Privacy Policy

Effective date: August 8, 2026

1. Scope

This Privacy Policy explains how CashVault AI ("CashVault," "we," "us," or "our") collects, uses, shares, and protects information when you use our website, the approved-access CashVault application, the standalone QuickBooks Connector, our MCP endpoints, and related support services (collectively, the "Service").

The Service is intended for business use. If an organization provides your access, that organization may control its workspace, members, connected accounts, and business records.

2. Information we collect

  • Account and access information, such as your name, email address, preferred language, organization membership, and role. Supabase Auth processes password credentials and authentication sessions; CashVault does not receive your plaintext password.
  • Information submitted when requesting approved access or contacting us, including your name, business name, email address, and message.
  • Manual CashVault records, including organizations, bank accounts and confirmed balances, balance overrides, beneficiaries, scheduled payments, sales and collection milestones, investments, notes, and related audit records.
  • QuickBooks information you authorize. In the CashVault application this includes selected bank-account identifiers and balance snapshots. Through the standalone connector and MCP, it may also include QuickBooks records needed for the read or write action and scopes you approve, such as accounts, customers, vendors, invoices, bills, payments, or attachments.
  • Connector and security information, including OAuth connection status, encrypted QuickBooks tokens, approved MCP clients, requested scopes, authorization status, token events, and records needed to investigate misuse or support revocation.
  • Technical information, such as IP address, browser and device details, request timestamps, error and security logs, and essential cookie values.

3. How we use information

  • Provide, secure, maintain, and troubleshoot the Service.
  • Authenticate users, enforce organization isolation and owner, editor, and viewer permissions, and preserve the selected organization context.
  • Display the effective CashVault balance and manual cash plan, synchronize authorized QuickBooks balance snapshots, and keep manual overrides separate from provider snapshots.
  • Execute the QuickBooks or CashVault MCP operations that an authorized user or approved agent requests within its granted scopes.
  • Send account, invitation, access-request, security, and service communications.
  • Prevent fraud and abuse, comply with law, and improve reliability using operational information.

4. QuickBooks and connected agents

QuickBooks access is optional and uses Intuit OAuth. We use QuickBooks data only to provide the connection and actions you authorize. Manual payments, sales, beneficiaries, investments, and balance overrides created in the CashVault application are not written back to QuickBooks in this release.

The standalone QuickBooks Connector can permit an approved AI agent or MCP client to read or update QuickBooks when the organization grants the relevant scopes. Data returned to that client is then also handled by the agent or platform you chose under its own terms and privacy practices. Review scopes before approval and revoke access when it is no longer needed.

We do not sell QuickBooks data, use it for targeted advertising, or use it to train generalized AI models.

5. How we share information

We do not sell personal information or financial records. We do not share them for cross-context behavioral advertising.

  • Supabase, which provides authentication and database infrastructure used by the Service.
  • Intuit, when you connect or operate QuickBooks Online.
  • Hosting, security, and email-delivery providers that process only the information needed to operate the Service and send requested communications.
  • The external agent or MCP client that your organization explicitly approves, limited to the scopes and operations authorized for that connection.
  • Professional advisers, authorities, or other parties when reasonably necessary to comply with law, protect rights or security, investigate abuse, or complete a corporate transaction subject to appropriate safeguards.

6. Security

We use reasonable administrative and technical safeguards, including encrypted transport, server-side handling of privileged credentials, organization-scoped access controls, role checks, and database row-level security. QuickBooks tokens and service credentials are not intentionally exposed in the browser.

No service can guarantee absolute security. Organization owners and users are responsible for protecting credentials, reviewing connected agents and scopes, and promptly reporting suspected unauthorized access.

7. Retention and deletion

We retain information while an account or organization uses the Service and for a reasonable period afterward when needed for backups, security, dispute resolution, legal obligations, or legitimate business records. Retention varies by record type and applicable law.

Disconnecting QuickBooks stops new provider retrieval but does not automatically delete records already stored in CashVault. Revoking an MCP client prevents future access by that credential. To request access, correction, export, or deletion of eligible information, contact us at martin@cashvault.ai. We may need to verify your identity and the requesting organization before acting.

8. Cookies and local preferences

We use essential cookies or similar browser storage for Supabase authentication sessions, organization selection, language, theme, and security. Blocking essential authentication cookies may prevent the application from working. CashVault does not use third-party advertising cookies in this release.

9. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of certain personal information. These rights may be subject to exceptions, including records we must retain or data controlled by your organization. You may also disconnect QuickBooks, revoke approved agents, or ask an organization owner to change your workspace access.

Submit privacy requests to martin@cashvault.ai. We will respond as required by applicable law after reasonable identity and authority verification.

10. International processing

The Service and its providers may process information in countries other than your own. Where required, we use appropriate safeguards for international transfers. By using the Service, you understand that privacy laws may differ between jurisdictions.

11. Children

The Service is designed for businesses and is not directed to children under 18. We do not knowingly collect personal information from children. Contact us if you believe a child has provided information to the Service.

12. Changes and contact

We may update this policy as the Service changes. We will post the revised effective date and provide additional notice when required by law. Material new data uses will not apply retroactively without an appropriate legal basis.

Questions or privacy requests may be sent to CashVault AI at martin@cashvault.ai. Website: https://www.cashvault.ai.