- Home
- Privacy notice
Privacy notice
As of: 27 September 2026
This page says which data Bilanzi processes, what for, where that happens, who else is involved and how long things stay.
It describes what the product actually does today, not what it is meant to do one day. Bilanzi keeps growing. This notice is kept up to date as it does, and the date above says when it last changed.
Controller
Mainbranch GmbHRainspergstrasse 68608 BubikonSwitzerlandTwo roles, and why the difference matters
For your account, Bilanzi is the controller: your email address, your sign-ins, your second factor, your language. Bilanzi needs that data to let you in and to keep your account.
For your business’s books, it is not. The receipts, contacts, invoices and entries belong to the business. Bilanzi processes them on its instructions and uses them for nothing else, not for analysis, not for advertising, not for improving a model.
In practice: the operator answers questions about your account. The business answers questions about its own figures; it alone decides roles, mandates and who sees which row.
Which data, what for
| Data | Purpose | Source |
|---|---|---|
| Account: email address, password as a hash, second factor, chosen language | Signing in, recovery, protecting the account | from you at registration |
| Signing in with Google or Apple: email address, the identifier of your account with the provider, and from Google also name and profile picture | Signing in without a separate Bilanzi password | from Google or Apple, if you choose that way in |
| Answers at registration, all optional: your role, the accounting software you use today, a note, your language, where the link came from | Understanding where people come from and what they need | from you at registration, the source from the link |
| Where you came from via an ad or a campaign link: Google’s click identifier, campaign details, landing page, previous page, time, an objection to reporting to Google | Seeing which campaigns bring registrations, and reporting to Google unless you object | from the link that brought you here |
| Invitations: email address of the invited person, role, who sent the invitation | Bringing someone into a business | from the person who invites |
| Billing for a paid plan: plan, payments, customer number at Stripe, card brand, last four digits and expiry date or TWINT, link to the receipt, Stripe’s messages about every payment | Access to the paid plan, renewal, the operator’s own books | from you when you buy, from Stripe after every payment |
| Earlier test requests: name, email address, company, role, message, language | Invitation to the earlier testing phase | from you, through the former request form |
| Feedback: your text, its kind, the screen and address you were on, the business you had open, browser, window size, language, your email address | Improving Bilanzi, telling you where your feedback stands | from you, through «Give feedback» |
| Business: company name, legal form, address, UID, VAT number, bank details | Invoices, payment parts, closings | from you, prefilled from the commercial register on request |
| Business partners: names, addresses, email, telephone, IBAN, payment terms | Issuing invoices, matching payments, dunning | entered by you, read from a receipt or taken over from your shop |
| Receipts: the original file and what was read from it | The ground of an entry, statutory retention | uploaded or photographed by you |
| Bank statements: the file, balances, transactions with counterparty, IBAN and payment reference | Bank reconciliation | uploaded by you |
| Connected shop: the shop’s name and address, its access key in encrypted form, orders with amounts, and the buyers’ names, email addresses and addresses | One entry per day of sales, new contacts if you want them | from Shopify, when you connect your shop |
| Entries and audit trail: amounts, accounts, who posted what and when | the books themselves and their traceability | arises from working in the product |
| Payroll data, if you run payroll: people, wages, deductions | Payroll runs, payslips, annual returns | entered by you |
| Use of the AI: when, what kind, what it cost, who started it. No question, receipt or answer | The plan’s allowance | arises from use |
| Access keys for the interface: name, the key only as a hash, its last four characters, permissions, last use | Programs your business connects itself | created by you |
| Technical logs: timestamp, request identifier, cause of failure | Operation and fault-finding | arises on the request |
What Bilanzi does not collect: no advertising identifiers, no profiling, no sale or disclosure to advertisers or data brokers. Visits to the public pages are counted, visits to the workspace are not; how that works is further down.
Where the data sits, and who else touches it
Bilanzi relies on a number of services to run. Every one of them that touches personal data is listed here, with what it is responsible for and the place where it processes.
