BKApp.ai
Terms of UsePrivacy PolicySign in
Version 2026-08-23

Privacy Policy

This policy explains what BKApp.ai collects, why, who it is shared with, and what you can ask us to do with it. Version 2026-08-23.

1. Policy summary

BKApp.ai does not sell raw customer bank-account credentials, transaction histories, or Secure Vault documents as a commercial data product.

We may use information lawfully available to us to personalise the service, identify relevant products or programs, and present advertisements or partner offers, subject to applicable privacy laws and opt-out rights.

We may use artificial intelligence and multiple AI providers to analyse authorised data. AI-generated results may be incomplete or wrong, and are not a substitute for professional accounting, legal, tax, lending, investment, or insurance advice.

The service is designed to use role, entity, account, and document permissions to limit access. You are responsible for sharing access appropriately and revoking it when it is no longer needed.

2. 1. Scope and introduction

This Privacy Policy explains how [LEGAL ENTITY NAME TO BE CONFIRMED], doing business as BKApp.ai ("we", "us", "our"), collects, receives, uses, processes, stores, derives, analyses, discloses, protects, and otherwise handles personal information when individuals or organisations access or use our websites, mobile applications, software, APIs, integrations, artificial-intelligence features, financial-data tools, document vault, communications, advertisements, partner services, and related products and services (the "Services").

This policy applies to the Services that link to or expressly reference it. admin.bkapp.ai is primarily an internal administrative environment and is governed by restricted administrative-access policies in addition to this policy.

By using the Services you acknowledge the data practices described here. Where applicable law requires consent for a particular activity, we will seek that consent separately and will not rely solely on your general use of the Services.

3. 2. Core privacy commitments

These are the commitments the rest of this policy is built on:

  • We do not sell raw customer bank-account credentials, raw transaction histories, or Secure Vault documents as a commercial data product.
  • We do not intend to store bank usernames or passwords when authentication is handled by a financial institution or authorised financial-data provider.
  • We may use information about you and your businesses to operate, personalise, secure, improve, and monetise the service, including to determine which features, advertisements, partner programs, financial products, loans, insurance products, business services, software, vendors, or other opportunities may be relevant to you.
  • We may receive advertising fees, referral fees, lead fees, commissions, sponsorship payments, revenue share, or other compensation from third parties whose products or services are displayed or recommended through the Services.
  • Where applicable privacy law treats a particular advertising or data-sharing activity as a "sale", "sharing", or "targeted advertising", we will provide the notices and choices required by law.

4. 3. What we collect

Account and identity information: your name, business name, email address, telephone number, account identifiers, authentication and verification status, user roles, organisation memberships, notification settings, time zone, language, AI-assistant name and preferences, and related profile information.

Business and entity information: legal entity names, trading names, entity type, addresses, state of formation, industry, ownership and management relationships, properties, locations, departments, managers, employees, accountants, vendors, customers, tenants, lenders, franchisors, counterparties, and business-performance information.

Financial account information: institution names, account type, masked account identifiers, balances, available balances, credit limits, transaction history, merchant names, transaction descriptions, deposits, withdrawals, credit-card activity, loan information, investment information, interest, fees, liabilities, and connection status.

Accounting and reporting information we collect, generate, or derive: categories, chart-of-account mappings, journal entries, general-ledger records, trial balances, profit and loss statements, balance sheets, cash flow statements, budgets, forecasts, receivables, payables, owner contributions, owner distributions, transfers, reconciliations, accounting rules, financial ratios, and historical trends.

Secure Vault and document information: contracts, loan agreements, promissory notes, amortisation schedules, franchise agreements, leases, insurance policies, tax documents, financial statements, invoices, receipts, check images, bank statements, credit-card statements, operating agreements, purchase agreements, licences, permits, appraisals, correspondence, and other business documents. We may extract or derive structured terms from them, including contract dates, loan maturities, balloon payments, interest rates, payment schedules, renewal dates, cancellation deadlines, franchise fees, vendor pricing, rate escalations, insurance expiration dates, obligations, rights, and restrictions.

Connected business-system information, depending on the integrations you authorise: property-management, point-of-sale, online travel agency, accounting, payroll, merchant-processing, inventory, revenue-management, CRM, banking, cloud, and other business systems.

AI interaction information: questions, instructions, conversation history, requested calculations, AI responses, your corrections, feedback, assistant settings, authorised financial records, authorised Vault documents, and preferences you have approved for the assistant to remember.

Technical and usage information: IP address, device information, browser type, operating system, application version, session identifiers, authentication activity, audit events, crash and diagnostic information, usage and referral information, performance information, and security logs.

Communications: customer-support interactions, emails, SMS, WhatsApp messages, push notifications, marketing preferences, and consent records.

5. 4. Where the information comes from

From you, from other authorised users of your organisation, from connected financial institutions and financial-data providers, from documents you upload, from your accountants, employees and managers, from business-software integrations, from service providers and partner services, from public sources, and from information we derive from other authorised information.

