Privacy Policy
Effective date: September 1, 2026 Last reviewed by counsel: September 1, 2026
This Privacy Policy explains how Bitment Inc. ("Bitment," "we," "us," or "our") collects, uses, shares, and protects information in connection with the Bitment platform and related services. Please read it carefully. If you have questions, contact us at the address in "Contact Us" below.
1. Scope
This Policy covers:
- The Bitment marketing website (bitment.co).
- The Bitment platform, including the operators workspace, the client portal, and the referrer portal.
- Per-firm subdomains (each firm you work with may have its own address, in the form
<firm>.bitment.co). - The self-serve bookkeeping product at books.bitment.co.
- The Bitment desktop apps (Mac and Windows) and the Bitment iOS app.
Throughout this Policy, "Customer Data" means the data a firm and its team submit, upload, generate, or store while using Bitment to serve their own clients (for example, client records, files, communications, and financial data). "Account Data" means information about you as an individual user or as a firm, collected in the course of operating the platform itself (for example, your sign-in credentials, billing details, and support requests).
2. Our Role: Processor and Controller
Bitment's role under privacy law depends on what data is at issue:
- Processor / service provider role. For Customer Data that a firm and its team put into Bitment to run their practice and serve their own clients, Bitment acts as a processor (or "service provider" under applicable state law) on behalf of the firm, which is the controller. The firm determines what data it collects from its clients, why, and how long to keep it. Bitment processes that data only to provide, maintain, and support the platform, as instructed by the firm, and as described in the firm's own agreement with Bitment.
- Controller role. For Account Data, billing records, marketing-site interactions, and support communications, Bitment acts as the controller and determines the purposes and means of processing, as described in this Policy.
- Self-serve bookkeeping. If you sign up directly for the self-serve bookkeeping product at books.bitment.co without going through a firm, you are Bitment's direct customer, and Bitment is the controller for the data associated with your use of that product.
If you are a client, contact, or other individual whose data was provided to Bitment by a firm you work with, your primary relationship for privacy purposes is with that firm. Please direct requests about your personal data to that firm in the first instance; Bitment will support the firm in responding as required by our agreement with them and applicable law.
3. Information We Collect
We collect the following categories of information, depending on how you use Bitment:
| Category | Examples |
|---|---|
| Account data | Name, email address(es), phone number, password hash, sign-in method, and two-factor authentication secrets once that feature is released |
| Firm and team data | Firm name and profile, team member roster, roles and permissions, invitations |
| Client records | Business and individual client profiles, contacts, and related CRM data your firm maintains |
| Communications | Email content and metadata, team chat messages, SMS and call recordings and transcripts, meeting recordings and transcripts |
| Files and tax documents | Uploaded files and documents, which may include tax documents containing Social Security numbers, Employer Identification Numbers, and financial statements |
| Financial and bookkeeping data | Bank transaction and statement data, invoices, and Bitcoin wallet activity (addresses, transaction history) |
| E-signature records | Signer identity, IP address, and timestamps associated with signature requests |
| AI conversations and agent activity | Messages, prompts, and files submitted to the AI assistant or autonomous agents, and records of actions those agents take |
| Usage and billing data | Feature usage, AI token consumption, invoices, and payment records |
| Device and push data | Device identifiers and push notification tokens used to deliver notifications |
| Log data | Server-side system logs, including request metadata and error information |
| Cookies and similar technology | Session identifiers and per-device preference data (see Section 9) |
We collect this information directly from you and your firm as you use the platform, and, where you choose to connect a third-party service, from that service (see Section 6).
4. How We Use Information
We use the information described above to:
- Provide, operate, and maintain the Bitment platform and its individual apps.
- Authenticate you, secure your account, and enforce roles and permissions within your firm.
- Process and route communications, files, and financial data at your firm's direction.
- Power AI features, including chat, autonomous agents, and transcription, as described in Section 5.
- Process payments and maintain billing and usage records.
- Provide customer support and respond to feedback.
- Send service notifications, security alerts, and, where you have agreed to receive them, marketing communications.
- Monitor, secure, and improve the reliability of the platform, including through system logs.
- Comply with legal obligations and enforce our agreements.
5. AI Features and Model Providers
Bitment's AI features (chat, the AI assistant, and autonomous agents) are bring-your-own-provider: your firm connects credentials for the AI provider(s) it chooses to use, such as Anthropic, AWS Bedrock, OpenRouter, or a self-hosted Ollama instance. When you submit a message, file, or other content to an AI feature, that content is sent to the provider your firm has selected and connected, under that provider's own terms and data-handling practices.
