LEGAL

Privacy Policy

This Privacy Policy explains how SuperBooks, operated by 14930398 Canada Inc., collects, uses, shares, and protects your information when you use our accounting and bookkeeping Services. Please read it alongside our Terms of Service.

Last updated · July 12, 2026

Who we are

SuperBooks is an AI-assisted accounting and bookkeeping product operated by 14930398 Canada Inc., a Canadian corporation ("SuperBooks", "we", "us", "our"). We help individuals and businesses connect their financial accounts, organize transactions and documents, and produce clean books, reports, and invoices.

This policy applies to the SuperBooks website (superbooks.io), the web application (app.superbooks.io), the SuperBooks browser extension, and related services (together, the Services). It doesn't cover third-party products we link to or that you choose to connect, which have their own privacy practices.

Information we collect

  • Account information — your name, email address, and a hashed password if you set one. For business accounts we also collect your company name and role. If you sign in with Google or Apple, we receive basic profile details (such as your name and email) from that provider.
  • Financial-account data — when you connect a bank or card account through Plaid, we receive read-only transaction history, balances, account and institution names, and similar details. We do not receive or store your online-banking username or password.
  • Documents you add — receipts, invoices, bills, and statements you upload or forward to your workspace (including through Magic Inbox or a mailbox you connect), and the data we extract from them.
  • Books and content — the categories, rules, notes, reconciliations, invoices, and reports you create in SuperBooks.
  • Billing information — your plan and subscription status. Subscription payments are handled by our billing providers (RevenueCat and Stripe); we receive limited details such as your card brand and its last four digits, never your full card number.
  • Usage and device data — log data, app interactions, approximate location derived from your IP address, device and browser type, and similar diagnostics.
  • Communications — messages you send to support and the preferences you set.

Bank and financial-account connections

SuperBooks connects to your financial institutions through Plaid, a specialized financial-data provider. The connection is read-only: SuperBooks can see transactions and balances to build your books, but it cannot move money, initiate payments, or make changes to your accounts.

You enter your banking credentials with Plaid, not with SuperBooks, and they are never shared with us. Plaid's handling of the information you provide during a connection is described in Plaid's end-user privacy policy. You can disconnect an account at any time from your settings, which stops further data from being retrieved.

Connected integrations

If you connect a third-party source — for example a Google (Gmail) mailbox so we can import receipts and invoices — we access only what's needed to provide that feature, and you can disconnect it at any time from your settings.

Browser extension

SuperBooks offers an optional browser extension. Its only purpose is to send a receipt, invoice, or other document you choose into your SuperBooks inbox. You install it yourself, and nothing reaches your SuperBooks inbox until you connect it to your account.

What it looks at, and when:

  • Only when you act. The extension captures something only when you start it: dragging a region after choosing "Clip this page", using one of its right-click "Send to SuperBooks" items, picking or dropping files in its popup, or pressing "Import this PDF". It does not capture pages on its own.
  • Screenshots are cropped on your device. A region clip takes a picture of the visible tab, crops it to the rectangle you drew, and uploads only that crop. The rest of the screenshot never leaves your browser.
  • Spotting an embedded PDF. A small script runs on the pages you open to check whether the page displays a PDF, so it can offer you an import button. It reads only the page's own markup to answer that question, sends nothing anywhere, and stops looking after a few seconds.
  • The address of the tab you're on. While the popup is open, the extension checks whether that tab is itself a PDF so it can offer to import it. It does not build, store, or send a record of the pages you visit.
  • Files you point it at. When you right-click an image or a link, the extension fetches that file from the site it's on and forwards it. It forwards only images, PDFs, and files whose type the site doesn't declare — a page's HTML, for example, is never uploaded.

Where your data goes: two destinations, both declared in the extension's manifest so your browser can show them to you before you install. It calls the SuperBooks app at app.superbooks.io to read your inbox and register a new item, and it uploads the file's bytes directly to our file-storage provider, Backblaze B2. Fetching a file you right-clicked is simply a request to the site already hosting it, and carries nothing about you beyond what your browser would send anyway. The extension contains no analytics or tracking service — diagnostic errors are written to your browser's own developer console and are not sent anywhere.

Connecting creates a separate access token for the extension, distinct from your web sign-in. It is issued only from a SuperBooks tab where you are already signed in and have approved the connection, and it cannot be used to issue further tokens. It is stored in your browser's local extension storage on that device only, and is never synced to your other devices.

Choosing Disconnect in the popup asks SuperBooks to revoke that token and removes the local copy from your browser. If that request doesn't reach us, the local copy is removed anyway, so the extension stops using it. Either way, disconnecting never signs you out of the web app. If the token stops working, the extension deletes it and asks you to reconnect.

The extension runs no remote code — everything it executes ships inside the package you install. It doesn't sell or share your data, show ads, or track you across sites. Documents you send through it become items in your SuperBooks inbox and are kept under the retention terms below.

How we use your information

  • Provide, operate, and maintain the Services — importing transactions, organizing documents, and generating books, reports, and invoices.
  • Categorize and reconcile transactions, including with automated and AI-assisted methods, to save you time.
  • Authenticate you, secure your account, and prevent fraud and abuse.
  • Process subscription payments and manage your plan.
  • Where you enable invoice payments, help you collect payment from your customers through Stripe.
  • Communicate with you about your account, security, and changes, and — where permitted — about product updates.
  • Understand and improve how the Services perform, and develop new features.
  • Comply with legal obligations and enforce our terms.

AI processing of your data

Some features use AI models to read your transactions and documents — for example to suggest a category, extract fields and text from a receipt or PDF (including optical character recognition), or answer a question about your books. This processing happens to deliver the feature you've asked for.

