Privacy Policy
Last updated September 28, 2026Effective September 28, 2026
We at Circo, Inc. ("Accountable", "we", "us" or "our") wrote this privacy policy (this "Privacy Policy") because we know that you care about how information you provide to us is used and shared. This Privacy Policy explains how Accountable collects, uses, discloses and protects personal information when you visit our website at https://accountable.im (the "Site"), when our customers use the Accountable accounting software and related services (the "Services"), and when you otherwise interact with us.
Please read this Privacy Policy carefully, and contact us at privacy@accountable.im if you have any questions. Capitalized terms not defined here have the meanings in our Terms of Service.
The short version: we use your information to run Accountable for you. We do not sell it, we do not share it for advertising, we do not use your books to train AI models, and we set no advertising or analytics cookies.
Who this policy applies to
This Privacy Policy applies to Accountable's processing of personal information as a "controller" or "business": information about visitors to the Site, the people who create and use Accountable accounts, and people who contact us. It also describes, for transparency, how we handle the data in our customers' books.
When a customer uses the Services to keep its books, the customer decides what data goes into them, and we process that data on the customer's behalf as its "processor" or "service provider" under our Data Processing Addendum. That data can include personal information about the customer's own customers, vendors, contractors and employees, such as names, payment details and tax identification numbers. We have no direct relationship with those people. If your information is in a customer's books and you have a question or request about it, please contact that customer directly; if you contact us, we will pass your request to them.
As used in this Privacy Policy, "personal information" or "personal data" means information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with a particular individual.
Information we collect
Information you provide
- Account details: your name, email address, and sign-in details, such as the one-time codes we email you, a password if you set one (stored only as a salted hash), your two-factor settings, and your sign-in through Google or your company's single sign-on.
- Workspace and company details: the workspaces and companies you create, their legal names, entity types, fiscal years and addresses, their employer identification numbers (stored encrypted), and the people you invite and their roles.
- Customer Data: the books themselves and what goes into them: transactions, accounts, entries, bills, invoices, documents and files you upload (such as statements, receipts and general ledgers), notes and comments, and the questions you ask the AI accountant.
- Billing information: your plan, billing interval and invoices. Card and bank details you enter at checkout are collected and processed by our payment processor, Stripe, under its own privacy policy; we do not receive or store full card numbers.
- Communications: messages you send us through the in-app help panel, by email or through the Service Desk, and the files you attach.
- Other information you choose to give us, which we use as described here or as explained when you provide it.
Information from connected services
When you connect a service to Accountable, we receive information from it under your authorization:
- Banks, cards and payment accounts: through Plaid, Teller or a provider's own API (such as Mercury, Brex, Ramp or Stripe), we receive account names, masked account numbers, balances and transactions. This access is read-only. The access tokens and credentials that let us read these accounts are encrypted with a key separate from the rest of our data.
- Payroll providers (such as Gusto, Rippling or Deel): payroll journals, which can include employee names and pay amounts.
- Accounting software (such as QuickBooks, Xero or the tool you are moving from): your existing books, including vendor and customer names.
- Google: if you sign in with Google, your name, email address and profile picture. If you connect Gmail or Google Drive for the month-end close, see "Google user data" below.
- Slack: if you connect Slack, your workspace and channel identifiers and the messages needed to post approvals and answer questions there.
- Connected Agents: if you authorize an AI agent or application (such as Claude, ChatGPT or Cursor) through our MCP server or API, the requests it sends on your behalf.
Information we receive automatically
- Log data: your IP address, browser type and settings, device and operating system, the date and time of your request, the pages and API endpoints you use, and error details. We keep a sign-in history (time, IP address, approximate country and device) so you and we can spot unauthorized access.
- Usage information: which features you use and the actions you take in the Services, including the activity log of every change to the books (who or what made it and when), which is a core part of the Services.
- Campaign information: if you arrive from a link with campaign tags (such as utm_source or an ad click identifier), we keep them in your browser session storage and save them with your account when you sign up, so we know which campaigns bring customers.
