Legal

Privacy Policy

Last updated: July 29, 2026

Plain-language summary

We collect your account details and the accounting data of the client companies you connect, and we use them for exactly one thing: running AboveBoard for you. Data is hosted in the United States, processed by a short list of subprocessors we publish, and never sold. AI commentary is drafted from aggregated figures, not raw transactions, and we tell you plainly what our AI provider retains. Export and deletion are handled by email: ask, and we respond within 30 days. If your data is ever compromised, we tell you without undue delay. This summary is a convenience; the sections below are the policy.

1. Who we are

AboveBoard is a product of Sprezza LLC, an Illinois limited liability company. For your account data, we act as the data controller. For the financial data of the client companies you connect, you (or your client, depending on your engagement) determine the purposes; we process it on your instructions to provide the service. A Data Processing Addendum is available on request.

In plain terms, why we process each category: to perform our contract with you (your account, client records, synced financials, reports, and forecasts), our legitimate interest in keeping the service secure and preventing abuse (operational data and the audit log), and your consent where the law requires it.

2. What we collect, and why

This inventory is derived from our actual database schema, plus the one collection point that lives outside the database:

CategoryWhat it includesWhere it comes fromWhy we have it
Your accountEmail address, name, organization name, logo, brand colorYou, at signup and onboardingSign-in, workspace identity, report branding
Client recordsClient company names, industry, fiscal year endYou, when adding clientsOrganizing the portfolio
QuickBooks connectionCompany identifier, OAuth tokens (encrypted), sync status and errorsIntuit, when you connect a clientReading the client's books
Synced financial dataChart of accounts, monthly P&L and balance sheet figures, open invoices and bills, transaction detail, including vendor/customer names and memo text as they appear in the booksQuickBooks OnlineDashboards, reports, forecasts, alerts
Reports and commentaryReport snapshots, AI-drafted commentary, your edits and approvalsGenerated in the product; edited by youThe monthly reporting package
Forecasts and alertsForecast adjustments and versions, alert rules and fired alert eventsYou; computed by the productCash forecasting and monitoring
Audit logWho did what, when: syncs, generations, drafts, edits, approvals, finalizationsGenerated in the productAccountability and defensibility
Demo and partner enquiriesName, work email, client count range, and anything you write in the message fields of the demo and design partner forms on this siteYou, when you submit a public formResponding to your enquiry; nothing else
In-app support requestsThe category and message you write, plus automatically attached diagnostics: your user and organization ids, the app version, the page you were on, and, from a client page, that connection's sync status and error identifiersYou, when you use the in-app support formAnswering your support request; nothing else
Operational dataRate-limit counters keyed by account identifiers (short-lived), job run records, scrubbed error reportsGenerated by the infrastructureAbuse protection and reliability

Demo and design partner form submissions and in-app support requests are delivered by email and live in our support inbox, not in the product database. We use them only to respond to you, they are not added to any marketing list, and we delete them after 12 months.

We do not use advertising or analytics cookies. The only cookies the product sets are the authentication session cookies required to keep you signed in. Because we set no advertising or analytics cookies and do not sell or share personal information, Global Privacy Control and Do Not Track signals have nothing here to opt out of.

3. Where it lives, and who processes it

Data is hosted in the United States: the database, authentication records, and uploaded files with Supabase on AWS (us-east-2), and the application on Vercel. The complete subprocessor list (every third party that touches customer data, what each one touches, and why) is published on the security page and is maintained as part of the product.

4. AI processing

To draft report commentary, we send Anthropic aggregated period figures (revenue, margins, expense category totals, deltas, balances) and the client company’s name; not raw transaction detail, not your clients’ customer or vendor names, not account numbers. Per Anthropic’s commercial API terms, this data is not used to train their models and is retained by them for up to 30 days before automatic deletion.

If the AI provider is unavailable or declines a request, a deterministic built-in drafter produces the starting text instead. In that case no data leaves our infrastructure for drafting at all.

5. Email

We send operational email only: alert digests (which contain client company names and summary figures) and account communications, delivered through Resend to the email addresses on your account. There is no marketing email list.

6. How long we keep it

  • While your account is active: we retain your data so the product works, including historical financials, which are the product’s core value.
  • Backups: encrypted database backups, including pre-migration copies, are retained for up to 90 days and then rotated out. Data deleted from the live database persists in backups until rotation completes, at most 90 days.
  • After deletion: we retain audit log entries needed for the security and integrity of the remaining system, and billing records the law requires. Everything else is removed from the live database on deletion and from backups within the rotation window.
  • Rate-limit counters: short-lived by design (minutes to hours) and never backed up.

7. Your rights, export, and deletion

Export and deletion are handled by email today: write to hello@aboveboardhq.com from your account address, and we respond within 30 days, usually much faster. We provide your organization’s data in a machine-readable format, or delete your account, organization, or a specific client’s data from the live database, after which it ages out of backups within 90 days. If your account is terminated, your data remains available for export for 30 days before we may delete it, as described in the Terms of Service. Your clients’ source books are unaffected either way; they live in QuickBooks.

Wherever you live, we honor these rights over your personal data: to know what we hold about you, to access it, to correct it, to delete it, and to receive a portable copy. Exercising them never changes how we treat you. We do not sell personal information, and we do not share it for cross-context behavioral advertising.

If you are unhappy with how we handled a privacy request, say so and a person will look at it again. Depending on where you live, you may also have the right to complain to your state attorney general or local privacy regulator.

8. Security

The measures protecting this data (database-level tenant isolation tested on every change, encryption in transit and at rest, application-layer encryption of connection tokens, verified backups, scrubbed error telemetry) are described in full on the security page.

9. If data is compromised

If we confirm a breach affecting your data, we will notify you without undue delay. The notice will say what happened, what data was involved, what we are doing about it, and what you should do. Our internal incident-response runbook backs this commitment, including engaging legal counsel the same day a breach is suspected so that notification deadlines are met.

10. Children

AboveBoard is a business tool for finance professionals and is not directed to children. We do not knowingly collect data from anyone under 16.

11. Changes to this policy

We will update this policy as the product evolves, for example when billing adds a payments subprocessor. Material changes will be communicated to active users by email, and the “last updated” date above always reflects the current version.

12. Contact

Privacy questions and requests: hello@aboveboardhq.com.