Last updated September 18, 2026
Privacy Policy
This policy explains what information Countorra collects, how it's used, who it's shared with, how long it's kept, and what control you have over it. It describes the product as it actually works today, not a roadmap.
Not yet final. Highlighted fields (legal entity name, registered address, contact email, governing law, refund policy, whether prices include sales tax / vat) are business details that have not been provided. They are set in src/domain/legal/facts.ts, and this page (src/app/privacy/page.tsx) should not be treated as binding until they are.
1. Who this policy covers
This policy applies to Countorra, provided by [Legal entity name — to be provided before launch], [Registered address — to be provided before launch]. Questions about this policy or your data: [Contact email — to be provided before launch].
2. Information we collect
- Account information — your name and email address. Accounts use an email address and password, managed by Supabase Auth. Your password is hashed by Supabase; we never see or store it in plain text.
- Financial information you enter — accounts, transactions, invoices, customers and the details you record about them.
- Bank connection data, if you choose to connect a bank — see §6.
- Tax preparation details you enter — for example your filing status, and your dependents' names, relationship to you and dates of birth. Countorra does not ask for and has nowhere to store a Social Security number or ITIN; it records only whether one exists.
- Uploaded documents — files you upload, stored in private storage isolated to your organization. For PDFs that contain text, that text is read on our servers so you can review the figures it contains. We do not currently send documents to an OCR or document-extraction service.
- AI conversations — your messages to the AI assistant and its responses, so your conversation history persists.
- Billing information, if you subscribe — see §7. Card details are entered with Stripe, not with Countorra.
- Security and operational information — an append-only audit log of sensitive actions in your organization, and server logs of errors and operational events. Logs are filtered before they are written so that passwords, tokens, email addresses, amounts and the content of your AI questions are not recorded in them. To limit abuse (for example repeated sign-in attempts), we process IP addresses and sign-in identifiers, and store them only as keyed hashes.
4. How we use your information
- To operate the product: sign you in, keep your data within your organization, and show your records, reports and tax figures.
- To import bank transactions you have chosen to connect, into the accounts you choose.
- To answer questions you ask the AI assistant, using the records needed to answer them (see §5).
- To take payment for a subscription, if you choose one.
- To secure the product: detect and investigate misuse, enforce rate limits, and keep an audit trail of sensitive actions.
- To contact you about your account, its security, or your subscription.
We do not sell your data, and we do not use your financial data to train AI models.
5. Service providers
We share the minimum data needed with these providers, each for one purpose:
- Supabase — database, authentication, file storage, and the emails that verify your address and reset your password. The account, financial, document and conversation data described in §2 is stored with Supabase.
- Vercel — hosting. Your requests pass through Vercel's servers, which process information such as your IP address and keep server logs.
- Anthropic — when you use the AI assistant, your message and the financial records needed to answer it are sent to Anthropic to generate a response, and for no other purpose.
- Plaid — only if you connect a bank. See §6 and Plaid's End User Privacy Policy.
- Stripe — only if you subscribe to a paid plan. See §7 and Stripe's privacy policy.
- Resend — only if invoice emailing is enabled: when you send an invoice by email, the recipient's address and the invoice message are sent through Resend for delivery.
We do not currently use a document-extraction or OCR service (such as Amazon Textract), a social or single sign-on provider, an analytics or advertising platform, or an error-tracking service. If we add one, we will update this policy before it receives your data.
6. Bank connections through Plaid
Connecting a bank is optional, and happens only when you choose it. Countorra uses Plaid to connect to your financial institution. You sign in to your bank in Plaid's window; Countorra never receives or stores your bank username or password.
With your permission, Plaid provides Countorra with:
- your institution's name and identifier;
- each account's name, type and subtype, currency and last four digits — never the full account number;
- each account's current and available balances;
- transactions: amount, currency, date, whether the transaction is pending or posted, the merchant name and description, and the category label Plaid assigns.
