Emori← Back to app

Contents

Privacy Policy

Last updated: 3 October 2026


Emori Intelligence Ltd.
Effective date: 19 September 2026

1. Who we are

Emori is an AI bookkeeping service for small business owners. It connects to your accounting, email, document storage and messaging accounts, reads the records it finds there, categorizes your transactions, and writes those categorizations back to your accounting software.

This policy explains exactly what we read, why we read it, who else sees it, where it is stored, and how to get it back or have it deleted.

ControllerEmori Intelligence Ltd.
Registered inIreland — Company No. 814805
Registered officeThe Black Church, St. Mary's Place, Dublin 7, D07 P4AX, Ireland
Contacthello@emori.ai

We are the controller of the personal data described here, within the meaning of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Irish Data Protection Act 2018. Where other companies process it on our behalf, they are listed in section 8.

If you are in Canada, Canadian privacy law — principally PIPEDA — also applies to how your information is handled, and nothing here limits a right you have under it. Where the two regimes differ, we apply whichever gives you more.

2. Who this policy covers

  • Account holders — the business owner who signs up.
  • Team members and accountants invited to a business account.
  • Visitors who request a free Books Health Score without creating an account.
  • Third parties whose data appears in your records — your customers, your suppliers, your employees. You give us this data when you connect an account. For that data you are the controller and we are your processor, acting on your instructions.

3. What we collect

3.1 Data you give us

  • Name, email address, phone number, password (stored hashed — we never see it).
  • Business name, legal entity type, jurisdiction, industry, fiscal year end, VAT or GST/HST filing frequency.
  • Messages you send us over WhatsApp, SMS or email, including photographs of receipts, and messages you send through our contact form (your name, email address, subject and message, delivered to us by email).
  • Payment details. Card numbers go directly to Stripe and never reach our servers.

3.2 Data from accounts you connect

Nothing is read until you connect an account, and each connection is a separate, revocable decision. Section 5 sets out each one.

3.3 Data we generate

  • Categorizations, confidence scores and the reasoning behind them.
  • Data extracted from receipts and invoices — vendor, amount, tax, dates, line items.
  • Weekly briefs, alerts, and score calculations.
  • Operational logs recording what ran, when, and whether it succeeded.

3.4 Data collected automatically

  • IP address, browser and device type, pages visited, timestamps.
  • Error reports when something breaks, which may include the URL you were on and the technical context of the failure.

We do not use advertising trackers and we do not sell anything about you to anybody.

4. Why we process it, and our lawful basis

GDPR requires a lawful basis for each purpose. Ours are:

PurposeLawful basis
Creating and running your account; providing the serviceContract — Art. 6(1)(b)
Reading your connected accounts to categorize transactions and extract receiptsContract — Art. 6(1)(b)
Sending alerts, the weekly brief, and questions about transactionsContract — Art. 6(1)(b)
Taking paymentContract — Art. 6(1)(b)
Keeping the service secure; preventing abuse; debuggingLegitimate interests — Art. 6(1)(f)
Improving the service using aggregated, de-identified statisticsLegitimate interests — Art. 6(1)(f)
Keeping billing and tax recordsLegal obligation — Art. 6(1)(c)
Marketing email you opted intoConsent — Art. 6(1)(a), withdrawable at any time

Where we rely on legitimate interests we have weighed them against your rights, and you may object — see section 11.

We do not knowingly process special category data (Art. 9). Financial records are not special category data; if a receipt you send happens to reveal it — a medical expense, say — we process it only as part of that document and for no other purpose.

5. Connected accounts — what each one does

5.1 QuickBooks Online (Intuit)

Access: read and write, with your authorization through Intuit's OAuth screen.

We read: your chart of accounts, transactions, vendors, customers, invoices, bills and attachments.

Who connected: when you connect, Intuit also tells us the email address and Intuit user ID of the person who connected (the openid and email permissions on Intuit's screen). We show it in Settings as “Connected by”, so you can see whether you or your accountant made the connection, and use it to help you if something goes wrong. We use it for nothing else. The free Books Health Score asks Intuit for the same permissions and keeps none of it.

We write: transaction categories, receipt attachments, and — only when you have switched the feature on and approved each one — bills.

You control it. Writeback can be turned off at any time in settings and it stops immediately for every feature. Bill creation is off by default and must be enabled separately.

