Legal

Privacy Policy

Last updated: July 2, 2026

JEFLAG is built for audit professionals who handle sensitive financial data. Privacy is not an afterthought — it is the foundation of our architecture. This policy explains exactly what we collect, what we never collect, and the choices you control.

1. Data we never receive

Your general ledger and trial balance files are parsed and analysed entirely inside your browser. Raw transaction data is never uploaded to, transmitted through, or stored on JEFLAG servers.

Only the results you explicitly choose to save — flagged entries, risk scores, and reviewer notes — are persisted to your account. You can delete these at any time.

2. Account information we collect

When you create an account we store your email address, and optionally your full name, firm name, and job title. This information is used to authenticate you, personalise reports, and communicate service updates.

Authentication is handled by our infrastructure provider. Passwords are salted and hashed; we never see or store your plain-text password.

3. How we use your information

To operate and secure your account, generate branded reports with the correct preparer details, maintain your audit trail, and respond to support requests.

We do not sell your personal information. We do not use your saved analysis data to train third-party models.

4. AI processing

When you request an AI explanation for a flagged entry, only the anonymised attributes of that single entry (amounts, dates, account codes, and the triggered risk criteria) are sent to our AI provider to generate the explanation. No file, no counterparty, and no full ledger is transmitted.

5. Data retention and deletion

Saved analyses and engagement records are retained until you delete them or close your account. On account closure, associated records are permanently removed within 30 days.

You may export or delete your data at any time from your account settings.

6. Security

All data in transit is encrypted with TLS. Access to stored results is enforced by row-level security so that you — and only you — can read your own records.

7. Contact

Questions about this policy can be sent to privacy@jeflag.io and we will respond within five business days.