Legal
Privacy Policy
Last updated: July 29, 2026
Plain-language summary
We collect your account details and the accounting data of the client companies you connect, and we use them for exactly one thing: running AboveBoard for you. Data is hosted in the United States, processed by a short list of subprocessors we publish, and never sold. AI commentary is drafted from aggregated figures, not raw transactions, and we tell you plainly what our AI provider retains. Export and deletion are handled by email: ask, and we respond within 30 days. If your data is ever compromised, we tell you without undue delay. This summary is a convenience; the sections below are the policy.
1. Who we are
AboveBoard is a product of Sprezza LLC, an Illinois limited liability company. For your account data, we act as the data controller. For the financial data of the client companies you connect, you (or your client, depending on your engagement) determine the purposes; we process it on your instructions to provide the service. A Data Processing Addendum is available on request.
In plain terms, why we process each category: to perform our contract with you (your account, client records, synced financials, reports, and forecasts), our legitimate interest in keeping the service secure and preventing abuse (operational data and the audit log), and your consent where the law requires it.
2. What we collect, and why
This inventory is derived from our actual database schema, plus the one collection point that lives outside the database:
| Category | What it includes | Where it comes from | Why we have it |
|---|---|---|---|
| Your account | Email address, name, organization name, logo, brand color | You, at signup and onboarding | Sign-in, workspace identity, report branding |
| Client records | Client company names, industry, fiscal year end | You, when adding clients | Organizing the portfolio |
| QuickBooks connection | Company identifier, OAuth tokens (encrypted), sync status and errors | Intuit, when you connect a client | Reading the client's books |
| Synced financial data | Chart of accounts, monthly P&L and balance sheet figures, open invoices and bills, transaction detail, including vendor/customer names and memo text as they appear in the books | QuickBooks Online | Dashboards, reports, forecasts, alerts |
| Reports and commentary | Report snapshots, AI-drafted commentary, your edits and approvals | Generated in the product; edited by you | The monthly reporting package |
| Forecasts and alerts | Forecast adjustments and versions, alert rules and fired alert events | You; computed by the product | Cash forecasting and monitoring |
| Audit log | Who did what, when: syncs, generations, drafts, edits, approvals, finalizations | Generated in the product | Accountability and defensibility |
| Demo and partner enquiries | Name, work email, client count range, and anything you write in the message fields of the demo and design partner forms on this site | You, when you submit a public form | Responding to your enquiry; nothing else |
| In-app support requests | The category and message you write, plus automatically attached diagnostics: your user and organization ids, the app version, the page you were on, and, from a client page, that connection's sync status and error identifiers | You, when you use the in-app support form | Answering your support request; nothing else |
| Operational data | Rate-limit counters keyed by account identifiers (short-lived), job run records, scrubbed error reports | Generated by the infrastructure | Abuse protection and reliability |
Demo and design partner form submissions and in-app support requests are delivered by email and live in our support inbox, not in the product database. We use them only to respond to you, they are not added to any marketing list, and we delete them after 12 months.
We do not use advertising or analytics cookies. The only cookies the product sets are the authentication session cookies required to keep you signed in. Because we set no advertising or analytics cookies and do not sell or share personal information, Global Privacy Control and Do Not Track signals have nothing here to opt out of.
3. Where it lives, and who processes it
Data is hosted in the United States: the database, authentication records, and uploaded files with Supabase on AWS (us-east-2), and the application on Vercel. The complete subprocessor list (every third party that touches customer data, what each one touches, and why) is published on the security page and is maintained as part of the product.
4. AI processing
To draft report commentary, we send Anthropic aggregated period figures (revenue, margins, expense category totals, deltas, balances) and the client company’s name; not raw transaction detail, not your clients’ customer or vendor names, not account numbers. Per Anthropic’s commercial API terms, this data is not used to train their models and is retained by them for up to 30 days before automatic deletion.
If the AI provider is unavailable or declines a request, a deterministic built-in drafter produces the starting text instead. In that case no data leaves our infrastructure for drafting at all.
5. Email
We send operational email only: alert digests (which contain client company names and summary figures) and account communications, delivered through Resend to the email addresses on your account. There is no marketing email list.
6. How long we keep it
- While your account is active: we retain your data so the product works, including historical financials, which are the product’s core value.
- Backups: encrypted database backups, including pre-migration copies, are retained for up to 90 days and then rotated out. Data deleted from the live database persists in backups until rotation completes, at most 90 days.
- After deletion: we retain audit log entries needed for the security and integrity of the remaining system, and billing records the law requires. Everything else is removed from the live database on deletion and from backups within the rotation window.
- Rate-limit counters: short-lived by design (minutes to hours) and never backed up.
7. Your rights, export, and deletion
Export and deletion are handled by email today: write to hello@aboveboardhq.com from your account address, and we respond within 30 days, usually much faster. We provide your organization’s data in a machine-readable format, or delete your account, organization, or a specific client’s data from the live database, after which it ages out of backups within 90 days. If your account is terminated, your data remains available for export for 30 days before we may delete it, as described in the Terms of Service. Your clients’ source books are unaffected either way; they live in QuickBooks.
Wherever you live, we honor these rights over your personal data: to know what we hold about you, to access it, to correct it, to delete it, and to receive a portable copy. Exercising them never changes how we treat you. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
If you are unhappy with how we handled a privacy request, say so and a person will look at it again. Depending on where you live, you may also have the right to complain to your state attorney general or local privacy regulator.
8. Security
The measures protecting this data (database-level tenant isolation tested on every change, encryption in transit and at rest, application-layer encryption of connection tokens, verified backups, scrubbed error telemetry) are described in full on the security page.
9. If data is compromised
If we confirm a breach affecting your data, we will notify you without undue delay. The notice will say what happened, what data was involved, what we are doing about it, and what you should do. Our internal incident-response runbook backs this commitment, including engaging legal counsel the same day a breach is suspected so that notification deadlines are met.
10. Children
AboveBoard is a business tool for finance professionals and is not directed to children. We do not knowingly collect data from anyone under 16.
11. Changes to this policy
We will update this policy as the product evolves, for example when billing adds a payments subprocessor. Material changes will be communicated to active users by email, and the “last updated” date above always reflects the current version.
12. Contact
Privacy questions and requests: hello@aboveboardhq.com.