Privacy Policy
This policy explains what Honest Record, operated by Ermaz LLC, stores about you and your organisation, why, for how long, and who processes it.
What we collect
- Account data: your email address, organisation name, membership and role.
- Evidence you upload: bank statement pages and receipts (photos, PDFs, CSV or Excel). These contain financial information and may contain names of people paid.
- Derived data: extracted statement rows and receipt readings, matches, categorisation rules learned from your edits, generated reports, and run logs.
- Billing data: plan, subscription status, renewal date and Paddle customer and subscription identifiers. Card details are entered on Paddle's checkout and never reach our servers.
How we use it
Solely to provide the Service: reading statements and receipts, matching and categorising them, producing reports, enforcing plan limits, sending sign-in codes, creating tenant-local rule backups, and responding to support requests. We do not sell data and do not use your documents to train models.
Processors
- OpenAI (United States): reads statement pages and receipt photos and suggests wording and categories. Documents are sent for processing only; OpenAI's API terms exclude use for training.
- Paddle: payments, taxes and receipts, as merchant of record.
- Resend: sends one-time sign-in codes and, only if an organisation's owner has opted in, a copy of that organisation's rules snapshot to the owner.
- Railway: hosting and storage of the Service and its data.
Retention
- Uploaded statement and receipt files are deleted automatically as soon as a run's analysis has succeeded.
- Extracted data, reports and run logs are kept for 60 days, or until you delete the run, whichever is sooner.
- Learned rules and fund layouts are kept while the organisation exists. Rule snapshots are stored inside that organisation's isolated server storage. An organisation's owner may additionally choose, in Team & billing, to receive a copy of each snapshot by email; it is off unless the owner switches it on, and is only ever sent to the owner's own address.
- Account and billing records are kept while the organisation exists and as long as required by law afterwards.
Security
Traffic is encrypted (HTTPS). Sign-in uses one-time emailed codes; there are no passwords to steal. Each organisation's data is isolated on the server. Access to production systems is limited to what is needed to operate the Service.
Your rights
You can export your learned rules, delete runs, and remove members at any time from within the Service. To access, correct or delete other data, or to delete an organisation entirely, email support@honestrecord.com. If you are in the EU or UK you also have the right to complain to your data protection authority.
Cookies
We use essential cookies for your signed-in session and selected organisation workspace. We do not use advertising or analytics cookies.
Contact
Ermaz LLC, support@honestrecord.com.
Last updated 23 August 2026.