Privacy Policy
Last updated: June 10, 2026
BS9x (the "Service") is a software product operated by Vinn Inc., a Delaware corporation ("we", "us"). This policy explains what information we collect when you use BS9x, why we collect it, where we store it, and what control you have over it.
1. Information we collect
From you, when you sign in
We use Google Sign-In. When you sign in we receive your name, email address, profile picture, and a stable Google user identifier from Google's OAuth response. We don't see or store your Google password.
From you, when you use the Service
- Bank statement PDFs you upload to extract transactions from.
- Accounting ledger files (CSV exports from Tally, QuickBooks, Xero, or Zoho Books) you upload to reconcile against.
- Extracted and derived data — transactions parsed from your PDFs, matches between bank entries and ledger entries, notes you add during review, and the configuration of your client workspaces.
- Usage counters — per-month counts of statements uploaded and reconciliations run, for billing and plan-limit enforcement.
From your browser, automatically
- IP address and approximate location (derived by AWS Amplify and CloudFront for security and abuse prevention).
- Browser type, operating system, and request timestamps in server logs.
- Session cookies set by our authentication layer (next-auth).
From Stripe, when you upgrade your plan
Payment processing is handled by Stripe. We receive only your subscription status, plan, and a Stripe customer identifier — we do not see or store your full card number, CVC, or bank account details. Stripe's privacy policy applies to information you give them directly: stripe.com/privacy.
2. How we use your information
- Run the extraction pipeline against your uploaded PDFs and return the parsed transactions to you.
- Match your bank transactions against your ledger entries during reconciliation, and persist the match outcomes so you can review and export them.
- Enforce monthly plan limits (free tier, Solo, Firm, Firm Pro) and process subscription billing via Stripe.
- Maintain a cross-tenant bank-layout template cache: when our system detects the column structure of a bank statement (for example, an HDFC Savings format), we store the *structural template* — column header keywords, column count, anchor-column name — so the next user's upload of the same format parses faster and cheaper. We do not store your actual transaction values, narration text, or account numbers in this cache.
- Operate the Service, prevent abuse, debug errors, and respond to support requests.
3. Where your data lives
- All persistent data is stored in AWS in the United States (us-east-1 region).
- Uploaded PDFs and generated outputs (CSV / XLSX / JSON) live in Amazon S3, encrypted at rest with AES-256.
- Extracted transactions, ledger entries, client workspaces, match sessions, and usage counters live in Amazon DynamoDB.
- Authentication sessions are stored as signed JWT cookies in your browser; we don't store session state on our servers.
- Our LLM-assisted extraction calls run against Amazon Bedrock in the same AWS account. Bedrock does not retain prompts or responses for model training.
4. How long we keep it
- PDF uploads and generated CSV/XLSX/JSON outputs: automatically deleted from S3 7 days after upload.
- Extracted transactions, ledger entries, match sessions, and notes: kept for as long as your account is active. Deleted within 30 days of account closure.
- Usage counters and billing records: retained for 7 years for tax and accounting compliance.
- Bank layout templates (structural cache, no customer data): retained indefinitely.
- Server logs and authentication events: retained for 90 days for security and debugging.
5. Who we share it with
We do not sell your data. We share information only with the processors required to run the Service:
- Amazon Web Services — hosting, storage, compute, and LLM inference. AWS acts as our data processor under the AWS Data Processing Addendum.
- Google — authentication only (we never push your uploaded data to Google).
- Stripe — subscription billing.
- Law enforcement — if compelled by valid legal process.
6. Your rights
You can, at any time:
- Access the data we hold about you — email us and we'll send an export.
- Delete your account and all associated data — email us at founder@vinn.ai with the subject "Delete my BS9x account". We process deletions within 30 days.
- Export your reconciliation data in CSV or Excel format directly from the dashboard, anytime.
- Withdraw consent by deleting your account.
If you're in the EU, UK, or California, you have additional rights under GDPR / UK GDPR / CCPA. Email us and we'll honour them.
7. Security
- All traffic between your browser and our servers is encrypted in transit with TLS 1.2+ (HTTPS).
- Data at rest in S3 and DynamoDB is encrypted with AWS-managed keys.
- Authentication uses Google OAuth — we never store passwords.
- Our backend is reachable only via our authenticated frontend; direct calls to the API endpoints require an internal authentication token plus a signed user session.
No system is perfectly secure. If you discover a vulnerability, please email us at founder@vinn.ai before disclosing publicly.
8. Cookies
We use only essential cookies — a signed authentication cookie from next-auth, and a CSRF token cookie. We do not use third-party analytics, advertising, or tracking cookies.
9. Children
BS9x is a business tool. It's not intended for users under 18, and we don't knowingly collect data from anyone in that age group.
10. Changes
We may update this policy as the Service evolves. We'll post the revised policy at this URL and update the "Last updated" date at the top. Material changes will be emailed to active users.
11. Contact
Questions, requests, or concerns about this policy or your data:
Vinn Inc.
founder@vinn.ai