Legal
Privacy Policy
Last updated: July 2, 2026
JEFLAG is built for audit professionals who handle sensitive financial data. Privacy is not an afterthought — it is the foundation of our architecture. This policy explains exactly what we collect, what we never collect, and the choices you control.
1. Data we never receive
Your general ledger and trial balance files are parsed and analysed entirely inside your browser. Raw transaction data is never uploaded to, transmitted through, or stored on JEFLAG servers.
Only the results you explicitly choose to save — flagged entries, risk scores, and reviewer notes — are persisted to your account. You can delete these at any time.
2. Account information we collect
When you create an account we store your email address, and optionally your full name, firm name, and job title. This information is used to authenticate you, personalise reports, and communicate service updates.
Authentication is handled by our infrastructure provider. Passwords are salted and hashed; we never see or store your plain-text password.
3. How we use your information
To operate and secure your account, generate branded reports with the correct preparer details, maintain your audit trail, and respond to support requests.
We do not sell your personal information. We do not use your saved analysis data to train third-party models.
4. AI processing
When you request an AI explanation for a flagged entry, only the anonymised attributes of that single entry (amounts, dates, account codes, and the triggered risk criteria) are sent to our AI provider to generate the explanation. No file, no counterparty, and no full ledger is transmitted.
5. Data retention and deletion
Saved analyses and engagement records are retained until you delete them or close your account. On account closure, associated records are permanently removed within 30 days.
You may export or delete your data at any time from your account settings.
6. Security
All data in transit is encrypted with TLS. Access to stored results is enforced by row-level security so that you — and only you — can read your own records.
7. Contact
Questions about this policy can be sent to privacy@jeflag.io and we will respond within five business days.