mainbook.aimainbook.aimainbook.ai
FeaturesHow it worksProductPricing
Log InSign Up
  • Terms
  • API Terms
  • Privacy
  • Refunds
  • Disclaimer
  • DPA
  • AI Disclosure
  • AUP
  • Cookies
  • Sub-processors

Legal

  • Terms of Service
  • Developer API Terms
  • Privacy Policy
  • Refund Policy
  • Disclaimer and Important Notices
  • Data Processing Agreement
  • AI and Data Processing Disclosure
  • Acceptable Use Policy
  • Cookie Policy
  • Sub-Processors

Privacy Policy

Version: 1.4

Last Updated: 2026-08-10

Effective Date: 2026-08-10 for users first accepting the MainBook Terms on or after that date; 2026-09-10 for users who accepted an earlier version.

This Privacy Policy explains how Human Beyond LLC ("MainBook", "Company", "we", "us", "our"), a Florida limited liability company with its principal place of business at 1818 Hollywood Blvd, Hollywood, FL 33020, collects, uses, shares, and protects personal information in connection with the MainBook service available at mainbook.ai (the "Service").

This Privacy Policy is incorporated by reference into our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms of Service. If you do not agree with this Privacy Policy, you may not access or use the Service.

This Privacy Policy is supplemented by our Data Processing Agreement, AI Disclosure, Cookie Policy, and Sub-Processors list.


1. Who Is Responsible for Your Data

The data controller for personal information processed under this Privacy Policy is Human Beyond LLC, a Florida limited liability company, contactable at:

  • Email: hello@human-beyond.ai
  • Mail: Human Beyond LLC, 1818 Hollywood Blvd, Hollywood, FL 33020, United States

For data-protection inquiries, including requests under the General Data Protection Regulation ("GDPR"), the UK GDPR, the California Consumer Privacy Act ("CCPA"), or other applicable privacy laws, please contact us at the email address above.

2. Whose Data Is This About

The Service processes several distinct categories of data. It is important to understand the distinction, particularly if you are a professional (bookkeeper, accountant, certified public accountant, tax preparer, or financial advisor) processing documents on behalf of clients.

2.1 Your personal data (you, the User). This includes your name, email address, account credentials, payment-related identifiers, IP address, device fingerprint, and usage data generated by your interaction with the Service. We are the data controller for this information.

2.2 Third-party personal data contained in documents you upload. When you upload a bank or credit card statement, that document may contain personal data of third parties — for example, the names, addresses, account numbers, transaction descriptions, and other identifying information of the account holder, employers, payees, vendors, customers, or others. If you determine the purposes and means of that processing, you are the controller and MainBook acts as your processor. If you process the data on behalf of another controller (for example, your client), you act as a processor and MainBook acts as your sub-processor. These relationships are governed by our Data Processing Agreement.

2.3 Aggregated and anonymized data. We may generate aggregated or anonymized statistics, performance metrics, and operational telemetry from the use of the Service. Such data, once anonymized so that no individual can reasonably be identified, is not personal data and may be used by us for any legitimate business purpose.

3. Your Representations as the Uploader

When you upload a document containing personal data of third parties, you represent and warrant that:

(a) you have all legal authority required to process such data through the Service, including any consent or notification required under applicable law;

(b) you have provided all required privacy notices to the data subjects whose data is contained in the document;

(c) you accept full responsibility in your applicable role as controller or processor for such third-party data; and

(d) MainBook acts as your processor, or as your sub-processor when you process the data on behalf of another controller.

If you are unable to make these representations, you must not upload the document.

4. Personal Data We Collect from You

4.1 Account data. Email address, password (stored in hashed form using industry-standard hashing algorithms), display name (if provided), and authentication-related identifiers (including identifiers from Google OAuth if you sign in via Google).

4.2 Onboarding data. If you complete the onboarding quiz, your responses (used to tailor the Service experience).

4.3 Profile and settings data. Any settings, preferences, dashboard layout choices, two-factor authentication configuration (TOTP secrets are encrypted at the application level; backup codes are stored using one-way password hashes), and similar customization data you create or modify.

