Privacy Policy

This policy explains how Comma handles personal information when you use our website, accounting application, bank connections, support, and optional AI connectors.

Scope & accountability

Comma is responsible for personal information under its control. This policy covers information handled by Comma; a bank, AI provider, or other service you choose also handles data under its own privacy terms. Questions, access requests, and privacy complaints can be sent to privacy@trycomma.app.

Information we collect

Depending on the features you use, we collect:

  • Account and security data, including your name, email, password verifier, terms-acceptance timestamp, session IP address and user agent, and two-factor authentication settings.
  • Company records you enter, including books, invoices, bills, payments, business contacts, company and tax identifiers, and audit history.
  • If your verified account is enabled for the private preview, personal-finance and income-tax preparation records you choose to add or import, including bank accounts, transactions, categories, budgets, source documents, working papers, and adjustments.
  • Messages you send us and limited operational data used for support, security, error diagnosis, and eligible page analytics.

Company records may contain personal information about customers, vendors, team members, or founders. The company entering that information is responsible for having authority to use it.

How we use information

We use information to authenticate you; operate the ledger, documents, reports, and company bank feeds; operate personal banking and income-tax workbenches when the private preview is enabled for your account; deliver messages you request; run connectors you authorize; provide support; monitor reliability; prevent abuse; and meet applicable legal obligations. We do not sell or rent personal information. We do measure our own advertising, which involves advertising cookies and interest-based ads on our public website and sign-up pages. The “Cookies, analytics & advertising” section below sets out what that covers, where it applies, and how to opt out. We never use the contents of your books, documents, or bank data for advertising.

Cookies, analytics & advertising

Comma uses essential cookies for sign-in, company selection, and security. On Vercel deployments, Vercel Analytics measures basic usage on ordinary website and application pages; Comma drops analytics events for private personal-finance, public-document, and sensitive Schedule 50 print paths before they are sent. If Sentry is configured, it receives error and performance diagnostics with default personal-data collection disabled, request data scrubbed, and browser replay text, inputs, and media masked.

We also use PostHog for product analytics and Google Tag Manager for Google Analytics, Google Ads, Meta, and Reddit marketing measurement. These services use cookies, session identifiers, IP address, browser and device information, page views, clicks, interaction events, web vitals, exception and performance data, and UTM and advertising click identifiers to help us understand product use and advertising results. PostHog is hosted in the United States. We do not enable PostHog session replay until its route allowlist and input masking have been separately verified.

Where this applies. Advertising tags run only on our public website and the sign-up, sign-in, add-company, and billing pages. Pages showing your books: ledgers, reports, transactions, sales, and documents: never load advertising tags. Private personal-finance pages, public document links, and Schedule 50 print views load no measurement at all.

What is shared. A small set of milestone events, such as creating an account, adding a company, or starting a paid subscription, together with an internal account identifier and plan and subscription status. For server-side advertising conversion matching, we may send a one-way hashed form of a verified email address and an internal identifier; we do not send ledger amounts, account names, transaction descriptions, invoice-line text, document contents, customer or vendor names, MCP prompts, or tool payloads.

Quebec. If you visit from Quebec, profiling and advertising technology is deactivated by default. We will only enable it after an explicit activation choice; otherwise these providers are not permitted to build an advertising profile from your visit.

How to opt out. Advertising measurement operates on an opt-out basis. You can decline it at any time by blocking third-party cookies in your browser, using Google's Analytics opt-out add-on or Google My Ad Center, adjusting Meta ad preferences, or turning off personalised ads in your Reddit account settings. You can also write to us at privacy@trycomma.app and we will exclude you. Declining has no effect on your ability to use Comma.

Retention. Product and marketing analytics events are retained for up to 84 months. If session replay is enabled after its separate review, recordings are retained for up to 30 days.

Bank data via Plaid

If bank connections are enabled and you connect an institution, Plaid Inc. provides account details, balances, and transactions that Comma uses for bank feeds, reconciliation, categorization, and budgeting. Plaid describes its own handling in the Plaid End User Privacy Policy. Comma encrypts Plaid access credentials at the application layer, and linking or repairing a bank connection requires recent two-factor authentication.

Company bank-feed data is scoped to that company. When the private preview is enabled, personal bank records are owned by your user account and kept separate from all company ledgers and memberships.

AI connectors

If you connect Claude, ChatGPT, or another MCP-compatible assistant, your chosen provider receives the information returned for actions you authorize. Business-accounting access is limited by your live role. Personal and income-tax connector tools are an allowlisted private preview: accounts without the entitlement cannot discover or invoke them, while enabled accounts still require the applicable company role and connector scopes. Connector actions are audited, and access can be revoked from Settings → Connections. See Security for more detail.

Service providers & disclosures

Providers process information for specific operational purposes: Vercel for hosting and web analytics; Supabase for database hosting; Resend for transactional email; Sentry for error monitoring; Plaid for bank connectivity; Stripe for subscription billing; PostHog for product analytics and its Stripe warehouse ingestion; and Google Analytics, Google Ads, Meta, and Reddit for marketing measurement as described above. An AI provider receives information only when you connect one. These providers may process information outside Canada, including in the United States, where it can be subject to local law. We may also disclose information when required by a valid legal process or when reasonably needed to protect users, the service, or the public.

Safeguards

Comma uses encrypted connections, tenant- and user-scoped access controls, live permission checks, two-factor gates for sensitive bank actions, encrypted provider credentials, audit logging, and telemetry scrubbing. No online service can promise absolute security; report a suspected privacy or security issue to privacy@trycomma.app.

Retention & deletion

We keep account and company data while the corresponding account or company remains active. Removing private-preview access hides and pauses those workbenches but does not itself delete their records. Deleting a company removes its books from the live application. Deleting your account removes your profile, sessions, connector tokens, and user-owned records after active personal Plaid connections have been revoked; the deletion fails if remote revocation cannot be confirmed.

Disconnecting a bank removes credentials and provider identifiers but can retain normalized posted history. A separate confirmed action permanently deletes disconnected personal history. Expired connector tokens are purged daily. Limited copies may remain in security logs or encrypted provider backups until their normal retention cycles expire; they are not available through the app.

Access, correction & complaints

Subject to applicable law, you may ask whether we hold your personal information, how it has been used or disclosed, and request access or correction. We may need to verify your identity. Where PIPEDA applies, we respond to access requests within 30 calendar days unless a permitted extension is required and explained. Send requests or complaints to privacy@trycomma.app. You may also contact the Office of the Privacy Commissioner of Canada.

Changes

We will update the date above when this policy changes and provide reasonable notice of material changes through the service or by email. Questions can be sent to privacy@trycomma.app.