← Back to AscenAi

Privacy Policy

Last updated: July 31, 2026

Download PDF

This page is maintained by the operator of AscenAi to describe how the application handles data. It is a description of current practices, not an independent audit or certification.

Information we collect

  • Account information — name, email address and the authentication method you use (email/password or Google sign-in).
  • Business and accounting data — corporations, locations, chart of accounts, journal entries, invoices, bills, payments and reports you create or import.
  • Connected source data — bank transactions, QuickBooks Online records and payroll runs retrieved from services you explicitly connect.
  • Uploaded documents — statements, receipts, invoices and payroll files you upload for processing.
  • Operational logs — sync results, import errors and security audit events used to run and troubleshoot the service.

How we use it

Data is used to provide the accounting features you request: importing and matching transactions, generating suggestions and postings, producing financial statements and tax packs, and maintaining audit trails. We do not sell your data or use your financial records for advertising.

AI processing

When you use AI features (document extraction, categorization suggestions, matching), the relevant content is sent to our AI model provider solely to return a result to you. AI output is a suggestion — you review and approve every posting.

Third parties and integrations

  • Cloud hosting, database, authentication and file storage provider
  • AI model provider for the features described above
  • QuickBooks Online (Intuit), when you connect a company
  • Plaid Inc., when you link a bank or credit card account
  • Payroll and banking data sources you choose to connect

Integration access tokens are stored encrypted. You can disconnect any integration from within the app, which stops further data retrieval.

Bank account connections (Plaid)

AscenAi connects your business bank accounts to automatically import balances and transactions into your accounting ledger.

We use Plaid Inc. to connect the bank and credit card accounts you choose to link. You enter your financial institution credentials directly with Plaid — we never see or store them. Plaid returns to us only account details (institution, account name, type and masked number), balances and transaction history for the accounts you authorize, which we use solely to import transactions into your books, match them to ledger entries and reconcile bank balances. We request only the Plaid products needed for this purpose (Auth, Transactions, Balance and Identity) and no other data.

We do not sell this data, use it for advertising, or share it with anyone other than the service providers required to operate AscenAi. Plaid's handling of your information is governed by the Plaid End User Privacy Policy. You may disconnect any linked institution at any time from within AscenAi; on disconnect we remove the item through Plaid and delete the stored access token immediately.

Security

Access is authenticated, and records are scoped per group, corporation and user role using row-level database policies. Data is encrypted in transit with TLS 1.2 or better and at rest with AES-256, and sensitive integration credentials are additionally encrypted at the application layer. No system can guarantee absolute security; we do not claim any certification such as SOC 2, ISO 27001, PCI or HIPAA compliance.

Retention and deletion

We retain your accounting data for as long as your account is active, because financial records generally must be preserved for statutory periods. Our defined retention schedule is: financial and payroll records and uploaded source documents, 7 years; security and authentication audit logs, 24 months; application logs, 90 days; encrypted backups, 35 days rolling; bank connection access tokens, only for the life of the connection.

You may request export or deletion of your data by contacting security@ascenai.io. We acknowledge requests within 5 business days and complete them within 30 calendar days, except where retention is legally required. This policy is reviewed at least annually.

Cookies

We use only cookies and local storage necessary to keep you signed in and remember your working preferences (such as the active corporation and fiscal year). We do not run third-party advertising trackers. Full details of every category, its purpose and its retention are in our Cookie Policy.

Your rights

You may request access to, correction of, or deletion of your personal information, and you may withdraw an integration authorization at any time. Contact us using the details below and we will respond within a reasonable period.

Contact

Privacy and security questions: security@ascenai.io

See also our End-User License Agreement.