4.3.1 Developer API credential data. If you use the Developer API, we store the name you assign to each API key, a non-secret key prefix, a one-way cryptographic digest of the key, and creation, last-used, and revocation timestamps. The full secret key is shown only once when created and is not stored in retrievable form. We also retain records of your acceptance of the version of the Developer API Terms presented when the key was created.

4.4 Content you upload. Bank statement and credit card statement PDFs, images, or other document files you submit for conversion.

4.4.1 Document unlock passwords. If a document you upload is password-protected (encrypted), we may ask you to enter that document's password so we can unlock it for conversion. We receive this password over an encrypted connection and use it one time, on our server, solely to decrypt that specific file. We do not store it in our database or our logs, do not use it for any other purpose, and discard it after the single decryption attempt.

4.5 Output data. Structured data generated by the Service from your uploaded documents (extracted transactions, balances, account metadata, and exported files in XLSX, CSV, or JSON format).

4.6 Payment-related data. When you purchase Credits, our payment processor (Stripe) collects your payment-method information directly. We receive a transaction identifier, the package code purchased, the amount paid, and a receipt URL. We do not receive or store your full payment-card number.

4.7 Communications data. If you contact us (for example, via the in-product help form or by email), we receive and retain the content of your communications, your email address, and any attachments you provide.

4.8 Technical and usage data. IP address, user agent (browser type, operating system version, device type), referral URL, timestamps of access, pages or features accessed, document processing metadata (file size, page count, processing duration, success or error status), and similar diagnostic information.

4.9 Device fingerprint. A device fingerprint generated from technical signals (used for anti-fraud and guest-tier abuse prevention).

4.10 Anti-fraud signals. Cloudflare Turnstile challenge results and similar anti-fraud telemetry generated during your interaction with the Service.

4.11 Error and crash telemetry. Diagnostic information about errors and crashes within the Service, including stack traces, request paths, error type, release, and pseudonymous internal identifiers. Server-side local-variable and incoming-request-body capture are disabled where applicable; request-body data is removed from events before transmission across our browser, server, and edge configurations; and document-content fields and common secrets are filtered. We do not use session replay or performance tracing and do not intentionally send uploaded documents or Output to Sentry.

4.12 Analytics data. With your consent, we use Google Analytics 4 to measure pages and features viewed and product-funnel events such as signup, upload, conversion, warnings, export, package selection, checkout, and purchase. Event parameters may include counts and categories, an opaque job or transaction identifier, Credit-package code and page quantity, and the price or amount paid for a MainBook Credit purchase. They do not include the transaction rows, descriptions, amounts, or balances extracted from your uploaded statements. Google may also receive a Google Analytics client identifier, page URL, device and browser metadata, and your IP address momentarily to derive approximate location. Before consent, Google Consent Mode may send cookieless event pings while analytics and advertising storage are denied; no analytics cookie or persistent Google Analytics client identifier is set by us at that stage. Cookie-based analytics, consent-dependent identifiers, and consent-dependent event payloads begin only after consent. Rejecting, withdrawing consent, or sending a Global Privacy Control signal immediately stops new browser-side consent-dependent collection and prevents identifiers from being attached to a new upload or checkout flow. We also send that denial to our backend. Once the denial is recorded by our server, pending consent-linked backend conversion or purchase events are rechecked at send time and are not sent. If the device is offline or the consent update temporarily cannot reach our server, the backend cutoff begins when the server records the denial; processing and event sends completed before that time remain unaffected. See our Cookie Policy.

