Bank-Grade Data Security

Privacy Policy

Last Updated: August 3, 2026 • Effective Version 2.4

256-Bit AES Encryption

All financial transactions, bank feeds, and invoice data are encrypted at rest and in transit.

Strict Multi-Tenant Isolation

Your organization data is isolated by user session. Incognito or unauthenticated access is blocked.

Zero Data Selling

We never monetize or sell your proprietary business financial records.

1. Information We Collect

When you use Finviva, we collect information necessary to provide automated bookkeeping, invoicing, AR aging, and financial analytics:

  • Account Information: Name, email address, password hashes, business entity type, and tax ID.
  • Financial Ledgers: Invoices, line items, expenses, client profiles, bank feed transactions, and payment logs.
  • QuickBooks Integration Tokens: Encrypted OAuth 2.0 access and refresh tokens when you connect your Intuit QuickBooks account.
  • AI Vision & Multimodal Scans: Images of uploaded receipts or PDF bank statements submitted to our Vision OCR parser.

2. How We Use Your Data

Your financial data is processed strictly to deliver our platform features:

  • Generating real-time Profit & Loss (P&L) statements and AR Aging reports.
  • Executing automated AI Assistant chat actions (creating invoices, logging expenses, checking cash flow).
  • Processing client invites and CPA read-only access dispatches via transactional emails.
  • Maintaining QuickBooks OAuth API synchronization and 60-second migration engines.

3. AI Processing & Privacy

Finviva integrates specialized AI models for financial parsing. We enforce strict privacy boundaries:

  • Secure AI API Processing: Your financial requests, receipt scans, and chat queries are processed securely through encrypted AI API endpoints solely to fulfill your requested accounting tasks.
  • Zero Permanent Image Storage: Uploaded receipt images or PDF statements parsed by AI Vision OCR are converted into structured DB records and ephemeral storage is pruned.

4. Data Sharing & Third-Party Services

We only share data with trusted infrastructure providers required to operate Finviva:

  • PostgreSQL Database Providers: Encrypted storage for Multi-LLC ledgers.
  • Intuit QuickBooks API: Secure OAuth communication when explicit consent is granted.
  • Resend API: Transactional email dispatch for CPA invites and invoice notifications.
  • Stripe / LemonSqueezy: Payment processing infrastructure. We do not store raw credit card numbers.

5. Your Data Rights & Export

You maintain 100% ownership of your business data. At any time, you may:

  • Export your entire ledger (Clients, Invoices, Expenses, Payments) in CSV or Excel format.
  • Request complete deletion of your account and organization ledgers from our database.
  • Revoke QuickBooks OAuth integration access via Intuit account settings or NovaBooks Settings.

6. Contact Security Team

For privacy inquiries, data deletion requests, or security audit logs, please reach out directly:

Email: security@finvivaapp.com • Support: support@finvivaapp.com