For document processing and related tasks we use Google's Gemini models through the Google AI API. Where we rely on external AI providers, they act as our service providers under contractual confidentiality and may only process your data to perform the task we request.

We do not sell your data, and we do not use the contents of your financial data or documents to train third-party foundation models.

How we share information

We don't sell your personal information, and we don't share it for cross-context behavioural advertising. We share it only in these limited circumstances:

  • Service providers / subprocessors — companies that aggregate financial data, process payments, host our infrastructure, and provide AI processing, acting on our instructions.
  • At your direction — when you ask us to share data, export it, or connect a third-party integration.
  • Legal and safety — when required by law, regulation, or legal process, or to protect the rights, property, or safety of you, us, or others.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.

Service providers we rely on

We use a small, vetted set of providers to run SuperBooks. We require each to protect your data and to use it only to provide services to us:

  • Plaid — read-only connections to your bank and card accounts.
  • Stripe and RevenueCat — subscription billing, and, where you enable it, collecting payment on the invoices you send (processed through Stripe).
  • Google — Gemini AI for document processing; Google sign-in, and Gmail import if you connect it.
  • logo.dev — bank and merchant logos (see the section below).

Our product analytics (PostHog) and error monitoring (Sentry) run on our own self-hosted infrastructure, and we send transactional email (such as sign-in links and receipts) from our own email infrastructure — so that data stays on systems we operate rather than a third-party SaaS. We also rely on cloud hosting providers to run our application and database. A current list of subprocessors is available on request at support@superbooks.io.

Bank and merchant logos

To show bank and merchant logos, our servers fetch images from logo.dev using only the institution's or merchant's public web domain (for example, chase.com). No information that identifies you is sent, and the request is made by our servers rather than your browser.

Cookies and analytics

We use cookies and similar technologies to keep you signed in, remember your preferences, and secure the Services. For product analytics we use PostHog, which we self-host on our own infrastructure. Our public marketing site may additionally use Google Analytics where it is enabled.

You can control cookies through your browser settings, and disabling some may affect functionality. We don't sell your personal information or use it for cross-context behavioural advertising.

Session recording

To understand how people move through the product and to reproduce bugs, we record replays of your sessions in the app using our self-hosted PostHog. A replay is a reconstruction of the pages you saw and the actions you took, rebuilt from the structure of the page — it is not a video, and it does not use your screen, camera, or microphone.

Replays are masked in your browser, before anything is sent to us. Visible text content is replaced with placeholder characters, so balances, transaction amounts, customer names, invoice line items, and document titles are never recorded. Everything you type into a form field is masked as well. Some surfaces are excluded from the recording entirely rather than masked: password fields, the Plaid window where you enter banking credentials, the payment window where you enter card details, previews of the documents you upload, and the two-factor QR codes shown when you set up an authenticator app or connect a messaging account.

Masking applies to the text a page displays, not to every value behind it. Link and image addresses and other element attributes — for example the address of a page you visited or the label a screen reader would read — are recorded as they are. A replay also contains the layout of the page, the elements you clicked, where you scrolled, and diagnostic messages the app logs to your browser console. Replays are linked to your account so we can investigate a problem you report. We keep them for up to five years and then delete them. Our error-monitoring tool (Sentry) is configured with the same masking rules; it records replays only if we switch that on, which is off by default.

Data retention

We keep your information for as long as your account is active and as needed to provide the Services. After you close your account we delete or de-identify your data within a reasonable period, except where we must retain certain records to comply with legal, tax, accounting, or audit obligations, resolve disputes, or enforce our agreements.

How we protect your data

We protect your data with encryption in transit and at rest, access controls, network isolation, and continuous monitoring. Connections to your financial institutions are read-only, and our analytics and error monitoring run on infrastructure we operate. No system is perfectly secure, but we work hard to safeguard your information and to notify you and the authorities of incidents where the law requires.

To report a security concern, email security@superbooks.io.

Your rights and choices

Depending on where you live, you may have rights over your personal information, including to:

  • Access, correct, or download a copy of your data.
  • Delete your data or close your account.
  • Withdraw consent, or object to or restrict certain processing.
  • Ask us not to share your information, and complain to a privacy regulator.

You can exercise many of these directly in the app — you can export your books and close your account from your settings — or by emailing support@superbooks.io. We'll respond as required by applicable law.

Canadian and other privacy laws

As a Canadian company, we handle personal information in line with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). If you're in Quebec, additional rights under Quebec's Law 25 may apply. You can raise a concern with us first, and you may also complain to the Office of the Privacy Commissioner of Canada or, in Quebec, the Commission d'accès à l'information.

If you're in the United Kingdom or the European Economic Area, we act as the controller of your personal information and rely on legitimate interests, performance of a contract, consent, or legal obligation as the basis for processing, and you may have additional rights under the UK or EU GDPR.

International data transfers

We operate from Canada and may process and store your information in Canada, the United States, and other countries where we or our service providers — such as Plaid, Stripe, and Google — operate. Where we transfer personal data across borders, we use appropriate safeguards as required by applicable law.

Children's privacy

The Services are intended for people aged 16 and older and are not directed to children. We don't knowingly collect personal information from anyone under 16; if you believe a child has provided us data, contact us and we'll delete it.

Changes to this policy

We may update this policy from time to time. When changes are material we'll take reasonable steps to let you know, such as posting a notice or emailing you. The "last updated" date above always reflects the current version.

Contact

Questions about this policy or your data? Email us at support@superbooks.io. For security matters, contact security@superbooks.io.