Legal · last updated 26 September 2026
Privacy Policy
Orla is a finance app, so we hold the line on data the way we hold the line on money: we collect what the product genuinely needs, we never sell it, and we tell you plainly where it goes. This page explains what that means in practice.
Who we are
Orla (“Orla”, “we”, “us”) is operated by Digital Flow Pte. Ltd., and provides the finance app at app.orla.finance and the site at orla.finance. For anything on this page, reach us at [email protected].
What we collect
We collect three kinds of data, and no more than we need for each.
- Account data: your email and display name, and the sign-in methods you set up (password hash, passkeys, linked Google or Ethereum wallet). We never store your password itself.
- Financial data you put in: the accounts, transactions, budgets, goals, invoices, documents and contacts you add or connect. This is your ledger, and it exists so the app can show it back to you.
- Technical and security data: the device, browser, IP address and timestamps behind sign-ins and account changes, kept so you and we can spot access that isn't yours.
- App version: every request the app sends to our server names which app it is and which version, such as the web app's build or the iPhone app's version number. We keep only the number of requests each version made per day, with no account, device or IP address attached, so we can tell whether an old version is still in use before we change something it relies on.
- Identity data, only if you use virtual cards, and only in passing: the card issuer has to verify the person a card belongs to, so the form collects their full name, date of birth, home address, country and an identity document type and number. Orla does not keep it. It is encrypted while the application is in flight and erased as soon as the issuer has taken it on, whether the card was approved or refused. If you invite someone else to hold a card, that is their data and they enter it themselves.
- Whether an invoice was opened: when someone opens the link to an invoice a space sent, we record when it was first opened, when it was last opened and how many times, and show that to the space that sent it. We record no IP address, no device, no location and nothing about who opened it, and nothing of what they did on the page. Visits within half an hour count as one, and link previews in chat apps and mail scanners that identify themselves are not counted, though a scanner that presents itself as an ordinary browser can be. It is stored on the invoice itself, for as long as the invoice is kept. It is not advertising measurement: none of it goes to Google or any other measurement provider.
- Blockchain addresses: the public addresses of the wallets you add or connect. Reading a balance or a history means asking a public blockchain about that address.
- Agent data, only if you connect an agent: the name you gave it, a hash of its key (never the key itself), which spaces and limits you granted it, and a record of every call it makes, so its actions sit in the same audit trail as everyone else's.
- A data-access log: the moments something of yours crossed out of Orla. An export taken, a file downloaded or shared to an email address, a question answered by a model, an agent reading, an action by our own staff, each with who caused it and when. It records those crossings and not your ordinary use of the app, because a log of every screen you opened would be surveillance dressed up as transparency. In a business space the owner and admins see every crossing in it; in a family or group space everybody sees only their own, the owner included. You can read it in Settings under Privacy & data, and it is deleted after 400 days.
- Mail sent to a space's receiving address, only if you turn that on: we keep who wrote, the subject, when it arrived and what came of it, for 90 days. Attachments we can read (PDFs and images) are stored as documents in that space like any other upload. We do not keep the message itself, and mail from a sender nobody in the space has vouched for is recorded without being downloaded or read at all until a person there releases it. If you connect a Gmail mailbox instead of forwarding, the access we ask for is read-only and you can revoke it at any time in your Google account.
- Replies to invoice emails, only where a space turns this on: the email with an invoice and its reminders then carry a second reply address and say so at the bottom. When the person the invoice went to replies, we keep their message (without the quoted email it answers) and its PDF and image attachments on that invoice for as long as the space keeps the invoice, and show them to the space that sent it. A reply we cannot confirm came from that person is recorded as who wrote and when, without keeping the text or downloading anything, until someone in the space says it is theirs. Where the space has AI on and a kept reply looks like it names a day for paying, the text of that reply (not its attachments) is sent to Anthropic, our AI provider, to read the day; the space sees it as a suggestion with the words it came from, and nothing is recorded as a promise until a person in the space confirms it.
