Privacy Policy

Last updated: February 2026

Overview

This privacy policy covers:
  • The VisiHub web application (app.visihub.app)
  • The VisiHub website (visihub.app)
  • The VisiHub API
  • Reconciliation controls

Data We Collect

Account information

When you create an account, we collect your email address and name. If you sign in via GitHub, we receive your GitHub profile information.

Uploaded data

Datasets, spreadsheets, and charts you upload are stored on our servers. Public data is visible to everyone. Private data is accessible only to you and your collaborators.

Financial credentials

If you use reconciliation controls, you provide API keys for services like Stripe, QuickBooks, and Mercury. These are stored encrypted and used only to fetch data for reconciliation runs. We never share credentials with third parties.

Reconciliation data

Transaction data fetched during control runs is processed in memory, stored as run artifacts, and retained for audit purposes. We do not use your financial data for any purpose other than providing the reconciliation service.

Website Analytics

We use Cloudflare Analytics for privacy-friendly website analytics. This provides aggregated data like page views and visitor counts. No cookies are used, and no personal data is collected by analytics. We do not use third-party tracking scripts, advertising pixels, or behavioral analytics.

Payments

Paid plans are processed through Stripe. When you subscribe:
  • Payment information is collected and processed by Stripe
  • We receive your email address and subscription details
  • We do not store credit card numbers
Stripe's privacy policy: stripe.com/privacy

Data Retention

  • Account data: Retained while your account is active
  • Public datasets: Retained indefinitely (snapshots are immutable)
  • Private datasets: Deleted when you delete them, or when your account is deleted
  • Reconciliation artifacts: Retained for audit trail; deleted when you delete the control
  • Financial credentials: Deleted when you remove the connection or delete the control
  • Payment records: Retained for accounting and legal purposes

Data Security

We take reasonable measures to protect your data:
  • All data in transit is encrypted via TLS
  • Financial credentials are encrypted at rest
  • Reconciliation proofs use Ed25519 signatures and BLAKE3 hashing
  • Access to production systems is restricted and audited
No system is perfectly secure. If we discover a breach affecting your data, we will notify you promptly.

Your Rights

You can:
  • Export your data at any time via the API
  • Delete your datasets, controls, and connections
  • Delete your account (which removes all private data)
  • Request a copy of any personal data we hold about you
For any privacy-related requests, contact: privacy@visihub.app

Contact

This service is operated by:

RegAtlas, LLC

privacy@visihub.app