- Bitment does not train AI models on your Customer Data. We are not a model provider; we route your requests to the provider you choose and record usage for billing purposes.
- Speech-to-text transcription (for example, meeting or call transcripts) uses Amazon Transcribe.
- Optional AI-driven web search may use Tavily (if your firm supplies a key) or Bitment's own built-in web search, which runs on Bitment's servers and retrieves public web pages on your behalf.
- We record which model was used and the associated token usage and cost for billing and transparency purposes. We do not sell this usage data.
Because AI providers are your firm's own connections, your firm is responsible for reviewing the data-handling terms of the provider(s) it selects.
6. How We Share Information
We do not sell your personal information. We share information with the following categories of third parties, and only for the purposes described. Many of these services are connected only if your firm chooses to connect them.
| Third party / subprocessor | Purpose | When data is shared |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, database, storage, secrets management for the entire platform | Always, as the platform's infrastructure provider |
| Google (Gmail, Google Calendar, Google Tasks) | Email, calendar, and task synchronization | Only when you connect Google |
| Microsoft (Outlook mail and calendar, via Microsoft Graph) | Email and calendar synchronization | Only when you connect Microsoft |
| Slack | Team messaging integration | Only when you connect Slack |
| Signal | Messaging integration (Bitment links as a linked device) | Only when you connect Signal |
| Telegram | Messaging integration | Only when you connect Telegram |
| Twilio | Telephony and SMS/MMS: numbers, calls, recordings, live transcripts, carrier registration data | Only if your firm uses a Bitment-provisioned phone number |
| Quo (OpenPhone) | Telephony, using your firm's own account | Only when you connect your own Quo/OpenPhone account |
| Fireflies.ai | Meeting notes and transcription, using your firm's own account | Only when you connect your own Fireflies account |
| Asana | Project and task synchronization | Only when you connect Asana |
| Intuit QuickBooks Online | Accounting data synchronization | Only when you connect QuickBooks |
| Wolters Kluwer CCH Axcess | Tax software synchronization, using your firm's own account | Only when you connect your CCH Axcess account |
| Plaid | Bank transaction and statement retrieval | Only when you connect a bank account |
| Bitment's on-chain indexing service | Reads public Bitcoin blockchain data for addresses/extended public keys you supply | Only when you add a Bitcoin address or extended public key |
| LND | Lightning node data, using your firm's own node | Only when you connect your node |
| Nostr Wallet Connect / Alby Hub | Wallet connectivity over public Nostr relays | Only when you connect a wallet this way |
| Strike, Coinbase, Kraken | Exchange or wallet data, using your firm's own API keys | Only when you connect these accounts |
| Whop, Zaprite, Maverick Payments | Payment processing for the bookkeeping product, using your firm's own keys | Only when you connect these |
| Stripe | Bitment's own billing for AI usage (card on file, credits, invoices) | When you use paid AI features |
| Coinbase (public price feed), TwelveData | Market data for price displays | As needed to display pricing information |
| Anthropic, AWS Bedrock, OpenRouter, Ollama | AI model providers, using your firm's own connected credentials | Only for the provider(s) you select and connect |
| Amazon Transcribe | Speech-to-text transcription | When you use voice-to-text or transcription features |
| Tavily | Optional AI web search, using your firm's own key | Only if enabled |
| People Data Labs | Prospecting and contact enrichment data, using your firm's own key | Only when you use Campaigns sourcing |
| Apple Push Notification service, Web Push services | Delivery of push notifications | To deliver notifications you have enabled |
| AWS SES | Bitment's own transactional email (sign-in links, notifications, campaign email) | As part of normal platform operation |
| AWS SNS | SMS delivery for two-factor authentication codes | When SMS-based two-factor authentication is released and you enable it |
We may also share information: with service providers who support our own operations (for example, customer support tooling) under confidentiality obligations; to comply with law, regulation, legal process, or governmental request; to protect the rights, property, or safety of Bitment, our customers, or others; and in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections.
