Privacy Policy
How we handle your data
Last updated: May 14, 2026
What we collect
When you use CMB we receive:
- The files you upload (PDF and CSV bank and credit-card statements)
- Contact details you provide (name, business email, phone, company name)
- Standard request metadata (IP, user agent) for abuse prevention
What we don't keep
- PDF statements are deleted after extraction. Raw PDFs never persist past the request that processed them.
- Account numbers and routing numbers are stripped during extraction. We retain only date, description, amount, and your categorization.
- Running balances are not stored. We use them once to verify extraction, then discard.
Tenant isolation
Every database query is scoped by your account ID. A bookkeeper's data, including categorized transactions, client engagements, and confirmed-categorization patterns, is never visible to another bookkeeper, even within the same organization. Processing batches are also scoped per (bookkeeper, client), so transactions from different clients are never mixed in the same call.
How automated processing works
We use Anthropic's API for transaction extraction, chart-of-accounts suggestions, and categorization. Your data is sent to Anthropic only for the duration of these requests and is subject to Anthropic'sprivacy policy. Per our contract, your data is not used for training.
Retention
Categorized transaction data, generated reports, and your confirmed-categorization patterns are retained for the lifetime of your account. You may request deletion of any client engagement at any time, which removes statement metadata, transactions, splits, confirmations, and chart-of-accounts records for that client.
Security
- Data at rest is encrypted in our managed Postgres instance (Neon).
- Data in transit is TLS 1.2+.
- Authentication is handled via Clerk with JWT-bearer tokens; admin access is role-gated.
Contact
Questions about privacy, deletion requests, or anything else? Reach us through the contact page.