Skip to content

Legal · last updated 14 September 2026

Privacy Policy

Orla is a finance app, so we hold the line on data the way we hold the line on money: we collect what the product genuinely needs, we never sell it, and we tell you plainly where it goes. This page explains what that means in practice.

Who we are

Orla (“Orla”, “we”, “us”) is operated by Digital Flow Pte. Ltd., and provides the finance app at app.orla.finance and the site at orla.finance. For anything on this page, reach us at [email protected].

What we collect

We collect three kinds of data, and no more than we need for each.

  • Account data: your email and display name, and the sign-in methods you set up (password hash, passkeys, linked Google or Ethereum wallet). We never store your password itself.
  • Financial data you put in: the accounts, transactions, budgets, goals, invoices, documents and contacts you add or connect. This is your ledger, and it exists so the app can show it back to you.
  • Technical and security data: the device, browser, IP address and timestamps behind sign-ins and account changes, kept so you and we can spot access that isn't yours.
  • Identity data, only if you use virtual cards, and only in passing: the card issuer has to verify the person a card belongs to, so the form collects their full name, date of birth, home address, country and an identity document type and number. Orla does not keep it. It is encrypted while the application is in flight and erased as soon as the issuer has taken it on, whether the card was approved or refused. If you invite someone else to hold a card, that is their data and they enter it themselves. When a cardholder confirms and asks for the card, we record that moment in the space's security log with the time, the IP address and the browser it came from, the same way a sign-in is recorded: it is what lets the space prove who asked for a card, and it is kept with the rest of that log.
  • Blockchain addresses: the public addresses of the wallets you add or connect. Reading a balance or a history means asking a public blockchain about that address.
  • Agent data, only if you connect an agent: the name you gave it, a hash of its key (never the key itself), which spaces and limits you granted it, and a record of every call it makes, so its actions sit in the same audit trail as everyone else's.
  • A data-access log: the moments something of yours crossed out of Orla. An export taken, a file downloaded or shared to an email address, a question answered by a model, an agent reading, an action by our own staff, each with who caused it and when. It records those crossings and not your ordinary use of the app, because a log of every screen you opened would be surveillance dressed up as transparency. In a business space the owner and admins see every crossing in it; in a family or group space everybody sees only their own, the owner included. You can read it in Settings under Privacy & data, and it is deleted after 400 days.
  • Mail sent to a space's receiving address, only if you turn that on: we keep who wrote, the subject, when it arrived and what came of it, for 90 days. Attachments we can read (PDFs and images) are stored as documents in that space like any other upload. We do not keep the message itself, and mail from a sender nobody in the space has vouched for is recorded without being downloaded or read at all until a person there releases it. If you connect a Gmail mailbox instead of forwarding, the access we ask for is read-only and you can revoke it at any time in your Google account.
  • What you send us through Support: the message you write, and the screenshot you attach if you choose to attach one. It travels with the page you were on, the space you were in, the app version, your browser and your window size, which is what turns “it broke” into something we can find. The form lists all of it above the Send button. It reaches our support mailbox and our own internal channel, we keep no copy of it in the app, and a screenshot is exactly the picture you picked: the app never takes one of your screen by itself.
  • Chat data, only if you connect Telegram or Slack: your member id in that chat, so we know which Orla account is asking, the messages you address to the app, and any file you send it to record. We read the messages around a request to answer it, and we do not index or keep the rest of a channel's history.
  • A question asked of our Telegram bot before you have an account: message the bot without signing up and the text you send is passed to our AI provider (Anthropic) once, to answer you about the product. The bot holds no account data and no tools, we do not store the text of what you asked, and the only trace kept is a count that a question was asked, with its language: no name, no Telegram id, and nothing that links the conversation to you if you sign up later. Photos, files and voice notes from people without an account are not downloaded or read at all.

The free invoice generator

The invoice generator on this site works without an account and keeps nothing. What you type (your details, your client's details, the lines and the logo) is sent to our server, laid out into a PDF, and dropped as soon as the file is built. There is no copy afterwards: not for you to open again, and not for us to look up, hand over or lose.

The logo is read by your browser and travels inside the request as part of the document, so no file is uploaded or kept either. The only thing that lasts is the PDF your browser downloads, which is yours.

What we deliberately do not collect

Your self-custody wallet keys never reach us. Seeds are generated and encrypted in your browser; only the public address is stored, so we could not move your crypto even if we wanted to.

The contents of documents you seal with the document-encryption add-on. Those files are encrypted in your browser before they are uploaded, under a key we never receive and cannot reconstruct: we hold the bytes and cannot read them, make no preview of them, and run no scan over them. What we still hold for a sealed file is its name, size, date and folder, and who you shared it with. Your phrase and your recovery code are not stored anywhere by us, which also means we cannot reset them: if you lose both, those files cannot be opened again by anyone, including us and including anyone who compels us.

