Privacy

Privacy notice

What we collect

When you create a Decyml account, we collect your name and email address and store a secure hash of your password. When you join the early-access list, we collect your email address and may also store basic campaign information from the link you used, such as UTM parameters, the referring page, and the landing-page URL. We place a first-party cookie on that browser so the site can remember that you joined; the cookie does not contain your email address. When you connect or import accounting data, we store normalized transaction details, including transaction notes, memos, and line-item descriptions, source categories, and review history. Uploaded CSV files are processed for import but are not retained after the request.

When a firm owner invites a team member, we store the invited email address, the firm, the inviting user, the member's role and QuickBooks approval access, and a one-way hash of the invitation link, and we email the invitation to that address. Members' names, email addresses and roles are visible to others in the same firm. When you request a password reset, we store a hashed reset token for a limited time and email the reset link to the account address.

How we use it

For two-factor authentication, we store an encrypted authenticator secret and encrypted recovery codes, whether setup is confirmed, and the last accepted code time to prevent reuse. We also record account security events, team invitation and access changes, approval-permission changes, QuickBooks connection or disconnection, requests to view or download original check and statement files and uploaded attachments, and deletion of those documents. These records identify the acting account, firm, affected record and client where applicable, the action, and its time. They help protect access and investigate security issues; they do not contain document contents, bank details, passwords, authentication codes, invitation links, or QuickBooks tokens. Authenticator QR codes are generated by Decyml without sending the setup key to an external QR service.

We use this information to operate your workspace, import and search transactions, suggest categories, surface items for human review, measure interest in Decyml, and send occasional product research or launch updates. We do not sell waitlist or transaction information.

Storage and sharing

Account, waitlist, normalized transaction, and review data is stored in Decyml's application database. The current site does not use third-party advertising pixels or behavioral analytics.

When you select transactions for AI review, Decyml sends the transaction fields needed for categorization and anomaly review, including their notes, memos, and line-item descriptions, together with the names of the client's accounts to choose from, to OpenAI for processing. API requests disable response storage, but provider processing remains subject to OpenAI's applicable terms and policies.

Check documents and extraction

When you upload a check, we store the original image or PDF encrypted in Decyml's database, its client association, extracted payee/date/check number/amount/memo, and your review corrections. The document and review data are retained until you delete the check in its review screen or request account deletion. Deleting a check removes its application record and stored document; existing backups follow the site's backup retention process.

The full check image or PDF is sent to OpenAI for extraction.

Any routing numbers, account numbers, signatures or other information visible in the document are included in that processing even though Decyml does not extract them as separate fields. OpenAI check requests disable response storage. Extracted check fields remain drafts until you confirm them. Extraction and confirmation do not post to QuickBooks; you can separately prepare and approve a QuickBooks expense.

Statements, financial reports and workflows

When you upload a bank or credit card statement, we store the original PDF encrypted in the application database, extracted and corrected statement data, the selected account, and comparison results. PDF extraction sends the complete document to OpenAI, including details printed on its pages. Response storage is disabled. Deleting a statement removes its PDF and application extraction/comparison record; existing backups remain subject to the site's backup retention process.

For clients whose books are kept in Decyml instead of QuickBooks, we store the client's chart of accounts, its bank and credit card account names with optional last four digits and currency, and which account each confirmed statement belongs to. Reports for these clients are calculated from the reviewed transactions when you open, print or export them; Decyml stores only the notes your team adds to a report month and any opening balances you enter for the balance sheet.

QuickBooks report review stores the requested P&L reports, periods, basis, computed comparisons and optional AI summary drafts and review questions. A report package loaded from QuickBooks stores the P&L and balance sheet reports it read for that month and basis. Generating a draft sends calculated financial observations, including totals, margins and selected account changes, to the configured AI provider described above. AI writes an introduction and selects highlights; Decyml inserts the corresponding saved financial figures. The generated wording and questions require accountant review. We also store workflow templates and published versions, client assignments and settings, linked review records, monthly runs and review notes to track your work.

When you request an allocation suggestion, the source payee, date, amount, memo and line descriptions, together with eligible company account and class names, are sent to the configured AI provider described above. We store the proposed allocations and review notes. Suggestions require your review and saving; posting still requires separate approval of the exact saved change.