| Who | What for | Where |
|---|---|---|
| Supabase | Database, sign-in including the links that confirm an address and reset a password, receipt storage: all account and bookkeeping data lives here | Zurich, Switzerland |
| Railway | Runs the application. Stores no bookkeeping data of its own | Amsterdam, Netherlands |
| Cloudflare | Receives every request to bilanzi.ch, the workspace included, and passes it on to Railway. It sees your IP address and the content of the pages as it does | Data centres worldwide. Cloudflare, Inc. is based in the United States |
| Resend | Sending Bilanzi’s emails: confirming your address, a new password, invitations, notices about access, locked periods and the subscription, progress on and answers to your feedback. Resend receives the address, the subject and the text | Dispatch from Ireland; account data, logs and email metadata held by Resend in the United States |
| Infomaniak | Reads a receipt and proposes an entry. Answers questions about the books. Paid plans only | Switzerland: see its own section below |
| Sign-in, if you choose «Continue with Google» | Ireland and United States: see the section on signing in | |
| Apple | Sign-in, if you choose «Continue with Apple» | Ireland and United States: see the section on signing in |
| Google Ads | Learns whether a click on an ad led to a sign-up, a company or a subscription, unless you object | Ireland and United States: see the section on measuring ads |
| Stripe | Payment for plans and AI packs on Stripe’s own pages, automatic charge for the renewal | Ireland, with processing in the United States as well |
| Shopify | Delivers your shop’s orders, if you connect it. Bilanzi only reads there | Your own Shopify account, under its terms |
| Umami | Counts visits to the public pages | The call goes through bilanzi.ch; Umami processes outside Switzerland |
| Zefix, the federal commercial register | Looks up a company when you search for one. During setup Bilanzi runs that search itself with your business’s name | Switzerland |
| AI development tool | The AI agents the operator builds Bilanzi with read the text of accepted feedback | United States |
Twilio is not in use, because Bilanzi sends no SMS: the second factor is an authenticator app on your own device.
Railway, Cloudflare, Resend, Umami, Google, Apple, Stripe and the AI development tool process outside Switzerland. Cloudflare, Resend, Google, Apple, Stripe and the development tool also process data in the United States. It is named here because it is a difference you should know about before you rely on it.
Signing in with Google and with Apple
Besides email and password you can sign in with Google or with Apple. It has its own section because in that case another company learns that you have an account at Bilanzi.
Bilanzi receives your email address, the confirmation that it is yours, and the identifier under which Google or Apple keeps your account. Google also sends your name and profile picture where they exist. Apple sends no name. Nothing more is requested: no access to contacts, calendar, files or mail.
Google, or Apple, learns that you signed in to Bilanzi, and when. Neither of them learns what you do inside Bilanzi afterwards.
If you choose Apple’s «Hide My Email», Bilanzi receives a relay address instead of your own. That works, but it leads to an account of its own, which does not coincide with an existing one.
Bilanzi never learns your password, and Google and Apple never learn one. Signing in runs through auth.bilanzi.ch, Bilanzi’s sign-in address at Supabase. The exchange uses a single-use secret that never reaches the browser.
Processing this data rests on the contract for your account. Involving Google or Apple rests on your consent: you choose that way in yourself, every time you sign in. You do not depend on it, because email and password get you to the same place.
Google and Apple are themselves responsible for the sign-in data. For people in Switzerland, according to their own statements, that is Google Ireland Limited and Apple Distribution International Ltd., both in Ireland. Both also process data in the United States.
For the United States, the Swiss Federal Council has recognised an adequate level of data protection only for companies certified under the Swiss-U.S. Data Privacy Framework. How Google and Apple safeguard the transfer is set out in their privacy policies:
- Google: https://policies.google.com/privacy
- Apple: https://www.apple.com/legal/privacy/
What we ask when you register
When you register, Bilanzi asks a few optional questions: whether you run your own business, work for a fiduciary or do something else, which software you keep your books in today, and whether there is anything you want to tell us. You can leave every question blank. Registration works either way.
Bilanzi also stores the language you registered in and the source named in the link that brought you here, if it carries one. That is a word inside the link itself, such as the name of a newsletter.
The operator reads these answers to understand where people come from and what they need. They are passed on to nobody and used neither for advertising nor for a profile. They are kept in the database in Zurich.
The answers stay until your account is deleted. If you want them deleted sooner, a message to the operator is enough.
From 15 to 22 September 2026 this website had a form for requesting test access. It is no longer in service. Requests that came in through it stay stored until you ask for them to be deleted: name, email address, company, role, message and language.
When you give feedback
In the workspace you can report a fault or suggest something through «Give feedback». Bilanzi stores your text and the kind of feedback. Along with it go the screen and address you were on, the name of the business you had open, your browser, the window size, the language and your email address.
The operator reads every piece of feedback and decides whether it gets built. In public Bilanzi shows only a feedback’s number and area and how many there are, never the text.
When the operator accepts feedback, it goes to the AI agents Bilanzi is built with, so that they can put it into practice. They run at a provider in the United States. What they get is the number, the kind, the text, the screen and the date. Your email address and the business’s name stay in Bilanzi.
