Privacy policy

What Plainbooks keeps about you and your businesses, where it’s stored, who helps us run it, how long it stays, and how it’s deleted.

Updated

Who we are

Plainbooks is an app for iPhone and iPad made by Enki Studios, LLC. In this policy, “we” and “us” mean Enki Studios, and “you” means the person who signs in to Plainbooks.

This policy covers the Plainbooks app and its widgets, the service behind it, the emails it sends, and this website, plainbooks.madebyenki.com. It explains what data we handle, why, and for how long.

For anything about privacy, email support@madebyenki.com.

The short version

  • Plainbooks keeps the books you create: your businesses, their transactions, the receipts and documents you add, and the categories and rules you set.
  • Receipts are read on your iPhone first. An AI model is sent the text that was read, never your whole library, and sees a receipt photo only when the phone’s read was weak.
  • You sign in with Apple or with Google. We never see or store a password.
  • Plainbooks doesn’t connect to your bank. It only knows what you give it: receipts, statements and payout reports you import.
  • The app has no ads, no analytics and no tracking. We don’t sell data, use it for advertising, or use it to train AI models.
  • You can delete your account in Settings. Every record and file is deleted within 24 hours.

What we collect

The App Privacy section of the Plainbooks listing in the App Store says the same thing in Apple’s words. Everything below is linked to your account, is used only to make the app work (“app functionality”), and is never used for tracking.

  • Name and email address. What your sign-in provider shares when you sign in with Apple or Google. Apple lets you hide your email; we store whatever Apple gives us, which may be a relay address.
  • User ID. The identifier Apple or Google gives us for your sign-in, and the account id Plainbooks makes for you.
  • Other financial info. Your books: each business or personal book, its name, what it does, its kind, its members and their shares, its money accounts and their opening balances, its categories, rules and year locks; every transaction (date, amount, kind, description, notes, vendor, category, account, splits, who paid); and the audit trail of changes.
  • Purchase history. Your plan and, from the App Store, the signed record of your subscription (which plan, when it renews or ended, refunds), so the app knows what to turn on. We never see your payment details.
  • Photos. The receipt photos and PDFs you add, and the text read from each receipt so you can search it. Only the receipts you choose to add; Plainbooks never reads your photo library.
  • Other user content. The documents you attach to a business (formation papers, the EIN letter, the operating agreement, 1099s, bank statements, prior returns) and the statements and payout reports you import. Imported files are read on the phone; we keep the transactions they produced and a record of each import (so a repeated import never duplicates a row), not the file.

We also keep, for each signed-in device, a scrambled copy (a hash) of its session token, never the token itself, the kind of device (iPhone, iPad or Mac), its model, its system version and when it signed in and was last used. We never store the name you gave your device.

We don’t collect your location, your contacts, your photo library, your browsing, or anything about people who aren’t you.

How receipts are read

When you photograph a receipt, your iPhone reads it: the shop, the date, the total and the lines, from the full-resolution original, before anything leaves the phone. A smaller copy (at most 2000 pixels on the long side, with camera metadata removed) is then uploaded and stored as your receipt.

To suggest how to file it, we send a short request to an AI model (currently Google’s Gemma) that Cloudflare runs on its own Workers AI service. The request contains the text read from the receipt (at most 2,000 characters), the names of your books and categories, any rule that matches, and your last few transactions with that shop. It doesn’t contain your name, your email address or your other receipts. If the phone’s read was weak (no total, or a doubtful one), the stored copy of the receipt image is sent along with the text, and the answer is marked “read by AI, please check” until you save it.

Cloudflare doesn’t train models on this content. The AI never changes your data and never computes a number you see; totals and reports are plain arithmetic on our server. If the model is unavailable, you still get a suggestion from your rules, and nothing fails.

The same model is asked, once per statement import, which column of a CSV is which, from the header and a few rows. Dates and amounts are always read by plain code on your phone, and you see a preview before anything is sent. Payout reports from Stripe, Shopify and the App Store are recognised by their columns and read entirely on the phone; they never go to the AI.

