Last updated: June 8, 2026
Clarity Books AI ("Clarity Books," "we," "us," or "our") is an AI-assisted bookkeeping service operated by Clarity Books AI, LLC, a Connecticut limited liability company. We help self-employed individuals and small business owners track income and expenses with AI-assisted categorization.
Contact: brayden@claritybooksai.com
This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have. It applies to our websites, our web application, our iOS and Android apps, the push notifications and emails we send, and the documents you upload. It does not cover the practices of any third-party services that are linked from our product (such as your bank or Plaid itself). Those are governed by their own policies.
3.1 Information you provide directly
3.2 Information collected automatically
3.3 Information from third parties
If you connect a bank via Plaid, we receive transaction and balance data from Plaid. We also receive subscription and billing-status events from Stripe (web) and Apple via RevenueCat (iOS).
When you enable payments, your customers' payment details (card or bank account) are collected and processed directly by Stripe to complete the payment. Clarity Books never receives or stores full card or bank-account numbers.
We do not sell your personal information. We do not share your financial data with advertisers, data brokers, or any third party for marketing purposes.
Where the General Data Protection Regulation or the UK GDPR applies, we rely on the following legal bases: (a) performance of a contract with you; (b) your consent, where you have given it (for example, connecting a bank account); (c) our legitimate interests in operating and improving the Service; and (d) compliance with legal obligations.
We use Plaid Inc. to connect to your financial institutions. Plaid authenticates you directly with your bank and shares transaction and balance information with us on your behalf. Plaid's handling of your data is governed by Plaid's End User Privacy Policy.
The Plaid access token we receive is read-only and scoped to transactions and balances. It cannot be used to move money, change account settings, or interact with your account beyond reading that data. We encrypt that token with AES-256-GCM before storing it.
We use Anthropic's Claude to do the bookkeeping work. What we send depends on the feature:
Anthropic is our only AI provider. Under our commercial agreement with Anthropic, content sent through its API is not used to train its models. This is a contractual commitment by Anthropic; the limits described in Section 14: Security apply to how this data is transmitted.
We share the minimum data necessary with the vendors below to operate the Service. A full, current list is also maintained in our Data Processing Addendum.
If you provide a CPA's email and trigger a year-end send, we email your report to the CPA you specify. The packet includes a tax summary and a CSV of every posted transaction for the year, plus your 1099 contractor names and totals (no tax IDs). You control each send.
We retain your data while your account is active. When you delete your account, we remove it as described below.
Depending on where you live, you may have some or all of the following rights:
To exercise any right, email brayden@claritybooksai.com. We may need to verify your identity before responding. We will respond within 30 days (or 45 where permitted by law).
California residents have the rights listed in Section 10, plus the right to know what categories of personal information we have collected, the sources, the business purpose, and the categories of third parties with whom we have shared it. The categories we collect are listed in Section 3 (identifiers, contact and business information, financial and transaction information, uploaded documents, and device/diagnostic information). We do not sell or share personal information as those terms are defined under the CCPA/CPRA.
Clarity Books AI is intended for users aged 18 or older operating a legitimate business. We do not knowingly collect personal information from children under 13 (or the equivalent minimum age in your jurisdiction). If you believe a child has provided us personal information, contact us and we will delete it.
Our Service is hosted in the United States. If you access the Service from outside the US, your information will be transferred to, stored in, and processed in the US. Where required, we rely on appropriate safeguards (for example, the EU Standard Contractual Clauses) for cross-border transfers.
We protect your data with the following measures:
No system is completely secure, but we have designed the Service so that even a successful breach should not expose your banking credentials (we never have them) or allow money movement (our access is read-only).
If we discover a breach of security that results in unauthorized access to your personal information, we will notify you by email within 72 hours of confirming the scope of the incident, describe what was accessed, and tell you the steps we are taking and the steps you should take.
We use strictly-necessary first-party cookies to keep you signed in (a Supabase authentication cookie). In our mobile apps, your session is stored on-device in secure app storage instead of a cookie. We do not use advertising, analytics, third-party, or cross-site tracking cookies, and we do not run a product-analytics SDK. The only automatic telemetry we collect is error/crash diagnostics (Sentry) and security / rate-limit logs (Upstash). See our Cookie Policy for a full list and controls.
We may update this policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. If we make material changes, we will notify you by email and, where required by law, obtain your consent before the changes take effect. Continuing to use the Service after changes take effect means you accept the updated policy.
Questions, requests, or complaints? Email us at brayden@claritybooksai.com. If you are in the EU/UK and are not satisfied with our response, you have the right to lodge a complaint with your local data-protection authority.