Privacy Policy

Effective July 29, 2026

BucketBooks is a bookkeeping service operated by Aphiliate Network, Inc. (“we”, “us”). Your books are some of the most sensitive data a business has, so this policy is written to be read: what we collect, why, where it lives, and what we will never do with it.

What we collect

  • Account details. A username, a password (stored only as a bcrypt hash — we cannot see it), and an optional email address used for account recovery and service notices.
  • Financial data you connect. If you link a bank or card account through Plaid, we receive account names, balances, and transactions. We never see or store your bank username or password — that credential exchange happens directly with Plaid.
  • Files you upload. Marketplace settlement reports (Amazon, Walmart, eBay) you import for reconciliation.
  • Billing. Subscriptions are processed by Stripe. Your card number never touches our servers; we store only your subscription status and Stripe’s customer reference.
  • Support. Emails you send us.
  • Campaign measurement. On www.bucketbooks.app, Google Analytics and OpenAI Ads receive limited visit data such as pages viewed, referring page, browser/device information, approximate location, and campaign parameters. Google Analytics also receives signup-button interactions through Google Tag Manager. On the founding-offer landing page, Reddit Ads receives a page-visit and content-view event. After account creation, OpenAI Ads receives a random event reference and whether registration and an eligible free trial completed; when available, it also receives OpenAI’s own privacy-preserving campaign reference and the signup page URL without its query string. After Stripe confirms a subscription payment, the payment-success step on app.bucketbooks.app sends Google Analytics, Google Ads, Reddit Ads, and OpenAI Ads only a unique Stripe invoice reference, the purchase value and currency, and the purchased plan. Campaign measurement does not load on other bookkeeping pages, and we do not send these services your books, bank data, username, email, phone number, or card details. Reddit automatic advanced matching is disabled, and we do not provide OpenAI Ads account or contact fields for user matching.

The logged-in product uses an essential session cookie that keeps you signed in. On most of the public marketing site, Google Analytics and advertising storage default to denied, the OpenAI Ads Pixel starts with consent denied, and the Reddit Pixel does not load until you allow measurement. On the founding-offer landing page, campaign measurement is on by default without a prompt, except when your browser sends a Global Privacy Control signal, which we honor as a decline. When measurement is on, Google may set analytics and ad-click measurement cookies, Reddit may set campaign-attribution cookies, and OpenAI may set first-party campaign and browser-reference cookies. When it is off, Reddit receives nothing, OpenAI receives no measurement-event pings, and Google may receive limited cookieless measurement signals. Your setting is saved in your browser and in a first-party consent cookie shared with the signup and payment-success pages, and can be turned off at any time with the marketing site’s Measurement settings control. Google user-data sharing and ad personalization remain disabled; OpenAI Ads events are marked as opted out of future user-level personalization.

How your data is used

To run your books — syncing transactions, reconciling settlements, producing reports — and to bill your subscription and answer support requests.

AI Assist is optional and can be turned off in Settings for a fully functional rules-only product. Automatic categorization may send a transaction’s description, merchant, amount, bank category, your category names, and entity profile to Anthropic’s Claude API. Document reading sends only the document you choose to upload and the context required to label it. Weekly digest narration may send code-computed summary facts. Ask your books sends your question, up to six browser-held text turns, and only the minimum category/profile context or code-computed, sanitized facts needed for read-only analysis. Exact ledger rows, local record identifiers, bank account details, and raw descriptions stay in BucketBooks. BucketBooks code—not Claude—computes every number, executes every ledger query, and validates the answer before showing private citations.

BucketBooks never intentionally includes credentials, bank account or routing numbers, or a full-books export in an AI request. Claude can label, select, and explain; it cannot post to your books. Ask questions and answers are not persisted as chat history; follow-up context stays in your browser and clears when you switch businesses, leave or refresh the app, sign out, lose access, or turn off AI Assist. Anthropic does not train its models on API data.

We use public-site analytics to understand site and campaign performance and to attribute completed subscriptions to ads, but never use your books, bank data, contact details, or card details for advertising. We never sell your data — to anyone, ever.

Where it lives

Your books are stored in their own isolated database — one per customer, not commingled tables — on servers in the United States. Bank connection tokens are encrypted at rest (AES-256-GCM). Encrypted backups replicate continuously to Cloudflare R2 storage, and the service is served exclusively over HTTPS.

Who else touches it (subprocessors)

  • Plaid — bank connections (see Plaid’s privacy policy at plaid.com/legal).
  • Stripe — subscription billing.
  • Anthropic — optional categorization, document reading, digest narration, and read-only books analysis.
  • Cloudflare — encrypted backup storage.
  • Google — public-site analytics plus narrowly scoped subscription-purchase measurement for Google Ads (see Google’s privacy policy at policies.google.com/privacy).
  • Reddit — consent-gated founding-offer visits and narrowly scoped subscription-purchase measurement for Reddit Ads (see Reddit’s privacy policy at reddit.com/policies/privacy-policy).
  • OpenAI — consent-gated public-page, completed registration and trial, and narrowly scoped subscription-purchase measurement for OpenAI Ads (see OpenAI’s privacy policy at openai.com/policies/privacy-policy).
  • Our hosting provider — the U.S. servers the service runs on.

Each receives only what its job requires. No data brokers.

Your data is yours

You can export everything — every transaction, category, rule, account, and settlement — as a ZIP of CSV files at any time from Settings, and that export keeps working even if your subscription has lapsed. You can disconnect a bank connection at any time in the app. To delete your account entirely, email us. We remove the active account and retain encrypted recovery snapshots for no more than 30 days before automatic deletion.

Retention

We keep your data for as long as your account exists. If you cancel, your books stay exportable so you can leave with everything. If you ask us to delete your account, we delete the active account immediately; encrypted recovery and disaster-recovery copies may persist for up to 30 days and are then purged automatically.

Other things you’d expect us to say

BucketBooks is a business tool and isn’t directed at children under 18. If we make a material change to this policy, we’ll post the update here and notify you by email if we have one on file.

Contact

Questions or requests: support@bucketbooks.app.