Usage analytics, meaning which sections and features you use to improve the product, never include your amounts, balances or contacts, and you can switch it off entirely in Settings.

Audio. The microphone in the cabinet's box is your browser's own speech recognition; we never receive, record or store the sound of your voice, only the text it puts in the field, and only once you send it.

Cookies on the site

The orla.finance site asks before it stores anything. All measurement on the site and in the app runs through one Google Tag Manager container, and until you answer, every tag in it runs with storage switched off: Google Analytics sets no cookie and carries no identifier, and Orla's own counter records the page you are on with a random id that dies with the tab.

Answer yes and two things become possible, each separately:

  • Traffic: how many people arrive, where from, and which pages they read. This is Google Analytics, and it uses cookies to tell a returning visit from a new one. Your answer travels with you into the app, where the same measurement continues on ordinary screens: which sections you open and that an account was created, never the amounts, balances, contacts or anything you type, and never on pages whose link carries a token (payment links, invoices, invites, inheritance and email links). The app never asks again, and the Allow usage analytics switch in Settings, Privacy & data switches Google off for your account as well. If you later subscribe, that payment is reported to Google too, so we can tell which ad brought a customer rather than only a click: the amount, the plan, and whether it was a first payment or a renewal, against the same cookie and an identifier we derive from your account by hashing it. Automatic renewals are reported the same way even though you are not there at the time. Refuse this and none of it happens, including the payments: there is no cookie, so there is nothing to report against and nothing is sent.
  • Ads: which ad or search brought you here and whether it led anywhere, so we can stop paying for the ones that bring nobody. This uses Google's advertising cookies and signals, and on the site the measurement pixels of LinkedIn, Meta, Reddit and OpenAI, one for each place we advertise. It is the only part that involves advertising at all, and unlike the traffic part it loads nothing at all until you say yes: none of those pixels has a consent mode to hold it back, so the container does not start any of them until the ads answer is yes, and a refusal means they never run.

Changing your cookie answer

The signup button carries your answer across to app.orla.finance, so you are not asked twice on the way in. It carries the answer, never a name or an identifier. Inside the app, product analytics is a separate switch in Settings, and it is never advertising.

Change your mind at any time with the Cookies link at the bottom of any page on orla.finance. Sign-in and security cookies in the app are not part of this question: the app cannot work without them, so they are not optional.

How we use it

We use your data to run the service, and for nothing you would not expect:

  • To operate the ledger and its features, and to sync balances from the accounts you connect.
  • To secure your account, with sign-in checks, the security activity log, and alert emails when something sensitive changes.
  • To send the messages the app produces (approvals, invoices, alerts) on the channels you chose.
  • To improve the product in aggregate, unless you have turned usage analytics off.

Why we are allowed to

Where the GDPR or a similar law applies to you, this is the basis we rely on for each thing we do:

  • To perform our contract with you: running the ledger, syncing the accounts you connect, issuing and servicing cards, and taking payment for a paid plan.
  • To meet a legal obligation: identity checks and sanctions screening around cards and crypto, and keeping billing records.
  • For our legitimate interests: keeping the service secure and available, preventing abuse, and diagnosing crashes. We weigh that against your interests, and it never extends to selling your data.
  • With your consent: usage analytics, and any channel you switch on such as Telegram or Slack. You can withdraw consent at any time in Settings, and it will not affect what came before.

Where your data is processed

Orla is operated from Singapore, and the providers above are spread across Singapore, the European Union and the United States, so your data crosses borders to reach them.

Where a transfer leaves a country whose law restricts it, such as the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision covering that provider. Ask us at [email protected] and we will tell you which one applies to a given provider.

Who we share it with

We do not sell your data. We share it only with the service providers that make the product work, each handling a specific job and bound to use it only for that:

