Privacy Policy
What TERM collects, why, who it goes to, and how to get it removed. Financial data gets its own section.
Last updated: September 2, 2026
1. Scope
This policy explains how Liam Kittok ("TERM", "we") handles information when you use https://www.term.business and the TERM application.
For accounting data you connect, you are the controller of that data and we process it on your instructions. For your own account and billing details, we are the controller.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Account | Name, email address, authentication events | You, via our authentication provider |
| Billing | Billing contact, plan, subscription status, payment method type and last four digits | You, via our payment processor |
| Connected accounting data | Transactions, amounts, dates, vendor names, categories, company profile | The accounting system you connect |
| Access tokens | OAuth access and refresh tokens for systems you connect | The provider, at the moment you consent |
| Usage and technical | Pages viewed, actions taken, IP address, browser and device type, timestamps | Automatically, as you use the Service |
| Support | Messages you send us and their contents | You |
We do not receive or store full payment card numbers. Card details are submitted directly to our payment processor.
We do not intentionally collect special category data such as health or biometric information. Do not send it to us.
3. Your accounting data specifically
This is the most sensitive information the Service handles, so it is worth stating precisely.
- We read accounting data only from the company you explicitly connect, and only within the permissions granted during that provider's consent screen.
- Access is read-only in normal operation. Write access is exercised only to apply a change you have approved.
- We use this data to operate the Service for you: organizing spend, detecting recurring commitments, surfacing renewals, and preparing suggestions.
- We do not sell it, rent it, or share it for advertising.
- We do not use your accounting data to train machine learning models for other customers.
- You can disconnect at any time. Disconnection stops further access immediately.
4. How we use information
- To provide, maintain, and secure the Service.
- To authenticate you and keep your session active.
- To take payment and manage your subscription.
- To respond to support requests.
- To detect, investigate, and prevent abuse, fraud, and security incidents.
- To understand aggregate product usage so we can improve it.
- To send service messages about your account, billing, or material changes. These are not marketing and you cannot opt out of them while you hold an account.
- To comply with legal obligations.
5. Legal bases
Where data protection law such as the UK GDPR or EU GDPR applies, we rely on the following bases:
- Performance of a contract — to deliver the Service you subscribed to.
- Legitimate interests — to secure the Service, prevent abuse, and improve the product, balanced against your rights.
- Consent — where you connect a third-party account, and for any optional communications. You may withdraw consent at any time.
- Legal obligation — for tax, accounting, and lawful requests.
6. Who we share with
We do not sell personal information. We share it only with service providers who process it on our behalf under contract, and only as needed:
| Provider | Purpose | Data involved |
|---|---|---|
| Intuit (QuickBooks Online) | Source of the accounting activity TERM reads, once you connect a company. | Transactions, vendors, and company profile from the company you authorize. |
| Clerk | Account creation, sign-in, and session management. | Email address, name, authentication events, session identifiers. |
| Stripe | Subscription billing and payment processing. | Billing contact and payment method. Card details go to Stripe directly. |
| Vercel | Application hosting and delivery. | Request metadata such as IP address and user agent, plus server logs. |
| Neon | The database TERM stores your workspace in. | Imported transactions and commitments, workspace and membership records, billing identifiers, audit history, and encrypted accounting-provider tokens. |
| Composio | Manages the connections to QuickBooks, Gmail, Outlook, and Slack, and carries the data TERM reads through them. | The authorization granted for each connected account, and the provider records TERM reads through it — accounting activity, and mailbox or channel content for the integrations you choose to connect. |
We may also disclose information where required by law or valid legal process, to protect our rights or the safety of others, or in connection with a merger or acquisition — in which case we will give notice before your information becomes subject to a different policy.
7. Retention and deletion
- Account and connected data is retained while your account is active.
- Access and refresh tokens are deleted when you disconnect a provider or close your account.
- After account closure we delete or anonymize your data, except where we must keep records for legal, tax, or dispute-resolution purposes.
- Backups and logs may persist for a limited period after deletion before they are overwritten on their normal cycle.
To request deletion, contact support@term.business.
8. Security
- Data is encrypted in transit using TLS.
- Access tokens for connected accounting systems are encrypted at rest using authenticated encryption.
- Access to production systems is limited to personnel who need it.
- Payment card data never reaches our servers.
No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting your personal information, we will notify you and any regulator as required by law.
9. Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct information that is inaccurate or incomplete.
- Delete your information, subject to our legal retention obligations.
- Receive a copy in a portable format.
- Object to or restrict certain processing.
- Withdraw consent where processing relies on it.
- Complain to your local data protection authority.
Exercise any of these by contacting support@term.business. We will not discriminate against you for making a request. We do not sell or share personal information for cross-context behavioural advertising.
10. Cookies
We use cookies that are necessary for the Service to function. We do not use advertising cookies.
| Cookie | Purpose | Lifetime |
|---|---|---|
| Session cookies | Keep you signed in and secure your session. Set by our authentication provider. | Session or as set by the provider |
| OAuth state cookie | Protects the accounting-system connection flow against cross-site request forgery. | 10 minutes, single use |
11. International transfers
Our providers may process information in countries other than yours, including the United States. Where required, we rely on appropriate safeguards such as standard contractual clauses.
12. Children
The Service is for business use and is not directed to anyone under 18. We do not knowingly collect information from children. If you believe a child has given us information, contact us and we will delete it.
13. Changes to this policy
We may update this policy. Material changes will be notified by email or in the Service before they take effect. The date at the top of this page shows when it last changed.
14. Contact
Privacy questions and rights requests: support@term.business.