Back to home

Privacy Policy

Last updated: June 8, 2026

1. Who We Are

Clarity Books AI ("Clarity Books," "we," "us," or "our") is an AI-assisted bookkeeping service operated by Clarity Books AI, LLC, a Connecticut limited liability company. We help self-employed individuals and small business owners track income and expenses with AI-assisted categorization.

Contact: brayden@claritybooksai.com

2. Scope of This Policy

This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have. It applies to our websites, our web application, our iOS and Android apps, the push notifications and emails we send, and the documents you upload. It does not cover the practices of any third-party services that are linked from our product (such as your bank or Plaid itself). Those are governed by their own policies.

3. Information We Collect

3.1 Information you provide directly

  • Account & business profile: your name, email address, phone number, and password (hashed by our authentication provider: we never see or store it in plain text), plus your business name, industry, business structure (sole proprietor, LLC, S-corp, etc.), state of operation, time zone, and a timestamp recording that you confirmed you are 18 or older.
  • Your invoicing profile: the business name, mailing address, email, and phone number you choose to display on invoices you send.
  • Payment handles & your accountant: an optional Venmo/Zelle display name (used to help recognize peer-to-peer transfers) and an optional CPA email address (used to send year-end packets).
  • Financial & tax records you create or import: transactions (date, description/memo, amount, type), the categories and tax lines assigned to them, cash and check entries, mileage trips (including the start and end locations you type, which can reveal physical addresses), and sales-tax entries.
  • People you add: contractor / 1099 records (name, business name, address, email, phone, and the last four digits of a tax ID: we never collect a full Social Security Number or full TIN) and invoice customer details (recipient name, email, phone, and billing address).
  • Uploads: receipt photos, e-receipt PDFs, bank and credit-card statements, and CSV files you upload. See Section 7: How AI reads your data for how these are processed.
  • Billing information: processed by Stripe (web) or Apple via RevenueCat (iOS). We receive a customer token and billing metadata, never full card numbers.
  • Communications: in-app chat messages, and anything you send us by email or through in-app forms.

3.2 Information collected automatically

  • Financial data via Plaid: connected bank and credit-card accounts, transaction history, running balances, account type, and institution name. We do not receive or store full account numbers, routing numbers, or your online-banking credentials.
  • Device & diagnostics: device type, operating system, app version, approximate region derived from your IP address, and crash / error diagnostics (via Sentry). On our mobile apps we also store a push-notification device identifier (via OneSignal) so we can deliver your weekly check-in. We do not run a product-analytics SDK and do not track which pages or features you use for marketing.
  • Strictly-necessary cookies and on-device session storage as described in our Cookie Policy.

3.3 Information from third parties

If you connect a bank via Plaid, we receive transaction and balance data from Plaid. We also receive subscription and billing-status events from Stripe (web) and Apple via RevenueCat (iOS).

4. How We Use Your Information

  • To provide the core bookkeeping service: importing, categorizing, and displaying transactions; matching invoice payments; generating reports; and producing year-end summaries.
  • To read the documents you upload (receipts, invoices, statements, CSVs) so we can extract amounts, dates, and vendors.
  • To send you push notifications and emails about ambiguous transactions, your weekly check-in, account activity, and service updates.
  • To train the AI categorization rules that apply only to your own account (rules are never shared across customers).
  • To authenticate you, secure your account, rate-limit abuse, and prevent fraud.
  • To process payments and send receipts.
  • To diagnose and fix errors and crashes.
  • To comply with legal obligations, respond to lawful requests, and enforce our Terms of Service.

When you enable payments, your customers' payment details (card or bank account) are collected and processed directly by Stripe to complete the payment. Clarity Books never receives or stores full card or bank-account numbers.

We do not sell your personal information. We do not share your financial data with advertisers, data brokers, or any third party for marketing purposes.

5. Legal Bases (EU / UK Users)

Where the General Data Protection Regulation or the UK GDPR applies, we rely on the following legal bases: (a) performance of a contract with you; (b) your consent, where you have given it (for example, connecting a bank account); (c) our legitimate interests in operating and improving the Service; and (d) compliance with legal obligations.

6. Plaid and Bank Data

We use Plaid Inc. to connect to your financial institutions. Plaid authenticates you directly with your bank and shares transaction and balance information with us on your behalf. Plaid's handling of your data is governed by Plaid's End User Privacy Policy.

The Plaid access token we receive is read-only and scoped to transactions and balances. It cannot be used to move money, change account settings, or interact with your account beyond reading that data. We encrypt that token with AES-256-GCM before storing it.

7. How AI Reads Your Data

We use Anthropic's Claude to do the bookkeeping work. What we send depends on the feature:

  • Categorization: the transaction's description/memo, amount, type, and date; your business type; your chart-of-account names; and a digest of how you've categorized similar vendors before. We do not send your login name, email, bank credentials, or full account/routing numbers on this path.
  • Reading documents: when you upload a receipt, bank or credit-card statement, or CSV, the file is sent to Claude so it can read the text. Image and PDF files are sent in full; for very large CSV files, only the first portion is sent. These files are sent as-is and are not redacted, so any names, addresses, or tax identifiers printed on them are included.
  • Your check-in and questions: your typed replies and questions, your business name, and a short summary of your books (income/expense totals and open-invoice details) so the assistant can respond.

Anthropic is our only AI provider. Under our commercial agreement with Anthropic, content sent through its API is not used to train its models. This is a contractual commitment by Anthropic; the limits described in Section 14: Security apply to how this data is transmitted.

8. Third-Party Service Providers (Sub-processors)

We share the minimum data necessary with the vendors below to operate the Service. A full, current list is also maintained in our Data Processing Addendum.