  • Hosting and infrastructure: DigitalOcean, which runs the application, the database and this site. Vercel is kept as a standby host for this site and serves it only if DigitalOcean is down.
  • Email: Resend, which sends our verification, security and notification emails, and, if the space has a receiving address, is also the provider that mail is delivered to before we fetch it.
  • Error monitoring: Sentry, for diagnosing crashes.
  • AI assistant: Anthropic, which processes Copilot requests, category suggestions, statement scans and receipt reading. Copilot sees your space through read-only tools. A space owner can switch all of it off in Settings under Privacy & data, at which point nothing from that space reaches an AI provider at all; the switch is independent of your plan. In the cabinet your conversations with the assistant are kept on our servers as your own thread, for as long as your plan keeps them (seven days on the free plan, ninety on Pro, without a limit on the company plans); Settings under Privacy & data counts them and forgets them all, and nobody else in the space reads yours. The notes you asked the assistant to keep are listed in Settings too and can be dropped by hand.
  • Payments: our subscription payment providers for card billing, and on-chain stablecoin transfers for crypto billing. Card numbers are entered in the provider's own form and never reach Orla.
  • Virtual cards: our card issuing partner and the identity verification service it uses, when you use Orla's virtual cards. Issuing a card passes that holder's identity data to them so they can verify it; from that point the record is theirs, not ours.
  • Compliance screening: AMLBot, which screens a destination blockchain address before you send to it. It receives the address, not your identity.
  • Blockchain data: public nodes and explorers, which we query to read balances and history for the addresses you add. This includes Etherscan, Arbiscan, Blockscout, mempool.space, TronGrid and public RPC endpoints. A public blockchain address is, by design, public.
  • Swaps: LI.FI, which routes an exchange between assets. It receives the addresses and amounts involved.
  • Market data: CoinGecko and DeFiLlama, for prices and rates. We ask them what an asset is worth, not what you hold.
  • Google, if you choose it: when you sign in with a Google account, and, if you connect a Gmail mailbox to a space, read-only access to that mailbox so bills in it can be filed.
  • Speech recognition, if you dictate: pressing the microphone in the cabinet's box hands what you say to your own browser's speech service, Google's in Chrome and Apple's in Safari, which returns it as text in the field. That audio is handled by the browser maker under their policy and never reaches Orla; the text reaches us only when you send the question.
  • Measurement, if you allow it, through Google Tag Manager: Google Analytics and Google Ads, for visits to orla.finance and for the screens you open in the app, and LinkedIn, Meta, Reddit and OpenAI, for visits to the site that arrived from an ad on one of them. They receive the pages and screens you opened, your approximate location from your IP address, and the ad or search that sent you. LinkedIn is additionally told when you click Start free, which is how we tell an ad that works from one that does not. Google is additionally told when a subscription payment succeeds: what it cost, which plan it was for, and whether it was a first payment or an automatic renewal, sent by our server rather than by your browser because a renewal happens while nobody is looking. That report carries no name and no email, only the cookie the measurement already uses and a hash of your account id, and it is not sent at all if you refused the cookies. They never receive your ledger, your balances or your contacts, nothing you type, and nothing from a page whose link carries a token, such as a payment link or an invoice.
  • Connections you choose: the banks, exchanges and open-banking providers you link, the creator and app-store platforms you connect to sync your earnings (Stripe, Shopify, PayPal, Gumroad, Lemon Squeezy, Bandcamp, the App Store and Google Play by key, and Etsy, YouTube or AdMob by consenting through the platform itself), and Telegram or Slack if you connect one.

Google user data

Orla's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Four features can ask for it, and only if you connect them: a Gmail mailbox, a folder in your Google Drive, an AdMob publisher account whose ad earnings you want filed, and a YouTube channel whose earnings you want in your books.

In plain terms, that means four things. We use what we read from your mailbox only to run the features you connected it for: finding bills and receipts, filing their attachments as documents in your space, and drafting the payables you then approve. We do not use it for advertising, and we never sell it. No Orla employee reads your mail: the only humans who see any of it are the people in your own space, looking at a document that arrived there. And we ask for read-only access, so nothing in your mailbox can be changed, sent or deleted by us.

One transfer is worth naming plainly, because it is the only one. To read what a bill says, an attachment is sent to Anthropic, our AI provider, and the covering message is sent with it as context. Anthropic processes that request and does not train models on it. A space owner can turn the AI off entirely in Settings under Privacy & data, and with it off no attachment and no message text leaves Orla for any AI provider; the mailbox connection then files documents without reading them.

A Drive folder works the same way and is read-only in the strictest sense. You point Orla at a folder where your bank statements already live; Orla lists it, reads those files and shows you a plan of what it proposes to do with each one before anything reaches your books. It never writes to your Drive: nothing there is modified, moved, renamed or deleted, at any point, including when you disconnect. The files themselves are not kept by us; the rows read out of a statement are encrypted, wait for you to approve or discard them, and are erased within thirty days if you do neither. A statement that has to be read by a model is sent to Anthropic exactly as an emailed bill is, under the same switch in Settings under Privacy & data.

You can withdraw the access at any time from your Google account's security settings at https://myaccount.google.com/permissions, or by disconnecting the mailbox or the folder in Orla. Either one stops the reading immediately. Documents already filed and entries already booked stay in your space, because they are yours.

YouTube data, if you connect a channel

Orla uses YouTube API Services. Connecting a channel means agreeing to the YouTube Terms of Service at https://www.youtube.com/t/terms, and Google's own handling of your data is described in the Google Privacy Policy at https://policies.google.com/privacy.

What we ask for is narrow and read-only: your channel's estimated revenue, day by day, from the YouTube Analytics API. We do not read your videos, your comments, your subscribers or your audience figures, and nothing about your channel can be changed, uploaded or deleted through this connection.

