Privacy Policy
Last updated 2026-08-27
myClerkBook is a private book of account. It has no connection to your bank, no data aggregator behind it, and no commercial interest in your financial history. This policy sets out exactly what we hold, why we hold it, who processes it on our behalf, and what you can require us to do about it.
Jump to a section
Who is responsible for your information
myClerkBook is operated from South Africa and is the responsible party for your personal information under the Protection of Personal Information Act 4 of 2013 (POPIA). Where the General Data Protection Regulation (EU) 2016/679 applies to you, the same entity is the data controller.
You can reach us about anything in this policy at legal@myclerkbook.com, or by post at the address below. We answer to that address ourselves; it is not routed to a third-party support desk.
- myClerkBook
- 90 William Campbell Drive
- La Lucia, Umhlanga
- Durban, 4051
- South Africa
We have not appointed a representative in the European Union. If you are in the EU and would prefer to raise a matter with a supervisory authority, you may complain to the authority in your country of residence at any time, whether or not you have contacted us first.
What we collect
We collect only what the product needs in order to work. There is no category below that exists to be analysed, sold or enriched.
| Category | What it is | Where it comes from |
|---|---|---|
| Account identity | Your first and last name, username, email address, and — if you set one — your phone number and WhatsApp number. | You, at sign-up or in settings. |
| Authentication data | Password hashes, session tokens, and the connected Google account identifier if you sign in with Google. We never see your password. | Clerk, our authentication processor. |
| Your financial entries | The transactions, groups, dashboards, widgets and alerts you create: amounts, dates, descriptions, currencies, counterparties. | You, by typing them or by approving a parsed document. |
| Uploaded documents | Receipts, invoices and statements you upload for parsing, and the extracted fields awaiting your confirmation. | You. Deleted when you approve or dismiss the parse. |
| Billing data | Your billing name and email, your plan, and payment metadata. Card numbers never reach us. | Polar, our merchant of record. |
| Usage analytics | Which pages were viewed and which controls were used, without a name or an email attached, and without your IP address being stored. | PostHog, in your browser. |
| Technical logs | Request logs and error traces produced by our hosting, retained for operational diagnosis. | Vercel and Supabase. |
We do not collect bank credentials, account numbers, card numbers, or any data from a financial aggregator, because myClerkBook has no facility to connect to one. This is an architectural property of the product, not a policy choice we could quietly reverse.
We do not knowingly collect information from anyone under 18. If you believe a child has created an account, write to us and we will delete it.
Why we are allowed to process it
POPIA requires a justification under section 11 and the GDPR requires a lawful basis under Article 6. Each category of processing rests on exactly one of the following.
| What we do | POPIA section 11 | GDPR Article 6 |
|---|---|---|
| Run your account and store the entries you create | 11(1)(b) — necessary to perform a contract with you | 6(1)(b) — performance of a contract |
| Take payment and issue receipts | 11(1)(b) and 11(1)(c) — contract, and a legal obligation to keep tax records | 6(1)(b) and 6(1)(c) |
| Send you the alerts and summaries you configured | 11(1)(a) — your consent, given by creating the alert | 6(1)(a) — consent |
| Send you marketing email | 11(1)(a) — your consent, opt-in only | 6(1)(a) — consent |
| Measure product usage without identifying you | 11(1)(f) — our legitimate interest in a product that works | 6(1)(f) — legitimate interests |
| Keep the service secure and prevent abuse | 11(1)(f) — legitimate interest | 6(1)(f) — legitimate interests |
Where processing rests on your consent you may withdraw it at any time, and withdrawing it does not affect anything we did before you withdrew it. Withdrawing consent for alerts stops the alerts; it does not delete your entries.
What happens to a document you upload
Document parsing runs on documents you upload or receive into a connected mailbox, and it is the only place your data is read by a system we do not operate. The commitments below bind it.
- The file is stored in our own object storage, under a path scoped to your account, and is fetched for processing through a signed link valid for sixty seconds.
- Text-based formats pass through a sanitisation step on our servers first, which removes names, email addresses, phone numbers and account numbers before anything is sent onward.
- Photographs and PDFs are handled by the model visually and do not pass through that step. Whatever a document shows, nothing reaches your book until you approve the extracted fields.
- For sanitised text, the model receives amounts, dates, descriptions and currencies with no identity attached, and it is not told whose document it is.
- Model calls are routed through OpenRouter, an inference intermediary that forwards each request to Anthropic under our own Anthropic account, key and credits. The endpoint your content reaches is operated by Anthropic under the same commercial API terms as before, including zero data retention. OpenRouter itself stores request metadata only — token counts and timings — and holds prompt content only if its opt-in logging were enabled, which ours is not. Your content is not used to train a model.
