Back to Home

Privacy Policy

Effective date: June 1, 2026

Last updated: June 28, 2026


01
Who We Are

Scriply (“Scriply,” “we,” “our,” or “us”) operates a cloud-based accounting ledger platform for small businesses, accessible at scriply.app (the “Service”). This Privacy Policy describes how we collect, use, store, share, and protect your information when you use the Service.

By creating an account or using Scriply, you agree to the practices described in this policy. If you do not agree, please do not use the Service.

02
Information We Collect

Account information

When you sign up, we collect your first name, last name, and email address. Your password is hashed and never stored in plain text.

Organization and KYC data

When you create or join an organization, we collect your business’s legal name, tax identification number (EIN/TIN), business type, registered address, and any documentation you upload as part of the Know Your Customer (KYC) verification process (e.g., Certificate of Incorporation, Proof of Address). This information is used to verify your business identity and is required to access certain features.

Financial records

We store all financial data you enter or import into Scriply, including invoices, bills, customers, vendors, chart of accounts, payment terms, and line-item detail. If you connect a third-party accounting system (such as QuickBooks Online), we also store data synced from that system on your behalf.

Uploaded documents

You may upload PDF or DOCX files (such as invoice documents or KYC verification documents). These files are stored and associated with their respective records. When you use the AI document parsing feature, the text extracted from your file is sent to a third-party AI provider for processing (see Section 5).

Email content (AI email integration)

If you enable the AI email integration feature, Scriply accesses email messages in the connected mailbox. The content of those emails — including subject lines, body text, and metadata such as sender and recipient addresses — is sent to a third-party AI provider to extract and categorize financial information (see Section 5). We do not read your emails for any purpose other than delivering this feature.

Blockchain addresses

If you add cryptocurrency wallet addresses for customers or vendors, those addresses are stored as part of that party’s profile. Vendor address verification requests and responses are also stored.

Support communications

If you contact our support team, we retain the content of your messages and any attachments in order to respond to your request and improve the Service.

Usage and technical data

We automatically collect technical information when you use the Service, including your IP address, browser type and version, device type, operating system, pages visited, features used, timestamps, and error logs. This data is used for security monitoring, debugging, and understanding how the Service is used.

Cookies and local storage

We use browser cookies and localStorage to keep you signed in, remember your active organization, and store your preferences (such as light or dark mode). We do not use third-party advertising cookies or tracking pixels.

03
How We Use Your Information

We use the information we collect to:

Provide the Service. Authenticate your identity, display your financial records, sync data from connected integrations, process KYC verification, and send transactional notifications (such as invoice approval requests).

Improve the Service. Analyze usage patterns to identify bugs, performance bottlenecks, and opportunities to improve features. Aggregated and anonymized usage data may be used for this purpose.

Communicate with you. Send account-related emails such as password resets, verification notices, and product updates. You may opt out of non-essential communications at any time.

Comply with legal obligations. Retain records as required by applicable law, respond to lawful requests from government authorities, and enforce our Terms of Service.

We do not use your financial records or business data to train AI models, and we do not sell your personal information or business data to third parties for any purpose.

04
How We Share Your Information

We do not sell, rent, or trade your personal information. We share information only in the following circumstances:

With your authorization. When you connect a third-party integration (such as QuickBooks), you authorize us to exchange data with that service on your behalf.

With service providers. We use third-party vendors to operate the Service (detailed in Section 5). These vendors are contractually restricted to processing your data only as directed by us.

For legal reasons. We may disclose information if required by law, subpoena, court order, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.

Business transfers. If Scriply is acquired or merges with another company, your information may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.

05
Third-Party Services and AI Integrations

Several features of Scriply rely on third-party services that receive your data to function. We describe each one below so you know exactly what is shared and why.

Firebase (Google) — Authentication and infrastructure

We use Google Firebase to handle user authentication and secure data storage. Your email address and hashed credentials are processed by Google. Google’s services are governed by the Google Privacy Policy.

Intuit QuickBooks Online — ERP integration

If you connect a QuickBooks Online account, Scriply uses OAuth to access your QuickBooks financial data on your behalf. This includes invoices, bills, customers, vendors, and chart of accounts. You can revoke this access at any time from the Profile page or from your QuickBooks account settings. Intuit’s data practices are governed by the Intuit Privacy Statement.

