Privacy

Your financial data stays under your control

Last updated: July 22, 2026. This page explains what Purely stores, how CSV and bank connection data is handled, and which controls are available to export, revoke or delete data.

What we collect

Purely stores profile data, source metadata, accounts, transactions, categories, rules, reports, Month Closes, supporting documents, CSV batches and billing state needed to operate the product.

Financial source data

Bank connections use provider authorization flows. We do not store bank passwords. Open Banking access is read-only for balances and transactions.

Tokens and provider payloads

Provider tokens are encrypted before storage. User exports exclude encrypted tokens and raw provider payloads by default.

CSV uploads

CSV files are parsed into import batches. Transactions are stored in your workspace and a batch can be undone from privacy settings.

How we use data

We use data to import sources, clean transactions, run Month Close, show analytics, create reports, manage subscriptions, detect errors and secure the service.

Sensitive data is not sold

Purely does not sell sensitive financial data. Trusted infrastructure providers process only the data needed to operate the service.

Available controls

Signed-in users manage these controls in settings. Destructive actions require authentication, use CSRF protection for cookie requests and are recorded as audit events.

Export all user data
Delete all workspace data
Delete your account
Delete a source
Revoke a bank connection
Undo a CSV import batch
View and revoke active sessions

Contact

For privacy requests, account help or security concerns, contact support or security.

Privacy Policy | Purely