Skip to content

Privacy Policy

Effective August 16, 2026 · Governed by Florida law

This Privacy Policy describes how Modern Accounting AI (“Modern Accounting AI,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information in connection with modernaccountingai.com and our accounting software (the “Service”). Modern Accounting AI is operated from the State of Florida, United States of America.

It should be read with our Terms of Service and Disclaimer. Capitalized terms not defined here have the meaning in the Terms.

1. Roles: your books vs. your account

For information you submit about your own customers, vendors, employees, or transactions (“Customer Data”), you are the business that decides why it is processed. We process Customer Data as your service provider / processor, only to provide the Service as you direct, to secure it, and to comply with law.

For account registration, billing identity, security logs, and our own marketing communications to you, we act as the business / controller.

2. Information we collect

We collect the following categories of information:

  • Account and organization information — name, work email, password (stored hashed), organization name, role, and similar profile data you provide.
  • Customer Data — ledgers, journal entries, invoices, bills, contacts, documents, and other financial records you enter or upload. This can include personal information about third parties if you put it in the Service. You are responsible for having a lawful basis to do so.
  • Billing information — subscription plan, status, and Stripe customer and subscription identifiers. Card numbers are collected and stored by Stripe, not on our servers.
  • Support and correspondence — messages you send to us, including via email or contact forms.
  • Security and usage information — IP address, browser and device type, timestamps, pages or features used, and similar logs needed to operate, debug, and protect the Service.
  • Bot-protection tokens — Cloudflare Turnstile runs on sign-in and sign-up to distinguish people from automated abuse.

3. Cookies and similar technologies

We use strictly necessary cookies and similar storage to keep you signed in (session/authentication cookies) and to protect the Service. These are required for the Service to function. We do not use advertising cookies, do not run a cross-site advertising pixel, and do not sell personal information.

We use a self-hosted Umami analytics instance to measure aggregate page views on marketing pages. It is configured not to use advertising cookies and to honor Do Not Track. It is not used to build advertising profiles.

You can block cookies in your browser. If you block authentication cookies, you will not be able to use signed-in features.

4. How we use information

We use information to:

  • Provide, maintain, secure, and improve the Service.
  • Create and administer accounts, workspaces, and user roles.
  • Process subscriptions, trials, invoices, and payment status.
  • Authenticate users, prevent fraud, abuse, and security incidents.
  • Provide customer support and operational notices.
  • Measure marketing-site traffic in aggregate and understand which public pages are used.
  • Comply with law, enforce the Terms, and protect the rights, safety, and property of Modern Accounting AI, our users, and others.

We do not use Customer Data to train public generative-AI models, and we do not sell Customer Data.

5. Legal bases (where a statute requires one)

Where a privacy law requires a legal basis, we rely on: performance of our contract with you; our legitimate interests in operating, securing, and improving a B2B software service; compliance with legal obligations (including tax, accounting, and the Florida Information Protection Act); and consent where we ask for it (for example, optional marketing email). You may withdraw consent for optional processing without affecting processing already completed.

6. How we share information

We do not sell personal information as that term is used in the California Consumer Privacy Act (as amended by the CPRA), and we do not share it for cross-context behavioral advertising. We disclose information only as follows:

  • Service providers / processors who assist us under contract, including: payment processing (Stripe); transactional email; bot protection (Cloudflare Turnstile); infrastructure and database hosting; error monitoring; and self-hosted analytics. They may process information only on our instructions, except where they act as independent controllers (for example, Stripe for card processing).
  • Organization users — people you invite to your workspace can see Customer Data according to the roles you assign.
  • Legal and safety — when we believe disclosure is reasonably necessary to comply with law, a valid legal process, or to protect rights, safety, or property.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy or a successor policy that is at least as protective.
  • With your direction — for example, if you export data or authorize an integration.

7. Retention

We retain account information for as long as your organization has an account and for a reasonable period afterward for billing, audit, dispute resolution, and legal compliance. Customer Data remains until you delete it or the account is closed and our deletion processes run, except for copies we must keep by law or that remain in encrypted backups until rotation. Security logs are kept for a limited operational period. When information is no longer needed, we delete or de-identify it.

8. Security and breach notice

We use administrative, technical, and organizational measures designed to protect information, including encryption in transit, access controls, and monitoring. No method of transmission or storage is completely secure. You are responsible for configuring user access in your workspace and for the security of devices you use.

If we become aware of a breach of security affecting personal information in our possession, we will investigate and notify affected individuals and regulators as required by applicable law, including the Florida Information Protection Act, Fla. Stat. § 501.171, and other state breach-notification statutes that apply to the incident.

9. Your privacy rights

Depending on your location, you may have the right to request access, correction, deletion, or a portable copy of personal information we hold about you as a controller; to appeal a denial; and to opt out of sale or sharing (we do not sell or share for advertising). We will not discriminate against you for exercising rights.

To submit a request, email privacy@modernaccountingai.com. We will verify your identity (and authority, if you use an authorized agent) before completing the request. We may deny a request that is unfounded, excessive, or that would interfere with our ability to provide the Service, detect security incidents, or comply with law.

If you are an individual whose information appears only inside a customer’s books (for example, a vendor contact), please contact that customer. We will redirect or support such requests as a processor where required.

10. Florida residents

Modern Accounting AI is operated from Florida. Florida law, including Fla. Stat. § 501.171, governs our data-breach obligations for covered personal information. Florida does not currently impose a general consumer privacy “right to know / delete” statute equivalent to the CCPA. We still honor the request process in Section 9 for Florida residents as a matter of practice, subject to the same verification and legal exceptions.

11. Additional U.S. state privacy disclosures

If you are a resident of California or another U.S. state with a comprehensive privacy law, the categories of personal information we collect are those listed in Section 2, collected from you, your organization, your devices, and our processors. We use them for the business purposes in Section 4. We disclose them to the parties in Section 6. We do not sell personal information or share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information (such as account-login credentials or precise financial account numbers we do not store) for purposes other than providing the Service, security, and legal compliance. Financial records you enter as Customer Data are processed as your service provider.

California residents may designate an authorized agent. We honor Global Privacy Control signals as an opt-out of sale/sharing; because we do not sell or share for advertising, GPC does not change our advertising practices.

12. International transfers

The Service is operated from the United States. If you access it from another country, you understand that information is processed in the United States and in other locations where our processors operate. Those laws may differ from the laws of your country. Where required, we use appropriate transfer mechanisms.

13. Children

The Service is for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe we have, contact privacy@modernaccountingai.com and we will delete it. We do not have actual knowledge that we sell or share personal information of consumers under 16.

14. Do Not Track

Our marketing analytics honors Do Not Track as configured. The authenticated product requires necessary cookies and is not an advertising tracker.

15. Changes

We may update this Policy from time to time. The effective date at the top of this page will change. Material changes will be posted here and may also be notified by email or in-product notice. Continued use after an update takes effect constitutes acceptance of the revised Policy to the extent permitted by law.

16. Contact

Modern Accounting AI
State of Florida, United States of America
Privacy: privacy@modernaccountingai.com
Legal: legal@modernaccountingai.com