Privacy policy
MarginFlow (bg.boazcohen.ai) is a private operations tracker for a single-operator resale business, operated by Boaz Cohen (“the operator”). It is not a consumer product: there is one account, the operator’s own, and the data it processes is the operator’s own business data. This policy explains what the application stores and how it is protected, including the financial data received through Plaid.
What is stored
- Buying-group commitments, retail orders, inventory serial numbers, shipments, payouts, and the accounting derived from them.
- Order details parsed from retailer confirmation emails that the operator submits for import.
- Bank transaction data (dates, amounts, descriptions) received through Plaid from accounts the operator has connected, used solely to reconcile buying-group payouts against real deposits.
- Sign-in identity (name, email, authentication identifiers) processed by Clerk, the authentication provider.
Plaid
Bank connections are made through Plaid Inc. When an account is linked, MarginFlow receives transaction data via Plaid’s API; it never sees or stores bank usernames or passwords. Plaid’s own handling of end-user data is described in the Plaid End User Privacy Policy. Plaid access tokens are encrypted at the application layer (AES-256-GCM) before storage, under a key held outside the database. Bank connections are read-only; MarginFlow cannot move money.
How data is protected
- All traffic is encrypted in transit (TLS).
- Data is stored in Neon (PostgreSQL), which encrypts storage at rest; the application runs on Fly.io.
- Bank credentials received from Plaid carry a second, application-layer encryption under a key that never reaches the database.
- Every record is scoped to the single owner account, and every request must carry an authenticated session for that account. All other callers are refused.
What is not done with data
- No data is sold, rented, or shared for advertising — there is no advertising.
- No data is shared with third parties beyond the processors named here (Neon, Fly.io, Clerk, Plaid), each used solely to run the application.
- No analytics or tracking beyond operational server logs.
Retention and deletion
Operational records are retained as business records. A connected bank account can be unlinked at any time, which stops all further data flow from Plaid; stored transaction data and any other records can be deleted on request to the operator.
Contact
Questions about this policy or requests concerning stored data: boaz.cn@gmail.com.