Skip to content
Bilanzi

Privacy notice

Controller

Two roles, and why the difference matters

For your account, Bilanzi is the controller: your email address, your sign-ins, your second factor, your language. Bilanzi needs that data to let you in and to keep your account.

For your business’s books, it is not. The receipts, contacts, invoices and entries belong to the business. Bilanzi processes them on its instructions and uses them for nothing else, not for analysis, not for advertising, not for improving a model.

In practice: the operator answers questions about your account. The business answers questions about its own figures; it alone decides roles, mandates and who sees which row.

Which data, what for

What Bilanzi does not collect: no advertising identifiers, no profiling, no sale or disclosure to advertisers or data brokers. Visits to the public pages are counted, visits to the workspace are not; how that works is further down.

Where the data sits, and who else touches it

Bilanzi relies on a number of services to run. Every one of them that touches personal data is listed here, with what it is responsible for and the place where it processes.

Twilio is not in use, because Bilanzi sends no SMS: the second factor is an authenticator app on your own device.

Railway, Cloudflare, Resend, Umami, Google, Apple, Stripe and the AI development tool process outside Switzerland. Cloudflare, Resend, Google, Apple, Stripe and the development tool also process data in the United States. It is named here because it is a difference you should know about before you rely on it.

Signing in with Google and with Apple

Besides email and password you can sign in with Google or with Apple. It has its own section because in that case another company learns that you have an account at Bilanzi.

Bilanzi receives your email address, the confirmation that it is yours, and the identifier under which Google or Apple keeps your account. Google also sends your name and profile picture where they exist. Apple sends no name. Nothing more is requested: no access to contacts, calendar, files or mail.

Google, or Apple, learns that you signed in to Bilanzi, and when. Neither of them learns what you do inside Bilanzi afterwards.

If you choose Apple’s «Hide My Email», Bilanzi receives a relay address instead of your own. That works, but it leads to an account of its own, which does not coincide with an existing one.

Bilanzi never learns your password, and Google and Apple never learn one. Signing in runs through auth.bilanzi.ch, Bilanzi’s sign-in address at Supabase. The exchange uses a single-use secret that never reaches the browser.

Processing this data rests on the contract for your account. Involving Google or Apple rests on your consent: you choose that way in yourself, every time you sign in. You do not depend on it, because email and password get you to the same place.

Google and Apple are themselves responsible for the sign-in data. For people in Switzerland, according to their own statements, that is Google Ireland Limited and Apple Distribution International Ltd., both in Ireland. Both also process data in the United States.

For the United States, the Swiss Federal Council has recognised an adequate level of data protection only for companies certified under the Swiss-U.S. Data Privacy Framework. How Google and Apple safeguard the transfer is set out in their privacy policies:

What we ask when you register

When you register, Bilanzi asks a few optional questions: whether you run your own business, work for a fiduciary or do something else, which software you keep your books in today, and whether there is anything you want to tell us. You can leave every question blank. Registration works either way.

Bilanzi also stores the language you registered in and the source named in the link that brought you here, if it carries one. That is a word inside the link itself, such as the name of a newsletter.

The operator reads these answers to understand where people come from and what they need. They are passed on to nobody and used neither for advertising nor for a profile. They are kept in the database in Zurich.

The answers stay until your account is deleted. If you want them deleted sooner, a message to the operator is enough.

From 15 to 22 September 2026 this website had a form for requesting test access. It is no longer in service. Requests that came in through it stay stored until you ask for them to be deleted: name, email address, company, role, message and language.

When you give feedback

In the workspace you can report a fault or suggest something through «Give feedback». Bilanzi stores your text and the kind of feedback. Along with it go the screen and address you were on, the name of the business you had open, your browser, the window size, the language and your email address.

The operator reads every piece of feedback and decides whether it gets built. In public Bilanzi shows only a feedback’s number and area and how many there are, never the text.

