Oikos Books — Privacy Policy
Effective date: August 21, 2026
Last updated: August 21, 2026
Contact: hello@oikosunited.com · Oikos United LLC, Commonwealth of Virginia, USA (mailing address available on request)
Plain-language summary (not a substitute for the full policy)
- Oikos Books is your accounting software. Your books are your financial data. We treat them as confidential.
- Desktop version: your books stay on your own device. We don't receive them.
- Cloud version: your books are stored on our managed infrastructure so you can sync across devices, invite your accountant, get paid online, and use the AI features.
- We use a small set of trusted providers — hosting, payments, optional bank feeds, email delivery, and the AI provider. Every one of them is listed in §4.
- We never sell your data, we run no advertising or analytics trackers, and we never use your financial records to train AI models.
- AI runs only when you ask it to. §6 sets out exactly what each AI feature sends — including the ones that do send a transaction description or a receipt photo, because that is the thing you are asking the AI to read.
- You can export or delete your data at any time. §9 and §10 tell you how, and how long we keep things.
1. Who we are and what this policy covers
This Privacy Policy explains how Oikos United LLC ("Oikos," "we," "us") collects, uses, shares, and protects information when you use Oikos Books (the "Service") — including the free downloadable desktop application, the cloud subscription at app.oikosbooks.com, the pay-links service at pay.oikosbooks.com, any trial or demo, and the marketing site at oikosbooks.com.
Oikos Books is offered two ways, and how your data is handled depends on which you use:
- Desktop (own-it): The application and your books run entirely on your own computer. Your accounting data is stored locally on your device and is not transmitted to Oikos unless you separately opt into a cloud or online feature. If you never connect an online feature, we do not receive your financial records at all.
- Cloud (subscription): Your books are stored on our infrastructure (as described below) so you can access them across sessions, sync, invite your accountant, get paid online, and use the AI features.
This policy applies to both, and calls out where they differ.
2. Information we collect
2a. Information you provide
- Account information (cloud): name, email address, password (stored only as a secure hash), and organization/business name.
- Billing information (cloud): your subscription plan, the number of businesses it covers, and billing status. Card and payment details are collected and stored by Stripe, our payment processor — we do not receive or store your full card number.
- Your books / financial data: everything you enter or import — chart of accounts, journal entries, invoices, bills, customers, vendors, contacts, transactions, tax settings, budgets, payroll totals you record or import, attachments, and notes. On cloud, this is stored on our managed database infrastructure as a per-business snapshot associated with your account. On desktop, it stays on your device.
- Receipt images (cloud): if you attach a receipt or document, the image file is stored in a private storage bucket namespaced to your account and read back only through short-lived signed links. It is not embedded in your books snapshot.
- Support communications: anything you send us when you contact support.
2b. Information collected automatically
- Authentication and usage data (cloud): sign-in events, session tokens, subscription-status checks, and basic technical logs (timestamps, IP address, error logs) needed to operate and secure the Service.
- Device/technical data: browser or app version and operating system, for compatibility and troubleshooting.
- AI usage metering (cloud): when you use an AI feature we record which feature ran, the model, the number of tokens processed, and the time. We do not keep the content of your AI requests or their answers in these records — the metering exists to understand cost and capacity, not to retain your questions.
- No advertising or analytics trackers. As of the effective date we run no third-party product-analytics, advertising, or session-recording tools of any kind. If an analytics or error-reporting tool is ever added, it will be listed in §4 as a sub-processor before it is switched on.
2c. Information from connected services (only if you opt in)
- Payments you receive via Stripe Connect: if you use "get paid online," Stripe processes your customers' payments and reports payment status to us so we can mark your invoices paid. See §5.
- Bank account data via Stripe Financial Connections (bank feeds): if you connect a bank or card account, we receive the account's identity basics (institution name, account name or its last digits) and its posted transactions, so the Service can import and reconcile them for you. See §5a for the full disclosure.
- Card transactions via your own Ramp account: if your business uses Ramp for corporate cards and you choose to connect it, we use read-only credentials that you create inside your own Ramp account to read your posted card transactions, so the Service can import and categorize them for you. See §5b for the full disclosure.
That is the complete list of third-party connections the Service currently offers. See §7 for integrations our marketing describes as planned but which are not available today and therefore move no data at all.
