Privacy Policy
BizAxcess Financial ("BizAxcess") turns bank and credit-card statements into profit & loss reports for tax professionals and their clients. This policy explains what we collect, how long it is kept, how you delete it, and which third parties ever see your data.
Last updated: September 2026 · See also our Security & privacy controls page.
1. What we collect
- Account data — your name, email address and sign-in credentials, used to authenticate you and secure your workspace.
- Billing data — subscription plan, billing interval and payment status. Card numbers are collected and stored by Stripe, our payment processor — BizAxcess never sees or stores your full card number.
- Your AI provider API key — the key you paste in Account so conversions run under your own provider account. It is stored only as AES-256-GCM ciphertext; we display back only the last four characters.
- Workspace data — business names, transaction categorization rules, conversion history (file names, dates, counts) and the audit log of security-relevant actions.
- Usage data — pages visited and conversion events, used to enforce plan limits and improve the product.
2. Statement & receipt data
Bank statements, credit-card statements and receipts you upload are processed in memory on the server for the duration of the conversion request. BizAxcess does not store the original files or the extracted transaction rows after the result is returned to your browser. What we retain is limited to conversion metadata: the file name, the detected business name, the provider used, the transaction count and the timestamp — plus any categorization rules you choose to save.
Because your clients' records pass through your own AI provider key, you are the controller of that data. Make sure your engagement letters cover AI-assisted processing where required.
3. How we use your data
- To authenticate you and isolate your workspace from other users.
- To convert statements into P&L reports at your request.
- To apply your saved categorization rules to future conversions.
- To enforce plan limits (business slots, conversion counts, trial limits).
- To process payments and manage your subscription via Stripe.
- To maintain the append-only audit log you can review in Account.
We do not sell your data, do not use statement content to train models, and do not use your client data for advertising.
4. AI provider disclosures
When you convert a statement, its content is sent directly from the BizAxcess server to the AI provider you selected, using your own API key. No other third party sits in between. Each provider's handling of that content is governed by the agreement between your firm and the provider:
Google Gemini gemini-3.6-flash
Retention: Paid Gemini API: prompts and files are not retained beyond the time needed to serve the request (abuse logs up to 55 days). Free-tier keys are handled under consumer terms.
Training: Paid Gemini API content is not used to train Google's models. Free-tier (unpaid) Gemini API content may be reviewed by humans and used for improvement — do not use a free-tier key for client data.
OpenAI gpt-4.1-mini
Retention: API inputs and outputs are retained up to 30 days for abuse monitoring, then deleted. Eligible accounts can request Zero Data Retention so nothing is stored.
Training: API content is not used to train OpenAI models by default.
Anthropic Claude claude-sonnet-4-5
Retention: API inputs and outputs are retained up to 30 days (shorter with zero-retention agreements), then deleted.
Training: Commercial API content is not used to train Anthropic models.
5. Retention
You control how long conversion history is kept: choose a window from 7 days to 7 years in Account → Privacy & retention. Records older than your window are purged automatically. Account and billing records are kept for as long as your account is active, and as required for tax and accounting compliance after closure.
6. Deletion
- Purge history on demand — Account → Privacy & retention lets you delete conversion history immediately.
- Delete your account — Account → Danger zone permanently removes your businesses, rules, keys, history, privacy settings and audit access.
- Statement files — never stored, so there is nothing to delete after a conversion completes.
7. Security
All traffic uses TLS 1.2+. Data at rest is encrypted with AES-256 on managed Postgres with encrypted backups. Your provider key is encrypted server-side with AES-256-GCM and never touches browser storage. Row-level security isolates every user's data. Security-relevant events are written to an append-only audit log. Full details are on the Security & privacy page.
9. Your rights & choices
You can access, correct, export and delete your data from within the app at any time. Depending on your jurisdiction (for example under CCPA/CPRA or GDPR), you may have additional rights such as portability or the right to object to certain processing. To exercise any right you cannot perform in-app, contact us and we will respond within a reasonable timeframe.
BizAxcess is intended for professional use and is not directed at children under 16.
10. Changes to this policy
If we make material changes, we will update the date above and announce the change in the in-app announcements and on the updates page before it takes effect.
Questions about this policy? Contact us at the support address shown in your Account page.
This policy describes product behavior and is not legal advice. Confirm it against your firm's professional and regulatory obligations.