When your feedback is shipped or answered, you get an email. A personal answer from the operator may also come from the operator’s own mailbox.
Feedback stays stored until you ask for it to be deleted.
Measuring Google ads
Bilanzi advertises with ads in Google Search and wants to know which of them work. No Google script runs on bilanzi.ch for this, and your browser talks to no Google address.
If you come from a Google ad, the link carries a click ID assigned by Google and details of the campaign. Your browser keeps both locally under «bz_attr», together with the page you landed on, the name of the page before it without its path, and the time. The entry stays there until you sign up and expires after 90 days. Right after the page loads, Bilanzi removes these details from the address bar so they do not end up in a shared link.
When you sign up, these details go to Bilanzi and are stored with your account, in the database in Zurich. The operator reads the campaign details to see which campaign brings sign-ups. This also applies to links with campaign details that do not come from Google, for example from a newsletter.
If your account carries a click ID, Bilanzi tells Google that your click led to a sign-up, a company set up or a subscription. A sentence below the «Create account» button points this out. You can object at any time, as described below.
Google receives the click ID, the time, the kind of event and, for a subscription, the amount of the first payment. No email address, no name and nothing from your books. Google collects these details once a day as a file from bilanzi.ch. Bilanzi does not allow them to be used for personalised advertising.
For people in Switzerland the recipient is Google Ireland Limited in Ireland. Google also processes the details at Google LLC in the United States. For the United States, the Federal Council has found an adequate level of protection for companies certified under the Swiss-U.S. Data Privacy Framework. According to its own statements, Google LLC is.
Bilanzi deletes the click ID 90 days after the click. The campaign details stay with your account until it is deleted.
You can object to this measuring at any time: in the workspace under More › Account › Privacy, with the box «Don’t use for measuring Google ads», or by email to the address above. After that, Bilanzi reports nothing more about you. What Google has already received stays with Google.
Paying with Stripe
You pay for paid plans and AI packs through Stripe Payments Europe Ltd. in Dublin, Ireland. To pay and to change your payment method, Bilanzi sends you to pages run by Stripe. That is where you give your card or TWINT. No Stripe script runs on bilanzi.ch.
You choose, change and cancel your plan in Bilanzi. Only the people who administer the organisation can do that, and only they see the payments. Bilanzi charges the renewal automatically to the saved payment method. If the plan runs yearly or no payment method is saved, an email arrives a week before.
Bilanzi gives Stripe the organisation’s name, the email address of the person buying, the language, the amount and internal numbers for the organisation, the payment and the plan. On Stripe’s pages your payment details are added. When you buy a plan, Stripe also asks for the billing address and, if you want to give it, your UID or VAT number. Stripe sends the receipt by email.
Bilanzi keeps Stripe’s messages about every payment in full. They include the customer number, the amount, the state of the payment, the brand, last four digits and expiry date of the card or TWINT, and the link to the receipt. Bilanzi never sees a full card number.
Processing rests on the contract for the paid plan. For part of the data Stripe is responsible itself, for example for fraud prevention and its own legal duties. Stripe also processes data in the United States. How it safeguards that is set out in its privacy policy: https://stripe.com/privacy
Payments and receipts belong to the operator’s own books and are kept for ten years (CO Art. 958f para. 1).
When a model reads a receipt
Bilanzi can have a receipt read by a language model and turn it into a proposed entry. This exists only in the paid plans and during a Starter trial that is still running.
A receipt goes to the model as soon as you upload it to the «Receipt inbox» or file it with «Scan a receipt». Under «Receipts» it happens only when you start it for that receipt. Payslips never go out.
Along with the receipt go your business’s name, the currency, today’s date, whether the business is registered for VAT, the file name and the chart of accounts. The model needs these to propose an entry.
The same model answers the questions you ask Bilanzi about your books. The question then goes out with an extract from the books, limited to what you are allowed to see yourself. The extract can contain the names of customers, suppliers and bank counterparties, payment references, figures from the income statement and the total of the latest payroll run.
The provider is Infomaniak Network SA in Geneva, and the processing takes place in Switzerland. In the workspace Bilanzi names the provider, the model and the countries on the screen where the work happens. Only what is expressly released on a recorded, evidenced and approved route goes out; otherwise the database refuses the call. Not the screen, the database.
By its own account, Infomaniak does not store the requests and does not use them to train models. The contract terms the operator agreed with Infomaniak apply.