2d. What we do NOT collect
- We do not collect the full card numbers of you or your customers. Stripe handles those.
- We do not collect employee personal data for payroll. Oikos Books records payroll as summary totals only — gross wages, employee withholding, employer taxes, and the pay date. The Service does not collect, store, or transmit employee names, Social Security numbers, dates of birth, home addresses, or direct-deposit bank details anywhere in the product.
- We do not use your financial records to train, fine-tune, or improve AI models. See §6.
- We do not knowingly collect information from children under 13. The Service is a business product not directed to children.
3. How we use information
We use information only to provide and operate the Service:
- To create and secure your account and authenticate you (cloud).
- To store, sync, and let you share your books (cloud).
- To process your subscription and manage billing (via Stripe).
- To let you get paid online and mark invoices paid (via Stripe Connect).
- To import and reconcile bank transactions when you connect a bank account (via Stripe Financial Connections). See §5a.
- To import and categorize card transactions when you connect your own Ramp account. See §5b.
- To deliver the invoices, statements, and payment reminders you choose to send (via our email provider).
- To run the AI features you invoke, and to meter their usage (see §6 and §2b).
- To provide support, fix bugs, prevent fraud and abuse, and keep the Service secure.
- To comply with law and enforce our Terms.
We do not sell your personal information or your financial data, and we do not share it for cross-context behavioral advertising. We do not use your books for advertising of any kind.
Legal bases (for users in the EU/UK, where applicable): performance of our contract with you (operating the Service), our legitimate interests (security, fraud prevention, improving reliability), your consent (optional features such as the AI features, online payments, and bank connections), and compliance with legal obligations.
4. How we share information — service providers (sub-processors)
We share information only with providers that help us run the Service, each bound to protect it and to use it only to perform services for us. Our current sub-processors, in full:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Cloud authentication, multi-tenant API, database storage of your books snapshot, and private storage of receipt images | Account and authentication data, your cloud books data, receipt images |
| Render | Hosting of the Oikos Books cloud API | Data in transit/processing for cloud API requests |
| Cloudflare | Web/app hosting (Pages), CDN, DNS, and network security | Technical/connection data |
| Stripe | Subscription billing and Stripe Connect payments ("get paid online") | Billing details, payment/transaction status; card data held by Stripe |
| Stripe Financial Connections | Automatic bank feeds (optional — only for accounts you connect) | Bank account identity (institution, account name or last digits) and posted transaction history for the accounts you authorize |
| Resend | Transactional email (invoices, statements, and payment reminders you send from the app; account emails) | Recipient email address and the message content being sent |
| Anthropic (Claude API) | Powers the Oikos AI features | Varies by feature — §6 sets out exactly what each one sends |
Notes:
- Ramp: if you connect your own Ramp account (§5b), Ramp is a source we read from on your instruction, using credentials you issue to us, rather than a provider we share your information with. We send Ramp nothing about you beyond authenticating with the credentials you gave us, which is why it is described here and not in the table above.
- Email: when you send an invoice, statement, or payment reminder from the app, it is delivered by our email provider (Resend); we share only the recipient address and the message being sent. You can always download the document and send it yourself instead.
- Accountant access: if you invite your accountant or bookkeeper, they get access to your books at the level you grant. That is you sharing, not us sharing. You can revoke it at any time.
- We may also share information (a) to comply with law, legal process, or lawful requests; (b) to protect the rights, safety, and property of Oikos, our users, or the public; and (c) in connection with a merger, acquisition, or sale of assets, in which case we will notify you and any successor will be bound by this policy.
- A current sub-processor list is maintained and, for business customers, a Data Processing Addendum is available on request.
5. Stripe — billing and getting paid online
- Subscription billing: Stripe processes your subscription payments. Stripe collects and stores your payment-card details under Stripe's own privacy policy (https://stripe.com/privacy). We receive only your subscription and billing status, not your full card number.
- Get paid online (Stripe Connect): If you enable payments, you create a Stripe Connect account and agree to Stripe's Connected Account Agreement. Payments from your customers are processed by Stripe and settle directly to you — you are the merchant of record for your customers' payments. Oikos does not take custody of those funds and charges no platform fee. We receive payment status so we can mark your invoices paid. Your customers' card data is handled by Stripe, not Oikos. See the Terms of Service.
