How Revenue GUI reads your Stripe account
Connecting
You connect an account by installing the Revenue GUI app from Stripe. Stripe shows you the list below and asks you to approve it, then sends you back here. You never paste an API key. Stripe gives Revenue GUI a token that works only for what you approved, and only until you uninstall the app.
What the app can read
subscription_read: Read subscriptions to work out MRR, new revenue and cancellations.plan_read: Read the prices on those subscriptions, including yearly and weekly ones.coupon_read: Read coupons, so running discounts come off MRR.invoice_read: Read open invoices to find failed and overdue payments.customer_read: Show who a failed payment or cancellation belongs to. Not stored.event_read: Read the last 30 days of cancellation events to find subscriptions that ended.connected_account_read: Read your account's name, to label it in Revenue GUI.
Every permission is read-only. The app can't create, refund, cancel or change anything in your account. If Revenue GUI ever adds editing, Stripe will ask you to approve the new permissions first, and nothing changes until you do.
What's stored
For each connected account: its Stripe account ID, its name, whether it's live or test mode, and the access tokens Stripe issued. The tokens are encrypted (AES-256-GCM) with a key that's kept apart from the database.
Nothing read from your account is saved to the database: no customers, invoices or amounts. Each page reads them from Stripe. The numbers are kept in the server's memory for up to 10 minutes, so moving between pages doesn't read your account again each time, and they're gone after that.
Cutting off access
In your Stripe Dashboard, go to Settings, then Installed apps, and uninstall Revenue GUI. Stripe stops accepting its tokens right away. Removing the account in Revenue GUI (Manage accounts) also deletes our copy of its tokens.
Questions
Email hello@revenuegui.com.