- Cookies: we use only the cookies needed to sign you in and keep your account secure. See our Cookie Policy.
How we use information
We use personal information for purposes consistent with this Privacy Policy, including:
- to provide and operate the Site and the Services, including keeping, reconciling and closing books, answering questions, moving books in from other tools, and performing Service Desk work you order;
- to create and secure your account, verify your identity, detect and prevent fraud, abuse and security incidents, and keep an audit trail of changes to the books;
- to process payments and manage subscriptions;
- to respond to your questions, requests and feedback, and to provide support;
- to send you service messages, such as sign-in codes, invitations, approvals, month-end reports, billing notices, and changes to our terms and policies, and, where you have not opted out, occasional product updates;
- to understand how the Services are used and to maintain and improve them, using aggregated or de-identified information where we can; and
- to comply with legal obligations and legal process, and to protect our rights, privacy, safety or property, and that of our customers and others.
Aggregated and de-identified information: we may aggregate or de-identify information so that it no longer identifies you, a company or anyone else, and use it to operate and improve the Services. We do not attempt to re-identify it.
AI features
When you use an AI feature, such as the AI accountant, categorization, document reading, the autonomous close or our AI support agent, the parts of your books and your request that the task needs are sent through the Vercel AI Gateway to the AI model provider that answers it (currently OpenAI). These providers process the data only to return a response to us, may retain it for a limited period for abuse monitoring where their terms require, and do not use it to train their models. Accountable does not use your books, your documents or your conversations to train or fine-tune AI models. Our AI support agent tells you it is an AI, and a person on our team reads anything it cannot resolve.
Google user data
If you connect Gmail or Google Drive, Accountable requests read-only access (the gmail.readonly and drive.readonly scopes) so that the month-end close can find receipts, invoices and bank statements for your company's transactions and file them with the matching entries. We read only the messages and files the close needs, store the documents it matches in your company's document vault, and keep the rest of your mail and files unread and unstored.
Accountable's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- we use Google user data only to provide and improve the user-facing features described above, which are visible in the Services;
- we do not transfer it to others except as needed to provide those features (for example, to our hosting provider or to the AI model provider that reads a receipt), to comply with law, or as part of a merger, acquisition or sale of assets with notice to you;
- we do not use it for advertising, including retargeting, personalized or interest-based advertising, and we do not sell it;
- we do not use it to train or improve generalized AI or machine learning models; and
- no person at Accountable reads it unless you give us permission for a specific message or file (for example, in a support request), it is necessary for security purposes such as investigating abuse, or it is required to comply with law.
You can disconnect Google at any time in the Services or at https://myaccount.google.com/permissions; we then stop reading from it and delete the stored access token.
How we disclose information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We disclose personal information only as follows:
- Service providers and subprocessors: companies that host and run the Services for us, such as Cloudflare (hosting, database and file storage), Vercel and our AI model providers (AI features), Stripe (payments), Resend (email) and the bank data providers you choose to connect. They may use personal information only to provide their services to us. The current list, with what each does and where, is on our Subprocessors page.
- The people and agents you authorize: the Authorized Users you invite to a company (such as your co-founder or accountant), the Connected Agents you authorize, the people you share a report with, and the recipients of invoices, W-9 requests and other messages you send through the Services.
- Services you connect: when you ask us to send data to a connected service, such as posting to Slack or syncing with QuickBooks or Xero.
- Business transfers: if we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of all or part of our assets, or transition of service to another provider, personal information may be shared in the diligence process with counterparties and others assisting with the transaction, and transferred to a successor as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
- Professional advisors: lawyers, accountants, auditors and insurers, where necessary for the professional services they provide to us, under duties of confidentiality.
- Legal requirements: if required by law, or in the good-faith belief that it is necessary to (i) comply with a legal obligation or valid legal process, (ii) protect and defend our rights or property, (iii) prevent fraud, (iv) act in urgent circumstances to protect the personal safety of users or the public, or (v) protect against legal liability. Where the request concerns a customer's books, we will notify the customer unless the law prohibits it.