7. Google API Services User Data Policy
Bitment's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When you connect a Google account, Bitment may access Gmail messages, Google Calendar events, and Google Tasks, as authorized by the Google permissions you grant during connection. We use this data only to provide the features you have connected it for, for example displaying and sending email, showing and creating calendar events, or syncing tasks within the platform. We do not use Gmail, Calendar, or Tasks data for advertising purposes, and we do not transfer this data to any other party except: (a) as necessary to provide or improve the specific feature you connected, (b) to comply with applicable law, or (c) as part of a merger, acquisition, or sale of assets, in which case the data will remain subject to this Policy's commitments. You can disconnect Google access at any time from Settings, which revokes Bitment's access to your Google data going forward.
8. Microsoft Data
When you connect a Microsoft account, Bitment accesses Outlook mail and calendar data through Microsoft Graph, using the permissions you grant during connection. We use this data only to provide the email and calendar features you have connected. You can disconnect Microsoft access at any time from Settings.
9. Telephony, SMS, and Consent
If your firm uses a Bitment-provisioned phone number, calls, SMS/MMS messages, recordings, and live transcripts are processed through Twilio, including any carrier registration information (such as A2P 10DLC brand and campaign data) required to send business text messages in the United States.
Mobile opt-in data is not shared with third parties for marketing purposes. Information collected to establish SMS consent (for example, a phone number and the fact that a person opted in to receive texts) is used only to deliver the messaging features your firm has enabled and is not sold or shared with third parties for their own marketing.
If your firm records calls or meetings, your firm is responsible for providing any notice and obtaining any consent required under applicable call-recording and wiretapping laws in the jurisdictions where the parties to the call are located.
10. Cookies and Local Storage
Bitment uses a minimal set of cookies and browser storage:
- Session cookie. Your signed-in session is maintained through a session cookie that is HttpOnly (not readable by page scripts) and scoped to the specific host you are signed in on. It is used solely to keep you authenticated.
- Per-device preferences. Some interface preferences (for example, layout or display choices) are stored locally on your device and are not transmitted to Bitment's servers unless needed to sync a preference you have asked to be remembered across devices.
We do not use third-party advertising or tracking cookies on the platform.
11. Data Retention
- Database backups. Automated database backups are retained for 7 days.
- Storage snapshots. Data volume snapshots are retained according to an internal snapshot lifecycle policy.
- System logs. Infrastructure-level logs are retained for 30 days.
- Your data. Customer Data persists until deleted by you or your firm, or until your firm's contract with Bitment ends. On termination, Customer Data remains available for export for 30 days, after which Bitment deletes it from production systems, unless a longer period is required by law, subject to a legal hold, or agreed in writing. Backups age out on the 7-day schedule described above.
- You and your firm control deletion of files, AI conversations, synced messaging threads (purge and exclude), and disconnection of any integration at any time. A firm owner can delete a firm entirely, which cascades the deletion of that firm's owned data.
12. Security
We apply administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction, including network isolation per firm, encryption in transit and at rest, and application-layer encryption for sensitive credentials. SOC 2 audit in progress. Full detail is available in our Compliance & Security document. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Support Diagnostics and "View As"
By accepting the Terms of Service and using the Services, Customer authorizes Bitment support and engineering personnel to access Customer's account and workspace, including by viewing the Services as a specific Authorized User ("view as"), solely to diagnose and resolve issues, provide support, and maintain security. Bitment limits this access to what is necessary for those purposes. An individual user may additionally control this access through the in-product Diagnostics setting in their account, and may revoke it at any time. This access does not currently generate its own dedicated audit log.
14. Data Location
Bitment is offered to customers in the United States only, and all data is hosted in the United States. The Services are not offered to customers located outside the United States. If you access the Services from outside the United States, you do so on your own initiative and are responsible for compliance with local law.
15. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to object to or restrict certain processing. These rights may arise, for example, under state privacy laws such as the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and other applicable state privacy laws.
If your data was provided to Bitment by a firm as Customer Data, please direct your request to that firm; Bitment supports firms in responding to such requests as required by our agreement with them and by law.
For requests concerning your own Account Data (for example, your individual sign-in profile), contact us using the details in Section 18. We will verify your request and respond within the time required by applicable law. We will not discriminate against you for exercising your privacy rights.
16. Children's Privacy
Bitment is not directed to, and is not intended for use by, individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will take appropriate steps to delete it.
17. Changes to This Policy
We may update this Policy from time to time. We will post the updated Policy with a new "Last updated" date, and where changes are material, we will provide additional notice as appropriate.
18. Contact Us
If you have questions about this Privacy Policy or wish to exercise a privacy right, contact us at:
Bitment Inc. 1521 Concord Pike, Suite 201, Wilmington, DE 19803 contact@bitment.co