Pocket-CFO

Legal

Privacy Policy

Last updated 2026-08-28. This policy explains how Pocket-CFO handles business and user data.

Data we collect

Pocket-CFO collects account and authentication information such as name, email address, login identifiers, organization membership, and security events. We collect company profile information, accounting-provider metadata, normalized accounting records, chart-of-accounts mappings, KPI settings, scenario assumptions, support messages, and product usage events. When you connect QuickBooks, Xero, or another accounting provider, access and refresh tokens are encrypted and stored server-side so the product can sync authorized data. Tokens are not intended to be exposed to the browser.

How we use data

We use data to authenticate users, operate workspaces, sync and normalize accounting data, calculate deterministic metrics, generate dashboards, prepare KPI briefings, troubleshoot errors, secure the service, respond to support requests, improve usability, and comply with legal obligations. Pocket-CFO does not provide financial, tax, legal, actuarial, insurance, accounting, investment, or fiduciary advice, and product outputs should be reviewed with qualified professionals before use in decisions, filings, financing, insurance, or tax positions.

Data we share

We share data with service providers that help operate the product. Supabase may process authentication, database, storage, and related infrastructure data. OpenAI may process selected KPI briefing prompts and context when you use briefing features. Paddle processes web subscription and payment data, and RevenueCat may process mobile in-app purchase and subscription-entitlement data when you subscribe through the iOS or Android apps. Google Tag Manager, Hotjar (session replay), Contentsquare (session replay and behavioural analytics), PostHog (product analytics), and Vercel Web Analytics (cookieless page-view analytics on the website) may receive usage, device, and interaction data only if you accept analytics cookies or similar storage. Not every subprocessor listed here is enabled in every build; see our Subprocessor List for the current status, purpose, and data received for each vendor we work with. We may also share information with accounting providers you connect (such as QuickBooks and Xero), professional advisers, legal authorities, or transaction partners when required to operate the service, protect rights, comply with law, or complete a business transfer.

How we protect data

We encrypt all traffic to Pocket-CFO in transit with TLS. Every account requires two-factor authentication (a time-based one-time code) to sign in, and this is enforced server-side on every authenticated request, not only at login. Accounting-provider OAuth tokens are encrypted at rest using AES-256-GCM. MFA recovery codes are stored only as one-way hashes; the plain codes are shown to you once at generation and are never retained afterward. Your company's financial and business data is isolated per tenant using database row-level security, and we have revoked direct database-API access to that data so it can only be read and written through our authenticated application server. Pocket-CFO staff can reach internal support tooling only through a separate authorization step that requires its own verified two-factor authentication, and staff actions are logged. We run automated secret scanning and dependency vulnerability scanning on every code change before it reaches production. We never store your password ourselves: authentication is delegated to our authentication provider, and two-factor authentication is mandatory on every account regardless of password strength.

Breach notification

If we confirm a breach affecting your personal data, we will notify affected users without undue delay. Where the EU or UK GDPR applies, we will also notify the relevant supervisory authority within 72 hours of becoming aware of the breach, consistent with GDPR Article 33. Our notice will describe the nature of the incident, the categories of data involved, the steps we have taken in response, and what you should do to protect yourself.

Retention and rights

We keep your account and company data while your account is active. When you request deletion and we confirm the request, we cancel any active subscription, revoke your organization's stored accounting-connection tokens, and delete the organization record, which cascades to erase its financial, tax, MEC, and briefing data, then we delete your authentication record. If you share a workspace with other members and are not its only owner, only your own membership is removed and the shared workspace's data remains intact for the remaining members. Webhook and billing event logs are retained for 90 days. Backup copies of deleted data persist for our infrastructure provider's backup-retention window before they are purged. You may request access, correction, export, or deletion of personal information and company data by contacting privacy@rippre.com. We may need to verify your identity and authority over the workspace before acting. Some information may remain in backups, logs, invoices, security records, or records we must retain by law, but we will limit further use where deletion is not immediately possible.