  • Supabase: database, authentication, and private file storage (US).
  • Vercel: application hosting, serverless functions, and CDN (US).
  • Plaid: bank-account connectivity (US).
  • Anthropic: the Claude AI used for categorization, reading uploaded documents, and answering your in-app questions (see Section 7) (US).
  • Stripe: web subscription billing and, when you enable payments, payment processing for the invoices you send to your customers via Stripe Connect (US).
  • RevenueCat & Apple: in-app purchase and subscription management on iOS (US).
  • OneSignal: push-notification delivery on iOS and Android (receives a device push identifier and the notification text) (US).
  • Resend: transactional email: invoices, reports, year-end CPA packets, and authentication emails (US).
  • Sentry: error and crash diagnostics and performance monitoring (US).
  • Upstash: rate limiting and abuse prevention (receives your IP address and request counters) (US).

If you provide a CPA's email and trigger a year-end send, we email your report to the CPA you specify. The packet includes a tax summary and a CSV of every posted transaction for the year, plus your 1099 contractor names and totals (no tax IDs). You control each send.

9. Data Retention

We retain your data while your account is active. When you delete your account, we remove it as described below.

  • Active accounts: retained for the life of your account.
  • When you delete your account: your live records (including transactions, invoices, contractor and mileage data, AI-learned rules, and the receipt and document files you uploaded) are deleted immediately and irreversibly. Encrypted backups held by our infrastructure providers roll off on their standard rotation (typically within about 30 days).
  • Billing records: our payment processor (Stripe) may retain payment and invoice records for up to 7 years to meet its own legal and tax obligations. We do not keep a separate financial archive of your books after you delete your account.
  • Security & diagnostic logs: error/crash diagnostics and rate-limit logs are retained for a limited period and do not build a product-analytics profile of you.

10. Your Rights

Depending on where you live, you may have some or all of the following rights:

  • Access: request a copy of the personal data we hold about you.
  • Correction: update your profile and business details from Settings.
  • Deletion: delete your account and associated data from Settings → Account → Delete Account (available in both the web and mobile apps), or by emailing us (emailed requests are actioned within 7 business days, after we verify your identity). Our account-deletion page explains the process and is reachable without signing in.
  • Portability: export your transaction history and reports as CSV from the report, sales-tax, mileage, and contractor pages in the web app. (CSV export is currently web-only; if you use the mobile app, sign in on the web to export, or email us for a copy.)
  • Opt out of sale or sharing: we do not sell or share your personal information for cross-context behavioral advertising, so this right does not apply in practice, but you may still submit a request and we will confirm in writing.
  • Withdraw consent: disconnect bank accounts or turn off push notifications at any time.
  • Non-discrimination: we will not deny, charge a different price, or degrade service because you exercise a privacy right.

To exercise any right, email brayden@claritybooksai.com. We may need to verify your identity before responding. We will respond within 30 days (or 45 where permitted by law).

11. California Residents (CCPA / CPRA)

California residents have the rights listed in Section 10, plus the right to know what categories of personal information we have collected, the sources, the business purpose, and the categories of third parties with whom we have shared it. The categories we collect are listed in Section 3 (identifiers, contact and business information, financial and transaction information, uploaded documents, and device/diagnostic information). We do not sell or share personal information as those terms are defined under the CCPA/CPRA.

12. Children's Privacy

Clarity Books AI is intended for users aged 18 or older operating a legitimate business. We do not knowingly collect personal information from children under 13 (or the equivalent minimum age in your jurisdiction). If you believe a child has provided us personal information, contact us and we will delete it.

13. International Users

Our Service is hosted in the United States. If you access the Service from outside the US, your information will be transferred to, stored in, and processed in the US. Where required, we rely on appropriate safeguards (for example, the EU Standard Contractual Clauses) for cross-border transfers.

14. Security

We protect your data with the following measures:

  • Encryption in transit: TLS for all traffic between your device, our servers, and our providers.
  • Encryption at rest: our database and file storage are encrypted with AES-256 at the infrastructure layer by our provider (Supabase). In addition, your Plaid bank-connection token is encrypted by us with AES-256-GCM before it is stored.
  • Database isolation: Postgres row-level security enforces per-account data isolation at the database layer, and access roles encoded in your session are checked on every request.
  • Read-only bank access: the Plaid token cannot move money or change account settings.
  • Least-privilege internal access and private, access-scoped storage for uploaded files.

No system is completely secure, but we have designed the Service so that even a successful breach should not expose your banking credentials (we never have them) or allow money movement (our access is read-only).

15. Breach Notification

If we discover a breach of security that results in unauthorized access to your personal information, we will notify you by email within 72 hours of confirming the scope of the incident, describe what was accessed, and tell you the steps we are taking and the steps you should take.

16. Cookies and Tracking

We use strictly-necessary first-party cookies to keep you signed in (a Supabase authentication cookie). In our mobile apps, your session is stored on-device in secure app storage instead of a cookie. We do not use advertising, analytics, third-party, or cross-site tracking cookies, and we do not run a product-analytics SDK. The only automatic telemetry we collect is error/crash diagnostics (Sentry) and security / rate-limit logs (Upstash). See our Cookie Policy for a full list and controls.

17. Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. If we make material changes, we will notify you by email and, where required by law, obtain your consent before the changes take effect. Continuing to use the Service after changes take effect means you accept the updated policy.

18. Contact

Questions, requests, or complaints? Email us at brayden@claritybooksai.com. If you are in the EU/UK and are not satisfied with our response, you have the right to lodge a complaint with your local data-protection authority.