Privacy Policy
How Wauvel collects, uses, shares, and protects information when you use the service. Read alongside our Terms of Service.
The short version
What we do with your data
Your financial data goes in encrypted, sits encrypted, and only leaves to generate your report.
Connect QuickBooks or Xero if you like — it's read-only, runs through the provider (never your password), and you can disconnect anytime.
The AI that writes your commentary never sees your name, email, or file names — just the numbers.
We never sell your data, target ads using your financial data, or share it with brokers. The AI provider can't train on it.
Our in-app analytics are first-party. The only outside tag is Google's ad-conversion measurement on our marketing pages — it runs only if you accept cookies, and never sees your financial data.
Delete everything anytime by emailing us. The full legal version is below.
If anything is unclear, ask us.
Section 01
What this coversWhat this policy is, and how it fits with our other terms.
01.1
Scope.
This Privacy Policy describes how Wauvel(“we”, “us”, “our”) collects, uses, shares, and protects information when you visit wauvel.com or use the Wauvel service.
01.2
Read alongside the Terms.
This policy works together with our Terms of Service. The Terms define the contract between you and Wauvel; this policy explains what we do with the information you give us along the way.
Section 02
What we collectThe information we collect, by category.
02.1
Account information.
When you sign up, we collect your email address and, if you set one, a one-way hash of your password (accounts created by connecting QuickBooks start without a password until you add one). We don't store your password in readable form — only the hash, used to verify future sign-ins.
02.2
Financial content you upload.
The financial statements you upload — profit and loss statements, balance sheets, transaction exports — are the core data you put into Wauvel. We store them encrypted, scoped to your account.
02.3
Reports we generate for you.
Each report you generate is stored in your account so you can revisit it. Reports contain calculated values, written commentary, and references to the source data.
02.4
Account activity.
We log basic activity — sign-in timestamps, uploads, report generations — to operate the service, debug issues, and detect misuse.
02.5
Device and connection data.
When you load the site or service, our servers receive standard request data — IP address, browser type, request timestamps, and pages requested. We use this for security, abuse prevention, and operational debugging.
02.6
Payment information.
If you subscribe, payment is processed by our payment processor (Stripe). We don't store full credit card numbers. We do store the customer ID Stripe issues us, the subscription status, and the last four digits of the card for display purposes.
02.7
Data from a connected accounting platform.
If you choose to connect an accounting platform — QuickBooks Online (via Intuit) or Xero — we use that platform's official authorization to read your financial reports — your profit and loss statement (including transaction-level detail where the platform provides it), balance sheet, cash flow statement, chart of accounts, and outstanding invoices and bills — along with your company or organisation name, so we can generate your reports. We only read this data: we do not write to, modify, or delete anything in your connected account. Connecting is optional, and you can disconnect at any time (see 06.5).
02.8
Usage analytics.
If you accept analytics cookies (see 08.1), we collect first-party usage data to understand how the site and service are used: the pages you view and buttons you click, the referring site and any UTM campaign tags from the link you arrived through, your device type, and your country (derived from your IP, which we do not store). We keep a random visitor and session identifier in your browser's local storage for this; when you are signed in, we also associate these events with your account. This is first-party only — never shared with advertisers and never used to track you across other websites. If you decline, none of it runs.
02.9
Newsletter and marketing list.
If you subscribe to our newsletter or content updates, we store the email address you give us and where you signed up from, so we can send what you asked for. You can unsubscribe at any time.
02.10
Referrals.
We operate a referral program. If you arrive through someone's referral link, we store a referral code in a cookie (only if you accept analytics cookies) so the referrer can be credited if you subscribe. If you refer others, we record which accounts you referred and the commissions you earn. See Section 06.7 of the Terms of Service for how the program works.
02.11
Advertising measurement (Google Ads).
We advertise Wauvelon Google. To measure whether those ads work, our marketing pages load Google's advertising tag (Google Ads, via gtag.js) and record a “conversion” when a visitor who arrived from an ad signs up or subscribes — together with the plan's value, so we can judge return on ad spend. This is a third-party tag (Google) that sets its own cookies. It loads only if you accept non-essential cookies (see 08.1); decline and it never runs. We use it to count and value conversions, not to build a profile of you or to show you behavioral ads on Wauvel. It never receives Your Content or financial data.
02.12
Data from a connected bank (Plaid).
If you choose to connect a bank account, we use Plaid to make the connection. You enter your banking credentials with Plaid — not with us — and Plaid returns a secure access token plus the account and balance information we need to show your live cash position and improve your forecast. We never see or store your online-banking username or password. Connecting is optional, and you can disconnect at any time.
02.13
What we don't collect.
