Skip to content

Privacy & security

How Fly Trap handles your data

A plain description of what the web app actually does today. It is not a legal policy; the owner's approved privacy policy will be linked here once it exists.

Where your data lives

The Fly Trap web app keeps your account in a hosted database (Supabase), not on your computer. Every table that holds your information is locked to your signed-in account with row-level security, and the server re-checks ownership for every change. Another user can't read or change your records.

  • Account: your email address and a hashed password, managed by Supabase Auth.
  • Your workspace: rules, purchases you add or import (date, amount, currency, merchant, optional description, category and note), your review decisions, chosen websites, pauses, and an activity history of those actions.
  • Bank-linked data (only if you link a bank): the institution name, account names and last four digits, and transactions (date, amount, currency, merchant, category, pending status). The bank access token Plaid issues is encrypted before it's stored and never sent to your browser.
  • Browser companion: a pairing record (a label you choose and when it last checked in) plus a hashed pairing key.

The demo is different: it runs entirely in your browser tab with sample data and saves nothing.

Bank linking and Plaid

Optional read-only bank linking through Plaid is in testing and not yet available for real bank accounts.

When it's available, linking is optional and read-only. You sign in to your bank inside Plaid's window; Fly Trap never sees or stores your bank username or password. Fly Trap asks Plaid only for transactions. It does not request account or routing numbers, balances, identity details, or the ability to move money.

Banks report transactions on their own schedule, often hours or a day later, so Fly Trap shows when each connection last updated. You can disconnect a bank at any time: Fly Trap asks Plaid to revoke access and then deletes that connection's accounts and transactions. If Plaid can't be reached, the app says so and lets you retry instead of pretending it worked.

What Fly Trap can and can't know

  • A transaction shows where money went, not what you bought. Flags are prompts for your judgment, not conclusions.
  • Fly Trap never freezes cards, stops payments, or moves money.
  • No automated system decides on your behalf: pauses start only when you confirm a catch.

The browser companion

The optional extension receives only your chosen websites and when the current pause ends. It doesn't read the pages you visit, your history, or any bank website, and it never receives your Fly Trap password or bank tokens. It uses a pairing key you can revoke from the app at any time. It covers only the browser profile you pair it with.

Export and deletion

From Account in the app you can download everything stored for your account as JSON, plus your purchases as CSV. Bank tokens are never included in an export.

Deleting your account first revokes every linked bank with Plaid and every paired browser, then removes your rules, purchases, bank data, decisions, pauses, history and the login itself. If a bank revocation fails, deletion stops and tells you, so nothing is left connected behind your back. Database backups kept by the hosting provider can hold deleted data until they expire on the provider's schedule.

Security practices

  • All traffic uses HTTPS. Secrets such as Plaid keys stay on the server and are never shipped to the browser.
  • Bank access tokens are encrypted with AES-256-GCM using a key kept outside the code repository.
  • Plaid notifications are accepted only with a valid Plaid signature.
  • Operational logs avoid bank details, tokens and transaction contents.

Fly Trap has not undergone an independent security audit or certification, and doesn't claim one.