Last updated: May 29, 2026
BOA ("we," "our," or "the Service") takes the privacy and security of your financial data seriously. This policy describes what data we collect, how we protect it, how we use it, and your rights regarding your data.
| Category | Examples | Purpose |
|---|---|---|
| Account | Email address, hashed password | Authentication and account management |
| Financial Profile | Filing status, state, AGI, tax liability, DOB | Tax strategy calculations |
| Business Data | Entity names, EINs, revenue, expenses, employee salaries | Entity structure optimization and strategy generation |
| Income Data | W-2 amounts, K-1 distributions, rental income, capital gains | AGI calculation, bracket placement, strategy sizing |
| Retirement Data | Account types, balances, contributions | Contribution maximization strategies |
| Trust Data | Trust names, values, beneficiaries | Estate planning strategies |
| Usage Data | API access logs, audit trail entries | Security monitoring, audit compliance |
If you choose to connect third-party services (QuickBooks, payroll providers, banking, document scanning), data flows are governed by those providers' privacy policies. All integration vendors are SOC 2 Type II certified.
| Integration | Data Shared | Vendor Privacy |
|---|---|---|
| QuickBooks (Intuit) | OAuth token; BOA reads financial data | intuit.com/privacy |
| Finch (Payroll) | OAuth token; BOA reads employee/salary data | tryfinch.com/privacy |
| Plaid (Banking) | Link token; BOA reads account balances and transactions | plaid.com/legal |
| Veryfi (OCR) | Uploaded document images; deleted within 24 hours | veryfi.com/privacy |
No integration is required to use BOA. All integrations are opt-in.
AI Governance Disclosure: When the Raptor governance engine is connected, BOA may send summarized business context (entity types, revenue ranges, filing status, and your questions) to the Raptor service for governed strategic analysis. This data is used to generate responses and is not retained after processing. Core tax calculations, alerts, and recommendations run locally on the BOA server and never leave the system. Raptor governance is optional — BOA functions fully without it.
BOA uses the Raptor governance engine for strategy validation and audit trail generation. When strategies are generated, a summary of the analysis (strategy count, savings total, filing status, state) is sent to the Raptor service for governance evaluation. No raw financial data (SSN, EIN, account numbers, salary amounts) is sent to Raptor. Raptor produces an audit attestation that is returned to your BOA account.
BOA is not intended for use by individuals under 18 years of age. We do not knowingly collect data from minors.
We may update this Privacy Policy from time to time. Material changes will be communicated via the Service. The "Last updated" date at the top reflects the most recent revision.
Questions about this Privacy Policy may be directed to privacy@boa.aaservent.com.