4.13 Advertising and measurement data (Meta). With your consent, we use the Meta Pixel in the browser and Meta Conversions API events initiated by our backend for advertising conversion measurement and audience building for our Meta (Facebook/Instagram) campaigns. Meta may receive the _fbp browser identifier and, if you arrived from a Meta ad, the _fbc click identifier; page URL and referrer; IP address and device/browser metadata; and funnel events such as PageView, registration, file upload, conversion, warning status, export, package selection, checkout, and purchase. Event parameters may include counts and categories, page count, document kind, export format, Credit-package code, a deduplication identifier, and the price or amount paid for a MainBook Credit purchase. They do not include your uploaded statement, row-level Output, or the transaction descriptions, amounts, or balances extracted from that statement. We do not enable Advanced Matching and do not send hashed email, phone number, or name to Meta. Browser events and capture of identifiers for backend events remain disabled unless effective consent is granted when the upload or checkout flow is initiated. Rejecting, withdrawing consent, or sending a Global Privacy Control signal immediately stops new browser capture. Once the denial is recorded by our server, any pending consent-linked backend Meta event is rechecked at send time and is not sent; if the update temporarily cannot reach our server, that backend cutoff begins when the server records it.

5. How We Use Personal Data

We use personal data for the following purposes:

5.1 To provide the Service. Authenticating you, creating and managing your Account, processing documents you upload, generating Output, delivering exports, charging you for Credits, sending Service notifications, and providing customer support.

5.2 To secure the Service. Detecting and preventing fraud, abuse, unauthorized access, and security incidents; enforcing our Terms of Service and Acceptable Use Policy; and maintaining the integrity, availability, and confidentiality of the Service.

5.3 To comply with our obligations. Meeting our legal, regulatory, tax, accounting, audit, dispute resolution, and contractual obligations, including obligations imposed by our payment processor, financial-services partners, and other sub-processors.

5.4 To operate, analyze, and improve the Service. Generating aggregated and anonymized analytics, monitoring performance, identifying bugs and errors, improving the reliability and accuracy of the conversion pipeline, prioritizing engineering work, and similar internal operational purposes. This includes, with your consent, first-party web analytics collected via Google Analytics 4, and advertising conversion measurement and audience building for our Meta (Facebook/Instagram) ad campaigns through the Meta Pixel and Conversions API.

5.5 To communicate with you. Sending transactional and Service-related communications (including notifications about your Account, document processing status, billing, security, and material changes to our Terms or this Privacy Policy). We may also send occasional account check-in and feedback messages — for example, asking how your first conversion went or what stopped you from using the Service — to understand how to improve the Service; we send these on the basis of our legitimate interests, and every such message includes a one-click unsubscribe link, so you can opt out at any time and we will stop sending them. Separately, with your opt-in consent, we may send product updates, tips, or other promotional communications; you may withdraw that consent at any time using the unsubscribe link in those messages.

5.6 To enforce our rights. Establishing, exercising, or defending legal claims, and complying with valid legal process.

6. Lawful Basis for Processing (GDPR)

Where the GDPR or UK GDPR applies to our processing of your personal data, we rely on the following lawful bases under Article 6:

PurposeLawful Basis
Providing the Service to you (Section 5.1)Performance of a contract (Article 6(1)(b))
Securing the Service, preventing fraud and abuse (Section 5.2)Legitimate interests in protecting our business, our users, and our infrastructure (Article 6(1)(f))
Complying with legal obligations (Section 5.3)Legal obligation (Article 6(1)(c))
Operating, analyzing, and improving the Service (Section 5.4)Legitimate interests in operating, maintaining, and improving a useful product (Article 6(1)(f))
Web analytics via Google Analytics (Section 4.12)Consent (Article 6(1)(a)) — only when you accept analytics on our cookie banner
Advertising and conversion measurement via the Meta Pixel and Conversions API (Section 4.13)Consent (Article 6(1)(a)) — only when you accept cookies on our banner
Transactional communications (Section 5.5)Performance of a contract (Article 6(1)(b))
Account check-in and feedback messages (Section 5.5)Legitimate interests in understanding user needs and improving the Service (Article 6(1)(f)); you may opt out at any time via the unsubscribe link, and object under Section 11
Non-transactional product updates (Section 5.5)Consent (Article 6(1)(a)) — only when you have opted in
Defending legal claims (Section 5.6)Legitimate interests, or where required, legal obligation

You have the right to object to processing based on legitimate interests, as set out in Section 11.

7. We Do Not Sell Your Personal Data

We do not sell your personal data for monetary consideration. Except where you have consented to analytics and advertising cookies as described in our Cookie Policy, we do not engage in cross-context behavioral advertising, and we do not authorize our service providers to use your personal data for purposes other than providing services to us.

