Legal

Privacy Policy

Last updated: October 6, 2026

This Privacy Policy explains how COSTTRAIL INC (“we”, “us”) handles information when you use Books2BI, including the website and web application at books2bi.com (together, the “Service”).

1. The short version

  • Your books and the documents you upload are stored encrypted in Amazon Web Services in the United States and are visible only to your workspace.
  • Teammates you invite work in the same books and share your token balance; each person's chat history stays private.
  • We do not sell personal information and we do not use your books, documents or questions to train AI models.

2. Who is responsible

For personal information about you as an account holder, COSTTRAIL INC is the data controller. For the contents of your books and documents, you control what you enter and upload and we process it on your behalf to provide the Service. Questions, access requests or complaints: support@costtrail.io. Mailing address: COSTTRAIL INC, 1900 Pleasant Street, Noblesville, Indiana 46061-0813, USA.

3. Information we collect

CategoryExamplesSource
Account informationname, email, business name (optional), password (stored only as a salted hash by Amazon Cognito)You, during sign-up
Authentication and sessionsession tokens, IP address, user-agent, sign-in timestampsAutomatically on use
Your booksthe screens of your tracker, entries, parties, items, accounts, opening balances, settings and invoice details (including your logo and tax registration numbers)You and your teammates
Documents you uploadbills, receipts, payslips, bank and wallet statements, spreadsheets and the fields and rows read from themYou
Questions and answersyour AI Chat questions and answers, kept as your private chat history; the conversation that designs your trackerYou
Workspace datateam members and pending invitations, audit log of changesYou and your teammates
Billing informationtoken purchases and balances; card details are handled by our payment partner, never by usYou; Lemon Squeezy
Usage recordswhich actions used tokens and how many, timings and error logsAutomatically on use
Support communicationsmessages you send through the contact form or by emailYou

4. How we use information

  • Provide, maintain and secure the Service, your account and your team's workspace.
  • Build your screens, keep your books, read the documents you upload onto them, check statements against them, and answer your questions.
  • Meter token usage, process purchases, and send transactional emails (verification codes, password resets, team invitations).
  • Detect and prevent fraud, abuse and security incidents.
  • Improve reliability and performance using aggregated, de-identified metrics.

We do not look at your books or documents except where you ask us to for support, or where the law requires it.

5. Legal bases

  • Contract: to deliver the Service you signed up for.
  • Legitimate interests: security, fraud prevention and service improvement, balanced against your rights.
  • Legal obligation: tax, accounting and responding to lawful requests.
  • Consent: optional communications, which you can withdraw at any time.

6. Automatic masking of sensitive data

When you upload a document, the Service detects and masks card numbers, card security codes and expiry dates, full bank account numbers and IBANs (the last four digits are kept so you can tell accounts apart), social security, Aadhaar and passport numbers, dates of birth and medical record numbers before the extracted content is stored, indexed or sent to an AI model. Values your books need are deliberately kept: tax registration numbers such as GSTIN, VAT, TRN and PAN on invoices, UPI IDs and payment references (UTR, cheque and transaction numbers) used to reconcile statements, amounts, dates, and person and business names. Detection uses pattern and checksum rules and Amazon Comprehend. Masking is provided on a best-effort basis and may not catch every instance (see section 7 of our Terms of Service). Your original uploaded file is kept unchanged, private to your workspace. Details you type into your own settings — such as your business's bank account and tax numbers for printing on invoices — are not masked.

7. AI processing

Designing your tracker, reading documents, answering questions and suggestions use AI models hosted on Amazon Bedrock (Anthropic Claude and Amazon Titan models). Only what is needed for each task is sent — for a question, your question and the relevant figures from your books and passages of your documents. These services process requests on an inference-only basis and do not use your content to train models. We do not train models on your data.

8. Who we share information with

  • Amazon Web Services (US) — hosting, storage, databases, sign-in (Amazon Cognito), email (Amazon SES), AI processing (Amazon Bedrock) and sensitive-data detection (Amazon Comprehend).
  • Lemon Squeezy (US) — our payment partner and merchant of record for token purchases.
  • Your teammates — members of your workspace see its books, documents and the team list.
  • People you share an invoice with — when you share an invoice link or PDF, its recipient sees that invoice.
  • Professional advisors — legal, accounting and audit firms, under confidentiality.
  • Authorities — when required by law or to protect rights, safety or property.

We do not sell personal information and we do not share it for cross-context behavioural advertising.

9. International transfers

The Service is hosted in the United States (AWS US East). If you use it from outside the US, your information is transferred to and processed in the US, with appropriate safeguards where required.

10. Retention and deletion

Your books and documents are kept until you delete them or close your account. Deleting a document removes it, what was read from it and its search index from the Service; backup copies are purged within 30 days. Chat history is deleted when you delete it or close your account. Account information is kept for the life of your account and a reasonable period afterwards for legal, tax and audit purposes; token usage and billing records are retained for up to 7 years. You can export your data or request deletion from the Your data page in the app.

11. Security

We use TLS 1.2+ in transit, encryption at rest, private storage that is not publicly reachable, per-workspace access checks on every request, least-privilege access, and monitoring. No method of transmission or storage is perfectly secure; we will notify affected customers of a confirmed incident without undue delay.

12. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, port your data, and withdraw consent. California residents have additional rights under the CCPA/CPRA. To exercise any right, email support@costtrail.io. We respond within the timeframes required by law.

13. Children

The Service is not directed to children under 16, and we do not knowingly collect their personal information.

14. Cookies and browser storage

We use strictly necessary cookies and browser storage to keep you signed in and remember preferences such as which set of books you have open. We do not use advertising cookies.

15. Changes

We may update this Policy. Material changes will be posted here with a new “Last updated” date and, where appropriate, communicated by email or in-product notice.

16. Contact

COSTTRAIL INC, 1900 Pleasant Street, Noblesville, Indiana 46061-0813, USA. Privacy: support@costtrail.io.