SYS_STATUS: OPTIMAL // DOUBLE-ENTRY: DB-ENFORCED // ANOMALY_DETECTION: ACTIVE // LEDGER_SYNC: REAL-TIME //SYS_STATUS: OPTIMAL // DOUBLE-ENTRY: DB-ENFORCED // ANOMALY_DETECTION: ACTIVE // LEDGER_SYNC: REAL-TIME //SYS_STATUS: OPTIMAL // DOUBLE-ENTRY: DB-ENFORCED // ANOMALY_DETECTION: ACTIVE // LEDGER_SYNC: REAL-TIME //SYS_STATUS: OPTIMAL // DOUBLE-ENTRY: DB-ENFORCED // ANOMALY_DETECTION: ACTIVE // LEDGER_SYNC: REAL-TIME //
Legal

Privacy Policy

Effective: April 12, 2026

01

What We Collect

Organization name, email address, Xero OAuth tokens (encrypted), Stripe Financial Connections tokens (encrypted), email OAuth tokens via Nylas (encrypted), transaction metadata, and invoice PDFs processed through the service.

02

What We Don't Collect

Personal emails, contacts, calendar data, bank credentials, Social Security numbers, passwords to third-party services, or any data outside the minimum required to operate Owwyl.

03

How We Use Data

Transaction data is used for categorization, anomaly detection, and reporting within your account. We never sell your data. We never share individual business data with other customers. Your financial data is yours.

04

The Knowledge Graph

Owwyl learns categorization patterns across all businesses to improve accuracy over time. This learning is aggregate — no individual transaction data is exposed to other organizations. Only pattern data (for example: businesses in the restaurant industry categorize Sysco as COGS) is used to improve system-wide categorization. Your specific transactions are never visible to other users.

05

Data Storage

All data is stored in Supabase on AWS us-east-1 infrastructure. Data is encrypted at rest and in transit. Every record is scoped to your organization, and reads and writes are isolated so that one organization's data is never returned to another. Cross-tenant isolation is verified by an automated test before each release.

06

Third Parties

Owwyl integrates with: Xero (ledger write access for bill creation), Stripe Financial Connections (read-only banking transaction access), Nylas (read-only email access for invoice scanning — works with Gmail, Outlook, Yahoo, and other providers), Anthropic (AI processing for categorization and anomaly detection), and Stripe (billing). Each integration operates with minimum required permissions.

07

Data Retention

Active accounts: data is retained for the life of the account. Terminated accounts: all data is deleted within 30 days of termination. You may export a full copy of your data at any time before account deletion.

08

Your Rights

You have the right to export your data at any time. You have the right to delete your account and all associated data at any time. You may request a copy of all data we hold about your organization by contacting us.

09

Contact

Privacy inquiries: privacy@kronos.ai. We respond to all inquiries within 5 business days.