Connecting a bank account to a company you've just met is a real decision. This page explains exactly what Rowan can and cannot do with that access, how we store what we hold, and what happens when you decide to stop — including the parts we can't promise.
We can look. We can’t touch.
Rowan exists to notice things — a charge that shouldn’t be there, a subscription that quietly doubled, a transfer that looks like the start of a scam. Noticing is all it can do.
When we connect an account, we request a single capability from Plaid — the ability to read transactions. We do not request, and therefore cannot use, the ability to move money, make payments, transfer funds, issue cards, or change anything about the account. This isn’t a policy we promise to follow; it’s the only access we hold.
What that one capability returns is each transaction as the bank describes it, plus account names and types, the masked last four digits, and balances. We store the bank’s complete record of a transaction rather than only the merchant, amount, date and category our detection runs on, so that a better method we write later can be applied to charges that already happened. What that record holds varies by bank; it can include the account holder’s name as the bank has it, who was paid and how, and where the purchase happened. It becomes eligible for deletion 60 days after we receive it, leaving only the fields we use, and a routine cleanup removes it once it does.
Two things we never receive, because we never ask for them: the full account and routing numbers that would let money be moved, and the identity products that return a date of birth, a Social Security number, or an address.
The one place money moves is your own subscription, which is billed through Stripe — a separate system that never touches a connected bank account.
Your bank password never reaches us
When you or a family member connects an account, the bank sign-in happens inside Plaid or on the bank’s own site — the same connection layer used by apps like Venmo and Robinhood. Your username and password go to them. They are never sent to Rowan, never pass through our servers, and are never stored by us, because we never have them in the first place.
What we receive back is an access token, not a credential. It works only for reading, and only until it’s revoked.
How we store what we hold
- Bank access tokens are encrypted at rest in our production database. They’re held server-side and are never sent to the app or exposed to a browser.
- Login codes are never stored in the clear. The six-digit code we text you is kept only as a hash computed with a server-side secret, so a copy of the database alone can’t be turned back into working codes.
- Session tokens are stored only as a hash on our server. The app keeps its own copy of your session in your device’s secure keystore — the operating system’s protected storage — so signing out revokes it everywhere.
- One family’s alerts can never reach another family’s contacts. Who may be notified about whom is enforced by the database schema itself, not by a check that application code has to remember to make.
What a text to a helper does and doesn’t say
If you route alerts to a trusted contact — a sibling, a caregiver — that person gets a deliberately sparse message. It names a first name and carries a link. It does not contain the amount, the merchant, the account, or what we thought was wrong.
The link goes to a page that holds no personal information either: it explains how to help, and nothing more. Someone who picks up the wrong phone learns almost nothing.
Links we text you are sent with a no-referrer policy, so if you follow a link onward from one of those pages, the address of the page you came from isn’t handed to the next site.
Stopping, and what happens when you do
If your account is being watched: reply STOP to any text, or return to your personal link and disconnect. We write the request down before we answer your phone carrier, so it survives anything going wrong on our side afterwards.
Then, in a single step that depends on nobody else: monitoring stops, the transactions we synced are deleted, and so is every alert we built from them. That part holds even if your bank or Plaid is having a bad day, because it never touches them. The person watching is told you’ve disconnected.
Closing the connection at Plaid does depend on Plaid, so we queue that and keep retrying for about three hours. If it still hasn’t gone through by then we stop retrying and flag it to a human here — it is never quietly dropped. That’s the honest shape of it: your data is already deleted by that point, and the last handshake with Plaid is the only part we can’t promise to the minute.
If you’re a trusted contact: replying STOP takes you off the list and we stop texting you. We hold no financial data about you to delete — only your name and number, which the person who added you can remove.
If any part of that doesn’t appear to have happened, email privacy@joinrowan.com and we’ll confirm it directly. We’d rather you check than assume.
What we don’t claim
A security page that only lists strengths isn’t much use, so here is the other half.
- We can’t catch every scam. Detection works on patterns, it can miss things, and it can flag a transaction that turns out to be perfectly normal. The absence of an alert doesn’t mean a transaction is safe.
- We can’t guarantee delivery. Texts and push notifications depend on carriers, Apple and Google, and your phone. They can be delayed, or fail.
- We see transactions, not everything. We read what the bank reports. Money moved in ways the account doesn’t show us is money we can’t see.
- We haven’t been independently audited yet. We’re a small, young company. We’re not going to imply a certification we don’t hold.
No system is perfectly secure, and we won’t pretend otherwise. If we ever learn of a breach affecting your information, we’ll tell you and the appropriate authorities as the law requires.
Reporting something
If you believe you’ve found a vulnerability, email security@joinrowan.com. Tell us what you found and how to reproduce it. We’ll acknowledge you, and we won’t pursue anyone who reports in good faith and doesn’t access other people’s data while doing it.
For questions about what we collect and who we share it with, see our Privacy Policy. For the rules of using Rowan, see the Terms of Service.