Data retention
We keep personal information for as long as reasonably necessary to provide the Services and for the other purposes in this Privacy Policy:
- Account and Customer Data: while your account is open. If a paid plan ends, your books stay readable and exportable on the Free plan; we do not delete a company's books because a plan ended.
- After you ask us to delete an account or a company, or thirty (30) days after the Terms of Service end: we delete the data from our active systems within thirty (30) days. Copies in encrypted backups expire within thirty-five (35) days after deletion.
- Billing records are kept for as long as tax and accounting law requires, generally seven (7) years.
- Security logs, sign-in history and records of your acceptance of our terms are kept for as long as needed for security, fraud prevention and to show what you agreed to, and as law requires.
- Support conversations are kept while your account is open, then deleted with it.
Personal information in customers' books is kept and deleted as the customer directs, under the Terms of Service and the Data Processing Addendum.
Security
We use technical and organizational measures designed to protect personal information, including isolating each company's books in its own data store, encrypting data in transit and at rest, encrypting bank credentials, access tokens and tax identification numbers with separate keys, two-factor sign-in, role-based access, and an activity log of every change. Our staff access a company's books only when needed to answer a support request or perform a Service the customer ordered, staff accounts require two-factor sign-in, and Service Desk access is recorded in the company's activity log. Read more on our Security page. No Internet transmission or storage system is ever completely secure, so we cannot guarantee absolute security. If a security incident affects your personal information, we will notify you and the relevant authorities as the law requires.
Your choices
- Update your information: you can change your name, email preferences and security settings in the Services, and edit company details in Settings.
- Email: you can opt out of product updates and other optional emails through the unsubscribe link in each one or in your email preferences. We will still send messages you need to use the Services, such as sign-in codes, approvals and billing notices.
- Disconnect services: you can disconnect a bank, payroll provider, Google, Slack, QuickBooks, Xero or a Connected Agent at any time.
- Export: you can export your books at any time, on every plan.
- Close your account: email privacy@accountable.im or ask in the help panel. We will ask you to export first, then delete your data as described under "Data retention."
Your privacy rights
Depending on where you live, you may have the right to:
- know and access the personal information we have about you and how we use and disclose it, and get a copy in a portable format;
- correct inaccurate personal information;
- delete personal information, subject to exceptions (for example, records we must keep by law);
- opt out of the "sale" or "sharing" of personal information, targeted advertising, and profiling in furtherance of decisions with legal or similarly significant effects (we do none of these);
- limit the use of sensitive personal information (we use it only as permitted by law, for example your sign-in credentials to sign you in);
- appeal our decision on your request; and
- not be discriminated against for exercising any of these rights.
To exercise a right, email privacy@accountable.im from the email address on your account, or write to us at the address below. We will confirm your identity by verifying control of that email address, and may ask for more information if needed. You may use an authorized agent; we will ask the agent for proof of your written permission and may ask you to verify your identity with us directly. We respond within forty-five (45) days (or within one month for requests under the GDPR or UK GDPR), and will tell you if we need more time, up to the extension the law allows, and why. If we deny your request, you may appeal by replying to our decision or emailing privacy@accountable.im with "Appeal" in the subject line; we will respond to your appeal within the time the law requires, and if we deny it, tell you how to contact your state attorney general.
We honor Global Privacy Control signals as a request to opt out of the sale or sharing of personal information; because we do not sell or share personal information, no further action is needed. We do not respond differently to "Do Not Track" signals because we do not track you across other websites.
Notice to California residents
The California Consumer Privacy Act, as amended by the California Privacy Rights Act (the "CCPA"), requires us to describe our practices for the personal information of California residents. This section applies to our processing as a business, not to personal information we process as a service provider for customers.