- What you send us through Support: the message you write, and the screenshot you attach if you choose to attach one. It travels with the page you were on, the space you were in, the app version, your browser and your window size, which is what turns “it broke” into something we can find. The form lists all of it above the Send button. It reaches our support mailbox and our own internal channel, we keep no copy of it in the app, and a screenshot is exactly the picture you picked: the app never takes one of your screen by itself.
- Chat data, only if you connect Telegram or Slack: your member id in that chat, so we know which Orla account is asking, the messages you address to the app, and any file you send it to record. In a group or channel you add the app to, Telegram and Slack deliver every message to us, not only the ones meant for the app. The app acts on a message only when it is meant for it: it names the app, replies to it, or is a command to it. The one exception is a document or image posted in the room: the app asks whether to record it, and downloads nothing until someone there says yes. Every other message people write there is dropped as it arrives: we do not store it, write it to our logs or pass it to any AI provider. We read the messages around a request to answer it, and we do not index or keep the rest of a channel's history.
- A question asked of our Telegram bot before you have an account: message the bot without signing up and the text you send is passed to our AI provider (Anthropic) once, to answer you about the product. The bot holds no account data and no tools, we do not store the text of what you asked, and the only trace kept is a count that a question was asked, with its language: no name, no Telegram id, and nothing that links the conversation to you if you sign up later. Photos, files and voice notes from people without an account are not downloaded or read at all.
The free invoice generator
The invoice generator on this site works without an account and keeps nothing. What you type (your details, your client's details, the lines and the logo) is sent to our server, laid out into a PDF, and dropped as soon as the file is built. There is no copy afterwards: not for you to open again, and not for us to look up, hand over or lose.
The logo is read by your browser and travels inside the request as part of the document, so no file is uploaded or kept either. The only thing that lasts is the PDF your browser downloads, which is yours.
What we deliberately do not collect
Your self-custody wallet keys never reach us. Seeds are generated and encrypted in your browser; only the public address is stored, so we could not move your crypto even if we wanted to.
The contents of documents you seal with the document-encryption add-on. Those files are encrypted in your browser before they are uploaded, under a key we never receive and cannot reconstruct: we hold the bytes and cannot read them, make no preview of them, and run no scan over them. What we still hold for a sealed file is its name, size, date and folder, and who you shared it with. Your phrase and your recovery code are not stored anywhere by us, which also means we cannot reset them: if you lose both, those files cannot be opened again by anyone, including us and including anyone who compels us.
Usage analytics, meaning which sections and features you use to improve the product, never include your amounts, balances or contacts, and you can switch it off entirely in Settings.
Audio. The microphone in the cabinet's box is your browser's own speech recognition; we never receive, record or store that sound, only the text it puts in the field, and only once you send it. A voice message you send to our Telegram or Slack bot is different: it reaches us so that it can be turned into text, and the recording is passed to our speech provider for that and not stored by us.
Cookies on the site
The orla.finance site asks before it stores anything. All measurement on the site, and on the app's sign-in and signup pages, runs through one Google Tag Manager container, and until you answer, every tag in it runs with storage switched off: Google Analytics sets no cookie and carries no identifier, and Orla's own counter records the page you are on with a random id that dies with the tab.
Answer yes and two things become possible, each separately:
- Traffic: how many people arrive, where from, and which pages they read. This is Google Analytics, and it uses cookies to tell a returning visit from a new one. Your answer travels with you into the app, where the same measurement covers only the pages on the way in: sign-in and signup, the forgotten password page and a space's public page. There it sees that you opened them and that an account was created. It does not run anywhere inside your account, so it never sees which sections you open, the amounts, balances, contacts or anything you type. On payment links, invoices, invites and inheritance links it does not run at all, and on the page an email link opens it starts only once the link's token is used up and gone from the address, to count the confirmation. The app never asks again, and the Allow usage analytics switch in Settings, Privacy & data switches Google off on that device as well. If you later subscribe, that payment is reported to Google too, so we can tell which ad brought a customer rather than only a click: the amount, the plan, and whether it was a first payment or a renewal, against the same cookie and an identifier we derive from your account by hashing it. Automatic renewals are reported the same way even though you are not there at the time. Refuse this and none of it happens, including the payments: there is no cookie, so there is nothing to report against and nothing is sent.
