Privacy

Privacy policy

Last updated: 24 September 2026

Early access. Countbean is in private beta and run by a solo maker. This policy describes how we handle your data today, in plain language. It is a starting point, not a finished legal document — it will grow more formal before general availability, and we'll date any material change. Questions? Email support@countbean.com.

01What Countbean is

Countbean gives you a cloud book — a private, git-versionedBeancount ledger with theFava web UI, hosted for you on Fly.io. An AI agent can read and write that ledger when you ask it to — the one we host, which you talk to in Telegram, or your own Claude connected through our plugin. This policy covers what we store, why, who else handles it, and how you stay in control.

02What we store

To run your book, we hold:

  • Your ledger itself — plain-text .beancount files and their full Git history (every entry, commit, and revert).
  • Account basics — the email address you sign up with and the settings needed to run and bill your book.
  • Your email preference — whether you asked for product updates, when you told us, and where you told us from. We keep that record so we can show we only sent what you agreed to.
  • Operational logs — ordinary server and request logs used to keep the service up and debug problems.

The marketing site. The public pages on countbean.com use Google Analytics to count visits and see which pages are worth writing. It runs on these public pages only — never inside your book or the app — so it never sees a transaction, a balance, or an account name.

Analytics cookies are off until you say otherwise. On your first visit we ask. Until you accept — and if you decline — Google Analytics runs without cookies and without anything that identifies you or follows you between visits: we get a count of the page view and nothing more. If you accept, it sets its own cookies and tells Google your IP address, browser and the page you are on. Either way you can change your mind from Cookies at the bottom of any page, and a browser-level tracking blocker stops all of it. Nothing on the site depends on any of this.

We do not sell your data, and we do not use the contents of your ledger to advertise to you.

The email we send you. Some of it you cannot turn off, because your account depends on it — password resets, receipts, security notices, and anything about a book you own. Product updates are separate and opt-in. We only send those if you asked for them, every one carries a one-click unsubscribe, and you can change your mind at any time from your profile. Turning them off never affects the first kind.

03Your financial data is text, in Git

A cloud book is just files. Your transactions live in plain.beancount text, versioned in a private Git repository we host for you. That is the whole design: nothing proprietary, nothing to decode, and a full, auditable history of every change — human or AI.

Because it is plain text there is nothing proprietary to decode, and you can read your whole book in the browser. The one-click export that hands you a copy is not built yet — it is on theroadmap, and until it ships the way to get a copy is to ask us. Your book is private to your account; it is not shared with other users.

04The AI features

There are two ways an AI can reach your book, and they involve different companies.

The agent we host. When you message it in Telegram — to log a transaction, read a receipt, or answer a question — the parts of your ledger it needs, and any receipt photo you send, go from our servers toOpenRouter, which passes the request to Google's Gemini model. Both process it on our behalf to produce the answer. We send every one of these requests with OpenRouter's setting that allows only providers whose policy is not to store or train on what they are sent.

Your own Claude. If you connect Claude to your book through our plugin, your Claude reads and writes the book under your own agreement with Anthropic. We do not send your data to Anthropic; your Claude asks for it.

If you use neither, your ledger is not sent to any AI. Every AI-written change lands as a reviewable Git commit, so you can see exactly what changed and revert it.

05Security & where it runs

Your book runs on Fly.io in Frankfurt, Germany, and is served only over HTTPS. Passwords are stored hashed, not in the clear. These are the companies that handle your data on our behalf, and what each one does:

  • Fly.io — runs the app and your book.
  • Tigris (object storage provided through Fly.io) — nightly backups of your book, and files you send us, such as receipt photos.
  • OpenRouter — routes requests from the agent we host to the AI model.
  • Google — runs that model (Gemini). Separately, Google handles sign-in if you choose "Continue with Google", and Google Analytics runs on the public marketing pages only.
  • Stripe — takes payments. We never see your card number.
  • Cloudflare — sends our email.
  • Telegram — carries messages between you and the agent we host, if you connect it.

Anthropic is not on this list because we do not send them anything; see section 04. Each of these processes data under its own terms. We keep the footprint small and the moving parts few — but this is a beta run by one person, so please don't treat it as a compliance-audited system yet.

06Your control

  • No lock-in. Your book is plain text plus Git — there is no proprietary format to escape. The one-click export is not built yet (roadmap); until it ships, ask us and we will get you a copy.
  • Delete it. Ask us to delete your book and account and we'll remove them, subject to short-lived backups aging out.
  • Reach a human. Email support@countbean.com to access, correct, export, or delete your data, or with any privacy question.

07Contact

Countbean is operated by an independent maker. For anything in this policy, or any question about your data, emailsupport@countbean.com.