In the 12 months before the "Last updated" date of this Privacy Policy, we collected the following categories of personal information, from the sources and for the purposes described above:
| Category | Examples | Disclosed for a business purpose to |
|---|---|---|
| Identifiers | Name, email address, IP address, account identifiers | Service providers; people and agents you authorize |
| Customer records | Company details, billing records | Service providers (such as Stripe) |
| Commercial information | Plans and services purchased | Service providers |
| Internet or other electronic network activity | Log data, sign-in history, usage of the Services | Service providers |
| Professional or employment information | Your company and role | Service providers; people you invite |
| Sensitive personal information | Account sign-in credentials; tax identification numbers you enter | Service providers, only to provide the Services |
| Inferences | None | None |
We have not sold or shared (for cross-context behavioral advertising) personal information in the preceding 12 months, and we have no actual knowledge of selling or sharing personal information of consumers under 16. We do not use or disclose sensitive personal information for purposes other than those the CCPA permits without a right to limit. We keep each category for the periods described under "Data retention."
California residents have the rights described under "Your privacy rights," and may exercise them as described there. We do not offer financial incentives for personal information.
Shine the Light: California Civil Code § 1798.83 permits California residents to request information about disclosures of personal information to third parties for their direct marketing purposes. We do not make such disclosures. You may email privacy@accountable.im with the subject line "Shine the Light Request."
Other U.S. states
Residents of Colorado, Connecticut, Delaware, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Utah, Virginia and other states with consumer privacy laws have the rights described under "Your privacy rights," to the extent their state's law provides them. We do not sell personal information, process it for targeted advertising, or use it for profiling that produces legal or similarly significant effects.
People in the European Economic Area, the United Kingdom and Switzerland
If the EU General Data Protection Regulation (GDPR), the UK GDPR or the Swiss Federal Act on Data Protection applies to our processing of your personal data, Circo, Inc. is the controller for the processing this Privacy Policy describes, and the customer is the controller for the data in its books.
Legal bases. We process personal data:
- to perform our contract with you or your organization (providing the Services, billing, support);
- for our legitimate interests in operating, securing and improving the Services, preventing fraud and abuse, keeping audit trails, and telling customers about product updates, balanced against your rights;
- to comply with legal obligations (such as tax and accounting records); and
- with your consent, where we ask for it (for example, connecting Google or another service). You can withdraw consent at any time without affecting processing before withdrawal.
Your rights. You have the right to access, rectify or erase your personal data, to restrict or object to its processing, to data portability, and to withdraw consent. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live or work, or where an alleged infringement took place; in the UK, that is the Information Commissioner's Office. Please contact us first at privacy@accountable.im so we can try to help.
International transfers. We are based in the United States, and our Services and main service providers operate in the United States. When we transfer personal data from the EEA, the UK or Switzerland to the United States or another country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, together with the security measures described in our Data Processing Addendum. You can ask us for a copy of the relevant safeguards at privacy@accountable.im.
Automated decisions. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. AI features suggest changes to a company's books; people decide.
Children
The Site and the Services are for businesses and are not directed to children under 18. Accountable does not knowingly collect personal information from children under 18. If you believe a child has provided us personal information, please contact us at privacy@accountable.im and we will delete it.
Links to other websites
The Site and the Services contain links to websites and services we do not operate, such as the services you connect. The information you share with them is governed by their own privacy policies and terms, not this Privacy Policy.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Every version stays readable at its own dated address, and the "Last updated" date shows when it last changed. If we make material changes, we will notify you in the Services or by email before they take effect. Your continued use of the Site or the Services after a change takes effect means you accept the updated Privacy Policy.
Contact us
If you have questions about this Privacy Policy or our information practices, or want to exercise your rights, contact us at privacy@accountable.im or write to: Circo, Inc., Attn: Privacy, 1625 San Carlos Ave, Unit D, San Carlos, CA 94070, USA.
Version history
- September 28, 2026Effective September 28, 2026First published version.
Questions about this document: legal@accountable.im.