- Ads: which ad or search brought you here and whether it led anywhere, so we can stop paying for the ones that bring nobody. This uses Google's advertising cookies and signals, and on the site the measurement pixels of LinkedIn, Meta, Reddit and OpenAI, one for each place we advertise. It is the only part that involves advertising at all, and unlike the traffic part it loads nothing at all until you say yes: none of those pixels has a consent mode to hold it back, so the container does not start any of them until the ads answer is yes, and a refusal means they never run. A yes starts Meta, Reddit and OpenAI the next time the site loads, not on the page where you gave it. None of these pixels runs in the app, whatever your answer: there only Google's own tags run, and only on the pages on the way in.
Changing your cookie answer
The signup button carries your answer across to app.orla.finance, so you are not asked twice on the way in. It carries the answer, never a name or an identifier. Inside the app, product analytics is a separate switch in Settings, and it is never advertising.
Change your mind at any time with the Cookies link at the bottom of any page on orla.finance. Sign-in and security cookies in the app are not part of this question: the app cannot work without them, so they are not optional.
How we use it
We use your data to run the service, and for nothing you would not expect:
- To operate the ledger and its features, and to sync balances from the accounts you connect.
- To secure your account, with sign-in checks, the security activity log, and alert emails when something sensitive changes.
- To send the messages the app produces (approvals, invoices, alerts) on the channels you chose.
- To improve the product in aggregate, unless you have turned usage analytics off.
Why we are allowed to
Where the GDPR or a similar law applies to you, this is the basis we rely on for each thing we do:
- To perform our contract with you: running the ledger, syncing the accounts you connect, issuing and servicing cards, and taking payment for a paid plan.
- To meet a legal obligation: identity checks and sanctions screening around cards and crypto, and keeping billing records.
- For our legitimate interests: keeping the service secure and available, preventing abuse, and diagnosing crashes. We weigh that against your interests, and it never extends to selling your data.
- With your consent: usage analytics, and any channel you switch on such as Telegram or Slack. You can withdraw consent at any time in Settings, and it will not affect what came before.
Where your data is processed
Orla is operated from Singapore, and the providers above are spread across Singapore, the European Union and the United States, so your data crosses borders to reach them.
Where a transfer leaves a country whose law restricts it, such as the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision covering that provider. Ask us at [email protected] and we will tell you which one applies to a given provider.
Who we share it with
We do not sell your data. We share it only with the service providers that make the product work, each handling a specific job and bound to use it only for that:
- Hosting and infrastructure: DigitalOcean, which runs the application, the database and this site. Vercel is kept as a standby host for this site and serves it only if DigitalOcean is down.
- Email: Resend, which sends our verification, security and notification emails, and, if the space has a receiving address, is also the provider that mail is delivered to before we fetch it.
- Error monitoring: Sentry, for diagnosing crashes.
- AI assistant: Anthropic, which processes Copilot requests, category suggestions, statement scans, receipt reading and the reading of client replies to invoice emails for a payment day. Copilot sees your space through read-only tools. A space owner can switch all of it off in Settings under Privacy & data, at which point nothing from that space reaches an AI provider at all; the switch is independent of your plan. In the cabinet your conversations with the assistant are kept on our servers as your own thread, for as long as your plan keeps them (seven days on the free plan, thirty on Starter, ninety on Pro, without a limit on the company plans); Settings under Privacy & data counts them and forgets them all, and nobody else in the space reads yours. The notes you asked the assistant to keep are listed in Settings too and can be dropped by hand. For each question we also keep, for ninety days, how it went and nothing of what it said: how long the answer took, how it ended, whether the assistant had to ask you back, and which language the question and the answer were in. If you press Helpful or Not helpful under an answer, that press is kept with it, and so is the note you choose to write under Not helpful; the note is the only text in that record, and it is deleted with it.
