What that means
Data minimisation
We collect what the product needs to work, and the largest category, your
financial records, is the thing you came here to store.
Purpose limitation
Your books are used to show you your books. They are not sold, not shared
with advertisers, and not used as training data.
Access is enforced, not promised
Every row is scoped to its owner by the database, not by application code
remembering to filter.
Deletion is real
Hard delete, with no retained shadow copy.
What we do not claim
What we can say is checkable: there is no bank connection, no aggregator, no card data, no session recording and no stored IP address. Each of those is a statement about what the system is capable of, which is a stronger guarantee than a statement about how carefully it is operated.Your rights under both frameworks
See Data retention and deletion
for how each of these works in practice.
Sub-processors
myClerkBook relies on a small number of providers to operate: hosting, authentication, the database, payments, email and product analytics. Each holds only the category of data its function requires. The payment provider holds card details and we do not; we hold your books and it does not. The current list is maintained in the Privacy Policy, which is the authoritative version.Not accounting software
myClerkBook is a book of account for your own record-keeping. It is not
double-entry accounting software and does not produce statutory financial
statements. Nothing here is tax or accounting advice.
Back to the privacy architecture
The three layers, and the capability that does not exist.

