Legal
Privacy Policy
This notice explains how personal data is handled when you visit the website, create an account, connect an inbox, process invoice emails, or contact us.
Last updated: 28 July 2026
1. Who is responsible for your data
Jonathan Renard, trading as Email Accounting Categorizer, is the data controller for account, billing, website, and support data. When a business uses the service to process invoice emails concerning its suppliers or staff, that business is generally the controller and we act as its processor.
Contact: support@example.invalidTEMPORARY PLACEHOLDER ADDRESS
123 Placeholder Street
Dublin 2
Ireland
2. Data we process
- Account identity, login, company profile, and support information.
- Subscription, plan, payment status, and billing identifiers. Full card details are handled by Stripe and are not stored by us.
- Gmail or Outlook connection identifiers, encrypted access and refresh tokens, connection health, and sync history.
- Financial emails likely to contain invoices, including sender, recipient, subject, message content, attachments, and provider IDs.
- Extracted invoice fields, category suggestions, review decisions, exports, and vendor-category memory.
- Essential authentication cookies, security logs, IP address, device, and request information needed to operate and protect the service.
3. Why we process data
- To create and secure your account, provide the service, process invoices, and manage subscriptions under our contract with you.
- To prevent abuse, diagnose faults, protect accounts, and improve reliability where we have a legitimate interest in operating a secure service.
- To keep billing, tax, and compliance records where required by law.
- To send marketing only where you have consented or another lawful basis applies. You can opt out at any time.
Category and field suggestions assist human review. The service does not make final accounting, tax, employment, credit, or similarly significant decisions about individuals.
4. Connected inboxes
Gmail access uses a read-only scope. Microsoft access uses delegated Mail.Read permission. We use connected-inbox data only to identify and process likely financial emails, present them for your review, and provide the features you request. We do not sell connected-inbox data or use it for advertising.
You can disconnect an inbox from the dashboard. This revokes provider access where supported and deletes the stored connection credentials. Previously imported records remain until deleted under your instructions or the retention rules below.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
5. Service providers and international transfers
We use suppliers to provide hosting, database and authentication, inbound email, inbox APIs, payments, and document extraction. These may include Vercel, Supabase, Postmark, Google, Microsoft, Stripe, and OpenRouter and its selected model providers.
Providers receive only the data needed for their function and are subject to contractual and security requirements. Where data is transferred outside the EEA or UK, we rely on an applicable adequacy decision or approved contractual safeguards. Customer-specific processor details will be made available before launch.
6. Retention
We retain account and service data while the account is active and for a limited period afterwards to close the service, resolve disputes, meet legal obligations, and maintain security. Connected-inbox credentials are removed when the connection is disconnected or the account is deleted. Invoice records and attachments are retained until the customer deletes them, asks us to delete them, or the account-retention period ends.
Billing and tax records may be retained for the period required by applicable law. Backup copies are deleted on a rolling schedule. Final numerical retention periods must be confirmed before launch.
7. Security
We use access controls, tenant isolation, encrypted provider tokens, private attachment storage, authenticated webhooks, rate limiting, and logging intended to protect the service. No online service can guarantee absolute security. Please contact us promptly if you suspect unauthorised access.
8. Cookies
The service currently uses cookies needed for authentication, security, and session continuity. We do not currently use non-essential advertising cookies. If analytics or other optional cookies are introduced, this notice and the consent controls will be updated before they are enabled.
9. Your rights
Depending on where you live, you may have rights to access, correct, erase, restrict, or object to processing; receive portable data; withdraw consent; and complain to a supervisory authority. We may need to verify your identity before acting on a request.
In Ireland, you may contact the Data Protection Commission. UK residents may contact the Information Commissioner's Office. You can also contact us using the details above.
10. Changes and contact
We may update this notice as the service or legal requirements change. Material changes will be communicated through the service or by email where appropriate.
For privacy questions or requests, use the details on our Contact page.