When the operator accepts feedback, it goes to the AI agents Bilanzi is built with, so that they can put it into practice. They run at a provider in the United States. What they get is the number, the kind, the text, the screen and the date. Your email address and the business’s name stay in Bilanzi.

When your feedback is shipped or answered, you get an email. A personal answer from the operator may also come from the operator’s own mailbox.

Feedback stays stored until you ask for it to be deleted.

Bilanzi advertises with ads in Google Search and wants to know which of them work. No Google script runs on bilanzi.ch for this, and your browser talks to no Google address.

If you come from a Google ad, the link carries a click ID assigned by Google and details of the campaign. Your browser keeps both locally under «bz_attr», together with the page you landed on, the name of the page before it without its path, and the time. The entry stays there until you sign up and expires after 90 days. Right after the page loads, Bilanzi removes these details from the address bar so they do not end up in a shared link.

When you sign up, these details go to Bilanzi and are stored with your account, in the database in Zurich. The operator reads the campaign details to see which campaign brings sign-ups. This also applies to links with campaign details that do not come from Google, for example from a newsletter.

If your account carries a click ID, Bilanzi tells Google that your click led to a sign-up, a company set up or a subscription. A sentence below the «Create account» button points this out. You can object at any time, as described below.

Google receives the click ID, the time, the kind of event and, for a subscription, the amount of the first payment. No email address, no name and nothing from your books. Google collects these details once a day as a file from bilanzi.ch. Bilanzi does not allow them to be used for personalised advertising.

For people in Switzerland the recipient is Google Ireland Limited in Ireland. Google also processes the details at Google LLC in the United States. For the United States, the Federal Council has found an adequate level of protection for companies certified under the Swiss-U.S. Data Privacy Framework. According to its own statements, Google LLC is.

Bilanzi deletes the click ID 90 days after the click. The campaign details stay with your account until it is deleted.

You can object to this measuring at any time: in the workspace under More › Account › Privacy, with the box «Don’t use for measuring Google ads», or by email to the address above. After that, Bilanzi reports nothing more about you. What Google has already received stays with Google.

Paying with Stripe

You pay for paid plans and AI packs through Stripe Payments Europe Ltd. in Dublin, Ireland. To pay and to change your payment method, Bilanzi sends you to pages run by Stripe. That is where you give your card or TWINT. No Stripe script runs on bilanzi.ch.

You choose, change and cancel your plan in Bilanzi. Only the people who administer the organisation can do that, and only they see the payments. Bilanzi charges the renewal automatically to the saved payment method. If the plan runs yearly or no payment method is saved, an email arrives a week before.

Bilanzi gives Stripe the organisation’s name, the email address of the person buying, the language, the amount and internal numbers for the organisation, the payment and the plan. On Stripe’s pages your payment details are added. When you buy a plan, Stripe also asks for the billing address and, if you want to give it, your UID or VAT number. Stripe sends the receipt by email.

Bilanzi keeps Stripe’s messages about every payment in full. They include the customer number, the amount, the state of the payment, the brand, last four digits and expiry date of the card or TWINT, and the link to the receipt. Bilanzi never sees a full card number.

Processing rests on the contract for the paid plan. For part of the data Stripe is responsible itself, for example for fraud prevention and its own legal duties. Stripe also processes data in the United States. How it safeguards that is set out in its privacy policy: https://stripe.com/privacy

Payments and receipts belong to the operator’s own books and are kept for ten years (CO Art. 958f para. 1).

When a model reads a receipt

Bilanzi can have a receipt read by a language model and turn it into a proposed entry. This exists only in the paid plans and during a Starter trial that is still running.

A receipt goes to the model as soon as you upload it to the «Receipt inbox» or file it with «Scan a receipt». Under «Receipts» it happens only when you start it for that receipt. Payslips never go out.

Along with the receipt go your business’s name, the currency, today’s date, whether the business is registered for VAT, the file name and the chart of accounts. The model needs these to propose an entry.