- PCI DSS: card data is collected and stored only by Stripe (a PCI Level 1 provider). The Service is designed so that Oikos does not receive, process, or store full card numbers (SAQ-A posture).
5a. Bank feeds — Stripe Financial Connections (required disclosures)
If you choose to connect a bank or card account, the connection is made through Stripe Financial Connections, a service of Stripe, Inc. — the same provider that already handles our payments. Connecting is always your choice, account by account. When you connect an account:
- Your bank sign-in happens with Stripe, not with us. You authenticate with your bank inside Stripe's interface. Oikos Books never sees or stores your bank username or password. Stripe processes that connection under Stripe's own privacy policy and its Financial Connections end-user terms.
- What we receive, exactly: the account's identity basics (institution name, account name or its last digits) and its transaction history (only transactions that have posted; pending items are not imported). We ask Stripe for one permission — transactions — and nothing else: not your balances, not account-ownership details, not payment credentials. US bank accounts only.
- How far back: the initial import brings whatever history Stripe makes available for that account, which varies by bank and is typically a few months rather than years. For older history, the statement-file importer remains available and is not limited.
- How often: after the initial import, new transactions arrive via a daily refresh. We do not continuously monitor your account.
- Where it goes: imported transactions land in your own books, exactly as if you had imported a statement file — from there they are your ledger data, covered by §9's retention clocks. We also keep an encrypted reference to the connected account and the institution name, so the app can show you which account is connected without re-asking your bank.
- Disconnecting: you can disconnect an account in the app at any time. Disconnecting stops all future imports and refreshes; transactions already imported remain in your books until you delete them, like any other entry. Connected-account records are deleted with your account under §9.
- Financial-privacy note: bank and financial-account information is sensitive. We treat it as confidential, use it only to provide the bank-feed feature, and never sell it or use it for advertising. Where federal financial-privacy rules (such as the Gramm-Leach-Bliley Act safeguards framework) apply to this data, we handle it consistent with those obligations.
5b. Card feeds — connecting your own Ramp account
If your business already uses Ramp for corporate cards, you can connect it so that card spend imports into your books instead of being keyed in by hand. This connection works differently from the bank feed in §5a, and the difference is worth understanding.
- You use your own Ramp credentials, and there is no partnership. An administrator of your Ramp account creates a developer application inside Ramp (Settings → Developer) with the read-only
transactions:readscope, and gives us the client id and secret that Ramp issues. Oikos has no partnership or agreement with Ramp and pays them nothing. You are authorizing us to read your own account, and you can revoke that authorization inside Ramp at any time, independently of us. - The access is read-only and limited to transactions. The scope you grant permits reading transactions and nothing else. The Service cannot move money, issue or freeze cards, change limits, or see anything the transactions endpoint does not return.
- What we receive, exactly: for each posted transaction, its date, its amount, the merchant name, any memo written on it, the spend category Ramp assigned, and Ramp's own transaction id, which we use so the same charge is never imported twice. We pull only transactions Ramp has marked ready to sync.
- What we do not receive: we do not request or receive cardholder identities, card numbers, your Ramp account balances, your Ramp user list, or any receipt or invoice image attached to a Ramp transaction. The import carries the charge, not the person who made it and not the paperwork behind it.
- How your credentials are held: the client secret is encrypted before it is written down, with the same application-layer encryption used for other third-party credentials (§11). The short-lived access token used for each sync is fetched when it is needed and is never stored.
- Where it goes: imported transactions land in your own books, through exactly the same import path a statement file uses. From there they are your ledger data, covered by §9's retention clocks.
- Disconnecting: you can disconnect in the app at any time, which deletes the stored credentials and stops all future imports. Transactions already imported remain in your books until you delete them, like any other entry. You can also revoke the application inside Ramp, which stops it at the source.
- If the way you connect changes: the credential exchange described above is the only way to connect Ramp today. Should we add another way to authorize it, what we receive and what we do not receive stay as set out here — the authorization method changes, the data does not — and we will update this section before any different method goes live.
6. Oikos AI — exactly what each feature sends
The Oikos AI features are powered by Anthropic's Claude API. Anthropic is our service provider and processes these inputs under its commercial API terms.
AI runs only when you invoke it. There is no background AI processing of your books. If you never use an AI feature, nothing goes to the AI provider at all.
