Privacy Policy

Effective date: 1 June 2026

AcctQAI ("we", "our", "the Service") is a financial investigation platform for Indian finance teams. This Privacy Policy describes what data we collect, how we use and protect it, and your rights as a data principal under the Digital Personal Data Protection Act 2023 (DPDP Act) and applicable Indian law.

1. Data We Collect

Account data: Email address, name, and (optionally) phone number when you create an account. For Google Sign-In, we receive the email and name from Google — no password is stored.

Uploaded GL data: CSV or Excel exports of your General Ledger that you upload for analysis. These files contain transaction records (dates, amounts, account names, voucher references). They may include vendor and customer names.

Query logs: The plain-English questions you type into the Query Studio, along with the SQL generated and the response. This is used to improve answer quality for your organisation over time (RAG learning).

Usage telemetry: Number of queries run, connections created, and features used — to measure subscription limits and improve the product. We do not track page clicks or browsing behaviour beyond the app.

Billing data: If you subscribe to a paid plan, payment is processed by Razorpay. We receive only a payment confirmation token — we never store your card number, UPI VPA, or bank details.

2. How We Use Your Data

GL data is used exclusively for analysis you request. We run data-quality scans and SQL queries on your uploaded data to surface anomalies, generate close tasks, and answer your questions. We do not sell, share, or use your GL data to train any external AI model.

PII is masked before any LLM call. Before your query or GL data reaches a Large Language Model (Groq / Anthropic), our tokeniser replaces vendor names, customer names, and amounts with anonymised tokens (e.g., VENDOR_T001). The raw values are re-injected only in the final response displayed to you. The LLM never receives or stores your actual vendor/customer names.

Query logs are used for RAG (Retrieval-Augmented Generation). Successful Q→SQL pairs are stored under your organisation and used as few-shot examples to improve future answers within your account. They are never shared across organisations.

3. Data Storage and Security

Location: All data is stored on Amazon Web Services in the ap-south-1 (Mumbai) region, within Indian jurisdiction.

Encryption: Data is encrypted at rest (AES-256 via AWS RDS) and in transit (TLS 1.2+). Uploaded GL tables are stored in isolated database schemas per organisation.

Access controls: Only your organisation's users (with valid session tokens) can query your GL data. Our engineering team may access anonymised telemetry for debugging but does not access individual GL tables without explicit support consent.

Secrets: API keys you provide for third-party LLMs are encrypted using AWS KMS before storage and decrypted only at call time, in memory.

4. Data Retention

Uploaded files: GL tables are retained for 90 days from upload, after which they are automatically deleted. You can re-upload to extend this window. You can also delete a connection at any time from Settings → Connections, which immediately drops the GL table.

Query logs: Retained indefinitely to support your RAG history. You can request deletion via privacy@acctqai.com.

Account data: Retained until you delete your account. On deletion, all personal data and GL tables are removed within 30 days.

5. Your Rights under the DPDP Act 2023

As a data principal under the Digital Personal Data Protection Act 2023, you have the right to:

  • Access — request a summary of personal data we hold about you
  • Correction — request correction of inaccurate data
  • Erasure — request deletion of your personal data and associated GL data
  • Grievance redressal — raise a complaint with our Data Protection Officer
  • Nomination — nominate a person to exercise your rights in the event of death or incapacity

To exercise these rights, email privacy@acctqai.com from your registered email address. We will respond within 7 business days.

6. Third-Party Services

We use the following sub-processors:

  • Amazon Web Services (AWS) — database hosting (Mumbai region)
  • Groq Inc. — LLM inference for query generation (PII-masked only)
  • Anthropic PBC — LLM fallback for complex queries (PII-masked only)
  • Razorpay Software Pvt. Ltd. — payment processing

We do not use Google Analytics, Facebook Pixel, or any advertising trackers.

7. Cookies

We use a single session cookie (auth_session) to keep you logged in. No tracking or advertising cookies are used. The session cookie expires when you log out or after 30 days of inactivity.

8. Children

AcctQAI is a professional finance tool not intended for users under 18. We do not knowingly collect data from minors.

9. Changes to This Policy

We will notify you by email at least 7 days before any material changes to this policy. Continued use of the service after the effective date constitutes acceptance.

10. Contact

Data Protection Officer: privacy@acctqai.com

AcctQAI — Financial Investigation Platform
India (registered under Indian law)

Last updated: 1 June 2026 · For questions, email privacy@acctqai.com