Last updated: September 2026
RowzX converts bank statements and invoices into spreadsheets. This policy explains what we collect when you use rowzx.com, why, who helps us process it, how long we keep it and what you can ask us to do with it. Questions go to support@rowzx.com.
The files you upload and the spreadsheets we produce from them are yours. They are encrypted in transit and while they are processed, read automatically — no person at RowzX looks at them — and every file is permanently deleted within 24 hours of upload. We do not sell your documents, and we do not use them to train any model.
Scanned pages and layouts our own parsers do not recognise are read by an AI model from OpenAI or Anthropic, through their business APIs. Under those terms the content is used only to answer our request and is not used to train their models. They are processors acting on our instructions, listed with the others below.
We use these providers, each only for the purpose shown and under contract with us. Some are outside your country, which means your data may be transferred internationally; we rely on the providers' standard contractual safeguards for those transfers.
You can ask us to show you the data we hold about you, correct it, export it, delete it or stop a particular use of it, and you can withdraw consent to analytics at any time from Cookie settings. Write to support@rowzx.com from the address on your account; we answer within 30 days. You may also complain to the data protection authority where you live.
Traffic is encrypted with TLS, files are encrypted at rest, passwords are stored only as salted hashes, and access to production systems is limited and logged.
RowzX is a business tool and is not intended for anyone under 18.
Most of what we store in your browser is there because the site cannot work without it. One thing is not, and that one is yours to decide — you were asked before it loaded, and you can change the answer at any time from Cookie settings at the bottom of any page.
Set regardless of your choice, because without them there is no working site. No consent is required for these, and they are not used to track you.
We use Microsoft Clarity to see how the site is used: which pages people read, what they click, where they get stuck. It sets its own cookies (_clck, _clsk) and sends the data to Microsoft as a processor on our behalf, which can mean transfer outside your country.
We also use Google Analytics and Google Ads to find out which advert brought a visitor and whether paying for it was worthwhile. With your agreement they set cookies (_ga, _gcl_*) and Google processes the data, which again can mean transfer outside your country. Without it they still load, but are instructed to store nothing in your browser and to send no identifier — Google receives only that an anonymous visit happened.
It does not run on your workspace at all — the pages where your documents and your converted data appear are excluded, and the recorder is stopped before it ever reaches them. On the public pages it runs on, all text is masked, so what we see is layout and interaction rather than content.
Clarity does not load until you accept it: declining, or simply not answering, means the script is never requested. The Google tags are the exception described above — they load either way, and a refusal is passed to them as an instruction to store nothing. In both cases, declining means no analytics or advertising cookie is ever set in your browser.
If we change this policy, the date at the top changes with it, and if the change matters to how your data is used, we tell account holders by email before it takes effect.