Different AI features need different information to do their job. Rather than offer one general reassurance, here is precisely what each one sends:
| Feature | What is sent to Anthropic |
|---|---|
| Ask Oikos AI — a question about your books | Your question, your database structure (table and column names, not the rows), and relevant help-article text. For questions about your own numbers the assistant writes a read-only query that runs locally against your books; the resulting figures are produced on your device and are not sent to the AI provider. |
| Categorize transactions | Your chart of accounts, the description and amount of each transaction being categorized, and — to improve accuracy — up to 40 examples of how you have categorized similar transactions before. |
| Quick entry — typing something like "spent $34 on gas" | Your chart of accounts and the text of the note you typed. |
| Receipt capture — snapping or uploading a receipt | The receipt image itself, so its vendor, date, total, and tax can be read. The extracted vendor and amount may then be passed through the categorize step above. |
| Industry suggestion — during setup | The short description of your business that you type. |
| Import file mapping — only if you choose the AI option when we can't recognize an imported file | The file's header row and up to five sample rows (each cell shortened), so the AI can say what kind of report the file is and which column is which. Sample rows can contain names and amounts from your file. This runs only when you explicitly choose it on the import screen, and nothing is imported until you confirm the mapping. |
In plain terms: asking a question keeps your ledger on your device. Categorizing, quick entry, receipt capture, and import mapping necessarily send the specific item you are working on — a transaction line, a note, a receipt image, or a small sample of an import file — because that is the thing you are asking the AI to read. Nothing else from your books travels with it, and your ledger is never uploaded in bulk to the AI provider.
- We do not use your data — financial or personal — to train AI models. Anthropic processes API inputs as our service provider under its commercial API terms; per those terms as of the effective date of this policy, Anthropic does not use API inputs or outputs to train its models. This describes Anthropic's stated practice under its terms, not a warranty by Oikos; Anthropic's terms govern its own processing.
- We record AI usage metadata only — feature, model, token counts, timestamp. See §2b.
- If we change what any feature sends, we will update this section before the change takes effect.
- AI answers can be wrong and are not professional advice. Always verify. See the Disclaimers page and the Terms of Service.
7. Integrations we do not currently offer
We would rather say this plainly than let you assume otherwise.
- Automatic payroll sync is not available. Payroll is recorded by hand or imported from a register file you export from your payroll provider. We are not currently connected to any payroll provider and none transmits data to us. As §2d says, payroll is held as summary totals and the Service holds no employee personal data.
- Plaid is not our bank-feed provider. Bank feeds are built on Stripe Financial Connections (§5a). To be complete about what our systems contain: our codebase also holds bank-connection code written for Plaid, but it is switched off at our server and every request to it is refused — we hold no Plaid credentials, and we have no agreement with Plaid. Stripe Financial Connections (§5a), the Ramp connector (§5b) and that disabled Plaid code are the only bank- or card-connection code our systems hold.
If an integration becomes available, we will list the provider in §4 and update this policy before any of your data flows to it — and connecting will always be your choice.
8. When Oikos Books powers another Oikos product
Oikos Books is also the accounting engine underneath other Oikos United products, such as our church, venue, and real-estate platforms. When you use one of those, the organization that bought it is our customer, and Oikos acts as its service provider (processor), handling data on that organization's instructions.
- The organization's own privacy notice governs its relationship with its people. This policy describes what Oikos does with the data as its provider.
- Where such a product offers a public payment or giving page, we receive what the payer enters at checkout — typically name, email address, and billing address — along with payment status from Stripe, so the organization's records and receipts are correct. That information is held for the organization, used only to provide the service, and never sold or used for advertising.
- Business customers who need a signed data-processing agreement can request our Data Processing Addendum.
9. Data retention
Desktop: your books are retained on your device for as long as you keep them; deletion is under your control (delete the file or app data). We have no copy.