6. 5. How we use it

We use personal information to:

  • Create and administer user accounts and organisations.
  • Authenticate users, verify identity or contact information, and secure the Services.
  • Connect authorised bank, credit-card, investment, loan, accounting, property-management, point-of-sale, payroll, online travel agency, merchant-processing, and other accounts or systems.
  • Import, normalise, categorise, reconcile, and report financial activity.
  • Maintain ledgers, journals, balance sheets, budgets, forecasts, and other financial reports.
  • Operate Find My Money, Crosscheck, the Attention Centre, the Daily Brief, the AI assistant, document intelligence, contract monitoring, and other analytics.
  • Identify duplicate transactions, missing deposits, contract variances, suspicious or unusual activity, upcoming maturities, expirations, rate changes, and other issues.
  • Provide customer support, troubleshoot problems, and respond to requests.
  • Prevent fraud, abuse, unauthorised access, and security incidents.
  • Improve, test, develop, and evaluate features, algorithms, AI systems, models, interfaces, and industry-specific functionality.
  • Perform business analytics, product planning, usage analysis, de-identified benchmarking, and research.
  • Send transactional, security, service, marketing, advertising, or promotional communications as permitted by law and your settings.
  • Comply with legal obligations and enforce our agreements.

7. 6. Artificial intelligence and automated processing

We may use artificial intelligence, machine learning, rules engines, document-intelligence systems, and automated decision-support tools to process authorised information. Depending on the feature, these systems may analyse transactions, financial statements, business metrics, contracts, documents, historical patterns, your questions, or preferences you have approved.

We may use multiple AI providers or models for different tasks, and may change providers based on capability, security, reliability, availability, cost, or other operational factors. We aim to provide only the information reasonably necessary for the requested task, subject to applicable contractual and legal restrictions.

AI and automated systems can produce errors, incomplete results, false positives, false negatives, outdated information, incorrect classifications, or incorrect interpretations. AI output is not independently verified professional advice unless separately reviewed and delivered by a qualified professional.

8. 7. AI memory and personalisation

Where enabled, the assistant may remember durable preferences, instructions, mappings, or business rules that help personalise future interactions — a preference for concise reports, a request to include credit-card due dates, or an instruction to surface transactions above a chosen threshold.

We do not intend to use stale conversational balances or other rapidly changing financial values as the authoritative source for current financial information. Current balances and results are retrieved from current financial records and connected data sources.

You may be offered controls to review, correct, delete, or disable stored AI memories or preferences. Accounting rules, classification rules, and financial posting rules remain separately auditable and are not held solely in conversational memory.

9. 8. Advertising, offers, and recommendations

We may use information lawfully available to us to determine whether products, services, advertisements, programs, or opportunities may be relevant to you or your business. Categories may include loans, refinancing, credit cards, deposit products, banking, insurance, payroll, merchant processing, accounting, legal services, software, equipment, hospitality services, property services, and vendors.

Recommendations may be based on business type, industry, geographic area, product usage, connected systems, account activity, expense categories, upcoming obligations, financial trends, or other legally permitted information.

We may receive advertising fees, referral fees, lead-generation fees, commissions, sponsorship payments, revenue share, or other compensation from participating providers. Where a material compensation relationship affects a recommendation or placement, we intend to identify that relationship in an appropriate manner.

10. 9. Our data-sale commitment, and what privacy law calls a sale

Our current business policy is not to sell raw customer bank-account information, raw transaction histories, authentication credentials, or Secure Vault documents as a commercial data product.

Privacy laws may define "sale", "sharing", "targeted advertising", or similar concepts more broadly than the ordinary meaning of selling a customer database. Certain advertising, measurement, or partner-data transfers may fall within those definitions even where we would not consider the activity a traditional sale.

Where applicable law provides a right to opt out of sale, sharing, targeted advertising, or certain profiling, we will provide the required notice and mechanism.

11. 10. How and why we disclose information

Service providers and subprocessors: vendors that help operate the Services, including cloud infrastructure, databases, financial connectivity, payment processing, AI, document processing, communications, analytics, security, monitoring, and customer support.

Financial connectivity providers: where authentication is handled by the financial institution or provider, we generally do not receive your bank username or password.

Business partners and advertisers: where permitted, information necessary to present, measure, facilitate, or administer partner offers, advertisements, referrals, or introductions you request.

Legal and safety: where we reasonably believe disclosure is necessary to comply with law or legal process, meet regulatory obligations, protect rights or property, investigate fraud or abuse, enforce agreements, protect users, or respond to a security incident.

Business transfers: information may be transferred as part of a merger, acquisition, financing, reorganisation, bankruptcy, or sale or transfer of all or part of the business or its assets, subject to applicable law.

12. 11. Aggregated and de-identified information

We may create aggregated or de-identified information for analytics, benchmarking, research, product development, security, service improvement, commercial insights, or other lawful business purposes. Where required by law we will take reasonable steps intended to prevent data treated as de-identified from being used to identify a particular individual.

13. 12. Cookies and similar technologies

We may use cookies, software-development kits, local storage, pixels, session technologies, and similar mechanisms for authentication, security, preferences, analytics, performance, attribution, and advertising where permitted.

Where applicable law requires consent for optional analytics or advertising technologies, we will provide a cookie or tracking preference mechanism, and we may honour legally recognised opt-out preference signals where required.