- Payments: our subscription payment providers for card billing, and on-chain stablecoin transfers for crypto billing. Card numbers are entered in the provider's own form and never reach Orla.
- Virtual cards: our card issuing partner and the identity verification service it uses, when you use Orla's virtual cards. Issuing a card passes that holder's identity data to them so they can verify it; from that point the record is theirs, not ours.
- Compliance screening: AMLBot, which screens a destination blockchain address before you send to it. It receives the address, not your identity.
- Counterparty checks, when you press one: dilisense, which screens a name you keep in Contacts against sanctions, politically exposed person, criminal and adverse-media lists. It receives that name, and for a person the country on the card, so that it can answer; it receives nothing else about you and nothing about what you paid them. The company registers we confirm a business in receive its registration or VAT number and nothing more: the European Commission's VIES service for an EU VAT number, GLEIF for an LEI, Companies House for a UK company, Middesk for a US company, and Apify, which routes the lookup to the national register elsewhere. A check happens only when somebody presses the button on that contact's card; nothing is screened by itself. A check is kept as the record that it happened: who was checked, when, by whom and with what verdict. If you delete a space, that record stays, because a screening is a compliance record. What the lists published about other people, their names, aliases and dates of birth, is removed from it.
- Blockchain data: public nodes and explorers, which we query to read balances and history for the addresses you add. This includes Etherscan, Arbiscan, Blockscout, mempool.space, TronGrid and public RPC endpoints. A public blockchain address is, by design, public.
- Swaps: LI.FI, which routes an exchange between assets. It receives the addresses and amounts involved.
- Market data: CoinGecko and DeFiLlama, for prices and rates. We ask them what an asset is worth, not what you hold.
- Google, if you choose it: when you sign in with a Google account, and, if you connect a Gmail mailbox to a space, read-only access to that mailbox so bills in it can be filed.
- Speech provider: OpenAI, which turns a voice message you send to our Telegram or Slack bot into text. It receives the recording and nothing else about your space, and the same Privacy & data switch that turns the assistant off turns this off. The text it returns is handled exactly like a message you typed.
- Speech recognition, if you dictate: pressing the microphone in the cabinet's box hands what you say to your own browser's speech service, Google's in Chrome and Apple's in Safari, which returns it as text in the field. That audio is handled by the browser maker under their policy and never reaches Orla; the text reaches us only when you send the question.
- Measurement, if you allow it, through Google Tag Manager: Google Analytics and Google Ads, for visits to orla.finance and to the app's sign-in and signup pages, and LinkedIn, Meta, Reddit and OpenAI, for visits to the site that arrived from an ad on one of them. They receive the pages you opened, your approximate location from your IP address, and the ad or search that sent you. LinkedIn is additionally told when you click Start free on the site, and Google when you finish signing up in the app, which is how we tell an ad that works from one that does not. LinkedIn, Meta, Reddit and OpenAI never run in the app, nothing of this runs inside your account, and turning off “Allow usage analytics” in the app keeps Google's cookies off on that device. Google is additionally told when a subscription payment succeeds: what it cost, which plan it was for, and whether it was a first payment or an automatic renewal, sent by our server rather than by your browser because a renewal happens while nobody is looking. That report carries no name and no email, only the cookie the measurement already uses and a hash of your account id, and it is not sent at all if you refused the cookies. They never receive your ledger, your balances or your contacts, nothing you type, and nothing from a page whose link carries a token, such as a payment link or an invoice.