Cloud: we retain your account and books while your account is active. When it ends, these are the clocks we work to:
| Data | After you cancel | If you ask us to delete |
|---|---|---|
| Your books and snapshots | Retrievable for 90 days so you can export, then closed to access and permanently purged at 1 year | Permanently deleted within 30 days |
| Receipts and uploaded documents | Same 90-day / 1-year clock | Deleted within 30 days |
| Personal data in your books (names, emails, tax identifiers) | Purged with the books at 1 year | Deleted within 30 days |
| Our own billing and tax records | Kept as long as tax, accounting, and audit law requires (up to 7 years) | Exempt — we are legally required to keep these |
| Connected account records (encrypted bank account reference and institution name; encrypted Ramp credentials) | Deleted when you disconnect the account or with your account under the clocks above | Deleted within 30 days |
- Backups: our database backups run daily and are kept for 7 days. They cover your books, and they do not cover receipt images and other uploaded documents, which are held in separate file storage. So "deleted" means removed from live systems promptly and gone from database backups within 7 days. Receipt images are not held in any backup at all.
- Legal hold: data subject to a legal hold is retained until the hold is lifted, which overrides every clock above.
- Please export before you go. Financial records often must be kept for several years for tax purposes, and after permanent deletion we cannot recover them. Your books are yours — take a copy. See §10.
10. Your rights and choices
- Access and export. Export your books at any time from the app, in formats you can open elsewhere. You are never locked in.
- Correct. Edit your account details and your books directly in the app.
- Delete. Delete your account and cloud data by emailing hello@oikosunited.com from your account email address; we action verified deletion requests within 30 days. See §9 for the records we are legally required to keep.
- Turn features off. The AI features and online payments are optional. Don't use them and no data is sent for them.
- Revoke sharing. Remove an accountant's access at any time.
EU/UK (GDPR) users additionally have rights to access, rectification, erasure, restriction, portability, and objection, may withdraw consent for optional processing, and may lodge a complaint with a supervisory authority. California (CCPA/CPRA) users have rights to know, access, delete, and correct, and to opt out of "sale" or "sharing" — we do not sell or share personal information as those terms are defined — and the right not to be discriminated against for exercising these rights. To exercise any right, contact hello@oikosunited.com; we may need to verify your identity first. For business-customer (controller/processor) terms, a Data Processing Addendum is available on request.
11. Security
We use technical and organizational measures designed to protect your data: TLS in transit; storage on managed provider infrastructure with access controls; secure password hashing (never plain text); role-restricted database access with row-level tenant isolation; and least-privilege access to production systems.
Specifically, so you can judge for yourself rather than take an adjective on faith:
- Connections between your device and the Service use TLS in transit.
- Your cloud books and receipt images are stored on managed provider infrastructure with encryption at rest provided by that infrastructure. We do not claim to hold a separate customer-specific encryption key for your books snapshot.
- Third-party access credentials held by the Service are additionally encrypted at the application layer before being written to the database.
- Receipt images live in a private bucket namespaced by account and are served only through short-lived signed links.
No method of transmission or storage is 100% secure, and we do not guarantee absolute security. Statements in this policy describe our intended design and are subject to ongoing verification and improvement; they are not a warranty that any particular safeguard is in place at a given moment.
12. Cookies and local storage
We use no advertising cookies, no cross-site tracking, and no third-party analytics. What we use is strictly functional:
- Sign-in session storage (cloud): your browser stores an authentication token so you stay signed in. Clearing your browser storage signs you out.
- Local app storage (desktop and browser): your books and small interface preferences — such as whether you dismissed a prompt — are stored on your own device. On desktop this is how the product works at all: your books live there, not with us.
- Network-security cookies: our hosting provider may set cookies necessary for security and abuse prevention.
None of this is used to profile you or to build an advertising audience.
13. International data transfers
Oikos United LLC is based in the United States and the Service is operated from the United States. If you access the Service from outside the US, your information will be processed in the US, where privacy laws may differ from those in your country. Where a transfer mechanism is legally required for EU/UK personal data, we will put an appropriate one in place before offering the Service to customers subject to those rules.
14. Children's privacy
Oikos Books is a business product intended for adults. It is not directed to children and we do not knowingly collect personal information from anyone under 13 (or the minimum age in your jurisdiction). If you believe a child has provided us information, contact us and we will delete it.
15. Changes to this policy
We may update this policy. If we make material changes — including any change to what the AI features send, or the addition of a new sub-processor — we will notify you (for cloud users, by email or in-app notice) and update the "Last updated" date. Continued use after the effective date means you accept the updated policy.
16. Contact us
Oikos United LLC
Commonwealth of Virginia, USA (mailing address available on request)
Privacy: hello@oikosunited.com
General: hello@oikosunited.com