Legal
Privacy Policy
This policy explains what information BennyBooks collects, why we collect it, and the choices you have.
Last updated: September 5, 2026
1. Who we are
BennyBooks (“BennyBooks”, “we”, “us”) provides AI-friendly accounting software for small companies. This Privacy Policy applies to our website, product, and related services (the “Service”).
Questions about privacy: benny@bennybooks.com.
2. Information we collect
We collect information in these categories:
- Account information — name, email address, and authentication data handled by our identity provider (Clerk), plus organization membership.
- Company profile — business name, website, company number, countries, currency, and fiscal-year settings you provide.
- Ledger data — transactions, notes, receipts, categories, proposals, and related bookkeeping records you or your connectors import into the Service.
- Connector and billing data — integration sync metadata, payment status, and billing details processed by Stripe (we do not store full card numbers).
- Agent API usage — API token identifiers, scopes, request metadata needed for security and audit logs, and proposal payloads agents submit for human approval.
- Technical data — IP address, browser type, device information, and product analytics events that help us operate and improve the Service.
3. How we use information
We use information to:
- Provide, secure, and maintain the Service
- Authenticate users and enforce organization tenancy
- Process bookkeeping workflows, approvals, and audit trails
- Enable optional AI-agent access via scoped API tokens
- Process subscriptions and communicate service notices
- Detect abuse, debug issues, and improve product quality
We do not sell your personal information. Agent writes create proposals for human review; they do not auto-post ledger changes in the current product version.
4. How we share information
We share information only as needed to run the Service:
- Service providers — infrastructure and processors such as Clerk (auth), Supabase (database), Cloudflare R2 (receipt storage), Stripe (billing), and analytics providers under contractual safeguards.
- Your organization — members of your organization can access org-scoped ledger data according to their roles.
- Agents you authorize — API tokens you create can read or propose writes within the scopes you grant.
- Legal requirements — when required by law, or to protect the rights, safety, and security of BennyBooks and our users.
5. Data retention
We retain account, organization, and ledger data while your account is active and as needed to provide the Service, meet legal obligations, resolve disputes, and enforce agreements. You may request deletion of your account data subject to legal and operational retention requirements.
6. Security
We use industry-standard measures including encryption in transit, org-scoped access controls, and scoped API tokens. No method of transmission or storage is completely secure; please protect your credentials and rotate tokens if they are exposed.
7. International transfers
We may process data in countries where we or our processors operate. Where required, we use appropriate safeguards for cross-border transfers.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to or restrict certain processing. Contact benny@bennybooks.com to make a request. You may also manage account details in Settings after signing in.
9. Children
BennyBooks is intended for business use. We do not knowingly collect personal information from children under 16.
10. Changes
We may update this policy from time to time. We will revise the “Last updated” date above and, when changes are material, provide additional notice as appropriate.
11. Contact
For privacy questions, email benny@bennybooks.com. See also our Terms of Service.