Privacy Policy
Last updated: Sep 4, 2026
This Privacy Policy explains how ActShark ("ActShark", "we", "us", or "our") collects, uses, discloses, and protects information when you use our accounting software and related services, including our website at actshark.com (collectively, the "Service"). Note: ActShark is currently operated by its owner as an individual; contracting entity details will be published here upon incorporation.
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
1. Who We Are
ActShark is an accounting software service that lets you manage business bookkeeping: documents, transactions, accounts, worksheets, and reports. Contact us at [email protected] with any privacy questions or requests.
2. Information We Collect
Account Information
When you register, we collect your name, email address, and an optional profile image. If you link the ActShark Telegram bot, we store the linkage between your Telegram account and your ActShark account.
Financial and Accounting Data
The core of the Service is processing your financial data. This includes the books, chart of accounts, transactions, journal entries, worksheets, and fixed-asset records you create, as well as documents (invoices, receipts, statements) that you upload. These documents are stored in encrypted object storage and processed with local OCR (running inside our own infrastructure) to extract text for categorization and data entry.
Bank Connection Data
If you connect a bank account, we use Plaid as our account aggregation provider. We store the access tokens Plaid issues (in encrypted form) and the account and transaction data you authorize Plaid to share with us. Plaid processes your bank credentials and data under its own privacy policy and end-user terms. We never see or store your online banking password.
Payment Information
Paid subscriptions are processed by Stripe. Your payment card details are collected and stored by Stripe, not by us. We receive and store your billing status, subscription tier, and your Stripe customer identifier.
Usage and Device Data
When you use the Service, we automatically collect log and usage data such as IP address, browser type and version, pages visited, time and date of visits, and session records (including IP address and user agent, retained for security and to keep you signed in).
Error and Performance Data
We use Sentry to capture error reports, performance traces, and limited browser session replays to diagnose problems. Session replay may capture how you interact with the interface; we use it only for debugging and support.
Content You Send to AI Features
If you use the AI assistant or AI document extraction, the text of your request, relevant document text, and related context from your books are sent to our AI providers to generate a response. See section 6 for details on AI processing.
3. How We Use Information
- Provide, operate, maintain, and improve the Service
- Create and manage your account and authenticate you
- Process your documents and transactions, including OCR and AI-assisted categorization and extraction
- Sync and display bank-connected account and transaction data
- Bill subscriptions and metered usage through Stripe, and detect fraud
- Send service, security, and account-related communications
- Monitor for errors, abuse, and security incidents
- Comply with legal obligations and enforce our terms
We do not sell your personal information, and we do not share it with third parties for their own marketing purposes.
4. Legal Bases for Processing (EEA/UK)
Where the GDPR applies, we process your data on the following bases: performance of a contract (providing the Service and billing); legitimate interests (security, fraud prevention, service improvement, error monitoring); consent (where required, withdrawable at any time); and compliance with legal obligations.
5. How We Share Information
We share information only with the following categories of processors and in the following situations:
- Stripe — payment processing and subscription management
- Plaid — bank account aggregation (only if you connect a bank account)
- AI providers — processing of AI requests (see section 6)
- IDrive e2 — encrypted object storage for your documents and backups
- ZeptoMail — delivery of transactional email (such as verification codes)
- Sentry — error monitoring and diagnostics
- Inngest — background job orchestration for document processing and other pipelines
- Railway — application hosting and infrastructure
- Business transfers, legal requirements, and protection of rights — in connection with a merger or asset sale (with notice), when required by law or valid legal process, or to protect the rights, property, or safety of ActShark, our users, or the public
Your financial data is treated as confidential and is not shared with other users. Businesses within your account are isolated from other accounts.
6. AI Processing Disclosure
ActShark's AI features (the assistant chat, document data extraction, and chat titling) send prompts, document text, and related context to third-party large language model providers, reached through OpenRouter and similar AI gateways. This may include excerpts of your financial documents and bookkeeping data.
- AI features are optional. Core bookkeeping does not require sending data to AI providers.
- We only send the text needed for the task (for example, extracted document text, capped at a size limit) rather than your entire books.
- AI providers process this content on our instructions to generate responses; where their terms permit it, we select options that exclude use of your content for model training. You should assume any content you submit to AI features is processed by those providers.
- AI output can be wrong. You are responsible for reviewing any categorization or extraction before relying on it. See our Terms, section on professional advice.
7. Cookies and Local Storage
We use a small number of strictly necessary cookies and local storage to keep you signed in, remember your theme preference, and protect against fraud. We do not use advertising or third-party marketing cookies. You can control cookies through your browser settings, but blocking strictly necessary cookies may prevent the Service from working.
8. Data Retention
We retain account, financial, and billing data for as long as your account is active and as needed to provide the Service, comply with legal and tax obligations, resolve disputes, and enforce our agreements. Session and log data are retained for shorter periods unless needed for security investigations. When you delete data or your account, we remove it from active systems within 30 days, except where retention is legally required (see our Data Deletion Request page). Encrypted backups roll off on a fixed schedule.
9. Data Security
We protect your data with encryption in transit (TLS), encryption at rest for sensitive tokens and backups, access controls, and audit logging. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If a breach affecting your data occurs, we will notify you as required by applicable law.
10. International Data Transfers
We are based in the United States and our providers operate in various countries. Where personal data is transferred outside the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (or the UK Addendum) with the relevant provider, or an adequacy decision.
11. Your Privacy Rights
Depending on your location, you may have some or all of the following rights:
- Access / know what personal data we hold about you and the categories collected
- Correction of inaccurate personal data
- Deletion of your personal data (see our Data Deletion Request page)
- Portability — export your books and data from within the Service
- Objection / restriction of certain processing
- Withdraw consent where processing is based on consent
To exercise any right, email [email protected]. We will verify your identity before fulfilling requests and respond within the timeframe required by applicable law (no later than 45 days for CCPA requests; one month for GDPR requests).
California (CCPA/CPRA) Rights
California residents have the right to know the categories of personal information collected, the right to delete, the right to correct, and the right to portability. We do not sell or share personal information as defined by the CCPA/CPRA, so no opt-out of sale/sharing is required. We will not discriminate against you for exercising your rights. Authorized agents may submit requests with proof of authorization.
EEA/UK (GDPR) Rights
EEA and UK residents have the rights listed above (access, rectification, erasure, restriction, portability, and objection), as well as the right to lodge a complaint with a supervisory authority.
12. Children's Privacy
The Service is not directed to anyone under 18, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal data, contact us and we will remove it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced by email and/or a notice within the Service before they take effect, and the "Last updated" date at the top will change. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
14. Contact Us
Questions about this Privacy Policy or our data practices can be sent to [email protected].