This Privacy Policy describes how Blue Cielo, Inc. ("Blue Cielo," "we," "us," or "our") handles information in connection with PolyAccounts (polyaccounts.com and related apps — the "Services"). PolyAccounts is a multi-tenant double-entry accounting product. Other Blue Cielo brands have separate notices.
1. Controller and contact
Controller: Blue Cielo, Inc.
1887 Whitney Mesa Dr Ste 1973
Henderson, NV 89014
Privacy / support (interim): support@polyaccounts.com
Security reports: email support@polyaccounts.com with subject line SECURITY (or use support@polyaccounts.com?subject=SECURITY) until a dedicated, monitored security@ address exists.
2. Information we process
Depending on how you use the Services, we may process:
- Account identity — name, email, password or auth tokens, role, and profile settings for you and invited users.
- Company / workspace — company or entity name, locale, currency, tax identifiers you enter, and workspace configuration.
- Books and records — chart of accounts, journal entries, invoices, payments, budgets, forecasts, reports, and other accounting data you or your users create or import. This includes law-firm time & billing and trust-accounting features when enabled in your workspace (product features, not a bar or professional certification).
- Bank import metadata — imported transaction descriptions, amounts, dates, account labels, and connection status. When Plaid bank connections are enabled, bank authentication is handled through Plaid. PolyAccounts stores encrypted Plaid access tokens on its server to download authorized account activity in the background. We retain downloaded transaction data and connection status for accounting review. We do not receive or store your bank password.
- Files and attachments — documents you upload (e.g. statements, receipts, exports).
- Billing references — subscription plan, invoices, and payment-processor references (e.g. Stripe customer/payment IDs). We do not store full payment card numbers; card data is processed by the payment provider when payments are enabled. During early access, access may be complimentary ($0). Stripe applies when paid plans or card payment links are enabled.
- Integration evaluations include the name, business email, organization, role and workflow you submit in our partner request form. Netlify processes that form so we can respond to your request. We record agent credential creation and first successful accounting-read timestamps to measure aggregate adoption, without copying accounting payloads into these metrics.
- Communications — support messages and related metadata.
- Technical logs — IP address, device/browser type, timestamps, approximate location derived from IP, and usage events needed to operate, secure, and debug the Services.
We do not claim to store bank credentials in PolyAccounts. Plaid access tokens are stored encrypted on the PolyAccounts server for authorized downloads. Stripe processes card details. PolyAccounts stores connected-account identifiers, invoice and subscription references, payment status and the platform fee associated with a payment.
3. How we use information
We use information to:
- Provide, maintain, and improve the Services (including live reports, imports, budgets, and multi-user workspaces).
- Authenticate users, manage invitations, and enforce tenant boundaries.
- Process subscriptions and payments when paid plans are enabled.
- Send transactional email (account, security, billing, product notices) and, with consent, limited marketing.
- Detect abuse, investigate security issues, and comply with law.
- Generate aggregated, de-identified metrics that do not identify you or your customers.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
4. Service providers (subprocessors)
We use vendors to host and operate the Services. Current infrastructure we may rely on includes:
| Role | Provider |
|---|---|
| Frontend hosting | Netlify |
| API hosting | Render |
| Database | Neon (PostgreSQL) |
| Transactional email | SendGrid |
Vendors process data only as needed to provide their services to us, under contractual and technical safeguards appropriate to the data.
5. Email, SMS, and phone
We may contact you by email, SMS, or phone for account, support, and (with consent) marketing purposes, including through automated systems when those channels are enabled.
- Email: opt out of marketing via the unsubscribe link. Transactional account messages may continue.
- SMS (when SMS features are enabled): reply STOP to cancel and HELP for help. Msg & data rates may apply. Consent to receive SMS is not a condition of purchase.
- Phone: ask to be removed or contact support@polyaccounts.com. Opting out of marketing does not stop transactional messages required to operate your account.
Text messaging originator opt-in data and consent will not be shared with third parties, except aggregators, carriers, and providers strictly necessary to deliver and support the text messaging service. We do not sell or rent SMS opt-in data or mobile numbers. SMS consent is not shared with third parties or affiliates for marketing purposes.
6. Retention
We retain account and workspace data while your account is active and for a reasonable period afterward as needed for backups, dispute resolution, security, and legal obligations. You remain responsible for exporting records you must keep under tax or professional rules. Contact support@polyaccounts.com for current practice.
7. Security (early-access honesty)
We implement technical and organizational measures appropriate to an early-access SaaS product (access controls, encrypted transit where configured, tenant scoping in the application layer, and operational monitoring).
We do not claim bank-grade security, SOC 2 certification, or multi-factor authentication (MFA) in the product at this time. Report suspected vulnerabilities to support@polyaccounts.com with subject SECURITY.
8. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, export, or object to certain processing of personal information. Contact support@polyaccounts.com. Workspace owners can typically manage user access and export books from within the product where those features exist.
9. Children and business use
The Services are for business and professional use by adults. They are not directed to children under 18 (or under 16 where a higher standard applies). We do not knowingly collect personal information from children.
10. International users
The Services may be hosted in the United States. If you access them from another country, you understand information may be processed in the U.S. and other locations where our providers operate.
11. Changes
We may update this Policy. We will post the revised effective date and, for material changes, provide additional notice where appropriate. Continued use after the effective date means you accept the updated Policy.
12. Contact
Blue Cielo, Inc.
1887 Whitney Mesa Dr Ste 1973
Henderson, NV 89014
Email: support@polyaccounts.com
Security: support@polyaccounts.com?subject=SECURITY