Privacy

Privacy Notice

Berean reads two exported general ledgers and compares them. This notice says what it does with those files: what is kept, what is not, and who can read it.

Effective July 29, 2026. Last updated August 8, 2026.

What Berean does

Berean compares two exported general ledgers — one from your property software, one from your accounting system — and shows the differences it finds. The free audit reports how many and how much; a paid workspace also shows the ledger rows behind each finding.

Berean never connects to your property software or your accounting system, never signs in on your behalf, and never writes anything back to either one. It asks for no login to either system and holds no credential for either.

The free audit keeps nothing

A free audit at /audit runs entirely in memory. No ledger row from a free audit is written to a database or to disk — the comparison runs, you read the result, and the rows are gone when the request ends.

What comes back on screen is aggregates: counts, dollar totals, dates and per-check subtotals. It structurally cannot contain a payee, a memo or a ledger line.

A free audit needs no account, and running one sets no cookie.

A signed-in run does store your ledger rows

This is the difference between the free audit and the product, and it is worth reading before you upload. When you are signed in and import a ledger, the rows are stored so the comparison can be re-run, filtered, printed and re-read later. That retention is what the product is for.

What is stored from an uploaded export:

  • every row of both files, including the account name and path, the entry date, the amount, the document number, the entry type, the counterparty or payee name, the memo, and any property or unit reference the export carries;
  • every other column of your export, kept verbatim, so a comparison can show you the original row rather than a reconstruction of it;
  • information about the upload itself — the filename, its checksum, the format it was read as, the accounting basis, the period the export states, row counts, and the confirmation you gave that you are authorised to upload it;
  • the results: comparison runs, the differences found, and the evidence rows attached to each one.

Berean also records a structural fingerprint of files it could not recognise — the column headings with every digit masked, and the file’s dimensions as counts — so unsupported formats can be found and supported. Amounts, dates, names and memos are removed before that record is written.

An account holds the email address and business name you sign up with. Passwords are handled by Supabase authentication: Berean passes yours straight to it and stores no password itself.

Who can read it

Your workspace is readable by people with an active membership in it. Separation between workspaces is enforced in the database by row-level security, not only in the application, so a query from one workspace cannot return another’s rows.

A support request you send is narrower still: it is readable only by the account that sent it, not by the rest of your workspace, because it carries your address and whatever you wrote about the problem.

Hineni Group Digital LLC operates Berean and its people can reach the database to run and support it.

Diagnostics and support

If you send Berean a diagnostic bundle from the support page, it carries shapes rather than contents: error codes, counts, sizes, timings and flags, together with your account email address so we can reply. It carries no ledger row, no amount, no party name and no memo. The bundle is shown to you in full before you send it.

Who else processes it

Three providers. Supabase provides authentication and the database that holds your workspace. Vercel hosts the application and provides aggregate traffic analytics about page requests. Stripe handles subscriptions and payments.

Stripe receives your email address, an identifier for your account and workspace, and whatever you type into its own checkout and billing pages — including your payment details, which are entered on a page Stripe hosts and serves. Those pages are not Berean’s. Berean never sees, receives or stores a card number or a bank account number, and there is no field anywhere in this application that accepts either.

Stripe receives no ledger data. Not a row, not an amount from your books, not an account name, not a party name, not a memo, and not a finding. What Berean sends Stripe is who is subscribing; what it reads back is whether that subscription is active. If no subscription has ever been started for your account, Stripe has received nothing about you.

Berean sends no marketing email and no notification email. Supabase sends authentication mail — confirming an address, resetting a password — when you ask for it.

What is not connected

QuickBooks, property-management software, payment processing and outside provider actions remain disconnected. Berean does not send messages, move money, or change outside accounting records.

Your controls

You can read your own data inside the product: the findings surface shows every difference with the rows behind it, and the printable report lays a comparison out as a document you can print or save as a PDF. Each document states how much of the run it covers.

There is no self-serve delete. Deleting an account or a workspace is not built yet. To have your data reviewed, corrected, exported or deleted, write to mike@hinenigroup.us and it is done by hand. We would rather say that plainly than offer a button that does not exist.

Changes to this notice

This notice describes Berean as it runs today. When it changes, the date at the top changes with it.

Contact

Privacy questions can be sent to mike@hinenigroup.us. See also the Terms.