This Privacy Policy explains how Docyt, Inc., the owner and operator of ProfitBooks ("ProfitBooks", "we", "us"), collects, uses, shares and protects information when you use our websites, web application, free tools and related services (the "Service"), and the choices and rights you have. Effective August 23, 2026.
In short: you upload financial documents; we use them to do your books for you. We never sell your personal information, we never ask for your bank login, and your documents and identifiable financial data are never shared with other customers. We use de-identified and aggregated data to improve the Service, including its AI models. You can export and delete your data at any time.
Two roles. For information about you and your use of the Service (account, billing, usage, marketing), ProfitBooks is the business or controller and this Policy applies. For personal information about other people that appears inside your books (your customers, vendors, employees and contractors named on statements, receipts and invoices), you are the business or controller and ProfitBooks processes it only as your service provider or processor under our Terms of Service. If you are one of those people, please direct requests to the business whose books contain your information; we will assist that business in responding.
1. Information we collect
Information you provide
- Account and business profile: name, email address, password (stored hashed), business name, industry, books start date, referral or promotion code, and the names and emails of people you invite.
- Customer Documents: bank and credit card statements, receipts, invoices, bills, payout reports and spreadsheet exports you upload. These contain financial account identifiers (typically institution name and the last digits of an account number), balances, transactions, merchant and payee names, and may contain personal information about third parties, and occasionally other sensitive information if it appears on a document you choose to upload. We never ask for online banking usernames or passwords.
- Books data: the transactions, categories, confirmations, corrections, journal entries, notes, tags, confidence thresholds and reports created in the Service from your documents and your inputs.
- Payment information: collected and stored by our payment processor. We receive and retain the card brand, last four digits, expiry, billing address, and transaction records; we do not store full card or bank account numbers.
- Communications: emails, support requests, survey responses, reviews and, if you use the in-app assistant or chat, the messages you send.
Information collected automatically
- Usage data: pages and features used, actions taken, documents processed, confidence scores and correction rates, timestamps, and performance and error logs.
- Device and connection data: IP address, browser type and version, operating system, device identifiers, language, time zone, and approximate location derived from IP address.
- Cookies and similar technologies: on our marketing website we use cookies, local storage and pixels for essential functions, analytics, attribution (for example, recording the campaign that brought you to us) and, where enabled, advertising. The application uses cookies and local storage required to keep you signed in and to remember settings. See Section 6.
Information from other sources
- Partners and people you invite: if an accountant, bookkeeper or business partner creates or manages your business in the Service, we receive the information they provide.
- Referral and marketing sources: referral partners, affiliate networks and advertising platforms may tell us that you arrived through them.
- Payment and fraud prevention providers: payment status, risk signals and chargeback information.
- Public and business data sources: industry classification data and merchant or vendor reference data used to improve categorization.
2. How we use information
We use information for the following purposes and, where a legal basis is required, on the bases indicated:
- To provide the Service (performance of our contract with you): reading your documents, extracting transactions, categorizing them with confidence scores, building your chart of accounts, reconciling accounts and preparing reports according to your plan, storing your documents, operating the assistant and chat features, processing payments and credits, and providing support.
- To operate AI Features (contract; legitimate interests): Customer Documents and books data are processed by machine learning and large language models operated by us and by our AI service providers under contract. Your identifiable Customer Data is used to train and tune the models and rules that serve your business, for example learning your vendors and your corrections. We do not use your identifiable Customer Data to train models that serve other customers; for that we use De-identified and Aggregated Data as described in Section 3. Our AI service providers are contractually prohibited from using your data to train their own models.
- To improve and develop the Service (legitimate interests): analyzing usage, testing features, measuring accuracy, fixing errors and developing new features, using De-identified and Aggregated Data wherever practicable.
- To secure the Service and prevent abuse (legitimate interests; legal obligation): authentication, fraud and abuse detection, enforcement of our Terms, including limits on free credits and promotions, and protection of our rights and those of our customers.
- To communicate with you (contract; legitimate interests; consent where required): transactional messages about your account, documents, credits, billing and renewals; responses to your requests; and marketing about ProfitBooks products and content, from which you can opt out at any time.
