27 August 2026
Account AI is a bookkeeping and financial-tracking product built for Malaysia. This policy explains what information Account AI collects, why, and how it's handled. It covers the product as it exists today — a Stripe TEST-mode subscription product, not yet open to paid public customers.
Account AI helps you record, categorise, and understand income and expenses — personal or for a small business — by letting you upload receipts, enter transactions, ask questions about your money in plain language, and track possible Malaysian tax reliefs.
When you create an account, we collect your email address (used for sign-in and account communication) and, if you choose to set one, a display name. Authentication is handled by Supabase; we never see or store your password in plain text.
You may create one or more workspaces (personal or business ledgers) inside your account. Each workspace has a name and type you choose. Workspaces belong to your account and are not visible to other customers.
When you upload a receipt, invoice, or similar document, the file itself is stored securely and linked to your account and the relevant workspace. Only you (and, if you ever grant it, someone you explicitly authorise) can access your uploaded documents.
To save you from typing everything by hand, uploaded receipts are processed by an AI extraction step that reads amounts, dates, and merchant names. You always review and confirm extracted information before it becomes a transaction — extraction is a starting point, not an automatic, unreviewed record.
We store the transactions you record or confirm — amounts, dates, categories, merchants, and any notes you add — so you can see your financial history and generate reports and tax-relief summaries.
When you ask a question about your finances, the question and the transaction data needed to answer it are processed to generate a response. Questions and answers are not used to answer other customers' questions and are not sold or shared for advertising.
We store which plan you're on, your subscription status, and renewal/period dates so the product can enforce plan limits and show you accurate billing information. Actual payment processing — including your card details — is handled entirely by Stripe; Account AI never receives or stores your full card number.
If you contact support, we store the message, the category you selected, and your email address (or account, if you're signed in) so we can respond and keep a record of the request.
Like most web applications, our servers keep operational logs (e.g. which action failed and why) to diagnose problems and keep the service secure. These logs are written to record what went wrong technically, not to capture the content of your receipts, transactions, or Ask My Money questions.
Account AI uses a small number of essential cookies: one to keep you signed in (managed by Supabase Auth) and one to remember your language preference (English or Simplified Chinese). We do not currently use advertising or cross-site tracking cookies.
We process your information to provide the product itself (recording and organising your finances), to operate your subscription and billing, to provide support when you ask for it, and to keep the service secure and working correctly.
Receipt extraction and Ask My Money are powered, where configured, by Anthropic's Claude AI models. Relevant receipt content and financial data are sent to Anthropic's API to generate a response. Where a live AI provider isn't configured, a deterministic (non-AI) fallback is used instead — either way, your data is used to answer your own request, not to train a shared model on your behalf.
Account AI is built on Supabase (database, authentication, and file storage), is hosted on Vercel, and uses Stripe for subscription billing. Using Account AI necessarily means your account data passes through these providers as part of how the product works; each operates under its own privacy and security practices as an infrastructure/processing provider to Account AI, not as an independent recipient of your data for its own purposes.
Data is stored in a managed Postgres database with row-level access rules that scope each customer's data to their own account, and traffic to and from Account AI is encrypted in transit (HTTPS). No security approach is perfect or guaranteed; we describe our approach honestly rather than promising an outcome we can't verify.
Financial records (transactions and their supporting documents) are kept as a historical ledger for as long as your account exists, by design — this is what lets Account AI show accurate year-over-year history and tax-relief tracking. We do not currently have an automated way to permanently purge an individual record once confirmed; if you need something corrected, contact support.
Account AI does not yet have a fully self-service "delete my account" button. If you want your account closed or your data deleted, contact us (see Contact & Support) and we will handle the request manually. Because financial records are kept as a running ledger, some information may need to be retained for a reasonable period afterward for accounting-integrity or legal reasons even after an account is closed.
Please only upload receipts, documents, or information that are genuinely yours (or your business's) to record, and that you're authorised to share. Account AI is not a place to store other people's personal data without their knowledge.
Because Account AI's infrastructure providers (Supabase, Vercel, Anthropic) operate internationally, your data may be processed or stored in countries other than Malaysia as part of how those providers deliver their services. We have not independently verified or restricted this to a single region.
Consistent with Malaysia's Personal Data Protection Act 2010, you can ask to access, correct, or request deletion of your personal data by contacting us — see Contact & Support. We aim to respond to genuine requests in a reasonable time, though as a small, early-stage product some requests (like full data export) may currently need to be handled manually rather than instantly.
If this policy changes in a material way, we'll update the date at the top of this page and, where practical, let you know inside the app.