Skip to content
myClerkBook
Legal

Privacy Policy

Last updated 2026-08-27

myClerkBook is a private book of account. It has no connection to your bank, no data aggregator behind it, and no commercial interest in your financial history. This policy sets out exactly what we hold, why we hold it, who processes it on our behalf, and what you can require us to do about it.

Jump to a section

Who is responsible for your information

myClerkBook is operated from South Africa and is the responsible party for your personal information under the Protection of Personal Information Act 4 of 2013 (POPIA). Where the General Data Protection Regulation (EU) 2016/679 applies to you, the same entity is the data controller.

You can reach us about anything in this policy at legal@myclerkbook.com, or by post at the address below. We answer to that address ourselves; it is not routed to a third-party support desk.

  • myClerkBook
  • 90 William Campbell Drive
  • La Lucia, Umhlanga
  • Durban, 4051
  • South Africa

We have not appointed a representative in the European Union. If you are in the EU and would prefer to raise a matter with a supervisory authority, you may complain to the authority in your country of residence at any time, whether or not you have contacted us first.

What we collect

We collect only what the product needs in order to work. There is no category below that exists to be analysed, sold or enriched.

CategoryWhat it isWhere it comes from
Account identityYour first and last name, username, email address, and — if you set one — your phone number and WhatsApp number.You, at sign-up or in settings.
Authentication dataPassword hashes, session tokens, and the connected Google account identifier if you sign in with Google. We never see your password.Clerk, our authentication processor.
Your financial entriesThe transactions, groups, dashboards, widgets and alerts you create: amounts, dates, descriptions, currencies, counterparties.You, by typing them or by approving a parsed document.
Uploaded documentsReceipts, invoices and statements you upload for parsing, and the extracted fields awaiting your confirmation.You. Deleted when you approve or dismiss the parse.
Billing dataYour billing name and email, your plan, and payment metadata. Card numbers never reach us.Polar, our merchant of record.
Usage analyticsWhich pages were viewed and which controls were used, without a name or an email attached, and without your IP address being stored.PostHog, in your browser.
Technical logsRequest logs and error traces produced by our hosting, retained for operational diagnosis.Vercel and Supabase.

We do not collect bank credentials, account numbers, card numbers, or any data from a financial aggregator, because myClerkBook has no facility to connect to one. This is an architectural property of the product, not a policy choice we could quietly reverse.

We do not knowingly collect information from anyone under 18. If you believe a child has created an account, write to us and we will delete it.

Why we are allowed to process it

POPIA requires a justification under section 11 and the GDPR requires a lawful basis under Article 6. Each category of processing rests on exactly one of the following.

What we doPOPIA section 11GDPR Article 6
Run your account and store the entries you create11(1)(b) — necessary to perform a contract with you6(1)(b) — performance of a contract
Take payment and issue receipts11(1)(b) and 11(1)(c) — contract, and a legal obligation to keep tax records6(1)(b) and 6(1)(c)
Send you the alerts and summaries you configured11(1)(a) — your consent, given by creating the alert6(1)(a) — consent
Send you marketing email11(1)(a) — your consent, opt-in only6(1)(a) — consent
Measure product usage without identifying you11(1)(f) — our legitimate interest in a product that works6(1)(f) — legitimate interests
Keep the service secure and prevent abuse11(1)(f) — legitimate interest6(1)(f) — legitimate interests

Where processing rests on your consent you may withdraw it at any time, and withdrawing it does not affect anything we did before you withdrew it. Withdrawing consent for alerts stops the alerts; it does not delete your entries.

What happens to a document you upload

Document parsing runs on documents you upload or receive into a connected mailbox, and it is the only place your data is read by a system we do not operate. The commitments below bind it.

  • The file is stored in our own object storage, under a path scoped to your account, and is fetched for processing through a signed link valid for sixty seconds.
  • Text-based formats pass through a sanitisation step on our servers first, which removes names, email addresses, phone numbers and account numbers before anything is sent onward.
  • Photographs and PDFs are handled by the model visually and do not pass through that step. Whatever a document shows, nothing reaches your book until you approve the extracted fields.
  • For sanitised text, the model receives amounts, dates, descriptions and currencies with no identity attached, and it is not told whose document it is.
  • Model calls are routed through OpenRouter, an inference intermediary that forwards each request to Anthropic under our own Anthropic account, key and credits. The endpoint your content reaches is operated by Anthropic under the same commercial API terms as before, including zero data retention. OpenRouter itself stores request metadata only — token counts and timings — and holds prompt content only if its opt-in logging were enabled, which ours is not. Your content is not used to train a model.
  • The uploaded file and the in-flight parse record are deleted when you approve or dismiss. A parse you abandon is pruned after thirty days.