- To comply with law (legal obligation): tax and accounting record-keeping, responding to lawful requests, and meeting regulatory obligations.
- For benchmarks, research and insights (legitimate interests): using De-identified and Aggregated Data only, as described in Section 3.
We do not make decisions about you that have legal or similarly significant effects based solely on automated processing. Categorization and other AI outputs are suggestions for your books that you can review and change.
3. De-identified and aggregated data
We create De-identified Data (information from which identifiers of you, your business and any individual have been removed so that it cannot reasonably be linked back to any of them) and Aggregated Data (De-identified Data combined across many customers, such as "the share of transactions at hardware stores that small landscaping businesses categorize as materials"). We use and may share De-identified and Aggregated Data for any lawful purpose, including to train, improve and evaluate our AI models and categorization knowledge for all customers, to build vendor and industry reference data, to produce benchmarks, statistics and research, to understand and report on our business, and to develop and market products.
When we do so we: keep the data in de-identified form; take reasonable measures to ensure it cannot be associated with you or any individual; publicly commit, as we do here, not to attempt to re-identify it; and contractually prohibit anyone we share it with from attempting to re-identify it. De-identified and Aggregated Data is not personal information, and this Policy does not restrict our use of it. Your documents, your transaction history and anything that identifies you are never shared with other customers.
4. How we share information
We do not sell personal information, and we do not share Customer Documents or books data with third parties except as described here:
- Service providers that process data on our behalf under contracts that limit their use of it to providing services to us: cloud hosting and storage, AI model providers, payment processing, email delivery, customer support tools, analytics, error monitoring and security services. Our AI providers process documents and text to provide extraction, categorization and assistant features and may not retain or use your data to train their models.
- People you authorize: users you invite to your business, and accountants, bookkeepers or Partner firms you grant access to. They see what you allow them to see. Remove their access at any time in settings.
- Referral and partner programs: if you arrived through a referral or partner link, we may confirm to the referring party that a signup or purchase occurred, in order to credit them, without sharing your Customer Data.
- Legal, safety and enforcement: to comply with law, legal process or governmental request; to enforce our Terms; to detect and prevent fraud, abuse or security issues; or to protect the rights, property or safety of ProfitBooks, our customers or others. We will notify you of a legal request for your Customer Data where the law permits and it is practicable.
- Business transfers: in connection with a merger, acquisition, financing, reorganization, bankruptcy or sale of all or part of our business, in which case this Policy continues to apply to your information until a successor notifies you otherwise.
- Affiliates: entities under common control with us, which must follow this Policy.
- With your direction or consent: for example, when you export data to a third party or connect an integration.
On our marketing website only, we may use advertising cookies and pixels from advertising platforms to measure campaigns and show ads for ProfitBooks on other sites. Under some state laws this may be considered "sharing" for cross-context behavioral advertising, and you can opt out as described in Sections 6 and 8. No Customer Documents or books data are ever used for advertising.
5. Retention
- Customer Documents and books data are retained while your business is active in the Service. After you delete a document, a business or your account, or after the export window following termination, we delete the data from active systems within 30 days and from backups within 90 days, subject to the exceptions below.
- Account, billing and transaction records are retained for as long as your account is open and thereafter as needed to satisfy legal, tax and accounting obligations, generally up to seven years, and to resolve disputes and enforce agreements.
- Communications and support records are retained for up to three years after the interaction.
- Usage, device and log data are retained for up to 24 months in identifiable form, and may be kept longer in de-identified form.
- De-identified and Aggregated Data may be retained indefinitely.
- We may retain information longer where required by law, a legal hold, or to protect our rights.
6. Cookies, analytics and your choices
Cookies and local storage on profitbooks.ai fall into three groups. Essential: sign-in, security and settings; these cannot be disabled. Analytics and attribution: understanding how the site is used and which campaign brought you here; we store the first campaign parameters in your browser's local storage and attach them when you sign up. Advertising: cookies and pixels from advertising platforms on the marketing website only, used for campaign measurement and retargeting.