Anthropic Claude — AI invoice document parsing

When you upload an invoice document and use the “Parse Document” feature, Scriply extracts the text from your file and sends it to Anthropic’s Claude API. Claude analyzes the text to identify fields such as invoice number, dates, line items, and customer name, which are then used to pre-fill the invoice form. The extracted text is not retained by Scriply or Anthropic beyond the duration of the API request. Anthropic’s data practices are governed by the Anthropic Privacy Policy.

Google Gemini — AI email integration

If you enable the AI email integration feature, email content from your connected mailbox — including message subject, body, and sender/recipient metadata — is sent to Google’s Gemini API. Gemini processes this content to identify and extract financial information (such as invoice details or payment confirmations) that can be imported into your Scriply ledger. This feature is opt-in and can be disabled at any time from your account settings. When disabled, no email content is sent to Gemini. Google’s data practices are governed by the Google Privacy Policy.

SendGrid (Twilio) — Transactional email

We use SendGrid to deliver transactional emails, including support ticket confirmations and account notifications. Your email address and the content of those messages are transmitted through SendGrid’s infrastructure. SendGrid’s data practices are governed by the Twilio Privacy Policy.

06
Cookies and Tracking

Scriply uses the following types of browser storage:

Session cookies. Used by Firebase to keep you authenticated across page loads. These expire when you sign out or after a period of inactivity.

localStorage.We store your active organization ID and UI preferences (such as color mode) in your browser’s localStorage. This data never leaves your device and is not transmitted to our servers.

We do not use advertising cookies, cross-site tracking, or analytics services that fingerprint individual users.

07
Data Security

We implement industry-standard security practices including encrypted connections (TLS/HTTPS) for all data in transit, token-based authentication with short-lived credentials, role-based access controls limiting data access to authorized users, and regular security reviews of our infrastructure and dependencies.

Despite these measures, no system is completely secure. In the event of a data breach that affects your personal information, we will notify you as required by applicable law.

08
Data Retention

We retain your account and organization data for as long as your account is active. Financial records are retained for a minimum of seven years from the date of creation to comply with standard accounting and legal record-keeping requirements, even after account closure, unless you request deletion and applicable law does not require us to retain them.

Uploaded documents are retained until deleted by you or until your account is closed. Support communications are retained for up to three years.

If you close your account and wish to request early deletion of your data, contact us at privacy@scriply.app. We will honor deletion requests to the extent permitted by law.

09
Your Rights

Depending on where you live, you may have the following rights regarding your personal data:

Access. Request a copy of the personal data we hold about you.

Correction. Request that we correct inaccurate or incomplete information.

Deletion. Request deletion of your personal data, subject to legal retention requirements.

Portability. Request your data in a structured, machine-readable format (applies to EEA/UK residents under GDPR).

Objection and restriction. Object to or request restriction of certain processing activities (applies to EEA/UK residents under GDPR).

California residents (CCPA/CPRA). You have the right to know what personal information we collect and how it is used, to opt out of the sale of personal information (we do not sell your data), and to non-discrimination for exercising your privacy rights.

To exercise any of these rights, contact us at privacy@scriply.app. We will respond within 30 days. We may need to verify your identity before processing your request.

10
International Data Transfers

Scriply is operated from the United States. If you access the Service from outside the United States, your information may be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.

For users in the European Economic Area or United Kingdom, we rely on Standard Contractual Clauses (SCCs) as the legal mechanism for transferring personal data to the United States where our service providers are based.

11
Children's Privacy

Scriply is intended for use by businesses and is not directed at individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, contact us at privacy@scriply.app and we will delete it promptly.

12
Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the features we offer, or legal requirements. When we make changes, we will update the “Last updated” date at the top of this page.

For material changes — such as new categories of data collected, new third-party AI integrations, or significant changes to how we use your data — we will notify you at least 30 days in advance by email to the address on your account and by displaying a notice within the Service. Continued use of Scriply after the effective date of the updated policy constitutes your acceptance of the changes.

For non-material changes(such as clarifications, formatting, or corrections), we may update the policy without advance notice beyond updating the “Last updated” date.

We recommend reviewing this page periodically to stay informed of how we handle your information. Prior versions of this policy are available upon request.

13
Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out:

Scriply

Privacy inquiries: privacy@scriply.app

General support: support@scriply.app

Scriply

High-performance accounting ledgers engineered for the future of small business finance.

© 2026 Scriply Inc. All rights reserved.