Privacy Policy
Akili Bookkeeping · Effective date: [EFFECTIVE DATE] · DRAFT for legal review
This Privacy Policy explains how [LEGAL ENTITY NAME] ("Akili", "we", "us") collects, uses, shares and protects information when you use akilibookkeeping.com and the client portal at app.akilibookkeeping.com (the "Platform").
1. Information we collect
Information you give us
- Account details: your name, email address, phone number and password (your password is handled by our sign-in system and is never visible to us).
- Business details: legal name, entity type, address, what the business does, and Employer Identification Number (EIN).
- Documents you upload: bank and credit card statements, receipts, agreements and other records.
- Messages: answers to our questions and support conversations.
Information from QuickBooks Online (when you connect it)
- Your chart of accounts, customers, vendors, transactions, invoices, bills, payments and related records, and the QuickBooks company name and ID.
- We access this only through Intuit's authorized connection (OAuth), which you approve and can revoke at any time.
Payment information
- Payments are processed by Stripe. We receive your plan, payment status, the card brand, last four digits and expiry date. We never receive or store your full card number.
Information collected automatically
- Sign-in and security records: the time of sign-ins, IP address, browser type, and actions taken in the Platform (an audit log kept for security and accuracy).
- Technical error reports, with sensitive values removed before they are sent.
- Cookies: we use only the cookies needed to keep you signed in and keep the Platform secure. We do not use advertising or tracking cookies.
2. How we use your information
- To provide the bookkeeping services: reading statements, matching and categorizing transactions, posting them to your QuickBooks company, reconciling accounts and preparing month-end summaries.
- To bill you and manage your subscription.
- To communicate with you: service emails such as statement reminders, questions about transactions, month-end summaries, receipts and payment notices.
- To keep the Platform secure, prevent fraud and misuse, and meet legal obligations.
- To improve the services, using your data only within our own systems.
We do not sell your personal or business information, and we do not use it for advertising.
3. QuickBooks data
- We use QuickBooks data only to provide the services you've asked for.
- We store the QuickBooks access credentials encrypted, and only for as long as your connection is active.
- When you disconnect QuickBooks (from the Platform or from your Intuit account), we stop accessing your company and delete the stored access credentials. Copies of QuickBooks data we hold are kept or deleted as described in Section 6.
- We do not share QuickBooks data with anyone except the service providers in Section 4 that we need to deliver the services.
4. Who we share information with
We share information only with service providers who process it on our behalf, under contracts that require them to protect it and use it only for our services:
| Provider type | Purpose |
|---|---|
| Intuit (QuickBooks Online) | Reading and updating your books, as you authorize |
| Stripe | Payment processing |
| Amazon Web Services | Hosting and encrypted storage of the Platform and its backups (United States) |
| Cloudflare | Security, network protection and website delivery |
| Postmark | Sending service emails |
| AI service provider [NAME] | Reading statements and suggesting categories and document names; data is not used to train their models [CONFIRM] |
| Error-tracking provider (Sentry) | Technical error reports, with sensitive values removed |
We may also disclose information if required by law, to protect the rights and safety of Akili, our clients or others, or as part of a merger or sale of our business (in which case we'll notify you).
5. How we protect information
- Encryption in transit (HTTPS) and at rest, including encrypted storage of sensitive fields such as EINs and QuickBooks credentials.
- Each business's data is kept separate at the application and database level.
- Two-step sign-in for all Akili staff, limited staff access, and audit logging of access and changes.
- Regular backups, tested restores, security monitoring and security testing.
No system is perfectly secure, but we follow an internal security standard and review it regularly.
6. How long we keep information
- While your account is active, we keep your information to provide the services.
- After your account closes, we keep records for [RETENTION PERIOD, e.g. 7 years] where needed for legal, tax and accounting obligations, then delete them. Backups are overwritten on a rolling basis within [35 days].
- You can ask us to delete your information sooner; we'll do so unless we're required to keep it.
[ALIGN WITH docs/security/data_retention.md ONCE ADOPTED]
7. Your choices and rights
- Access and correction: view and update your account and business details in the Platform, or ask us.
- Export: download your documents and reports from the Platform.
- Deletion: ask us to delete your account and information, subject to Section 6.
- QuickBooks: disconnect at any time.
- Emails: service emails are part of the services; you can ask us to stop non-essential ones.
Depending on where you live, you may have additional rights under privacy laws (for example, the Texas Data Privacy and Security Act). Contact us to exercise them.
8. Children
The Platform is for businesses and is not directed to anyone under 18. We do not knowingly collect information from children.
9. Changes to this policy
We'll post any changes here with a new effective date and, for material changes, notify you by email or in the Platform.
10. Contact
[LEGAL ENTITY NAME] · [MAILING ADDRESS], Houston, Texas · hello@akilibookkeeping.com · (832) 303-0777
---
Open items (for legal review)
- Legal entity name, mailing address and effective date.
- The AI provider's name and whether its terms guarantee no training on our data and zero retention.
- Retention period after account closure (7 years suggested for financial records), aligned with data_retention.md.
- Whether any state privacy law beyond Texas needs specific wording for the client base.
- Confirm this policy meets Intuit's app review requirements (QuickBooks data use, storage, disconnect and deletion).