You can control cookies through your browser settings and, where we provide one, our cookie preferences control. We honor the Global Privacy Control browser signal as a request to opt out of sale or sharing in states that recognize it. We do not respond to other "Do Not Track" signals. You can opt out of marketing email using the link in any message; transactional messages about your account will continue.
7. Security
We protect information with safeguards designed for the sensitivity of financial documents: encryption of data in transit (TLS) and at rest, role-based access controls and least-privilege access for our staff, logging and monitoring, secure development practices, vendor review, and hosting on infrastructure that is independently audited against recognized security standards. We never request or store your online banking credentials. Access to a customer's business by our support staff occurs only with your permission for a specific request and is logged.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your password and verification codes confidential and for the people you invite. If we learn of a security incident affecting your personal information, we will notify you and any regulator as required by law. Report concerns to [email protected].
8. Your rights and choices
Wherever you live, you can access, export, correct and delete your information directly in the Service: export reports and transactions as CSV, download your documents, edit your profile, and delete documents, a business or your whole account from settings. You can also email [email protected] to make any request described below. We will verify your identity, typically by confirming control of your account email, and respond within the time required by law (generally 45 days in the United States, extendable once). You may use an authorized agent if the agent provides your written permission and we can verify your identity. We will not discriminate against you for exercising your rights.
United States state privacy rights
Residents of California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia and other states with comprehensive privacy laws have the right to: know and access the personal information we hold about them, including the categories collected, sources, purposes and categories of recipients; obtain a portable copy; correct inaccurate information; delete personal information, subject to legal exceptions; opt out of the sale of personal information, of sharing or processing for targeted or cross-context behavioral advertising, and of profiling in furtherance of decisions with legal or similarly significant effects; limit the use of sensitive personal information to purposes permitted by law; and appeal a denied request by replying to our decision, after which we will respond with our reasons and, where applicable, how to contact your state attorney general.
California notice at collection. In the preceding 12 months we collected the categories of personal information described in Section 1 (identifiers, customer records including financial information, commercial information, internet and device activity, geolocation derived from IP address, professional information, inferences, and sensitive personal information consisting of account log-in credentials and financial account information) for the purposes in Section 2, and disclosed them to the categories of service providers and recipients in Section 4. We do not sell personal information. We do not use or disclose sensitive personal information for purposes other than those permitted by the CCPA. Advertising cookies on our marketing website may constitute "sharing"; opt out through your cookie preferences or the Global Privacy Control. We do not knowingly sell or share the personal information of anyone under 16.
Information about other people in your books
If you are a customer, vendor, employee or contractor of a ProfitBooks customer and your information appears in that customer's books, please contact that business. We will support the business in responding to your request as its service provider. Where the law requires us to respond directly, we will do so after verifying your identity.
Outside the United States
The Service is operated from the United States and is intended for businesses in the United States. If you access it from elsewhere, you understand that your information will be transferred to, stored and processed in the United States and other countries where our service providers operate, which may have different data protection laws. Where the data protection laws of the European Economic Area, United Kingdom or Switzerland apply to our processing, our legal bases are those described in Section 2, you have the rights described above together with the rights to object to and restrict processing and to lodge a complaint with your supervisory authority, and international transfers are protected by standard contractual clauses or another lawful mechanism. Contact [email protected] to exercise these rights.
9. Children
The Service is for businesses and adults. We do not knowingly collect personal information from anyone under 18, and we do not permit them to create accounts. If you believe a person under 18 has provided us personal information, contact us and we will delete it.
10. Accountants, partners and integrations
When an accountant, bookkeeper or Partner firm accesses your business, they act on your behalf under your authorization and their own professional obligations, not as our agent; review their privacy practices directly. When you direct us to export data to, or import data from, a third-party product, that product's terms and privacy policy govern its handling of the data.
11. Changes to this Policy
We may update this Policy. We will post the updated version with a new effective date and, for material changes, notify you by email or in the Service at least 30 days before they take effect, unless a change is required sooner by law. Your continued use after the effective date means you accept the updated Policy.
12. Contact us
Docyt, Inc.
Mountain View, California, United States
Privacy requests: [email protected]
Security: [email protected]
Legal: [email protected]