Privacy Policy
Last Updated September 28, 2026
This policy explains what information BurnRateIQ ("we", "us") collects, how we use it and the choices you have.
1. Information We Collect
- Account information: your email, password (stored only as a secure hash), role and the company details you enter.
- Financial data: records from accounting, billing and payroll systems you connect, and files you upload, such as P&L statements, balance sheets and employee lists. This can include employee names, titles, locations, start dates and pay.
- Model inputs: assumptions, scenarios, comments and settings you create.
- Support requests: the email, subject and message you send us.
- Technical data: IP address, browser type, pages visited and error logs, collected to secure and run the Service.
2. How We Use It
- to build, update and display your financial model;
- to keep your account secure and enforce permissions within your company;
- to answer support requests and send service emails (for example, sign-up confirmation or tax-rate change alerts);
- to improve the Service, including benchmarks built only from de-identified, aggregated data;
- to meet legal obligations.
We do not sell your information, and we do not use it for third-party advertising.
3. AI Processing
We use AI models to read uploaded documents and match your accounts to model line items. We send those providers only the data each task needs, under terms that bar them from training their models on it. AI never sets the numbers in your model without a validation step.
4. Who Can See Your Data
Inside your company, the people you invite see what their role allows. For example, department heads can be limited to summary payroll figures. Outside your company, we share data only with service providers that run the Service for us:
- Supabase (database, authentication and file storage)
- Vercel and Fly.io (application hosting)
- Anthropic (AI document processing)
- Stripe (payments for our plans)
- Resend (email delivery)
We may also disclose information when the law requires it or to protect the Service and its users.
5. Security
Connections to your systems use read-only access. We encrypt data in transit and at rest, store connection tokens in an encrypted vault and isolate each company's data with database-level access rules. No system is perfectly secure; if a breach affects your data, we will notify you as the law requires.
6. Retention and Deletion
We keep your data while your account is open. If you close your account, we delete your company data within 30 days, except for records we must keep for legal or billing reasons. You can disconnect any integration at any time; we then stop syncing from it.
7. Your Rights
You can access, correct, export or delete your information. Depending on where you live (for example, California or the EU), you may have additional rights under laws such as the CCPA or GDPR. To make a request, submit a support ticket.
8. Cookies
We use only essential cookies, the ones that keep you signed in. We do not use advertising or cross-site tracking cookies.
9. Children
The Service is for businesses and is not directed to anyone under 18.
10. Changes to This Policy
We will notify you by email or in the app before material changes take effect.
11. Contact
Privacy questions: submit a support ticket.