Privacy policy

Privacy policy

Version 2026-08-18 · last updated 18 August 2026

1. Who we are

[Company legal name] (“we”) provides Attest. This policy explains what we collect, why, who else processes it, and how to have it removed. Contact: abe.kim92@gmail.com.

2. What we collect

  • Account data — your email address, and authentication records from the sign-in method you use (magic link or Google). We do not store a password.
  • Financial data you provide — the files you upload (bank statements, ledger exports), their contents, and transactions retrieved from a bank connection you authorize. This includes the verbatim source record for each transaction, which we deliberately keep so any figure can be traced back to what the source actually said.
  • Work product — the rules you author and approve, the entries drafted from them, saved closes, and the record of who posted what and when.
  • Connection credentials — where a connector needs a stored API token, we hold it encrypted. We never receive your bank username or password: those are entered inside the aggregator's own flow.
  • Operational logs — request and error logs from our hosting providers, which include IP address and timestamps, used to keep the service running and to investigate failures.

We keep the original file as well as its contents. A file is parsed on our server into rows; the rows, their verbatim source records, and the file itself are stored against your account in private per-account storage, so any figure can be traced back to the document it came from. Deleting your data deletes the stored files with it.

3. Why we process it

  • to provide the Service you asked for — drafting and explaining a close;
  • to keep an audit trail, which is the point of the product;
  • to secure the Service, investigate abuse, and diagnose failures;
  • to communicate with you about your account.

Where GDPR applies, our bases are performance of a contract with you, our legitimate interest in securing and improving the Service, and your consent where we ask for it.

4. What we do not do

  • We do not sell your data, and we do not share it for advertising.
  • We do not use your financial data to train machine-learning models, ours or anyone else's.
  • We do not send your data to a model provider to compute a number. AI is used only to help author rules and read file structure, and those requests are covered by the provider's zero-retention-for-training commitments described below.

5. Who else processes it (subprocessors)

  • Vercel — application hosting (United States).
  • Supabase — database and authentication (United States).
  • Railway — hosting for the accounting engine (United States).
  • Anthropic — the AI used at rule-authoring time. Prompts contain the transaction descriptions and chart of accounts needed to propose a rule; API inputs are not used to train models.
  • Plaid — bank connectivity, where you choose to connect a bank. Your bank credentials go to Plaid, never to us.
  • Google — only if you sign in with Google, for authentication.

We will update this list before adding a subprocessor that handles Customer Data.

6. How long we keep it

Account and financial data are kept for as long as your account is active, because the audit trail is only useful if it persists. Operational logs are kept for the retention period of our hosting providers (typically 30 days). On account closure or a deletion request we delete Customer Data within 30 days, except where we must keep something to comply with law.

7. Your choices

You can delete an imported period or a saved close from within the product. You can ask us to export or delete everything by emailing abe.kim92@gmail.com — we will confirm and act within 30 days. Depending on where you live you may also have rights to access, correct, restrict, or object to processing, and to complain to a supervisory authority.

One deliberate exception: imported source records and posted entries are write-once. We can delete them at your request, but we cannot edit them in place — an audit trail you can quietly rewrite is not an audit trail.

8. Security

Encryption in transit, per-tenant row-level security in the database, secrets held server-side only, and an append-only audit trail. What we have and have not done is set out in full on the security page, including that we have not completed a SOC 2 audit.

9. Cookies

We use cookies for authentication and session management only. We do not use advertising or cross-site tracking cookies.

10. International transfers

Our providers process data in the United States. If you are in the EEA or UK, transfers rely on the providers' standard contractual clauses. [Confirm transfer mechanism with counsel.]

11. Children

The Service is for businesses and is not directed to anyone under 16.

12. Changes

We will post updates here and notify account holders by email of material changes.