With your consent (given via our cookie-consent banner), we use Google Analytics and Meta advertising measurement. We may transmit online identifiers, product-usage and funnel events, and Credit-package and purchase parameters (including the package, page quantity, and amount paid for MainBook Credits) to Google or Meta as described in Sections 4.12–4.13 and our Cookie Policy. We do not transmit uploaded statements, row-level Output, or statement transaction descriptions, amounts, or balances for these purposes. Depending on your jurisdiction, this may be treated as "sharing" for cross-context behavioral advertising under the CCPA or other U.S. state privacy laws. You can decline at any time by choosing Reject, changing your choice through the footer "Cookie settings" link, or sending a Global Privacy Control signal; each forces the effective consent state to denied. We do not sell personal data for monetary consideration.

8. Whom We Share Your Data With

We share personal data only as described in this Section 8 and in our Sub-Processors list.

8.1 Sub-processors, other service providers, and independent controllers. We use third parties to operate the Service. Section 2 of our Sub-Processors and Other Providers page identifies processors that handle Customer Personal Data on our documented instructions and under our DPA. Section 3 identifies providers handling Account, payment, network, authentication, or consented analytics/advertising data for MainBook's own purposes; depending on the function and governing terms, they may act as our service provider, our processor, or an independent controller. The current list, roles, data categories, and processing locations is published on that page and includes:

  • Mistral AI (France) — optical character recognition (OCR) of uploaded documents
  • Google LLC (United States) — large-language-model structured extraction of transaction data via the Gemini API (accessed on a paid basis), authentication (Google OAuth, only if you sign in via Google), and audience analytics via Google Analytics 4 (only with your consent)
  • Meta Platforms, Inc. (United States) — advertising conversion measurement and audience building via the Meta Pixel (Facebook Pixel), only with your consent
  • Stripe, Inc. (United States) — payment processing
  • Plus Five Five, Inc. d/b/a Resend (United States) — transactional, lifecycle/feedback, and consented product-email delivery, including support-message content and a support attachment where applicable
  • DigitalOcean, LLC (United States) — application hosting and object storage (Spaces)
  • Vercel, Inc. (United States) — front-end application hosting and content delivery
  • Functional Software, Inc. d/b/a Sentry (United States) — error tracking
  • Cloudflare, Inc. (United States) — anti-fraud challenges (Turnstile)
  • Telegram (Telegram Messenger Inc. / Telegram FZ-LLC) — one-way internal operator alerts containing opaque internal identifiers, event state/reason, counts, routing categories, and payment/cost values. We do not send names, email addresses, support content or attachments, institution names, filenames, source documents, Output rows, API key secrets/prefixes, or Sentry issue titles to Telegram

8.2 Legal and protective disclosures. We may disclose personal data when we reasonably believe disclosure is required to: (a) comply with a valid legal obligation, subpoena, court order, or other legal process; (b) enforce our Terms or other policies; (c) protect our rights, property, safety, or those of our Users or others; or (d) detect, prevent, or address fraud, security, or technical issues.

8.3 Government access requests. If we receive a request from a governmental or public authority to disclose personal data, and unless we are legally prohibited from doing so or determine in good faith that an urgent risk of serious harm requires immediate disclosure, we will: (a) endeavor to redirect the requesting authority to obtain the data directly from you; (b) assess the request and challenge it where we determine it is unlawful, overly broad, or disproportionate; and (c) disclose only the minimum amount of personal data strictly required.

8.4 Business transfers. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of all or part of our assets, or similar transaction, personal data may be transferred as part of that transaction, subject to the acquirer or successor honoring this Privacy Policy (or providing equivalent protections) as it applies to the transferred data.

8.5 With your consent. We may share personal data with other parties when you have given us your consent to do so.

9. International Data Transfers

9.1 Cross-border processing. The Service is operated from the United States. Most of our sub-processors are located in the United States or the European Union. Your personal data may be transferred to, stored in, and processed in countries other than the country in which you reside. These countries may have data-protection laws that differ from those of your country.

