Privacy Policy
This policy explains what Stateful collects, why it is used, where it is processed, and the choices available to private-beta users.
Effective August 12, 2026 · Last updated August 12, 2026
Scope
Stateful is accounting software for real-estate investors. This policy applies to the Stateful web application and its private beta. Stateful is not a bank, property manager, bookkeeping service, tax adviser, or financial adviser.
Information we process
- Account and profile data: email address, authentication identifiers, organization membership, role, and multi-factor authentication status. Authenticator secrets and credentials are managed by Supabase Auth; Stateful does not display your password.
- Property, entity, and ownership data: property details, legal entities, portfolios, owners, economic interests, loans, fixed assets, and accounting configuration.
- Financial data: account metadata, balances, transaction dates, amounts, merchant and description data, categories, reconciliations, journals, and audit events.
- Plaid-connected data: institution and account identifiers, account names/types, balances, transaction and merchant data, sync state, and error state. Plaid access tokens are encrypted by Stateful before database storage. Stateful does not receive or store online-banking passwords.
- Documents: files you upload and extracted data created to support accounting workflows.
- Technical and security data: authentication events, request metadata, error codes, and limited diagnostic records. Telemetry is designed to avoid secrets, access tokens, full documents, and transaction descriptions.
How we use information
We use data to authenticate users, enforce organization boundaries, connect financial accounts, stage and code transactions, produce accounting records and reports, reconcile accounts, provide audit history, troubleshoot failures, secure Stateful, and improve the private beta.
AI-assisted features
If an AI feature is enabled, Stateful may send only the content needed for the requested feature to OpenAI. AI output is assistive and cannot bypass deterministic posting, approval, RLS, or period-lock controls. AI features may be disabled by configuration. Do not upload material you are not authorized to process.
Billing
Paid billing is not active. If Stripe billing is added, Stripe will process payment-card and billing information for the organization. Stateful would store customer, subscription, plan, and status identifiers—not full card numbers. This policy will be updated before paid billing launches.
Service providers
Stateful currently relies on Vercel for application hosting, Supabase for database/authentication/storage, Plaid for financial-account connectivity, GitHub for source control and deployment integration, and email delivery through Supabase SMTP configuration. Cloudflare Turnstile may be used for bot protection. OpenAI is used only when AI features are enabled. Stripe is planned but is not currently active. Providers process data under their own terms and security programs.
Sharing
Stateful does not sell personal information. Data is shared with service providers only to operate the product, with organization members you or an administrator authorize, when legally required, or to protect users and the service.
Retention and deletion
Accounting records are retained while an organization is active and may need to be preserved for legal, tax, audit, fraud-prevention, or dispute purposes. Plaid connections can be disconnected and access tokens deleted. Account or organization deletion requests are handled as a controlled process so records are not accidentally destroyed. Backups may retain deleted records until the applicable backup-retention window expires.
Security
Stateful uses encrypted HTTPS connections, Supabase row-level security, role-based access, deterministic posting controls, audit events, encryption of Plaid access tokens before storage, and provider-managed encryption at rest. No system is perfectly secure. See the Security page for current controls and candid limitations.
Your choices and rights
You may request access, correction, export, disconnection, or deletion of your data, subject to identity verification and accounting/legal retention requirements. Administrators can deactivate organization access. To make a beta privacy request, use the contact channel in your Stateful invitation or contact the person who invited you; a dedicated public support address has not yet been established.
Changes
We will update the effective date when this policy changes materially and will provide an appropriate notice to active users when required.