Last updated 27 July 2026
Prowl handles the most private data you have. This page says plainly what it does with it, what it never does, and how your account is protected. Everything stated in the present tense describes the app as it is shipped today; what is planned is described too, and always named as planned.
Today, Prowl reads the statements you upload. There is no bank connection to authorise and no bank password to hand over, so Prowl holds no bank credentials — there is nothing in it for anyone to take.
Bank linking is coming, and it deserves describing before it exists. Prowl will offer an optional connection to your bank through Plaid, a regulated bank-data provider. You would sign in at your bank inside Plaid's own window — Prowl never sees or stores your bank username or password, before or after that launch. What Prowl would receive is the same information a statement carries: transactions and balances, entering the app through the same rules as an uploaded file. The connection would be yours to switch off at any time, and statement upload stays forever for anyone who would rather not link anything. This page and the privacy policy will be updated the day it goes live.
An uploaded PDF, CSV or spreadsheet exists in memory only, for as long as it takes to read the transactions out of it. It is never written to disk. What is stored is the cleaned transactions themselves — dates, descriptions, amounts, account names, currencies — and nothing else from the file.
Most statements are read entirely by Prowl itself. When a bank's format is new, that statement's text is sent once to Anthropic's API to be read, and Prowl learns the layout so every future statement from that bank is read locally and free. The account holder's identifying details — account and reference numbers, IBANs, email addresses, and the name and postal address printed at the top — are stripped out before the text leaves the machine, and the statement file itself is never sent. The reading is only accepted if the transactions reconcile against the totals the statement prints for itself. The full detail, including the one thing that cannot be stripped, is in the privacy policy.
After an import, Prowl suggests a readable name and a category for the shops it hasn't met — "SQ *BLUE BOTTLE 0412" comes up as "Blue Bottle", already filed under coffee. To do that it sends the shop's description as the bank printed it, and nothing else, to Anthropic's API: never an amount, a date, a balance, an account, or how often you shop somewhere. Each shop is looked up roughly once ever, then remembered in your own account. A suggestion is never applied on its own — it waits on screen, dimmed, until you accept it.
There is no newsletter, no product email, no push notification and no digest. You cannot be subscribed to anything, because there is nothing to subscribe to. Today exactly three emails exist: your invite, the link you ask for when you have lost every device, and a warning the moment a new device gains access to your account. That warning deliberately contains no links and no buttons — it tells you what to do, not where to click — so a fake of it has nothing to steal.
Prowl is opened with a passkey — the same fingerprint, face or PIN that unlocks your own device. Nothing you could reuse or be tricked out of is stored here: your device keeps the private half of the key and never hands it over, and Prowl keeps only the public half, which cannot sign in anywhere. Two things follow, and they are the reason for the choice. A break-in here leaks no way to log in as anybody. And a convincing fake of this site cannot collect a passkey, because your browser will not offer one to a domain it wasn't made for — the check that people cannot be expected to do by eye is done for them.
The cost is honest and worth stating: if you lose every device you have registered, the emailed link is the only way back in, which makes your email account the last key. Registering a second device — a laptop as well as a phone — is what prevents that. And since that mailbox is the last key, protect it like one: turn on the strongest sign-in protection your email provider offers. Prowl does its part by warning you the moment any new device is added.
The disk holding the database is snapshotted daily and those snapshots are kept for about seven days, so a hardware failure costs at most a day. Deleted data is gone from backups once that window passes.
You can export every transaction to a spreadsheet whenever you like, and you can delete your account and everything in it from inside Prowl, without asking anyone. Leaving has to be safe, or joining never was.
If you find a security problem, email support@prowl.money and say what you found. You will get a reply, and credit if you want it.