Legal

Privacy Policy

Last updated: August 2026

Who we are

CPAgents, Inc. ("CPAgents," "we," "us") provides accounting automation software for CPA firms and small businesses. Our agent, Ruby, connects to accounting ledgers on our customers' behalf, codes transactions, and routes items for professional review. This policy describes how we collect, use, and protect information when you visit our website or use our services.

Information we collect

Information you give us. When you request a demo or contact us, we collect the information you submit: your name, email address, firm or company name, and the contents of your message.

Customer ledger data. When a customer connects an accounting ledger to the service, we access transaction and account data from that ledger through the ledger provider's authorized connection, solely to provide the service: coding transactions, building the firm's rulebook, routing items for review, and maintaining the audit trail.

Usage and technical data. We collect standard technical information when you use the site or service, such as IP address, browser type, and pages visited, used for security, troubleshooting, and improving the service.

How we use information

We use information to provide and improve the service, respond to demo requests and inquiries, secure our systems, meet legal obligations, and communicate with customers about their accounts. We do not sell personal information.

Your ledger trains no one. We hold zero-retention arrangements with the AI providers we use. Customer ledger data is not used to train third-party models and is never shared across customer accounts: one firm's rulebook and institutional knowledge are private to that firm.

How information is shared

We share information only with service providers who help us operate (such as cloud hosting and email delivery), under agreements that restrict their use of the data; with a customer's connected ledger provider as required to operate the authorized connection; when required by law; and in connection with a corporate transaction such as a merger or acquisition, in which case this policy continues to apply to previously collected data.

Security

Data is encrypted in transit and at rest. Access to customer data is restricted by role, firm data is isolated per tenant, and administrative access requires multi-factor authentication. Every agent action and human decision in the service is logged.

Data retention

We retain customer data for as long as the customer account is active and as needed to meet legal and audit obligations. Customers may request deletion of their data upon termination of service, subject to records we are required to keep.

Your choices

You may request access to, correction of, or deletion of your personal information by contacting us. If you are located in a jurisdiction that grants additional privacy rights, we will honor requests as required by applicable law.

Cookies

Our site uses only the cookies necessary for it to function and for basic analytics. We do not use advertising cookies.

Children

Our services are for businesses and professionals and are not directed to anyone under 18. We do not knowingly collect information from children.

Changes to this policy

If we make material changes, we will update this page and revise the date above. Continued use of the site or service after changes take effect constitutes acceptance of the updated policy.

Contact

Questions about this policy or our data practices: [email protected].