Privacy Policy

Effective August 6, 2026

Who we are

Zelims is a multi-entity accounting platform operated by Zelims LLC. It is used by businesses to keep their own books. This policy explains what data the platform handles, how it is protected, and the choices you have.

What we collect

Account information: your name and email address, used to sign you in and to attribute your actions in the audit trail. We use passwordless sign-in links — we never store passwords.

Accounting data you enter or upload: invoices, bills, journals, customers, vendors, documents, and files emailed to your workspace's intake address. This data belongs to your business; we process it solely to provide the service.

Bank data via Plaid: when you connect a bank account, Plaid Inc. provides us read-only transaction data for the accounts you choose — dates, amounts, descriptions, the merchant name and category Plaid derives, and the account's name, type and last four digits, along with your institution's name. We request transaction history only; we do not request the products that would give us your account or routing numbers, your identity details, or your balances. We never see or store your bank credentials — you enter them with your bank through Plaid. Plaid's handling of your data is described in their End User Privacy Policy at plaid.com/legal.

How we use it

To do your bookkeeping: recording, reconciling, reporting, and closing your books.

AI features (document reading, transaction classification, the finance assistant) process your workspace's data to propose entries — every proposal requires a person's approval before anything is recorded, and every AI action is logged with what it read.

We do not sell your data, share it for advertising, or use one customer's data to serve another.

How it is protected

Encrypted in transit (TLS) and at rest (AES-256). Bank connection tokens are additionally encrypted at the application layer with a separately held key.

Workspace data is isolated by PostgreSQL row-level security — enforced by the database itself beneath the application's own scoping, and tested continuously rather than trusted. A short, documented set of exceptions is enforced in the application instead: the tables we must read to identify your workspace before that context can exist, the file-attachment registry, and the customer-portal link registry.

Financial records are append-only: corrections happen by reversal, in the open, so the audit trail is complete by construction.

Nightly encrypted backups are stored off-site, and restores are rehearsed. See our Trust Center for the full set of enforced controls.

Who processes it for us

We use a small set of infrastructure providers, each processing data only to provide their service to us: Supabase (database and file storage), Vercel (application hosting), Resend (transactional email), Anthropic (AI processing), Plaid (bank connectivity), and Stripe (payments, where enabled). All processing occurs in the United States.

Retention and deletion

Accounting records are retained for as long as your workspace is active — bookkeeping and tax rules require durable records, and the platform's append-only design reflects that.

Disconnecting a bank feed immediately revokes our access at Plaid. Removing a user removes their access at once; their past actions remain in the audit trail.

To close a workspace and request deletion of its data, contact admin@zelims.com. We will delete or irreversibly anonymize the workspace's data except where law requires retention, and confirm when done.

Your choices and contact

Questions, access requests, corrections, or complaints: admin@zelims.com. We respond to verified requests from workspace owners about their workspace's data.

If we make material changes to this policy, we will update this page and note the new effective date below.

See also the Trust Center — how these protections are enforced and tested.