14. 13. Security

We use administrative, organisational, and technical safeguards intended to protect information. Depending on the Service and its implementation status, these may include encryption in transit and at rest, private object storage, multifactor authentication, role-based permissions, entity-level access controls, account-level access controls, document-level access controls, row-level security, audit logging, secure secret management, security monitoring, backups, and recovery procedures.

No computer system, transmission method, cloud platform, database, encryption method, security control, or organisation can guarantee absolute security. Security incidents may occur despite reasonable safeguards. Nothing in this policy waives responsibilities that cannot legally be waived.

15. 14. Your security responsibilities

Some of what keeps an account safe is only in your hands:

  • Protect your account credentials and your devices.
  • Use the multifactor authentication and security controls available to you.
  • Assign team roles and account and document access carefully.
  • Revoke access promptly when employees, managers, accountants, or other users no longer require it.
  • Tell us promptly if you discover unauthorised access, suspected compromise, or suspicious activity.

16. 15. How long we keep it

We may retain personal information for as long as reasonably necessary to provide the Services, comply with law, maintain financial and audit records, prevent fraud, enforce agreements, resolve disputes, satisfy litigation holds, maintain backups, or meet legitimate security and operational needs.

Different categories may have different retention periods. Document retention may be configurable, and some records may remain longer where required by law, contract, accounting practice, security needs, or legal claims.

17. 16. Deletion and account closure

You may request deletion of personal information where applicable. Some information may remain after a deletion or account-closure request where retention is legally permitted or required — including financial records, audit logs, fraud-prevention and security records, litigation holds, contractual records, backup copies during normal backup cycles, and information necessary to establish or defend legal claims.

18. 17. State privacy rights

Depending on your state of residence, the nature of your relationship with us, and whether applicable statutory thresholds are met, you may have rights to access, know, correct, delete, obtain a portable copy, opt out of certain sales or sharing, opt out of targeted advertising, limit certain sensitive-data uses, appeal certain request decisions, and receive nondiscriminatory treatment for exercising protected privacy rights.

We may need to verify your identity or authority before fulfilling certain requests. Authorised agents may be required to provide proof of authority. Rights and exceptions vary by jurisdiction.

19. 18. Privacy choices and requests

Privacy requests may be submitted at /legal/privacy-choices or by emailing privacy@bkapp.ai. We may provide additional request methods where required by law.

Where applicable, you may also manage marketing communications, cookie preferences, targeted-advertising choices, AI memory preferences, and certain other privacy settings inside the service.

20. 19. Sensitive personal information

Financial information, authentication information, certain identifiers, precise location data if collected, and other categories may be treated as sensitive under applicable law. We process sensitive information only for permitted purposes, with consent where required, and subject to applicable contractual, security, and legal restrictions.

21. 20. Financial products and lending-related information

We may display or facilitate access to loans, refinancing, banking, insurance, credit, merchant-processing, payroll, or other financial or business products. Unless expressly stated otherwise, we are not the lender, do not make the credit decision, do not guarantee approval, and do not guarantee that an offer is the lowest-cost or most suitable option available.

Providers determine eligibility, underwriting, pricing, terms, and availability. We may receive compensation from participating providers. Sponsored or compensated placements are identified where legally required or materially relevant.

22. 21. Communications, SMS, and WhatsApp

If you provide contact information and enable notifications, we may send service-related communications such as authentication codes, security alerts, Daily Brief notifications, financial alerts, account notices, document alerts, and support communications.

Marketing SMS or WhatsApp communications are subject to separate consent where required. Message and data rates may apply. You may withdraw marketing consent through the applicable opt-out mechanism.

23. 22. International use

The service is currently designed primarily for United States business users unless otherwise stated. If we intentionally expand to other jurisdictions, additional privacy notices, contractual mechanisms, transfer safeguards, or regulatory requirements may apply. We do not represent compliance with a foreign privacy regime unless expressly stated.

24. 23. Children

The service is intended for business owners, employees, accountants, managers, and other authorised adult business users. It is not directed to children under 13, and users must ordinarily be at least 18 years old to create an account unless we expressly provide otherwise.

25. 24. Changes to this policy

We may update this policy from time to time. Material changes may be communicated through the website, the mobile application, an account notice, email, or another reasonable method. The version recorded against your acceptance says which text you agreed to.

26. 25. Contact

Privacy: privacy@bkapp.ai

Legal: legal@bkapp.ai

Security: security@bkapp.ai

Support: support@bkapp.ai

[LEGAL ENTITY NAME TO BE CONFIRMED], [MAILING ADDRESS TO BE CONFIRMED].

27. 26. Additional United States regulatory notice

Depending on our activities, customer population, partner relationships, and regulatory classification, additional laws or notices may apply, including state comprehensive privacy laws and potentially federal financial-privacy or information-security requirements. If we are determined to be subject to the Gramm-Leach-Bliley Act Privacy Rule, an applicable GLBA privacy notice will be provided in the form and manner required by the relevant regulator.

BKApp.ai is a financial awareness utility, not accounting software. Check every figure and consult your own adviser.