You are never required to upload anything. Every entry in myClerkBook can be typed by hand, and the product is fully functional that way.

Who else processes your information

These are the operators we use to run myClerkBook. Each is bound by a data processing agreement, each processes only what its function requires, and none of them is permitted to use your information for its own purposes. We do not sell personal information, and we do not share it with advertisers or data brokers.

ProcessorFunctionWhat it processes
ClerkAuthentication and session managementName, username, email address, password hash, session data
SupabaseDatabase and file storageEverything you enter or upload
VercelApplication hosting and deliveryRequest metadata and IP address in transit; no application data at rest
OpenRouterRouting for document-parsing model callsThe sanitised document content it forwards to Anthropic, and request metadata such as token counts
AnthropicDocument parsing and the AgentSanitised document content only, with no identity attached
PolarPayments, as merchant of recordBilling name, email address, payment metadata
PostHogProduct analyticsPseudonymous usage events. Session recording is disabled and IP addresses are not stored
ResendTransactional emailEmail address and message content
LoopsLifecycle and marketing emailEmail address and engagement events, on opt-in
SentSMS and WhatsApp alertsPhone number and message content, only if you link a number
UpstashRate limitingA counter keyed to your account identifier. No content
ChatbaseSupport chat on public pagesWhatever you type into the chat widget
Google AnalyticsWebsite analytics on public pagesPseudonymous page views and device metadata, only after you allow analytics cookies
AttioCustomer recordsName and email address, so we know who our customers are and can answer you

Some of these operate outside South Africa and outside the European Economic Area, principally in the United States. Transfers are made under the standard contractual clauses or an equivalent safeguard in each provider's data processing agreement, as POPIA section 72 and GDPR Chapter V require.

How long we keep it

WhatHow long
Your transactions and everything you built around themUntil you delete them, or until you delete your account
Your accountUntil you delete it. Deletion is immediate and permanent
Uploaded documents and in-flight parsesUntil you approve or dismiss the parse. Abandoned parses are pruned after 30 days
Usage analytics90 days
Model provider logsA maximum of 7 days, held by Anthropic. OpenRouter holds request metadata only
Billing recordsAs long as tax law requires us to keep them, held by our merchant of record
Exchange rate cache7 days. It contains no personal data

Deleting your account deletes your books with it. There is no soft delete, no hidden archive, no recovery window and no copy retained for training. If you want your data after that point, you must export it before you delete.

Your rights

POPIA sections 23, 24 and 11(3), and GDPR Articles 15 to 22, give you the following. You may exercise any of them by writing to us; most are also available directly in the product.

  • Access — ask what we hold about you, and receive a copy of it.
  • Correction — have anything inaccurate or incomplete corrected. Every entry in your book is editable in place.
  • Deletion — have your account and everything in it destroyed. This is immediate and cannot be undone.
  • Portability — receive what you have entered in a format you can open elsewhere. Download it yourself from Data in your account settings, or ask at the address below and we will send it to you.
  • Objection — object to processing that rests on our legitimate interests, including analytics.
  • Restriction — ask us to hold processing while a dispute about accuracy or lawfulness is resolved.
  • Withdraw consent — for alerts or for marketing email, at any time, without affecting anything else.
  • Complain — to the Information Regulator of South Africa, or to your own supervisory authority in the EU.

We will respond within thirty days. We do not charge for any of this, and we will not ask you why.

The Information Regulator (South Africa) can be reached at JD House, 27 Stiemens Street, Braamfontein, Johannesburg 2001, or at enquiries@inforegulator.org.za.

How your information is protected

Privacy here is enforced in three independent layers, so that it never rests on a policy statement alone.

  • At the edge: every request is authenticated and rate-limited before any code that can read data runs at all.
  • In the application: text-based document content is stripped of identifying information before it is sent anywhere for processing, and nothing a document produces reaches your book until you approve it.
  • In the database: row-level security is enforced by PostgreSQL itself, on every table, so a query for someone else's rows returns nothing regardless of what the application code asks for. This is the layer that cannot be defeated by an application bug.

All traffic is encrypted in transit, and data is encrypted at rest by our database and storage providers. No system is perfectly secure, and we will not claim otherwise; if a breach occurs that creates a real risk to you, we will notify you and the Information Regulator as POPIA section 22 requires.

Changes to this policy

If we change this policy in a way that affects how your information is handled, we will tell you by email before the change takes effect, and update the date at the top of this page. Continuing to use myClerkBook after a change means you accept the revised policy; if you do not, you may export your data and delete your account.