What we do with it is the whole reason it exists: those daily amounts become income rows in your own books, next to what the other platforms paid you, so a month adds up in one place. We do not use them for advertising, we do not sell them, and no Orla employee reads them. The only people who see them are the people in your own space.

What we store is the daily figures we already filed and an encrypted token that lets us read the next day's. We keep no copy of anything else. Disconnecting the channel in Orla stops the reading, and you can revoke the access outright at https://myaccount.google.com/permissions, which has the same effect from Google's side. Rows already filed stay in your space, because they are your income.

Agents you connect yourself

If you connect an agent of your own, a Claude or ChatGPT connector, an automation flow, a script you wrote, then what it reads travels to whoever operates that agent. That is the point of connecting one, and it is a decision only you can make: we are not the processor of what happens on the other side, and their policy governs it, not ours.

So the product is built to hand over as little as it can. An agent reads amounts, dates, categories and names, and by default it does not see card numbers, IBANs, wallet addresses or your counterparties' contact details; those are masked before they leave. You can lift the mask for one agent in one space, and the app says plainly what that means when you do.

You scope each agent to the spaces and the accounts it needs, you can put a time limit on that access, and freezing or disconnecting it takes effect on its very next call. An agent can never do more than you can, and it can never sign a payment.

Where connections are read-only

Bank and exchange connections are read-only by design. Bank links run in the provider's own secure window, so we never see your banking password. Exchange keys are stored encrypted, and on all five a key that carries trade or withdrawal rights is refused outright: Binance, Bybit and OKX report the rights, Coinbase answers through its key permissions endpoint, and Kraken is asked indirectly. Hyperliquid has no API keys at all, so we hold nothing but the public wallet address you paste in, and reading is the only thing that address can do.

Creator-platform connections are read-only too. The Stripe, Shopify or PayPal key you paste is your own, made with read access only, and it is stored encrypted the same way an exchange key is. Etsy and YouTube have no key to paste: you consent on the platform, and what comes back is a read-only token, encrypted here the same way. On Etsy that reads the shop payment ledger, meaning sales, fees, refunds and the deposits paid to your bank. In every case Orla reads to sort your earnings into your book, and can neither charge your customers nor move the money.

The App Store and Google Play are read the same way, with a key you make yourself: on the App Store an App Store Connect key with the Finance or Sales role, which reads the daily sales report and nothing else, and on Google Play a service account you invite to your own developer account with permission to view financial data, which reads the monthly earnings report out of that account's own reports bucket. AdMob has no key: you consent through Google, and the read-only token that comes back reports one figure, the earnings estimated for each of your apps day by day. None of the three can change anything: no app, no listing, no price, no payout.

How long we keep it

We keep your data while your account is open. Deleting your account erases your files and every sign-in method, and strips the identifying fields from the account record; what remains is an anonymised row that no longer points at a person, kept so shared ledgers other people still rely on do not break.

Two things have to be settled before we can erase: a shared space you solely own must be handed over or deleted, and any live card must be closed first, because a card is a live financial instrument at the issuer. The app tells you which one is blocking.

A card holder's identity data is not kept at all: it lives encrypted only while the application is with the issuer and is erased the moment that finishes, either way. The card issuer keeps its own verification record, under its own policy. The holder's name, email and phone stay only while the card exists, and are erased when it is closed.

Records we are required to keep, billing and compliance among them, are kept for as long as the applicable law requires and no longer.

Your choices

You are in control of the data we hold:

  • See and edit most of your data directly in the app.
  • Open Settings → Privacy & data for the version of this page built from your own account: where it is stored, who can reach it, which of the providers above actually receive anything from you, and the log of what has left.
  • Switch AI processing off for a space, which stops Copilot, category suggestions, statement scans and receipt reading from sending anything to a model.
  • Forget your conversations with the assistant, one or all of them, and drop any note it keeps for you, in Settings under the assistant and under Privacy & data.
  • Turn off usage analytics in Settings, at any time.
  • Change what the site may measure with the Cookies link at the bottom of orla.finance, at any time.
  • Choose which notifications reach you, and on which channels.
  • Delete your account, which erases your personal data as described above. Where you have rights under laws such as the GDPR, the UK GDPR, Singapore's PDPA or the CCPA (access, correction, deletion, portability, and objecting to processing we base on legitimate interests), contact us at [email protected] and we will honour them.
  • Complain to a regulator. If you are in the EEA or the UK you can complain to your national data protection authority; in Singapore, to the Personal Data Protection Commission. We would rather you told us first at [email protected], but that choice is yours.

Security

The measures behind this policy are described on our Security page: encrypted secrets, hashed passwords, passkeys and two-factor sign-in, browser-held wallet keys, and read-only connections.

Changes

If we change this policy in a way that affects you, we will update the date above and, for material changes, tell you in the app or by email.