9.2 EU/UK to U.S. transfers. Where personal data subject to the GDPR or UK GDPR is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision from the European Commission or equivalent body, we rely on the Standard Contractual Clauses ("SCCs") approved by the European Commission (Module 2: controller-to-processor; or Module 3: processor-to-processor, as applicable), the UK International Data Transfer Addendum to the EU SCCs, or another lawful transfer mechanism, as applicable. A copy of the relevant transfer mechanism is available on request to hello@human-beyond.ai.

9.3 Supplementary measures. Where required, we apply supplementary technical and organizational measures (such as encryption in transit and at rest, access controls, and contractual restrictions on government-access requests) to protect transferred personal data.

10. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected and as set out below. After the applicable retention period, we delete or anonymize the data, except where we are required to retain it for a longer period to comply with a legal obligation, defend or assert legal claims, or for similar legitimate purposes.

Category of dataRetention period
Uploaded documents (your Content)Authenticated Account and Developer API uploads are scheduled for automatic deletion ninety (90) days after upload; guest uploads are scheduled for deletion after twenty-four (24) hours. A daily deletion sweep removes data from active object storage and the primary database, including abandoned uploads that never complete submission. If an API deletion request is available and accepted for a completed job, that job becomes unavailable immediately and physical purge from active systems normally occurs in the next daily sweep, within approximately twenty-four (24) hours; a failed storage deletion is retried. Encrypted database backups may retain a recoverable copy for up to seven (7) additional days, isolated from normal processing. Third-party providers may retain limited abuse, security, or legal-compliance logs under their published terms.
Output (extracted transactions, exports)The same active-system schedule and backup qualifications as the underlying uploaded document.
Direct Account data (profile, hashed password, settings, two-factor configuration)For the duration of your Account. Account closure deletes this data from the primary database; encrypted backups expire on their normal cycle, currently up to seven (7) days.
Deleted-account suppression recordWe retain the normalized email address and deletion date for as long as reasonably necessary to prevent unauthorized re-creation of a deleted Account, enforce the deletion choice, and prevent abuse. This record is not used for marketing.
Payment, billing, and tax recordsFor the period required by applicable tax, bookkeeping, chargeback, and payment laws and reasonably necessary for disputes and legal claims; this is commonly at least seven (7) years from the transaction. User-facing profile fields are detached or minimized where practicable.
Audit logs, security logs, legal-acceptance records, and incident recordsFor as long as reasonably necessary for security, fraud prevention, contract evidence, dispute resolution, and legal defense; this is commonly at least seven (7) years from the event. Legal-acceptance evidence may retain an opaque Account UUID snapshot, acceptance IP address, and User-Agent after the Account FK is detached.
Anti-fraud signals (device fingerprint, GuestSession record, Turnstile results)The device fingerprint and GuestSession record are retained while needed for guest abuse controls and become eligible for deletion after at least ninety (90) days of inactivity once no Document row remains, whether the session is anonymous or was previously linked to an Account. A daily sweep normally removes an eligible record within approximately twenty-four (24) hours; an infrastructure outage may delay the sweep. Turnstile and other provider security logs follow the applicable provider terms.
Internal task-queue recordsWhile a task is pending, running, or retrying. Once a task reaches a terminal state, its stored arguments are retained for a twenty-four (24) hour operational and incident-debugging window and then removed by an hourly sweep, normally within less than twenty-five (25) hours after the terminal event.
Error and crash telemetry (Sentry)Up to thirty (30) days under our current Sentry plan and retention configuration.
Communications, support tickets, and inbound repliesFor the duration of your Account and as long thereafter as reasonably necessary for support history, security, dispute resolution, and legal claims. When you delete your Account, an Account-linked support ticket is detached and minimized in our primary database: its email is replaced with a non-deliverable placeholder, its original subject is replaced with a content-free placeholder, its description is cleared, and any active attachment is queued for deletion as described below. Other communications and inbound replies that are not linked through that Account record may retain the sender email, subject, message body, and attachments where reasonably necessary for these purposes.
Email opt-out and suppression recordsFor as long as reasonably necessary to honor your unsubscribe or suppression choice and prevent messages that should not be sent.
Anonymized or aggregated dataIndefinitely, as it is no longer personal data.

