Where your data lives, and who can read it
This is your money we are holding. So rather than a page of adjectives, here is what is actually true about where your books sit, what protects them, what we deliberately do not claim, and what you can do about any of it. The Privacy Policy is the binding version and this page never contradicts it.
Two products, two different answers
What actually protects your Cloud books
Your books are stored as an encrypted blob, not as a readable database. A set of books is compressed and then encrypted with AES-256-GCM before it is written down. What sits in our database is opaque: it is not a table of your transactions that someone could query, browse, or accidentally export.
We hold the key, and we are not going to imply otherwise. This is encryption at rest with a key our service holds, not end-to-end encryption where only you can decrypt. Anyone who tells you their cloud product is zero-knowledge while also generating your reports on their servers is describing something that cannot be true. Ours is the ordinary honest version: opaque at rest, decrypted in the service that serves you.
It changes how the rest of the product had to be built. Because the server genuinely cannot read your ledger, features that need to know something about your books, such as an accountant's cockpit showing which clients need attention, are fed by a small summary your own app computes and sends. The raw ledger does not leave for them.
The AI, feature by feature
Oikos AI runs only when you invoke it. There is no background AI reading your books. Different features need different things, so one blanket reassurance would be dishonest. The short version:
| When you | What leaves your device |
|---|---|
| Ask your books a question | Your question and the structure of your database, meaning table and column names. Not your rows. The AI writes a read-only query and that query runs locally against your own books, so the numbers in the answer were never sent anywhere. |
| Type "spent $34 on gas" | That sentence, because it is the thing you are asking it to read. |
| Snap a receipt | The photo, for the same reason. |
| Auto-categorize an import | The specific items being categorized, and your category list. |
| Let AI identify an unrecognized import file | Only if you choose it: the header row and up to five shortened sample rows. This one is behind an explicit click because sample rows can contain customer names. |
Your financial records are never used to train AI models, ours or anyone else's. We record which feature ran and how many tokens it used, for cost, and not the content of the request or the answer. Never using the AI means nothing goes to the AI provider at all.
What we do not claim
We hold no security certifications. No SOC 2 report, no ISO 27001. Plenty of companies our size imply otherwise with a badge and a vague sentence. We would rather you knew, and weighed it.
We are not end-to-end encrypted, for the reason set out above.
We are not connected to your bank. Automatic bank feeds are not available: no bank connection can be made in the product today, and the routes that would make one refuse in code rather than merely being hidden. You import a statement instead, so we never hold your banking credentials. If that ever changes, the provider gets named in the Privacy Policy before any data moves.
We do not collect employee personal data. Payroll is held as summary totals only. No employee names, no Social Security numbers.
We sell nothing and track nothing. No advertising, no analytics trackers, no data sold, ever.
What you can do
For firms and larger businesses
A Data Processing Addendum is available for business customers, and we put one in place before go-live for firms handling real client financials. A current sub-processor list is maintained: hosting, payments, email delivery and the AI provider, each named in the Privacy Policy rather than described in general terms. Oikos Books is available in the United States only.
A security question this page does not answer? Email [email protected] and you will get a specific answer, including "we do not do that yet."