For the plan’s allowance Bilanzi records when the AI was used, for what, what it cost and who started it. The question, the receipt and the answer are not part of that record.
The proposal stays a proposal. Nothing is posted until a person accepts it, and the acceptance is recorded in the audit trail.
How visits are counted
On the public pages Bilanzi counts which page was opened. Nothing is counted in the workspace: a path there can carry the id of a receipt or an invoice, and such a path belongs in no statistic.
Counting works without a cookie and without an identifier left behind in your browser. That is why no consent banner appears on these pages.
Your browser talks to no foreign address for it. The counting script is served by bilanzi.ch, and this server takes the measurement and passes it on to Umami. What travels with it:
- the page you opened and the page you came from
- language, screen size, browser and operating system
- your IP address, so that Umami can tell one visit from the next; Bilanzi does not store it
Anyone whose browser is set to Do Not Track is not counted. The browser still loads the counting script, and while it does, bilanzi.ch passes your IP address and your browser’s identification on to Umami.
Nothing from your books is ever part of a measurement: no amount, no name, no receipt.
Cookies and what stays in the browser
Bilanzi sets neither an advertising cookie nor a counting cookie: the counting described above does without one, and the workspace is not counted at all. That is why no consent banner appears: the four cookies below are needed for a sign-in, and a necessary cookie is not something you are asked to accept.
These four cookies are needed for a sign-in to work at all:
| Name | Purpose | How long |
|---|---|---|
| __Host-bilanzi-access | Your signed-in session. No script in the browser can read it | up to one hour |
| __Host-bilanzi-refresh | Renews the session while you are working | until the browser is closed |
| __Host-bilanzi-oauth | The single-use secret of a sign-in through Google or Apple | ten minutes, then spent |
| bilanzi-workspace-locale | The language you chose | until you change it |
Your browser also keeps a few things locally: which way you signed in last time, which business and which screen you had open last, which notices you dismissed and which changelog entries you have already seen. None of that ever reaches Bilanzi.
Until you register it remembers the plan you chose, and until you accept it, an invitation. Both reach Bilanzi when you register or accept.
While a tab is open it holds actions whose outcome is still open and Bilanzi’s answers to your questions. Both disappear with the tab.
Whether a help panel is open or closed is stored by Bilanzi with your account, so that it stays the way you left it on every device. The browser keeps a copy.
If you came from an ad or a link with campaign details, your browser keeps them under «bz_attr» until you sign up, for at most 90 days. They reach Bilanzi only when you sign up. More in the section on measuring Google ads.
How long things stay
Bookkeeping data is subject to a statutory retention duty: the books, the vouchers and business correspondence for ten years (CO Art. 958f para. 1), papers connected with immovable property for twenty years (VAT Act Art. 70 para. 3).
Bilanzi treats that as a rule rather than a hint: inside the period the database refuses to destroy a receipt attached to an entry or an expense claim. An entry is never overwritten; a correction is a visible, linked reversal.
You can have your account closed at any time. Your business’s books are untouched by that while the period runs. That is not Bilanzi’s decision but the business’s duty.
For anything outside the retention duty there is no automatic deletion today: invitations, feedback and the records of AI use stay stored. If you want any of it deleted, a message to the operator is enough. Bilanzi does not store the text of the emails it sends.
What is enforced to protect this data
The following points are enforced in code and covered by automated tests; they are not statements of intent:
- The separation between businesses lives in the database and is checked on every single query, not in the application in front of it.
- Your access credential never reaches the browser in readable form: it sits in a cookie no script can get at.
- The second factor is optional and belongs to signing in: whoever sets up an authenticator app confirms once after the password. What a person may then do is decided by their role and their mandate.
- The audit trail is chained: a later change would be detectable from the data alone.
- Transport is encrypted throughout, and the browser talks only to bilanzi.ch. Cloudflare receives that connection and passes it on to Bilanzi. No connection leaves your session for another service, except a redirect you start yourself, such as signing in with Google or Apple or paying at Stripe.
Your rights
You may ask which data about you is processed, require the correction of wrong details, request your data in a common format, and object to processing where it does not rest on a statutory duty.
For your account, turn to the operator named above. For a business’s books, turn to that business; Bilanzi acts there on its instruction and passes on a request that reaches it.
Handing the data over is not a favour but a function: under «Take the books out» the workspace hands over a business’s books as a file, with nobody to ask.
The route to the Federal Data Protection and Information Commissioner is open to you as well.
Changes
This notice is updated when the processing changes, for example when a service is connected or replaced. The date above names the state, and material changes are communicated to the businesses that have signed up.