Wauvel
Your data

Your numbers are yours.

Financial data is sensitive, so here's exactly what happens to it — written plainly, so you can decide you're comfortable before you hand Wauvel a single number.

  • Encrypted in transit and at rest

    Your files and financial data travel over HTTPS and sit on encrypted disk storage. Standard for any serious app — worth saying plainly.

  • Only your account can see your data

    Per-user storage paths plus database row-level security: one account can never read another's, and every request for your data goes through the same sign-in wall. The server-side jobs that build your reports and alerts run with a separate key that never reaches a browser.

  • Connected through Intuit, never your password

    QuickBooks links over Intuit's official sign-in, so your QuickBooks credentials never reach us. The tokens that authorize the connection are encrypted at rest and never stored in plaintext.

  • We only ever read your books — and the switch is yours

    We read your reports and the records behind them: profit & loss, balance sheet, cash flow, chart of accounts, invoices, bills and transactions. Intuit doesn't offer apps a read-only permission, so here is the commitment instead: Wauvel never creates, changes, or deletes anything in your books. Disconnect anytime and the access is revoked at Intuit and the connection deleted.

  • Read by Claude, never used to train models

    The AI that reads your statements is Claude, by Anthropic. Their API terms explicitly forbid training on customer data. Your numbers go in, your commentary comes back — that's the whole loop.

  • The AI doesn't know whose books it's reading

    For your reports and your dashboard, your name, email, business name, and file names never reach the model. It sees the numbers and the line-item categories, then writes the read blind to who you are. The one exception is yours to make: a letter you upload to Documents is read as it is, so the AI sees whatever is printed on it.

  • A strict Content-Security-Policy

    The app enforces a strict CSP to shut down whole classes of injection and data-exfiltration attacks, and publishes a security.txt (RFC 9116) so researchers have a clear way to report anything.

  • Never sold, never shared

    No data resale, and your financial data never goes to an advertiser or an analytics company. Site analytics are our own, first-party. The one outside tag is a Google Ads conversion counter on the marketing pages, and it loads only if you accept it in the cookie banner. Your data exists to run your numbers — that's it.

  • Delete your data anytime

    Email hello@wauvel.com and we'll wipe your files and reports within 24 hours. Self-serve deletion is coming to the dashboard.

Report a security issue

Found something? Email hello@wauvel.com — you'll hear back from a human. Our disclosure details live at /.well-known/security.txt. For how we handle data day to day, see the privacy policy.

Free · no account · no card

Want to test it first? Connect QuickBooks for your free budget: we read your books once, and give the access back within the hour.

Build my 2027 budget →

Comfortable? Put an AI CFO on your books.

$99/mo, everything included. Free for 14 days, no card.

Meet your AI CFO →