Privacy Policy

Last updated: August 26, 2026 · Version 2026-08-26.1

This Privacy Policy explains how CashflowReviewer ("we", "us") collects, uses, and protects information in connection with the CashflowReviewer service (the "Service"). The Service is a business-to-business tool: our customers are businesses that upload bank-statement data to underwrite commercial deals. By using the Service you agree to this Policy.

1. Information we collect

2. How we use information

3. Product improvement, training, and evaluation

CashflowReviewer is designed to improve as the Service is used. We may retain and use Customer Data and related results to train, test, evaluate, develop, and improve CashflowReviewer, including its statement parsers, transaction classifiers, funder and recurring-obligation detection, scoring and pricing logic, AI-assisted features, reconciliation controls, support tooling, and other product models and workflows.

Training and evaluation materials may include raw or redacted statement text and images; transaction descriptions, dates, amounts and balances; account, institution and layout information; extracted fields; classifications, corrections and rules; deal, pricing and offer outcomes; parser, reconciliation and confidence results; AI inputs and outputs; support and error records; and usage signals. We may combine information and learnings across customers to evaluate the Service and build product-wide improvements.

Where reasonably practicable for the improvement purpose, we minimize, redact, aggregate, or remove direct account, business, organization, and user identifiers before use. Access is restricted to authorized personnel and service providers who need the information for the disclosed purpose. De-identification is a safeguard, not a promise that every retained training or evaluation item is anonymous. Another customer does not receive direct access to your identifiable statements, deals, files, account rules, or pricing records, although generalized patterns learned from many customers may affect shared product behavior.

For statement-layout learning, the Service may also create a privacy-reduced format descriptor containing the detected financial-institution name, generic statement section or column headings, coarse column positions and types, page and parsed-row counts, reconciliation status, and a one-way layout fingerprint. A format descriptor does not contain raw PDF text, transaction descriptions, dollar amounts, balances, account numbers, filenames, merchant or business names, user email addresses, or organization identity. The server filters every descriptor before it can enter the system-wide format queue.

Training and evaluation copies may be retained for as long as reasonably necessary to improve and protect the Service, subject to applicable law. Deleting an operational deal or account does not necessarily remove information already incorporated into a restricted training or evaluation dataset, aggregated or de-identified information, a format descriptor, evaluation result, parser rule, or trained model parameter. We will honor deletion or objection rights where applicable law requires.

4. What we do NOT do

5. Third-party processors

We use infrastructure and service providers to run, secure, support, and improve the Service. They process data for us under their applicable service terms and for the functions described below:

6. Third-party data inside statements

Statements you upload typically describe a third-party business (e.g., a merchant applying to you for funding). For that data, your business is the party responsible for having a lawful basis to process it, and we process it only as your service provider to deliver the analysis you requested (see the Terms of Service, Section 4).

7. Retention and deletion

8. Security

CashflowReviewer uses layered technical and organizational safeguards. The Service runs on Netlify infrastructure; Netlify states that its Blobs storage encrypts data at rest and in transit. CashflowReviewer also uses TLS for network transport, server-verified identity, server-enforced tenant authorization, restricted server-side analysis, file validation, rate and abuse controls, integrity checks and recovery history, and an independently encrypted disaster-recovery copy when that backup is enabled. Optional processors such as Anthropic, Google Drive, Resend, Stripe, and Supabase receive only the information needed for their disclosed functions. Access to production systems is restricted. No method of transmission, storage, or processing is 100% secure, but we use commercially reasonable safeguards and review the Service's security on an ongoing basis.

9. Your choices and rights

10. Changes

We may update this Policy prospectively. When the current legal version changes, every organization owner, manager, and member must affirmatively accept the updated Terms and Privacy Policy before continuing to use authenticated features.

11. Contact

Privacy questions or requests: ml7779@gmail.com.