If you delete your Account, direct profile data and document database rows are logically deleted when the closure transaction commits. In that same transaction, each active source-object or support-attachment locator is copied to a durable deletion queue before its Account-linked database row is removed or minimized. The queued deletion from active object storage is normally attempted promptly after commit. An unconfirmed locator remains queued for idempotent retry by a worker that runs every ten minutes; deletion generally completes within twenty-four (24) hours, although an infrastructure outage may delay completion. Until deletion is confirmed, the queue retains only the exact storage locator required to delete the object and operational retry metadata. Under our current object-key format, that locator may contain opaque Account and document identifiers and the sanitized filename embedded in the key; it is not written to operational logs. Retained payment, audit, legal-acceptance, suppression, support, and security records may remain pseudonymous or identifiable where reasonably necessary for the purposes in the table above or required by law. We detach or minimize Account references where practicable, but we do not describe those retained records as anonymous when they still contain an opaque UUID, email address, IP address, User-Agent, message content, or other identifier. Encrypted backup copies expire on the backup cycle described above.

11. Your Privacy Rights

Depending on where you reside, you may have certain statutory rights in relation to your personal data. We will respect and honor these rights to the extent required by applicable law.

11.1 Rights you may have. Subject to applicable law, you may have the right to:

(a) access personal data we hold about you;

(b) rectify personal data that is inaccurate or incomplete;

(c) erase ("right to be forgotten") personal data, subject to applicable retention obligations;

(d) restrict processing of your personal data in certain circumstances;

(e) object to processing based on legitimate interests;

(f) data portability — receive your personal data in a structured, commonly used, machine-readable format;

(g) withdraw consent at any time where we rely on your consent (this does not affect the lawfulness of processing carried out before withdrawal);

(h) lodge a complaint with your local data-protection authority (in the EU/EEA, the supervisory authority of your member state; in the UK, the Information Commissioner's Office);

(i) not be subject to automated decisions producing legal or similarly significant effects without human review (we do not currently make such automated decisions about you).

11.2 California residents (CCPA / CPRA). Subject to the CCPA and related California laws, California residents have the rights to (a) know what personal data we collect, use, disclose, and (where applicable) sell or share; (b) request deletion of their personal data; (c) correct inaccurate personal data; (d) limit the use and disclosure of "sensitive personal information"; and (e) not be discriminated against for exercising any privacy right. We do not sell your personal data for monetary consideration. We "share" personal data for cross-context behavioral advertising only where you have consented to analytics and advertising cookies — specifically, the consent-based use of Google Analytics and the Meta Pixel and Conversions API described in Section 7 and our Cookie Policy; note that the CCPA may treat this advertising-related disclosure as "sharing." You may opt out at any time via the "Reject" option, the footer "Cookie settings" link, or a Global Privacy Control signal.

11.3 How to exercise your rights. To exercise any of these rights, contact us at hello@human-beyond.ai. We will respond within the time period required by applicable law (generally within 30 days under the GDPR; within 45 days under the CCPA, with a possible 45-day extension where allowed). We will require you to verify your identity before fulfilling your request. Verifiable requests are free of charge. We may charge a reasonable fee or decline to act on a request that is manifestly unfounded or excessive (for example, repetitive requests), as permitted by applicable law (GDPR Article 12(5)).

11.4 Authorized agents (California). California residents may designate an authorized agent to make a request on their behalf. We may require the agent to provide proof of authorization and may require you to verify your own identity directly with us.

11.5 Limits. We may decline a request or partially comply where required or permitted by law, including where we cannot verify your identity, where compliance would adversely affect the rights of others, or where we are required to retain the data under another legal obligation.

