How EveryCent collects, uses, and protects your personal information.
EveryCent (“we”, “us”, or “EveryCent”) is an AI-native accounting and bookkeeping platform for small businesses. This Privacy Policy applies to everycent.ai and any related services we offer.
If you have privacy questions, please contact us at security@everycent.ai.
EveryCent uses AI to help you categorize transactions, extract data from receipts, and answer questions about your books. Before any personal or business data is sent to a third-party AI provider, we pseudonymize it: personal identifiers and company identity are masked. AI-suggested actions never execute without your explicit confirmation.
We rely on the following sub-processors to run EveryCent. Each is contractually required to protect your data.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Hosting (Cloud Run, Cloud SQL, Secret Manager, Cloud Storage) | United States (us-central1) |
| Plaid | Bank connections | United States |
| Gusto | Payroll partner | United States |
| Stripe | Payment processing | United States |
| Resend | Outbound transactional email | United States |
| Postmark | Inbound email capture | United States |
| Anthropic | AI processing (Claude) | United States |
| Nebius Token Factory | AI processing (open-weight inference) | United States |
| Sentry | Error monitoring | United States |
| PostHog | Product analytics | United States |
A current sub-processor list is also maintained at our Trust page.
We retain your data as follows:
Depending on where you live, you may have some or all of the following rights:
To exercise any right, email security@everycent.ai. We’ll respond within 30 days.
EveryCent is hosted in the United States. If you access the service from outside the United States, your information is transferred to and processed in the United States.
EveryCent does not currently onboard customers resident in the European Union. Before doing so, we will complete a cross-border transfer analysis (Standard Contractual Clauses, sub-processor DPAs) as required under GDPR Articles 44–49.
We use industry-standard technical and organizational measures to protect your data, including TLS 1.2+ in transit, AES-256 encryption at rest, field-level encryption for sensitive data (bank tokens, employee SSNs, webhook secrets), and multi-factor authentication on every personnel-held account.
Details of our security program are available at everycent.ai/trust.
EveryCent is a B2B accounting product and is not directed at children under 13 (or the local equivalent). We do not knowingly collect personal information from children. If you are aware that a child has provided us data, contact us and we will delete it.
We may update this Privacy Policy from time to time. Material changes will be communicated by email to registered account holders and by posting the updated policy at this URL. The “Last updated” date reflects the most recent revision.
EveryCent
Email: security@everycent.ai