The same model answers the questions you ask Bilanzi about your books. The question then goes out with an extract from the books, limited to what you are allowed to see yourself. The extract can contain the names of customers, suppliers and bank counterparties, payment references, figures from the income statement and the total of the latest payroll run.

The provider is Infomaniak Network SA in Geneva, and the processing takes place in Switzerland. In the workspace Bilanzi names the provider, the model and the countries on the screen where the work happens. Only what is expressly released on a recorded, evidenced and approved route goes out; otherwise the database refuses the call. Not the screen, the database.

By its own account, Infomaniak does not store the requests and does not use them to train models. The contract terms the operator agreed with Infomaniak apply.

For the plan’s allowance Bilanzi records when the AI was used, for what, what it cost and who started it. The question, the receipt and the answer are not part of that record.

The proposal stays a proposal. Nothing is posted until a person accepts it, and the acceptance is recorded in the audit trail.

How visits are counted

On the public pages Bilanzi counts which page was opened. Nothing is counted in the workspace: a path there can carry the id of a receipt or an invoice, and such a path belongs in no statistic.

Counting works without a cookie and without an identifier left behind in your browser. That is why no consent banner appears on these pages.

Your browser talks to no foreign address for it. The counting script is served by bilanzi.ch, and this server takes the measurement and passes it on to Umami. What travels with it:

Anyone whose browser is set to Do Not Track is not counted. The browser still loads the counting script, and while it does, bilanzi.ch passes your IP address and your browser’s identification on to Umami.

Nothing from your books is ever part of a measurement: no amount, no name, no receipt.

Cookies and what stays in the browser

Bilanzi sets neither an advertising cookie nor a counting cookie: the counting described above does without one, and the workspace is not counted at all. That is why no consent banner appears: the four cookies below are needed for a sign-in, and a necessary cookie is not something you are asked to accept.

These four cookies are needed for a sign-in to work at all:

Your browser also keeps a few things locally: which way you signed in last time, which business and which screen you had open last, which notices you dismissed and which changelog entries you have already seen. None of that ever reaches Bilanzi.

Until you register it remembers the plan you chose, and until you accept it, an invitation. Both reach Bilanzi when you register or accept.

While a tab is open it holds actions whose outcome is still open and Bilanzi’s answers to your questions. Both disappear with the tab.

Whether a help panel is open or closed is stored by Bilanzi with your account, so that it stays the way you left it on every device. The browser keeps a copy.

If you came from an ad or a link with campaign details, your browser keeps them under «bz_attr» until you sign up, for at most 90 days. They reach Bilanzi only when you sign up. More in the section on measuring Google ads.

How long things stay

Bookkeeping data is subject to a statutory retention duty: the books, the vouchers and business correspondence for ten years (CO Art. 958f para. 1), papers connected with immovable property for twenty years (VAT Act Art. 70 para. 3).

Bilanzi treats that as a rule rather than a hint: inside the period the database refuses to destroy a receipt attached to an entry or an expense claim. An entry is never overwritten; a correction is a visible, linked reversal.

You can have your account closed at any time. Your business’s books are untouched by that while the period runs. That is not Bilanzi’s decision but the business’s duty.

For anything outside the retention duty there is no automatic deletion today: invitations, feedback and the records of AI use stay stored. If you want any of it deleted, a message to the operator is enough. Bilanzi does not store the text of the emails it sends.

What is enforced to protect this data

The following points are enforced in code and covered by automated tests; they are not statements of intent:

Your rights

You may ask which data about you is processed, require the correction of wrong details, request your data in a common format, and object to processing where it does not rest on a statutory duty.

For your account, turn to the operator named above. For a business’s books, turn to that business; Bilanzi acts there on its instruction and passes on a request that reaches it.

Handing the data over is not a favour but a function: under «Take the books out» the workspace hands over a business’s books as a file, with nobody to ask.

The route to the Federal Data Protection and Information Commissioner is open to you as well.

Changes

This notice is updated when the processing changes, for example when a service is connected or replaced. The date above names the state, and material changes are communicated to the businesses that have signed up.