, however often you use the app. The record is removed once it has expired and is no longer needed for account-security checks.
  • Trusted-contact verification codes and payment links. Each is valid for minutes to hours; the record becomes eligible for deletion after 30 days.
  • Alerts. Kept for as long as the person they're about is being watched, and deleted along with them — looking back at why you called your mother in March is much of the point of having them. They are not aged out on a timer.
  • Billing records. Retained as required for tax, dispute, and chargeback purposes.

To request deletion, contact us at privacy@joinrowan.com. Closing your account also asks Amplitude to delete the analytics profile tied to it.

How we protect your information

We use administrative, technical, and physical safeguards designed to protect personal information. Data is encrypted in transit, one-time login codes are stored only in hashed form, bank access tokens are encrypted at rest, and access to financial data is limited to what the Services require. Bank access tokens are held server-side and are never exposed to the app or the browser.

No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security. If we learn of a breach affecting your information, we will notify you and the appropriate authorities as required by law.

Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. We honor these rights regardless of where you live, to the extent practicable.

U.S. state privacy rights (including California)

We do not sell personal information or share it for cross-context behavioral advertising. California residents and residents of other states with privacy laws may request access to or deletion of their personal information and may appeal a decision. We will not discriminate against you for exercising these rights.

EU/UK rights

Where the GDPR or UK GDPR applies, our legal bases for processing are performance of a contract, your consent (which you may withdraw), our legitimate interests in operating and securing the Services, and compliance with legal obligations. You may have the right to lodge a complaint with your local supervisory authority.

To exercise any right, email privacy@joinrowan.com. We may need to verify your identity before acting on a request.

Children's privacy

The Services are intended for adults and are not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Services after an update means you accept the revised Policy.

Contact us

Questions about this Policy or your information? Reach us at:

Rowan, Inc.