How we use data

We use the data above only to run Plainbooks:

  • to keep your books, file your receipts and build your reports;
  • to suggest how to file a receipt, as described above;
  • to check your plan and turn on what it includes;
  • to send you the emails described below;
  • to find and fix problems, and to keep the service secure.

We don’t sell data, share it for advertising, or use it to train AI models.

Emails and notifications

Plainbooks sends email only when something about your account needs your attention: before data is deleted when a plan has ended, and to answer messages you send us. There’s no newsletter and no marketing email.

Notifications are local to your device: a reminder two days before a free trial ends, reminders a week before each federal estimated-tax due date, and a note when an export is ready. They’re scheduled on the phone, not sent by us, and you can turn them off in your iPhone’s Settings.

On your device

The app keeps a small cache (your books and categories, recent transactions, thumbnails) so it opens quickly and so you can capture receipts offline. Receipts captured offline wait in an outbox on the phone until they upload. Exports are built on the phone as a zip in the Files app, under On My iPhone › Plainbooks; they’re never stored on our server, and they’re removed from the phone after 7 days, on sign-out, and when the account is deleted.

The Profit widget shows numbers from a snapshot the app writes on the phone; widgets never contact our server. Face ID or Touch ID, if you turn it on, is checked by iOS; Plainbooks never sees your face or fingerprint. The camera is used only to photograph receipts and documents you choose to add.

How long we keep data

Data How long we keep it
Books, transactions, receipts, documents, rules For the life of the account
Transactions you deleted 30 days in Recently deleted, then permanently deleted
Receipts captured but never filed Kept until you file or delete them
Files that belong to nothing (an upload that was never attached) Deleted after 7 days
Signed-in devices Until you sign out, or 90 days without use
Audit trail of changes For the life of the account
Exports Never on our server; on your phone for 7 days

A new account. You have 7 days after creating an account to start the free trial or a plan. An account that hasn’t is deleted, with everything in it.

When a plan ends. Your account becomes read-only: you can still view, search and export everything. It stays that way for 30 days after a free trial that wasn’t continued and 6 months after a paid subscription ends. Before the date, the app shows a banner with the date and we send two emails, 7 and 3 days before, each with a reminder to export. On the date, the account and all its data are deleted. Subscribing again before then keeps everything.

Two kinds of copies follow their own schedules:

  • Technical logs. Cloudflare keeps logs of the service’s activity for us, so we can find and fix problems. They record which account a request was for, the IP address and device type it came from, counts, timings and error codes. They never contain receipt text, file contents or request bodies. Logs are kept for 7 days.
  • Error reports. When the service hits an unexpected error, a short report goes to Sentry so we can fix it: the error, where in our code it happened, and the request’s method and path. It never contains your receipts, documents, books, the contents of a request, your IP address or your account. Sentry keeps reports for up to 90 days.
  • Backups. Deleted data can remain in our database provider’s recovery history for up to 30 days.

Service providers

We share data only with these providers, and only as needed to run Plainbooks:

  • Cloudflare: hosts the service and this website (and counts its page views without cookies), stores our database and your files, runs the AI model (Workers AI, currently Google’s Gemma; Cloudflare doesn’t train on customer data), and sends our emails.
  • Apple: signs you in (Sign in with Apple), handles your subscription through the App Store, and distributes the app. Apple never tells us your payment details.
  • Google: signs you in, if you choose Sign in with Google. Google tells us your name, email address and an identifier, nothing else, and we send Google nothing about your books. On this website, Google Analytics counts visits (see This website).
  • Ahrefs: counts visits to this website without cookies (Ahrefs Web Analytics) and checks how it appears in search.
  • Sentry (Functional Software, Inc.): receives the error reports described above, with nothing about you or your books.

If you email us, your message is stored by our email provider. Each provider handles data under its own terms and privacy policy.

We may also disclose data if the law requires it. If Enki Studios or Plainbooks is sold or merged, data may pass to the new owner, and this policy will keep applying to it.