We don't ask for your business legal name, EIN, or tax ID. We don't build advertising profiles about you, run behavioral ad-targeting, or track you across other websites. The one exception to “no third parties” is the opt-in Google Ads conversion tag described in 02.11 — it measures ad performance only, and never sees Your Content.
Section 03
How we use itWhat we do with the information you give us.
03.1
To run the service.
We use Your Content and account information to generate your reports, store them in your account, and provide the service you signed up for.
03.2
Customer support.
If you contact us, we use your email and any context you share to respond.
03.3
Service communications.
We may email you about account activity (sign-in attempts, password resets), billing (renewals, failed charges), and material changes to these policies. You can't opt out of these — they're operationally required.
03.4
Product communications (optional).
We may also send occasional product updates. You can opt out of these from your dashboard or any email footer; doing so will not affect the service communications above.
03.5
Security & abuse prevention.
We use account activity and device data to detect unauthorized access, abuse, fraud, and violations of our Terms — including the business-use-only provisions in Section 03 of the Terms of Service.
03.6
Improving the service.
We may use aggregated, de-identified usage patterns (for example, “X% of uploads include a balance sheet”) to understand how the service is used and improve it. This never includes identifiable customer data.
03.7
Referrals and updates.
If you take part in our referral program, we use the referral data in 02.10 to credit referrers and pay commissions. If you join our newsletter, we use your email to send the updates you asked for, until you unsubscribe.
Section 04
How we share itWho else sees your data, and why.
04.1
The AI provider (Anthropic).
To generate your report, the calculated values and line-item categories from Your Content — whether you uploaded it or we retrieved it from a connected QuickBooks account — are sent to Anthropic's Claude API. The same API powers our optional conversational features — the in-app assistant you can ask about your numbers and the site-wide help bubble — so text you type into those is sent to it as well. For report generation we do not send your name, your email, the file name, your business name, or any accounting-platform account identifier. By connecting an accounting platform and generating a report — or by typing into the conversational features — you consent to this processing by the AI provider. We never permit the AI provider to use your data to train, fine-tune, or otherwise improve any AI model, and its API terms contractually prohibit it. If you save notes to your company's memory, those notes are included with future reports and messages so the assistant stays consistent, and are sent to the AI provider the same way — so keep sensitive identifiers out of them.
04.2
Infrastructure providers.
We use third-party infrastructure to host the service — including Supabase (database and authentication) and Vercel (hosting). These providers process data on our behalf under written data processing terms and only as needed to operate the service.
04.3
Payment processor.
Subscription payments are processed by Stripe. Stripe handles card data directly; we receive only the limited information described in 02.6.
04.4
Legal compliance.
We may disclose information if required by law, court order, or to respond to a valid government request, or to protect the safety, rights, or property of Wauvel, our users, or the public.
04.5
Never sold. Your financial data is never advertised against or used to train AI.
We do not sell your personal information or Your Content — including any data we retrieve from a connected QuickBooks or Xero account. We never use Your Content or your financial data for advertising, and we don't share it with data brokers. The only advertising-related processing we do is the opt-in Google Ads conversion tag on our marketing pages (see 02.11 and 04.7): it measures whether an ad led to a sign-up or subscription and never has access to your financial data. We do not use any of it to train any AI model, and the AI provider is contractually prohibited from training on it.
04.6
Business transfers.
If Wauvel is involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction. We will notify you in advance, and your information becomes subject to a different privacy policy.
04.7
Advertising measurement (Google).
If you opt in to non-essential cookies, our Google Ads tag reports to Google that a sign-up or subscription happened — with the plan's value and Google's own click identifiers — so we can measure and bid on our ads. It runs only with your consent (see 02.11) and never receives Your Content or financial data.
04.8
Bank connection (Plaid).
If you connect a bank account, Plaid Inc. is our banking-connection provider. You authenticate directly with Plaid — we never receive your online-banking credentials — and Plaid provides the account and balance information you authorize so we can show your cash position and forecast. Plaid processes this under its own privacy policy and our agreement with it.
04.9
Delivery channels you connect (Slack, Microsoft Teams).
If you set up delivery to Slack or Microsoft Teams, we send the reports, digests, or alerts you've asked for to that platform through the connection you create, where they then live under that provider's terms. You choose what's delivered and can disconnect at any time.
Section 05
How we secure itThe practical steps we take to keep your data safe.
05.1
Encryption.
Data is encrypted in transit (HTTPS) and at rest (encrypted database and object storage).
05.2
Access controls.
Per-user storage paths and database row-level security ensure that only your account can see your data. Our infrastructure cannot bypass this without going through the same authentication wall you do.