12. Security

We implement commercially reasonable technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures currently include encryption of data in transit (using TLS 1.2 or higher), encryption of data at rest where supported by our hosting and storage providers, role-based access controls within our internal systems, password hashing using industry-standard algorithms, one-way storage of Developer API key secrets, two-factor authentication for sensitive operations, server-side error monitoring with local-variable and incoming-request-body capture disabled where applicable, removal of request-body data from browser, server, and edge events before transmission, filtering of document-content fields and common secrets (including any document unlock password described in Section 4.4.1), anti-fraud challenge mechanisms, and routine security review.

No method of transmission over the Internet or method of electronic storage is 100% secure. While we use commercially reasonable efforts to protect your personal data, we cannot guarantee absolute security.

In the event of a personal data breach affecting your personal data, we will notify you without undue delay following our discovery of the breach. For incidents affecting personal data subject to the GDPR or UK GDPR, we will notify affected Users or, where applicable, the data controller, no later than forty-eight (48) hours after we become aware of the breach. Notification will describe the nature of the breach, the categories and approximate number of individuals affected, the likely consequences, and the measures we have taken or propose to take in response, consistent with GDPR Article 33(3). Any such notification will not be deemed an acknowledgment of fault or liability on our part.

13. AI and Machine Learning

The Service uses optical character recognition and large-language-model technology provided by third-party AI sub-processors. We do not use your uploaded documents, the extracted data, or your Output to train or improve our own AI models. We engage AI sub-processors that, in accordance with their published terms applicable to commercial or API customers, are configured for no-training defaults or are contractually committed not to use Customer data to train their models, in each case where such configuration or commitment is available. For full disclosure of our current AI sub-processors and their specific data-use commitments, please see our AI Disclosure, which we update as our sub-processor mix changes.

14. Cookies and Local Storage

We use a small number of strictly necessary cookies and local-storage items required to operate the Service (including authentication tokens, CSRF tokens, anti-fraud signals, and limited UI preferences) and, only with your consent, Google Analytics 4 analytics cookies and Meta Pixel (Facebook Pixel) advertising cookies (_fbp / _fbc). No analytics or advertising cookies are set until you accept them on our cookie-consent banner. Full details and the consent mechanism are in our Cookie Policy.

15. Children

The Service is not directed to, and we do not knowingly collect personal data from, children under the age of eighteen (18). If we become aware that we have collected personal data from a person under eighteen (18), we will delete that data as soon as reasonably practicable. If you believe we may have collected personal data from a person under eighteen (18), please contact us at hello@human-beyond.ai.

16. Third-Party Links and Services

The Service may link to or integrate with third-party websites or services that we do not control. This Privacy Policy does not apply to those third parties. We are not responsible for the privacy practices of any third party. Please review the privacy policies of those third parties before providing them with your personal data.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The "Last Updated" date at the top of this Privacy Policy reflects the date of the most recent change. If we make a material change, we will provide at least thirty (30) days' advance notice by email to the address associated with your Account or by prominent notice within the Service. Material changes take effect at the end of the notice period; your continued use of the Service after the effective date constitutes acceptance of the updated Privacy Policy.

Non-material changes (such as formatting, typographical corrections, or clarifications that do not adversely affect your rights) take effect immediately upon posting.

18. Contact

For privacy questions, complaints, or to exercise your rights:

Human Beyond LLC Attn: Privacy 1818 Hollywood Blvd Hollywood, FL 33020 United States Email: hello@human-beyond.ai

EU and UK data subjects: if you are not satisfied with our response, you may lodge a complaint with your local data-protection authority. We are based in the United States; if you require a U.S.-based point of contact for your privacy inquiry, the email address above is our designated contact.

mainbook.aimainbook.ai

Convert PDF bank statements to Excel and CSV with automatic reconciliation. Built for bookkeepers, accountants, and anyone who works with financial data.

support@mainbook.ai

Product

  • Formats
  • Features
  • How it works
  • See it in action
  • Bank statement to Excel
  • Bank statement API
  • MCP server
  • Security
  • Pricing
  • Compare
  • Supported banks

Legal

  • Terms of Service
  • Privacy Policy
  • Refund Policy
  • Data Processing Agreement
  • Cookie Policy
  • Sub-Processors

© 2026 mainbook.ai. All rights reserved.

Bank-grade TLS 1.3 + AES-256 encryption