Review rules can store separate account and class mappings for each client, tied to that client's connected company. Saved rule proposals retain the mapping used for the review. Rule-based allocation proposals run locally without an AI request and still require review and separate posting approval.

Preparing QuickBooks changes stores account, vendor and class references, a source snapshot, allocations, an approval record and the posting result. Each write requires explicit accountant approval. Deleting an uploaded source document does not delete a separate posting approval or change anything already recorded in QuickBooks. Contact us to request deletion of retained workflow, report or posting records.

When you edit a QuickBooks transaction in Decyml, we store the pending edit with who made it: the chosen payee, location, class and customer (their QuickBooks references and names), whether lines are billable, memo text, and any split lines with their accounts, amounts and descriptions. A bulk edit of many transactions also keeps a record of the requested edit, the transactions it covered and its result. Pending edits are sent to the client's QuickBooks company only when an approver posts the reviewed change, and are removed once it is posted or discarded.

When you attach a receipt or other file to a QuickBooks transaction, we store the file encrypted in Decyml's database with its name, type, size and the transaction it belongs to. Uploaded receipts are stored and sent to the client's QuickBooks company, attached to that transaction, only when an approver posts them; until then, removing a file deletes it from Decyml and nothing is sent. When an approver posts an expense created from a check, the check image is also sent to QuickBooks and attached to that expense. A file sent to QuickBooks stays there until it is removed in QuickBooks; Decyml keeps its copy until you ask us to delete it.

For a client connected to QuickBooks, the Vendors page reads that company's vendors and stores each vendor's name, company name, primary email, billing address, 1099 status, active status and balance, and the tax ID as QuickBooks returns it, masked to its last four characters. When you edit a vendor or deactivate a duplicate, the changed name, email, billing address, 1099 status, active status and any new tax ID are sent to QuickBooks only after an approver posts the change. A newly entered tax ID is stored encrypted only until that change is posted, then removed; Decyml shows it masked and does not write it to logs. Merging duplicate vendors saves payee changes on the duplicates' transactions, which are reviewed and posted the same way.

Client contacts and portal

A firm keeps a list of the people at each of its clients. For each contact we store their name, and, where entered, email address, mobile phone number and title or role, which of the firm's clients they are listed on, and which person is each client's primary contact. Firm members enter these details; a contact who uses the client portal can update their own mobile number there. Decyml does not currently send text messages.

A firm can give contacts read-only access to a client portal. For each portal account we also store a hashed password, which of the firm's clients the contact may see in the portal and whether they may see reports, documents or both, who granted that access, and when they last signed in or used the portal. Each sign-in sends a six-digit code to the contact's email; we store only a keyed hash of the code with its expiry and attempt count, and clear it once used. A contact who uses an authenticator app has an encrypted authenticator secret and encrypted recovery codes, stored the same way as for workspace accounts. Password reset tokens for contacts are stored hashed and expire after one hour.

When a firm publishes a report to the portal, we store a copy of the report package exactly as published, including its figures and the accountant's notes, so later changes in Decyml or QuickBooks do not change what the client sees. Replaced and withdrawn versions are kept for the firm's history. Files a firm shares in the portal are stored encrypted in Decyml's database; removing a file deletes it and keeps only its name, size and who shared and removed it. A firm's portal logo is stored with its other settings.

We record portal activity: contact sign-ins, sent and failed sign-in codes, password and authenticator changes, report views and document downloads, and firm changes to portal access, publishing and shared files. These records identify the contact or team member, the firm, the client and the record involved, and the time; they do not contain codes, passwords, email addresses or document contents. Portal invitations, sign-in codes, password resets and portal notices are sent by email from Decyml's mail server. The portal makes no AI requests and no QuickBooks requests.

Connected services

If you connect QuickBooks Online, Intuit handles the authorization screen and Decyml stores your QuickBooks company ID, encrypted authorization tokens, and the transaction details imported for your workspace. These credentials maintain the connection and will be used only for QuickBooks features you choose to use. You can revoke the connection from Settings; imported transaction data remains available until you ask us to delete it.

Your choices

You may ask to access or delete your account or waitlist information, or unsubscribe from future messages, by contacting admin@decyml.com.

Product status

Decyml is early-stage software in active development. AI categories and anomaly flags are suggestions that require human review and may be incomplete or incorrect. Decyml does not provide accounting, tax, legal, or financial advice. See our Terms of use and end-user license agreement for conditions of use.