On this page
- 1. The short version
- 2. Who this policy covers
- 3. Information we collect
- 4. How we use your information
- 5. How the AI features handle your data
- 6. When we share information
- 7. What we never do
- 8. How we protect your information
- 9. Data retention and deletion
- 10. Your rights and choices
- 11. Cookies
- 12. Children's privacy
- 13. International users
- 14. Changes to this policy
- 15. Contact us
Sumwell (“Sumwell,” “we,” “us,” or “our”) provides accounting and bookkeeping software for small businesses, freelancers, and the accountants who serve them, available at sumwellbookkeeping.com and through the Sumwell application (together, the “Services”). Your books are among the most sensitive information a business has. This policy explains, in plain English, what we collect, why we collect it, who we share it with, and the controls you have. It is designed to be read, not skimmed — but if you only read one section, read the short version below.
1. The short version
- Your books are encrypted with your password, and we cannot read them. Your financial data is sealed into an encrypted vault on your device before it is ever stored or synced. We hold the sealed vault; only your password opens it.
- We never see your bank credentials. Bank connections are handled by Stripe Financial Connections, a regulated financial data service, and are read-only.
- We never see your full card number. Payments are processed by Stripe; card details go directly to them.
- We do not sell your data. Ever. Not to advertisers, not to data brokers, not in anonymized form, not to anyone.
- AI features process only what they need. Transaction descriptions, receipt images, and chat messages you submit are sent to our AI provider (Anthropic) to be categorized or read, then the answer comes back. We do not permit them to be used for training.
- Your data is yours. Export everything to CSV anytime, and erase your account and books with one action — no phone call, no exit fee.
2. Who this policy covers
This policy applies to everyone who uses the Services: business owners, their team members, and accountants and bookkeepers using accountant seats. It covers our website, the Sumwell application, and communications we send you (like password reset and invoice reminder emails).
If you invite an accountant to your books, or a client grants you access to theirs, the account owner controls that data and this policy governs how we handle it. It does not cover what your accountant or client does with information outside Sumwell.
3. Information we collect
Account information
When you create an account we collect your email address and a password. We store a cryptographic hash of your password — never the password itself — plus a random salt used to derive your vault’s encryption key. During onboarding we also ask for your business name and entity type (sole proprietor, S-corp, and so on), which configure your reports and tax packages and live inside your encrypted vault.
Your books (the encrypted vault)
Everything you put into Sumwell — transactions, categories, invoices, customers, vendors, bills, journal entries, reconciliations, learned vendor rules, notifications, and your audit trail — is encrypted on your device into a single vault using AES-256-GCM, with a key derived from your password (PBKDF2, 310,000 iterations). The vault is stored on your device and, when sync is enabled, a copy of the sealed vault is stored on our servers so you can sign in from another device.
What this means in practice
We store your books the way a bank stores a safe-deposit box: we hold the box, you hold the only key. If you reset your password, we can restore your ability to sign in, but the previous vault cannot be decrypted — your books start fresh. That is the honest trade-off of encryption we cannot bypass.
Tax documents
Documents you upload to the Taxes tab (W-2s, 1099s, K-1s, and similar) are stored locally in your browser’s storage on your device. Filenames and document types you confirm are used to organize your tax checklists. Issuer names and account numbers you provide are remembered so next year’s uploads file themselves; that memory lives in your encrypted vault.
Bank and financial account information
If you connect a bank or card account, the connection is established through Stripe Financial Connections. You enter your bank credentials directly with Stripe — Sumwell never sees, receives, or stores them. Stripe provides us a read-only feed of transaction data (dates, descriptions, amounts, account balances), which flows into your books and is then protected the same way as everything else in your vault. Stripe’s handling of your information is governed by its own privacy policy at stripe.com/privacy.
Payment information
Subscription payments are processed by Stripe. Your card number goes directly to Stripe and never touches our servers. We receive and keep only what we need to run your subscription: your plan, payment status, and a customer reference ID. Stripe’s privacy policy is at stripe.com/privacy.
Content you submit to AI features
When you use AI-powered features — chat (typed or dictated), transaction categorization, review questions, and receipt photo capture — the content you submit (your message, the transaction description, or the receipt image) is sent to our servers and relayed to our AI provider to produce a result. Section 5 explains this in detail. Voice dictation uses your browser’s built-in speech recognition; audio is handled by your browser, not sent to Sumwell.
Technical and usage information
Like most websites, our servers automatically receive basic technical data when you use the Services: IP address, browser type, and request logs, which we use for security, debugging, and abuse prevention. We use a single session cookie to keep you signed in. We do not run third-party advertising trackers or analytics pixels on the Services.
Communications
If you email support, we keep the correspondence so we can help you and improve the Services. If you request a password reset, we send the reset link through our email delivery provider (Resend).
4. How we use your information
- To provide the Services — authenticate you, sync your encrypted vault across devices, import bank transactions, process receipts, generate reports, send invoices and reminders, and everything else the product does.
- To process payments — manage your subscription through Stripe.
- To keep the Services secure — detect and prevent fraud, abuse, and unauthorized access; maintain audit logs.
- To support you — respond when you contact us, and send you service emails (password resets, billing notices). We keep marketing email minimal and you can opt out of it entirely.
- To improve the Services — using aggregate, technical information (like which features error out), never the contents of your books, which we cannot read.
- To comply with law — meet our legal obligations, enforce our terms, and protect our rights and our users.
We do not use your information for any purpose not listed above.
5. How the AI features handle your data
Sumwell’s AI features are powered by Anthropic’s Claude models. Here is exactly what happens when you use them:
- Categorization: the transaction’s description, date, and amount are sent to Anthropic, which returns a suggested category and confidence level. Your full books are not sent.