- People your space sends documents to: an invoice, a payment reminder, a receipt or a quote that your space emails can be answered by pressing Reply. The reply goes to the billing email printed on that document, and when none is set, to the verified email of the member who created it, or of the space owner, so the recipient sees that address.
- Connections you choose: the banks, exchanges and open-banking providers you link, the creator and app-store platforms you connect to sync your earnings (Stripe, Shopify, PayPal, Gumroad, Lemon Squeezy, Bandcamp, the App Store and Google Play by key, and Etsy, YouTube or AdMob by consenting through the platform itself), and Telegram or Slack if you connect one.
Google user data
Orla's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Four features can ask for it, and only if you connect them: a Gmail mailbox, a folder in your Google Drive, an AdMob publisher account whose ad earnings you want filed, and a YouTube channel whose earnings you want in your books.
In plain terms, that means four things. We use what we read from your mailbox only to run the features you connected it for: finding bills and receipts, filing their attachments as documents in your space, and drafting the payables you then approve. We do not use it for advertising, and we never sell it. No Orla employee reads your mail: the only humans who see any of it are the people in your own space, looking at a document that arrived there. And we ask for read-only access, so nothing in your mailbox can be changed, sent or deleted by us.
One transfer is worth naming plainly, because it is the only one. To read what a bill says, an attachment is sent to Anthropic, our AI provider, and the covering message is sent with it as context. Anthropic processes that request and does not train models on it. A space owner can turn the AI off entirely in Settings under Privacy & data, and with it off no attachment and no message text leaves Orla for any AI provider; the mailbox connection then files documents without reading them.
A Drive folder works the same way and is read-only in the strictest sense. You point Orla at a folder where your bank statements already live; Orla lists it, reads those files and shows you a plan of what it proposes to do with each one before anything reaches your books. It never writes to your Drive: nothing there is modified, moved, renamed or deleted, at any point, including when you disconnect. The files themselves are not kept by us; the rows read out of a statement are encrypted, wait for you to approve or discard them, and are erased within thirty days if you do neither. A statement that has to be read by a model is sent to Anthropic exactly as an emailed bill is, under the same switch in Settings under Privacy & data.
You can withdraw the access at any time from your Google account's security settings at https://myaccount.google.com/permissions, or by disconnecting the mailbox or the folder in Orla. Either one stops the reading immediately. Documents already filed and entries already booked stay in your space, because they are yours.
YouTube data, if you connect a channel
Orla uses YouTube API Services. Connecting a channel means agreeing to the YouTube Terms of Service at https://www.youtube.com/t/terms, and Google's own handling of your data is described in the Google Privacy Policy at https://policies.google.com/privacy.
What we ask for is narrow and read-only: your channel's estimated revenue, day by day, from the YouTube Analytics API. We do not read your videos, your comments, your subscribers or your audience figures, and nothing about your channel can be changed, uploaded or deleted through this connection.
What we do with it is the whole reason it exists: those daily amounts become income rows in your own books, next to what the other platforms paid you, so a month adds up in one place. We do not use them for advertising, we do not sell them, and no Orla employee reads them. The only people who see them are the people in your own space.
What we store is the daily figures we already filed and an encrypted token that lets us read the next day's. We keep no copy of anything else. Disconnecting the channel in Orla stops the reading, and you can revoke the access outright at https://myaccount.google.com/permissions, which has the same effect from Google's side. Rows already filed stay in your space, because they are your income.
Agents you connect yourself
If you connect an agent of your own, a Claude or ChatGPT connector, an automation flow, a script you wrote, then what it reads travels to whoever operates that agent. That is the point of connecting one, and it is a decision only you can make: we are not the processor of what happens on the other side, and their policy governs it, not ours.
So the product is built to hand over as little as it can. An agent reads amounts, dates, categories and names, and by default it does not see card numbers, IBANs, wallet addresses or your counterparties' contact details; those are masked before they leave. You can lift the mask for one agent in one space, and the app says plainly what that means when you do.