Plaid also gives Countorra an access key for your connection. Countorra encrypts it (AES-256-GCM) before storing it, with a key kept only in our server environment and separate from the database. It is never sent to your browser. It is used only to fetch updates from Plaid for your connection, on our servers.
Nothing enters your books until you choose which Countorra account each bank account feeds. Pending transactions are kept but not added to your books until they post. Changes you make to an imported transaction are not overwritten by later updates from your bank.
Disconnecting. You can disconnect a bank at any time from Bank connections. Countorra asks Plaid to end its access and destroys the stored access key. Transactions already imported stay in your books until you delete them, and the record of the connection and the transactions it reported stays with your organization's history until the organization is deleted. Plaid's own policy explains what Plaid keeps and how to manage it.
7. Payments through Stripe
If you subscribe to a paid plan, payment is handled by Stripe. You enter your card details on Stripe's pages, and manage your subscription in Stripe's billing portal. Countorra never receives or stores your full card number or security code. Countorra stores the Stripe identifiers for your customer record and subscription, your plan, its status and the current billing period — what it needs to know which plan your organization is on.
8. How your data is protected
- Every table containing your data enforces row-level security scoped to your organization, in the database itself — another organization's members cannot read or change your records, whatever the application asks for.
- Connections to Countorra are encrypted in transit (HTTPS), and the site instructs browsers to refuse unencrypted connections.
- Bank access keys are additionally encrypted by Countorra before storage, as described in §6, in a table no user can read.
- Credentials for our providers are held only on our servers, never sent to your browser.
- Messages from Plaid and Stripe to Countorra are accepted only after their signatures are verified.
- Uploaded documents are private; a download link is issued only to a member of your organization and expires within minutes.
- Sensitive account actions, such as deleting your account, require you to enter your password again.
See Security for more detail. No system is perfectly secure, and we cannot guarantee that it is.
9. Retention and deletion
We keep your data for as long as your account and organization exist. You can delete individual records at any time.
Deleting your account is self-serve, in Settings, and requires your password. It permanently deletes every workspace you are the only member of — with all of its financial records, documents, tax information and bank connections (Countorra first asks Plaid to end its access, and destroys the stored access keys) — removes you from workspaces you share with others, deletes your AI conversations, and deletes your sign-in. If you own a workspace that other people use, you are asked to transfer it first, so their data is not deleted with yours. Records you created in a shared workspace stay there for its other members, no longer linked to you.
Subscriptions: deleting your account cancels the paid subscription of every workspace being deleted, before anything else is deleted, and Countorra confirms with Stripe that it will not be charged again. If that cannot be confirmed, nothing is deleted. Stripe retains records of payments made, under its own obligations.
Security audit log entries are append-only and are kept after a workspace or account is deleted, no longer linked to it or to you. Some entries record the name you gave a workspace. Deleted data may also remain in our database provider's backups until those backups expire.
10. Tax and financial figures
Tax figures in Countorra are estimates from the information you provide, with the limitations described in our Terms of Service. They are not tax returns, and Countorra does not file anything with a tax authority on your behalf.
11. Your rights
You can, at any time:
- view and correct your profile, organization and records in the product;
- disconnect any bank connection;
- delete your account, as described in §9;
- ask us for a copy of your data, or what we hold about you, by contacting us.
Depending on where you live, you may have additional rights under laws such as the GDPR or the CCPA. Contact [Contact email — to be provided before launch] to exercise them.
12. International processing
Our service providers may process data in countries other than your own. Where that involves transferring data out of the European Economic Area, the UK or other regions with transfer requirements, we rely on the safeguards those providers make available. Governing law: [Governing law — to be provided before launch].
13. Children
Countorra is not directed at children and is not intended for anyone under 18.
14. Changes to this policy
If we make a material change, we will update the date at the top of this page and, where appropriate, tell you directly before it takes effect.
15. Contact
[Contact email — to be provided before launch], [Registered address — to be provided before launch].