- The uploaded file and the in-flight parse record are deleted when you approve or dismiss. A parse you abandon is pruned after thirty days.
You are never required to upload anything. Every entry in myClerkBook can be typed by hand, and the product is fully functional that way.
Who else processes your information
These are the operators we use to run myClerkBook. Each is bound by a data processing agreement, each processes only what its function requires, and none of them is permitted to use your information for its own purposes. We do not sell personal information, and we do not share it with advertisers or data brokers.
| Processor | Function | What it processes |
|---|---|---|
| Clerk | Authentication and session management | Name, username, email address, password hash, session data |
| Supabase | Database and file storage | Everything you enter or upload |
| Vercel | Application hosting and delivery | Request metadata and IP address in transit; no application data at rest |
| OpenRouter | Routing for document-parsing model calls | The sanitised document content it forwards to Anthropic, and request metadata such as token counts |
| Anthropic | Document parsing and the Agent | Sanitised document content only, with no identity attached |
| Polar | Payments, as merchant of record | Billing name, email address, payment metadata |
| PostHog | Product analytics | Pseudonymous usage events. Session recording is disabled and IP addresses are not stored |
| Resend | Transactional email | Email address and message content |
| Loops | Lifecycle and marketing email | Email address and engagement events, on opt-in |
| Sent | SMS and WhatsApp alerts | Phone number and message content, only if you link a number |
| Upstash | Rate limiting | A counter keyed to your account identifier. No content |
| Chatbase | Support chat on public pages | Whatever you type into the chat widget |
| Google Analytics | Website analytics on public pages | Pseudonymous page views and device metadata, only after you allow analytics cookies |
| Attio | Customer records | Name and email address, so we know who our customers are and can answer you |
Some of these operate outside South Africa and outside the European Economic Area, principally in the United States. Transfers are made under the standard contractual clauses or an equivalent safeguard in each provider's data processing agreement, as POPIA section 72 and GDPR Chapter V require.
How long we keep it
| What | How long |
|---|---|
| Your transactions and everything you built around them | Until you delete them, or until you delete your account |
| Your account | Until you delete it. Deletion is immediate and permanent |
| Uploaded documents and in-flight parses | Until you approve or dismiss the parse. Abandoned parses are pruned after 30 days |
| Usage analytics | 90 days |
| Model provider logs | A maximum of 7 days, held by Anthropic. OpenRouter holds request metadata only |
| Billing records | As long as tax law requires us to keep them, held by our merchant of record |
| Exchange rate cache | 7 days. It contains no personal data |
Deleting your account deletes your books with it. There is no soft delete, no hidden archive, no recovery window and no copy retained for training. If you want your data after that point, you must export it before you delete.
Your rights
POPIA sections 23, 24 and 11(3), and GDPR Articles 15 to 22, give you the following. You may exercise any of them by writing to us; most are also available directly in the product.
- Access — ask what we hold about you, and receive a copy of it.
- Correction — have anything inaccurate or incomplete corrected. Every entry in your book is editable in place.
- Deletion — have your account and everything in it destroyed. This is immediate and cannot be undone.
- Portability — receive what you have entered in a format you can open elsewhere. Download it yourself from Data in your account settings, or ask at the address below and we will send it to you.
- Objection — object to processing that rests on our legitimate interests, including analytics.
- Restriction — ask us to hold processing while a dispute about accuracy or lawfulness is resolved.
- Withdraw consent — for alerts or for marketing email, at any time, without affecting anything else.
- Complain — to the Information Regulator of South Africa, or to your own supervisory authority in the EU.
We will respond within thirty days. We do not charge for any of this, and we will not ask you why.
The Information Regulator (South Africa) can be reached at JD House, 27 Stiemens Street, Braamfontein, Johannesburg 2001, or at enquiries@inforegulator.org.za.
How your information is protected
Privacy here is enforced in three independent layers, so that it never rests on a policy statement alone.
- At the edge: every request is authenticated and rate-limited before any code that can read data runs at all.
- In the application: text-based document content is stripped of identifying information before it is sent anywhere for processing, and nothing a document produces reaches your book until you approve it.
- In the database: row-level security is enforced by PostgreSQL itself, on every table, so a query for someone else's rows returns nothing regardless of what the application code asks for. This is the layer that cannot be defeated by an application bug.
All traffic is encrypted in transit, and data is encrypted at rest by our database and storage providers. No system is perfectly secure, and we will not claim otherwise; if a breach occurs that creates a real risk to you, we will notify you and the Information Regulator as POPIA section 22 requires.
Changes to this policy
If we change this policy in a way that affects how your information is handled, we will tell you by email before the change takes effect, and update the date at the top of this page. Continuing to use myClerkBook after a change means you accept the revised policy; if you do not, you may export your data and delete your account.
