Privacy
Last updated 1 October 2026
Business Manager is a tool for running a business: clients, deadlines, invoices and the money behind them. This page describes exactly what it stores and who can reach it. It is written to be accurate rather than reassuring — if something here reads as a limitation, it is one.
What is stored
When you sign in. Your name, email address and profile picture, from Google. If you use a password instead, your name and email, and the password itself only as a scrypt hash — it is never stored in a form anyone can read, including us.
What you put in. Everything you enter: businesses, clients and their contact details, tasks, invoices and their lines, income and expense entries, notes, documents you upload, subscriptions, and the calendars you connect.
What the app records itself. Sign-ins and failed sign-in attempts, and changes to money and to who has access. Reading a page is not recorded.
How fast it was. Each page load reports how long it took to appear and to respond. What is kept is the route — /b/[slug]/invoices, never your business’s name — the name of the measurement and the timings, added into a running total. No account, no address, no device, nothing that could be traced back to a visit. It is the app measuring itself, and it is the only way to know whether it is slow for the people using it.
Who can see it
Your businesses are private to you and to people you explicitly invite. Every query is scoped to the business you belong to, so another account cannot reach your records by guessing an address.
Whoever administers this installation can see that businesses exist, who has an account, and counts — how many invoices, how many entries. They cannot open your invoices, your documents or your notes.
Where it lives, and who else touches it
Everything is processed inside the European Union. These are the only companies involved, each acting on our instructions and under their own terms:
- Neon — the database, in Frankfurt, Germany.
- Vercel — runs the application; the code that touches your data runs in Frankfurt.
- Cloudflare R2 — files the app stores itself, and the nightly backups, in the EU jurisdiction.
- Google — sign-in, and Google Drive if your business connects one.
- Microsoft — OneDrive, if your business connects one.
- Resend — sends the app’s email.
Where your business connects its own Google Drive or OneDrive, documents go there instead and the app holds nothing but the record of them. It is given access to one folder it creates, and can see nothing else in that account. Folders you link from your own computer are never copied or read — the app records where they are and opens them.
Calendars you connect
Connecting Outlook or Google Calendar asks only for permission to read your calendars — never to create, change or delete anything in them. The app reads the appointments falling in the month you are looking at, to draw them beside your own deadlines, and it stores no copy of them: they are fetched when the page is drawn and gone when you leave it. What is kept is the permission itself, encrypted, so the page can be drawn again without asking you to sign in each time. Disconnecting on the Calendar page deletes that permission; your calendar is untouched.
Business Manager’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data is never sold, never used for advertising, never used to train any model, and never read by a human — it is shown to you, on your own screen, and nowhere else.
Cookies
One cookie, holding your session so you stay signed in. No advertising, no third-party analytics and no tracking of any kind — nothing on these pages is loaded from, or reports to, anybody else. Signing out deletes the session.
How long it is kept
A sweep runs every night and deletes what is past its time. This table is the same list of numbers the sweep uses, so the policy and the code cannot disagree.
- Your records — businesses, clients, invoices, entries, documents, notesUntil you delete them
- They are the reason the app exists, and accounting records that vanish on a schedule are a liability rather than a courtesy. Deleting a business deletes all of them at once.
- Your accountUntil you delete it
- You can delete it yourself, from the account page, without asking anybody.
- Sessions30 days, and until you sign out
- A session that has expired can no longer sign anybody in, so keeping the row serves nothing.
- Who changed what — the activity record2 years
- Long enough to answer who changed an invoice last accounting year; not a permanent history of everyone's working day.
- Failed sign-in counters1 day
- They exist to slow down somebody guessing a password this hour. A day later they are only a record of who tried.
- Server errors90 days once dealt with, 365 days if nobody sees them again
- An error carries the address of the page it happened on. It is worth keeping while it is a to-do, not afterwards.
- Slow query records90 days
- They hold the shape of a query and its timing, never its arguments, so they contain none of your data — they are pruned because stale timings mislead.
- Invitations nobody accepted90 days
- An unaccepted invitation is somebody's email address being held for an offer they did not take.
- Nightly backups30 days
- Far enough back to recover from something noticed on Monday. Deleting your data also removes it from every backup taken after that.
Your rights
Under the GDPR you may ask for a copy of your data, correct it, have it deleted, or object to its processing. Two of those need nobody’s permission here, because they are buttons:
- A copy. Your account downloads everything the app knows about you; a business’s settings page downloads that whole business as one JSON file, records and all.
- Deletion. The same two places delete them, immediately and for good. Deleting a business deletes its records and the files the app holds; files in your own Drive stay in your Drive, because the app was never given permission to tidy it.
- Correction. Everything you entered, you can edit.
For anything else, write to hello@actcfo.com and we will answer within thirty days.
You may also complain to your data protection authority. In Lithuania that is the State Data Protection Inspectorate.
Changes
If this page changes in a way that affects what is stored or who can see it, the date above changes too. Nothing is applied retroactively to data already collected.