Skip to content

Legal

Privacy Policy

How OwnCents collects, uses, protects, shares, retains, and deletes personal and financial information.

Last updated: 3 August 2026

1. Who we are

OwnCents is operated by Humanbo INC (“Humanbo”, “OwnCents”, “we”, “us”, or “our”). Humanbo INC is the primary operator of OwnCents. Humanbo Limited may support operations as our Bangladesh affiliate.

OwnCents is a business financial-management product available at https://owncents.com.

2. Information we collect

  • Account information, including name, email address, display name, Firebase user identifiers, workspace membership, and role information.
  • Workspace and business information, including organization name, team members, permissions, onboarding financial inputs, tasks, reports, notifications, and audit events.
  • Authentication and security information, including Firebase Authentication identifiers, session metadata, passkey public-key credentials, WebAuthn counters, MFA assurance timestamps, and security logs.
  • Financial information imported from integrations you connect, including customers, subscriptions, invoices, transactions, revenue entries, expenses, balances, and related provider metadata where supported.
  • Billing information, including subscription plan, billing interval, Stripe customer/subscription identifiers, invoice metadata, subscription status, and billing portal activity. Payment-card details are handled by Stripe.
  • Usage, device, and diagnostic information, including IP address, browser information, request logs, error logs, and actions taken in OwnCents.
  • Communications you send to us, including support and billing requests.

3. Authentication, passkeys, and WebAuthn

OwnCents uses Firebase Authentication for account sign-in and server-side Firebase Admin verification for protected API requests. OwnCents also supports WebAuthn/passkeys. When you use Touch ID, Face ID, Windows Hello, a security key, or a similar authenticator, biometric verification happens on your device or platform. OwnCents does not receive or store biometric templates. We receive cryptographic authentication results and store passkey public keys, counters, labels, and related metadata needed to verify future authentications.

OwnCents requires passkey-based step-up MFA before creating a Plaid Link token for bank-account connection. MFA assurance is stored server-side for a short period and is scoped to the authenticated user and workspace.

4. Connected Financial Accounts and Plaid

OwnCents uses Plaid to allow users to connect eligible financial accounts. The current Plaid Link token configuration requests the Plaid Transactions product. Users choose when to connect a financial institution, Plaid handles financial-account authentication separately, and Plaid's own privacy practices also apply to Plaid's processing.

Depending on the Plaid products enabled and the institution connected, OwnCents may receive financial institution information, account names, account type/subtype, balances, transaction history, transaction descriptions, merchant information, transaction dates, transaction amounts, currency, and recurring transaction information if enabled in the future. OwnCents does not receive users' online banking passwords from Plaid.

Connected financial data is used to provide OwnCents functionality such as cash-flow analysis, transaction categorization, expense analysis, revenue analysis, cash balance visibility, burn rate, runway, forecasting, reporting, recurring financial activity analysis where available, and AI CFO insights.

5. Integrations and third-party services

OwnCents integrates with providers only when you or your workspace authorizes the connection. The application includes configured workflows involving Google Cloud, Firebase, Stripe, Plaid, Composio, Google/Gmail, Google Sheets, Slack, and Gemini. Availability and supported data scope depend on the configured provider workflow. For Composio-managed connections, OwnCents stores the connected-account identifier rather than provider OAuth tokens.

  • Stripe data may include customers, subscriptions, invoices, charges, refunds, payment intents, products, and prices where used for billing or financial intelligence.
  • Gmail is used to create user-authorized draft emails; OwnCents does not automatically send those drafts in the verified implementation.
  • Google Sheets is used for user-authorized spreadsheet exports.
  • Slack is used for user-authorized test notifications and future financial alerts.
  • Gemini is used for AI CFO responses and interpretation, but raw financial synchronization and authoritative metrics are calculated deterministically by OwnCents backend services.

6. Cookies and similar technologies

OwnCents uses browser storage and technologies necessary for authentication, security, preferences, and application operation. The repository does not verify advertising cookies or third-party behavioral advertising tracking on these pages.

7. How we use information

  • Provide, secure, maintain, and improve OwnCents.
  • Authenticate users, enforce workspace isolation, roles, subscriptions, and passkey step-up MFA for sensitive financial connection actions.
  • Connect to user-authorized financial and workflow integrations.
  • Normalize financial data, calculate revenue, MRR, ARR, customers, subscriptions, burn, runway, receivables, and other deterministic metrics.
  • Generate dashboards, forecasts, reports, alerts, tasks, and AI CFO insights.
  • Manage subscriptions, trials, billing, invoices, cancellations, and payment issues through Stripe.
  • Detect, prevent, investigate, and audit security incidents, misuse, and technical problems.
  • Comply with legal, contractual, accounting, tax, and dispute-resolution obligations.

8. How we share information

We share information with infrastructure and service providers, user-authorized integrations, payment providers, financial-data providers, security and fraud-prevention services where applicable, professional advisers, legal authorities where required, and parties to a corporate transaction where applicable. We do not disclose provider credentials or secrets to the browser.

9. Security

Application controls include Firebase Authentication, Firebase Admin server-side authorization, workspace-scoped access checks, server-side financial-data writes, server-only secrets, passkeys/WebAuthn, step-up MFA before Plaid Link, and sanitized audit logs. Deployment controls such as HTTPS, IAM, managed-secret configuration, and storage encryption must also be verified in the environment where OwnCents is operated.

No system is perfectly secure. We do not claim SOC 2, ISO 27001, PCI DSS, GLBA compliance, banking-license status, or financial-adviser status because those claims were not verified in the repository.

10. International processing

Humanbo INC operates OwnCents from the United States and may work with Humanbo Limited in Bangladesh. Our service providers may process information in the United States, Bangladesh, and other countries where they or their subprocessors operate.

11. Retention, disconnection, and deletion

We retain information for the duration of an active account or workspace and as needed to provide the Service, maintain security, prevent fraud, satisfy legitimate business needs, resolve disputes, and meet legal or contractual obligations. The repository does not verify fixed automatic deletion periods.

Disconnecting a Composio-managed integration attempts to revoke/delete the Composio connected account, removes the stored connectedAccountId, and stops future sync for that integration. Disconnecting an integration does not automatically delete historical normalized financial data that was already imported.

You may request account or data deletion by contacting us. Requests are subject to identity verification, applicable retention obligations, and the operational capabilities available for the relevant provider.

12. Your privacy choices and rights

Depending on applicable law, you may have rights to access, correct, delete, or request information about processing of personal information; withdraw applicable consent; and disconnect financial accounts. These rights may vary by location and may be subject to verification, exceptions, and legal retention requirements.

13. Children

OwnCents is intended for business use and is not directed to children. Users must be old enough to form a binding contract for business use of the Service.

14. Changes

We may update this Privacy Policy. If a change is material, we will update the date above and may provide notice through OwnCents or by email.

15. Contact

OwnCents is operated by Humanbo INC.

Humanbo INC
30 N Gould St Ste R
Sheridan, WY 82801
United States
Email: hey@humanbo.com

Bangladesh affiliate:

Humanbo Limited
51/B Kemal Ataturk Avenue
Banani, Dhaka 1213
Bangladesh
Email: hey.bd@humanbo.com

Website: https://owncents.com