5.2 Google — Gmail and Drive

Access: gmail.readonly and drive.readonly. Both are read-only. We cannot send email as you, delete anything, or change any file. Each is asked for separately: connecting Gmail asks Google only for Gmail, and connecting Drive asks only for Drive.

ScopeWhat we do with it
https://www.googleapis.com/auth/gmail.readonlyFind receipts, invoices and bank statements in your inbox, and read those messages and their attachments so we can extract the vendor, amount, tax and date and match them to your transactions.
https://www.googleapis.com/auth/drive.readonlyFind receipt and invoice documents you have saved to Drive and read those files for the same purpose.
openid, https://www.googleapis.com/auth/userinfo.email, https://www.googleapis.com/auth/userinfo.profileOnly if you choose “Sign in with Google”: Google shares your email address, your name and your profile picture. We use the email address to sign you in and to identify your account. We do not use your name or picture for anything else.

How we narrow what we read. We do not read your whole mailbox or your whole Drive indiscriminately:

  • In Gmail we search for messages that look like financial documents and read those.
  • In Drive we list only PDF, JPEG and PNG files that are not in the trash and were modified no earlier than the period your plan covers for bookkeeping clean-up — 90 days on a free trial, and further back on a paid plan — and we open only the ones you own. Files other people have shared with you can appear in that list, but we never open them. If you point Emori at a specific folder, we read only that folder.
  • We keep the extracted financial data and the document itself. We do not retain the wider contents of unrelated messages.

You can disconnect Google at any time. Disconnecting Gmail or Google Drive in Emori's settings stops Emori reading from that source immediately. Disconnecting Gmail also ends Emori's Google access entirely, because when Gmail and Drive are connected with the same Google account they share one Google authorisation — so if you disconnect only Drive, that authorisation stays listed in your Google account until you disconnect Gmail too, or remove it yourself at myaccount.google.com/permissions. Revoking it there stops all future reads immediately.

5.3 Bank connections (Plaid)

Access: read-only, when you choose to connect a bank.

We read: account names, balances and transactions.

Plaid handles the bank login. Your banking credentials are never seen by, or stored on, Emori's systems.

5.4 WhatsApp and SMS

Emori works over WhatsApp and text. To check that a mobile number is yours, we text it a one-time code through Vonage; you type it back and we pass it to Vonage to check. We do not store the code.

When you confirm your number, you agree to receive messages about your books at that number, on WhatsApp and by SMS: questions about transactions, requests for receipts and statements, alerts, and your weekly brief. These messages are the service itself, so we send them under our contract with you (section 4), not as marketing. We record when you confirmed and the wording you confirmed under.

When you message us a photograph of a receipt, we receive the image, the phone number it came from, and the message content. We use these to extract the receipt and to reply.

Reply STOP at any time to stop all WhatsApp and SMS messages from Emori to that number, for every business that uses it. Reply START to turn them back on. You can also choose which alerts and briefs come by text in your notification settings.

6. Google API Services — Limited Use disclosure

Emori's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, and without exception:

  1. We use Google user data only to provide and improve the features you can see — finding your receipts and invoices, extracting their contents, and matching them to your transactions.
  2. We do not transfer Google user data to anyone except: the processors listed in section 8, under contract and only for these purposes; where you direct us to (for example, attaching a receipt to your own QuickBooks); or where the law requires it.
  3. We do not use Google user data for advertising of any kind.
  4. We do not sell Google user data.
  5. We do not use Google user data to develop, improve or train generalized artificial intelligence or machine learning models. We use a third-party AI service to read an individual document for you, and that provider is contractually prohibited from training on it. See section 7.
  6. No human reads your Google data except: with your explicit consent, for a specific problem you have asked us to fix; where it is necessary for security purposes or to comply with the law; or in aggregated, de-identified form for internal statistics.

7. Artificial intelligence, and automated decisions

Emori uses AI to read documents and suggest categories. We send the contents of a receipt, invoice or transaction description to Anthropic (the provider of Claude) to extract the details or propose a category.

  • Anthropic does not train its models on what we send. This is a contractual term of the commercial API we use, not a setting.
  • We send only what the task needs — the document or the transaction line, not your account as a whole.

Automated decision-making (Art. 22). Emori's categorizations are automated, but they produce no legal or similarly significant effect on you: they are suggestions in your own books, you can change any of them, and your change takes precedence over anything Emori decides. We do not use automated decision-making to decide whether you can have an account, what you pay, or anything else with a legal effect. If you want a human to look at a categorization, write to us.

