Security & Privacy

How EasyAcco handles your financial data

EasyAcco processes all tax calculations at the edge — your financial numbers never touch our servers. All estimations run entirely in your browser. We only store data when you explicitly choose to save it, and only after you authenticate with Google.

Edge-First Calculations

Every tax calculation runs client-side in your browser or at the Vercel edge. No calculation data is transmitted to or stored on our servers.

Zero Storage by Default

In Guest Mode, nothing is persisted beyond your local browser session. We have no record of your income, expenses, or tax figures.

Consent-Gated Persistence

Data is only saved to Supabase when you sign in and explicitly trigger a Save or Export action. You are always in control.

Supabase Infrastructure

Where data is stored, it lives in Supabase — SOC 2 Type II compliant, encrypted at rest (AES-256) and in transit (TLS 1.3).

No Third-Party Analytics

EasyAcco does not embed tracking pixels, analytics SDKs, or ad networks. Your browsing behaviour on this platform is not monetised.

Auth via Google OAuth

Authentication is handled by Supabase Auth with Google OAuth 2.0. We never see or store your Google password.

Your Device, Your Keys

Expenses, invoices, and mileage you enter are stored in your browser's IndexedDB, encrypted with an AES-GCM 256 device key generated on first use. The key is marked non-extractable— it cannot be read or exported, not even by this app's own code. Xero, QuickBooks, FreeAgent, and Sage all require server round-trips; we don't.

The trade-off: clearing site data or switching browsers loses access to the key, and therefore the data. Use Settings → Backup to export a passphrase-protected snapshot. The passphrase derives a separate key via PBKDF2 (310,000 iterations, SHA-256) — keep it somewhere safe; it cannot be recovered.

What We Store (Only After Sign-In)

Email addressRequired for account identification via Supabase Auth
Saved transactionsOnly if you use the Save feature — encrypted at rest
Display nameOptional, editable in Settings at any time

Receipt Scanning & Third-Party Processing

EasyAcco has no AI features enabled and sends your data to no AI provider. Receipt OCR runs entirely in your browser via Tesseract — the photo never leaves your device. The Payslip Reader is the one feature that does upload: the image is sent to our own server, read once and discarded — never stored, never logged, never passed to a third party — and using it is optional, since every figure on a payslip can be typed in by hand. Your transactions, invoices and ledger are never transmitted to any third party other than HMRC, and then only for a return you actively choose to file.

Questions? Contact us at baradfiona14@gmail.com — or read the full privacy notice, which sets out every recipient of your data and your rights under UK GDPR.

EasyAcco is independent software. It is not produced, endorsed or approved by HM Revenue & Customs.