You scope each agent to the spaces and the accounts it needs, you can put a time limit on that access, and freezing or disconnecting it takes effect on its very next call. An agent can never do more than you can, and it can never sign a payment.
Where connections are read-only
Bank and exchange connections are read-only by design. Bank links run in the provider's own secure window, so we never see your banking password. Exchange keys are stored encrypted, and on all five a key that carries trade or withdrawal rights is refused outright: Binance, Bybit and OKX report the rights, Coinbase answers through its key permissions endpoint, and Kraken is asked indirectly. Hyperliquid has no API keys at all, so we hold nothing but the public wallet address you paste in, and reading is the only thing that address can do.
Creator-platform connections are read-only too. The Stripe, Shopify or PayPal key you paste is your own, made with read access only, and it is stored encrypted the same way an exchange key is. Etsy and YouTube have no key to paste: you consent on the platform, and what comes back is a read-only token, encrypted here the same way. On Etsy that reads the shop payment ledger, meaning sales, fees, refunds and the deposits paid to your bank. In every case Orla reads to sort your earnings into your book, and can neither charge your customers nor move the money.
The App Store and Google Play are read the same way, with a key you make yourself: on the App Store an App Store Connect key with the Finance or Sales role, which reads the daily sales report and nothing else, and on Google Play a service account you invite to your own developer account with permission to view financial data, which reads the monthly earnings report out of that account's own reports bucket. AdMob has no key: you consent through Google, and the read-only token that comes back reports one figure, the earnings estimated for each of your apps day by day. None of the three can change anything: no app, no listing, no price, no payout.
How long we keep it
We keep your data while your account is open. Deleting your account erases your files and every sign-in method, and strips the identifying fields from the account record; what remains is an anonymised row that no longer points at a person, kept so shared ledgers other people still rely on do not break.
Two things have to be settled before we can erase: a shared space you solely own must be handed over or deleted, and any live card must be closed first, because a card is a live financial instrument at the issuer. The app tells you which one is blocking.
A card holder's identity data is not kept at all: it lives encrypted only while the application is with the issuer and is erased the moment that finishes, either way. The card issuer keeps its own verification record, under its own policy. The holder's name, email and phone stay only while the card exists, and are erased when it is closed.
Records we are required to keep, billing and compliance among them, are kept for as long as the applicable law requires and no longer.
Your choices
You are in control of the data we hold:
- See and edit most of your data directly in the app.
- Open Settings → Privacy & data for the version of this page built from your own account: where it is stored, who can reach it, which of the providers above actually receive anything from you, and the log of what has left.
- Switch AI processing off for a space, which stops Copilot, category suggestions, statement scans, receipt reading and the reading of client replies from sending anything to a model.
- Forget your conversations with the assistant, one or all of them, and drop any note it keeps for you, in Settings under the assistant and under Privacy & data.
- Turn off usage analytics in Settings, at any time.
- Change what the site may measure with the Cookies link at the bottom of orla.finance, at any time.
- Choose which notifications reach you, and on which channels.
- Delete your account, which erases your personal data as described above. Where you have rights under laws such as the GDPR, the UK GDPR, Singapore's PDPA or the CCPA (access, correction, deletion, portability, and objecting to processing we base on legitimate interests), contact us at [email protected] and we will honour them.
- Complain to a regulator. If you are in the EEA or the UK you can complain to your national data protection authority; in Singapore, to the Personal Data Protection Commission. We would rather you told us first at [email protected], but that choice is yours.
Security
The measures behind this policy are described on our Security page: encrypted secrets, hashed passwords, passkeys and two-factor sign-in, browser-held wallet keys, and read-only connections.
Changes
If we change this policy in a way that affects you, we will update the date above and, for material changes, tell you in the app or by email.