- Receipt capture: the photo you upload is sent to Anthropic to extract the vendor, date, amount, and tax, then the extracted values are written into your encrypted books.
- Chat: the message you type or dictate is sent to Anthropic to be understood and turned into a bookkeeping action, which you confirm.
- Review questions and suggestions: the specific ambiguous items are sent so the AI can phrase a plain-English question or propose an entry, which you approve or dismiss.
- The AI never changes your books without your confirmation.
- We use Anthropic’s commercial API, under which submitted content is not used to train their models.
- AI processing happens per-request; results are stored only inside your encrypted vault.
6. When we share information
We share information only with the service providers required to run Sumwell, each limited to its specific job:
- Anthropic — AI categorization, receipt reading, and chat (Section 5).
- Stripe Financial Connections — read-only bank and card connections.
- Stripe — subscription payments.
- Resend — transactional email delivery (password resets, notices).
- Our hosting provider — runs our servers and stores the sealed vaults and account records.
Beyond service providers, we disclose information only:
- With your direction — for example, when you invite an accountant to your books, email an invoice to a customer, or export your data.
- When legally required — in response to valid legal process. Where the law allows, we will notify you before disclosing. Note that because your books are encrypted with your password, what we are technically able to produce is the sealed vault and account metadata — not your readable financial records.
- In a business transfer — if Sumwell is acquired or merges, your information may transfer with the business. This policy would continue to apply, and we would notify you before any materially different policy took effect.
7. What we never do
- We never sell, rent, or trade your personal or financial information — including in “anonymized” or “aggregated” form sold to third parties.
- We never use your financial data for advertising, or allow anyone else to.
- We never use your data to market lending, credit, payroll, or other financial products to you inside the product.
- We never store your bank credentials or full card numbers.
- We never read your books — by design, we cannot.
8. How we protect your information
- Client-side encryption: your books are encrypted on your device with AES-256-GCM before storage or sync, keyed from your password via PBKDF2 with 310,000 iterations. A wrong password decrypts nothing.
- Encryption in transit: all traffic between your device and our servers, and between our servers and our providers, uses TLS.
- Password protection: passwords are stored only as salted cryptographic hashes.
- Session security: sign-in sessions use secure, HTTP-only cookies that expire automatically.
- Read-only bank access: bank connections cannot move money; they can only read transaction data.
- Audit trail: changes in your books are logged — what happened and when — so you can always review activity in your account.
No system is perfectly secure, and the strongest link in this design is your password — choose a long, unique one. If we learn of a breach affecting your personal information, we will notify you and the relevant authorities as required by law, without undue delay.
9. Data retention and deletion
- Your books: kept (in sealed, encrypted form) for as long as your account is active, so the Services work.
- Erase all data: the “Erase all data” control on your Profile page permanently deletes your books from your device and your synced vault from our servers.
- Account closure: when you close your account, we delete your account record and sealed vault within 30 days, except where the law requires us to keep specific records (for example, payment records retained for tax and audit purposes).
- Local documents: tax documents stored in your browser are under your control and can be removed from the Taxes tab or by clearing your browser storage.
- Server logs: technical logs are retained briefly for security and debugging, then deleted or anonymized.
10. Your rights and choices
Regardless of where you live, we give every Sumwell user the same controls:
- Access and portability: export your transactions, ledger, statements, and invoices to CSV at any time, from inside the product.
- Correction: edit anything in your books directly; the audit trail records the change.
- Deletion: erase your books and close your account yourself, or email us and we will do it.
- Marketing opt-out: unsubscribe from any non-essential email with one click. Service emails (resets, billing) are sent only when needed.
Depending on your location, you may have additional legal rights — for example under the California Consumer Privacy Act (CCPA/CPRA) or the EU/UK General Data Protection Regulation (GDPR) — including the right to know, the right to delete, the right to correct, the right to object to or restrict processing, and the right to complain to your local data protection authority. We honor these rights for all users. We do not “sell” or “share” personal information as those terms are defined in the CCPA, so there is nothing to opt out of. To exercise any right, use the in-product controls or contact us (Section 15); we will respond within the timeframe your local law requires, and we will never discriminate against you for exercising a privacy right.
11. Cookies
We use one cookie: a secure, HTTP-only session cookie that keeps you signed in for up to 30 days. It is strictly necessary for the Services to function. We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies, which is why you will not see a cookie consent banner on our site — there is nothing to consent to.
12. Children’s privacy
Sumwell is a business tool and is not directed to children. You must be at least 18 to create an account. We do not knowingly collect personal information from anyone under 18; if you believe a minor has provided us information, contact us and we will delete it.
13. International users
Sumwell is operated from the United States, and your information is processed on servers located in the United States. If you use the Services from outside the U.S., you understand that your information is transferred to and processed in the U.S. Where required, we rely on appropriate safeguards (such as standard contractual clauses with our service providers) for those transfers. The strongest safeguard remains structural: your books cross borders only in sealed, encrypted form.
14. Changes to this policy
We will update this policy as the Services evolve — for example, when we add a new integration. When we make material changes, we will notify you by email or an in-product notice before the change takes effect, and we will update the effective date at the top of this page. Continuing to use the Services after a change takes effect means you accept the updated policy. We will never change this policy to permit selling your data.
15. Contact us
Questions, requests, or concerns about privacy? Email us at ryan.fraioli@sumwellbookkeeping.com — a human who knows both bookkeeping and this policy will answer. If you are in the EU or UK, you also have the right to lodge a complaint with your local supervisory authority.