8. Processors and recipients

Each processes personal data on our behalf, under a contract meeting Art. 28 GDPR, and for no other purpose.

ProcessorWhat it doesWhere
SupabaseDatabase and file storage — the primary home of your dataCanada (ca-central-1)
VercelApplication hostingUnited States
AnthropicAI extraction and categorizationUnited States
IntuitQuickBooks OnlineUnited States
GoogleGmail and Drive accessUnited States
StripePayment processingUnited States
PlaidBank connectionsUnited States / Canada
VonageSMS and WhatsAppUnited States
ResendTransactional and weekly emailUnited States
SentryError monitoringUnited States
InngestBackground job processingUnited States
UpstashRate limitingUnited States

We may also disclose personal data where the law requires it, to establish or defend legal claims, or to a buyer as part of a sale or reorganization — in which case this policy continues to apply until you are told otherwise.

We do not sell your personal data, and we never have.

9. International transfers

Your records are stored in Canada, in Supabase's ca-central-1 region. Canada holds an adequacy decision from the European Commission for commercial organisations, so transfers there require no further safeguard.

Several processors are in the United States. Those transfers rely on Standard Contractual Clauses under Art. 46(2)(c) GDPR, or on the processor's certification under the EU–US Data Privacy Framework where it holds one. We send only what the task requires. You can ask us for a copy of the safeguards in place.

10. How long we keep it

WhatHow long
Account and business recordsWhile your account is open
Transactions180 days in active storage, then archive storage
Weekly briefs90 days in active storage, then archive storage
Receipts and invoice documentsWhile your account is open, unless you delete them
Operational logsWhile your account is open — removed when it closes
Books Health Score sessions (no account)Deleted automatically after expiry
Billing recordsAs long as Irish and Canadian tax law require
Database backupsRolling 7 days — deleted records age out within a week

When you close your account we delete your personal data from our systems within 30 days, apart from what we must keep by law. Copies held by our processors expire on their own schedules, the longest of which is 13 months (message logs).

Data you have already written into your own QuickBooks stays in your QuickBooks — it is yours, and closing your Emori account does not remove it.

11. Your rights

Under GDPR you have the right to:

  • Be informed — this policy.
  • Access your personal data and receive a copy (Art. 15).
  • Rectify anything inaccurate (Art. 16).
  • Erase your data — the "right to be forgotten" (Art. 17).
  • Restrict processing while a dispute is resolved (Art. 18).
  • Portability — receive your data in a structured, machine-readable format (Art. 20).
  • Object to processing based on legitimate interests (Art. 21).
  • Withdraw consent at any time where consent is the basis — including by disconnecting any connected account, which stops all reading from it immediately.

Write to hello@emori.ai. We respond within one month. Where a request is complex or you have made several, we may extend by up to two further months and will tell you why within the first month (Art. 12(3)).

To exercise them: ask us and we will act. To get your data, ask and we will send it to you in a structured, machine-readable format. To have it erased, ask and we will delete your personal data within 30 days. You do not need to find a button — a message to hello@emori.ai is enough, and it is the route we ask you to use.

To complain: the Irish Data Protection Commission — dataprotection.ie — or the supervisory authority where you live.

If you are in Canada you may also complain to the Office of the Privacy Commissioner of Canada — priv.gc.ca — 1-800-282-1376.

Where the data you ask about belongs to your customers or suppliers rather than to you, we act as your processor. We will help you respond to them, but you decide.

12. Security

  • Connection tokens are encrypted at rest with AES-256-GCM.
  • All traffic runs over TLS.
  • Database access is restricted per business, enforced at the database level.
  • Payment card details never touch our servers.
  • Access to production systems is limited to people who need it.

No system is perfectly secure. We report a personal data breach to the Data Protection Commission within 72 hours where Art. 33 requires it, and tell you directly where Art. 34 requires it.

13. Children

Emori is for businesses. It is not directed at anyone under 18 and we do not knowingly process children's data.

14. Cookies

We use cookies necessary to keep you signed in and to keep the service secure. We do not use advertising or cross-site tracking cookies.

15. Changes

If we change this policy we post the new version here and update the date above. If the change is significant — a new purpose, a new category of data, a new recipient — we email you before it takes effect.

16. Contact

Emori Intelligence Ltd. — Company No. 814805
The Black Church, St. Mary's Place, Dublin 7, D07 P4AX, Ireland
hello@emori.ai