Where data is stored

Our database and your files are stored in North America. Requests and the AI model can be processed in Cloudflare data centers in different countries, so your data may be processed outside the country where you live.

Deleting your data

  • Your whole account. In the app, Settings › the account card › Delete account. Every record and every file is deleted within 24 hours, your Sign in with Apple connection is revoked with Apple, and the exports on your phone are removed at the same time. Deleting the account doesn’t cancel an App Store subscription; do that in your Apple Account’s Subscriptions settings.
  • A receipt, a document, a transaction, a book. Delete it in the app. Transactions wait 30 days in Recently deleted so you can change your mind; files and books go at once.
  • Signed-in devices. Settings › Account › Signed-in devices, or “Sign out everywhere.”

Copies in technical logs and backups expire on the schedule described above.

Your choices and rights

You can see and change everything Plainbooks holds about you in the app, export it at any time (Settings › Export), and delete it as described above.

Depending on where you live, you may have rights over your personal data, such as the right to access it, correct it, delete it, get a copy of it, or object to or restrict how it’s used. To use any of these rights, email us. We may need to confirm that you’re the account holder before we act. We’ll reply as soon as we can, and within the time the law requires. You can also complain to your local data protection authority.

Security

  • Encrypted connections. The app, this website and every link in our emails use HTTPS.
  • No passwords. Sign in with Apple and Sign in with Google issue tokens that we verify against the provider’s published keys. Sessions are long random tokens, stored on your device in the Keychain and only as a hash on our side.
  • Private files. Your receipts and documents live in a private bucket and are downloaded only through the service with your session, or through signed links that expire within 15 minutes. Nothing is ever public.
  • Checked uploads. Only JPEG, PNG and PDF files are accepted, verified by their content, with size and page limits.
  • Limited access. Access to our Cloudflare account is limited to the people at Enki Studios who run Plainbooks.

No system is perfectly secure. If we learn of a security incident that affects your data, we’ll tell you as the law requires.

This website

plainbooks.madebyenki.com has no accounts and no ads.

Analytics. We use Google Analytics to see how people find and use the site. In the European Union, the European Economic Area, the United Kingdom and Switzerland, a banner asks first: if you decline, no analytics script is loaded and no cookies are set. Elsewhere, Analytics is on when you visit, and you can turn it off at any time. With Analytics on, the site loads Google Analytics from Google and sets two first-party cookies, _ga and _ga_<id>, which keep a random identifier for up to 2 years so repeat visits can be counted. Google Analytics then receives the pages you view, the site that sent you, your browser, device type and screen size, and your approximate location (country and city, worked out from your IP address, which Google Analytics doesn’t store). We turned off Google signals and advertising features, the data isn’t linked to the Plainbooks app or your account, and we keep it for 2 months. Google processes it for us under its Google Analytics terms. Wherever you are, Cookie settings at the bottom of every page lets you change your answer; Decline turns Analytics off and removes its cookies.

Your choice is remembered in your browser’s local storage, not in a cookie.

Page counts without cookies. Cloudflare Web Analytics, from our host, and Ahrefs Web Analytics count page views, the site that sent you and load times with small scripts. They set no cookies, store nothing on your device and don’t identify you, so they run for every visitor. Apart from these and Google Analytics, the site doesn’t load scripts, fonts or images from other websites.

Cloudflare hosts the site. Like any web host, it receives technical details such as your IP address and browser type when you visit, in order to deliver the pages.

The “Get Plainbooks” buttons link to the App Store. The links include a tag that shows which page of our site the click came from. Apple’s privacy policy covers your visit to the App Store.

If you email us, we use your address and message only to reply and to keep a record of the conversation.

Children

Plainbooks is a tool for people who run businesses and isn’t meant for children. We don’t knowingly collect personal data from anyone under 16.

Changes to this policy

We’ll update this policy when the way Plainbooks handles data changes, and change the date at the top of this page. If a change significantly affects how we handle your data, we’ll post it on this page at least 30 days before it takes effect.

Contact