Privacy & Data Handling

Applies to this deployment · Last updated: August 24, 2026

What we collect: nothing

This deployment collects no personal data. There are no accounts, no analytics, no tracking cookies, no third-party scripts, and no server-side storage of anything you enter. Every transaction, document, and business detail you add lives exclusively in your own browser’s local storage, on your own device, under a single namespaced key. The operator’s servers never receive it — there is no upload path in the code.

Your controls

You can erase everything at any time: use “Reset demo data” in Settings, or clear your browser storage for this site. Because storage is local, clearing your browser data or using a private window produces the same effect. Nothing survives on our side, because nothing ever reaches our side.

Production commitments

The production architecture specified for this product commits to stricter handling than most financial tools: encryption of all financial data in transit (TLS 1.2+) and at rest (AES-256 disk encryption plus application-layer envelope encryption with KMS-held master keys for provider tokens and PII), least-privilege scoped API credentials with recorded consent, immutable audit logs, seven-year record retention aligned to Israeli bookkeeping law, and compliance with the Israeli Privacy Protection Law 5741-1981 including Amendment 13, with GDPR-aligned controls retained for future expansion. Those commitments bind when a server-backed version launches — this local demo needs none of them, and says so rather than implying otherwise.

Simulated integrations

The Bit, PayBox, and Israel Tax Authority connections shown in the interface are simulations. No real credentials are requested, stored, or transmitted, and no document is actually submitted to any authority. See the Terms for the full scope and the Contact page for reaching the operator.