05.3
Employee access.
A small number of authorized personnel may access systems for debugging or support, only as necessary, and under strict confidentiality and access controls.
05.4
Connected-account tokens.
When you connect an accounting platform or a bank, the provider (Intuit for QuickBooks, Xero, or Plaid for a bank connection) issues us access tokens that authorize the connection — your QuickBooks, Xero, or online-banking password is never shared with us. We encrypt those tokens (AES-256-GCM) and never store them in plaintext. They are accessible only to the server-side process that retrieves your data, and are revoked at the provider and deleted when you disconnect.
05.5
No system is perfectly secure.
While we work hard to protect your information, we can't guarantee that all transmissions and storage are absolutely secure. If we become aware of a breach affecting your data, we will notify you in accordance with applicable law.
Section 06
How long we keep itRetention windows for each category.
06.1
Your Content.
Files and reports you generate are retained in your account until you delete them or close your account. After account closure, we retain Your Content for up to 30 days, then delete it.
06.2
Account records.
We retain basic account records (email, account creation date, subscription history) for as long as your account is active, plus a period afterward for legal, tax, and accounting purposes (typically up to seven years).
06.3
Activity logs.
Operational logs (sign-ins, request logs) are retained for up to 90 days, then aggregated or deleted.
06.4
On request.
You may request earlier deletion of Your Content at any time. See 07.3.
06.5
Connected accounts.
You can disconnect a connected accounting platform or bank at any time. When you do, we revoke the connection at the provider (Intuit, Xero, or Plaid) and delete the stored access tokens. Reports already generated from that data are retained in your account like any other report until you delete them or close your account.
Section 07
Your rightsWhat you can ask us to do with your data.
07.1
Access.
You can see the information associated with your account — your email, your subscription status, and Your Content — directly from your dashboard.
07.2
Correct.
You can update your email or password from your dashboard. For anything else, email us.
07.3
Delete.
Email hello@wauvel.com to request deletion of Your Content. We will delete the requested files and the reports derived from them within 24 hours, except where we are required to retain certain records for legal, tax, or accounting purposes.
07.4
Export.
On request, we will provide a copy of Your Content and your reports in a portable format.
07.5
Withdraw consent.
You can stop using the service at any time by canceling your subscription and requesting account deletion.
Section 08
Cookies & trackingWhat we set in your browser, and what we don't.
08.1
Cookies and local storage.
Essential cookies keep you signed in and secure — session authentication and security tokens. These are required to operate the service and are always on. Non-essentialstorage — the first-party usage analytics described in 02.8 (kept in your browser's local storage), a referral-attribution cookie, and Google's advertising-measurement cookies (see 02.11) — runs only after you opt in. On your first visit a banner lets you accept or decline; we remember your choice, and you can change it at any time by clearing this site's data in your browser. Google's conversion cookies are the only third-party cookies we set, and they load only if you accept; we don't use behavioral ad-targeting or cross-site tracking cookies.
08.2
Analytics.
Our product analytics — how you use the app — are first-party and built in-house; there is no third-party analytics provider for them, and that data is never shared with one. When you are signed in, analytics events are associated with your account (see 02.8); for signed-out visitors they are tied only to a random identifier. Analytics run only if you accept (see 08.1). Separately, our marketing pages load one third-party tag — Google Ads conversion measurement (see 02.11) — which also runs only with consent and never receives your in-app activity or financial data.
08.3
Do Not Track.
We respect “Do Not Track” signals where technically practical.
Section 09
Children's privacyWauvel is not for anyone under 18.
09.1
Not for kids.
Wauvelis not directed to children under 18 and is intended for use by business owners and operators. We don't knowingly collect information from anyone under 18. If we learn that we have, we will delete it.
Section 10
International usersWhere your data lives, and what rights you have.
10.1
Where data is processed.
Wauvel is operated from the United States. If you access the service from outside the U.S., your information will be transferred to and processed in the U.S. and other locations where our infrastructure providers operate.
10.2
Region-specific rights.
Depending on where you live, you may have additional rights under laws such as the EU GDPR or the California Consumer Privacy Act — including rights of access, correction, deletion, and portability. We honor these rights for all users regardless of location. To exercise them, email hello@wauvel.com.
Section 11
Changes to this policyHow and when we update what's here.
11.1
Updates.
We may update this policy as the service evolves. For material changes — to what we collect, how we use it, or who we share it with — we will notify you by email at least 30 days before the change takes effect.
11.2
Effective date.
The current version's effective date appears at the top of this page.
Section 12
ContactHow to reach us about privacy.
12.2
Effective date.
This Privacy Policy is effective as of August 4, 2026.