AccountingIQAccountingIQ

Privacy Policy

Last updated: March 14, 2026

This Privacy Policy applies to the AccountingIQ web platform at accountingaitutor.com. The AccountingIQ iOS app has a separate privacy policy.

1. Introduction

Format Partners LLC ("we," "us," or "Company") operates AccountingIQ, an AI-powered accounting tutoring platform available at accountingaitutor.com (the "Service"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and your rights regarding your data. By using the Service, you consent to the practices described in this Privacy Policy.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address
  • Display name (from your Google account, if applicable)
  • Profile photo URL (from your Google account, if applicable)
  • Firebase authentication user ID

2.2 User-Generated Content

When you use the Service, we store:

  • Chat messages and AI responses in your tutoring conversations
  • Documents you upload for analysis (PDFs, images)
  • Lecture audio files you upload for transcription
  • Flashcard decks and individual cards you create
  • Practice problems you save
  • AI-generated lecture notes and transcripts
  • Study schedules and completion progress
  • Exam prep session history and scores
  • Course configuration settings (textbook, professor, syllabus topics)

2.3 Subscription and Billing Information

When you subscribe to a paid plan, payment processing is handled entirely by Stripe. We do not store your credit card number, bank account details, or other payment instrument data on our servers. We do store:

  • Your Stripe customer ID (to link your account to your subscription)
  • Subscription status (free, active, trialing, past_due, canceled)
  • Plan type (monthly, semester, annual)

2.4 Usage Data

We automatically collect:

  • Feature usage counts (for rate limiting and free tier enforcement)
  • Login timestamps
  • Anonymous analytics data through Vercel Analytics and Vercel Speed Insights (page views, performance metrics)

2.5 Cookies

We use a single essential cookie (__session) to maintain your authenticated session. This cookie is HttpOnly (not accessible to JavaScript), Secure (only transmitted over HTTPS), and expires after 1 hour (automatically refreshed while you remain active). We do not use tracking cookies, advertising cookies, or third-party cookies for marketing purposes.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Authenticate your identity and manage your account
  • Process your documents, lectures, and queries through AI services to generate educational content
  • Store your study materials (flashcards, notes, schedules, chat history) so you can access them across sessions
  • Process subscription payments and manage billing through Stripe
  • Enforce usage limits and rate limiting to prevent abuse
  • Monitor and improve the Service's performance and reliability
  • Respond to support inquiries
  • Comply with legal obligations

We do not use your data for advertising, profiling, or selling to third parties. We do not use your User Content to train AI models.

4. Third-Party Services and Data Sharing

To provide the Service, your data is processed by the following third-party providers. We only share the minimum data necessary for each service to function:

Google Firebase (Authentication, Firestore Database, Cloud Storage)

Stores your account information, all user-generated content, and uploaded files. Data is stored in Google Cloud servers in the United States. Governed by Firebase Terms of Service and Firebase Privacy Policy.

Anthropic (Claude AI)

Processes your chat messages, uploaded documents, and lecture transcripts to generate AI-powered educational content. Content is sent to Anthropic's servers for processing. Anthropic does not use data sent via their API to train their models. Governed by Anthropic's Privacy Policy.

Deepgram

Processes lecture audio files you upload to generate text transcriptions. Audio data is sent to Deepgram's servers for transcription processing. Governed by Deepgram's Privacy Policy.

Stripe

Handles all payment processing for web subscriptions. Stripe collects and processes your payment information directly — we never see or store your full card details. Governed by Stripe's Privacy Policy.

Vercel (Hosting, Analytics)

Hosts the web application and collects anonymous performance and usage analytics (page views, load times). No personally identifiable information is collected by Vercel Analytics. Governed by Vercel's Privacy Policy.

We do not sell, rent, or trade your personal information to any third party. We may disclose your information if required by law, court order, or governmental regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

5. Data Storage and Security

Your data is stored on Google Firebase infrastructure in the United States. We implement the following security measures:

  • All data transmitted between your browser and our servers is encrypted via HTTPS/TLS
  • Authentication tokens are stored in HttpOnly, Secure cookies (not accessible to client-side JavaScript)
  • Firebase Authentication tokens are verified server-side before any data access
  • Firestore security rules restrict each user to accessing only their own data
  • Firebase Storage rules restrict file access to the uploading user
  • API keys and secrets are stored as server-side environment variables, never exposed to the browser
  • Content Security Policy (CSP) headers restrict resource loading to trusted origins
  • All server-side operations verify authentication before processing

While we take reasonable measures to protect your data, no method of electronic storage or internet transmission is 100% secure. We cannot guarantee absolute security.

6. Data Retention

  • Account data: Retained as long as your account is active. Upon account deletion, your data will be deleted within 30 days.
  • User-generated content (chats, flashcards, notes, documents, lectures): Retained as long as your account is active. You can delete individual items at any time through the Service. Files in Firebase Storage are deleted when you delete the associated item.
  • Subscription data: Billing records may be retained as required by tax and accounting regulations, even after account deletion.
  • Rate limiting data: Daily rate limit counters reset automatically every 24 hours.
  • Analytics data: Anonymous analytics data is retained according to Vercel's data retention policies.

7. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you
  • Deletion: Request deletion of your account and associated data by contacting hello[at]format[dot]partners
  • Correction: Request correction of inaccurate personal data
  • Portability: Request your data in a machine-readable format
  • Objection: Object to certain processing of your personal data
  • Withdraw consent: You may stop using the Service at any time

To exercise any of these rights, contact us at hello[at]format[dot]partners. We will respond within 30 days.

8. Children's Privacy

The Service is designed for college-level students and professionals studying accounting. We do not knowingly collect personal information from children under 13 years of age. If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact us at hello[at]format[dot]partners, and we will delete such information promptly.

9. International Data Transfers

The Service is operated in the United States. If you access the Service from outside the United States, your data will be transferred to and processed in the United States. By using the Service, you consent to this transfer. We rely on the data processing agreements of our third-party providers (Google, Anthropic, Stripe, Deepgram, Vercel) for compliance with international data transfer requirements.

10. California Privacy Rights (CCPA)

If you are a California resident, you have the right to: (a) know what personal information we collect about you; (b) request deletion of your personal information; (c) opt out of the sale of your personal information (we do not sell personal information); and (d) not be discriminated against for exercising your privacy rights. To exercise these rights, contact hello[at]format[dot]partners.

11. European Privacy Rights (GDPR)

If you are in the European Economic Area (EEA) or the United Kingdom, you have additional rights under the General Data Protection Regulation, including the right to access, rectify, erase, restrict processing, data portability, and object to processing. Our legal basis for processing your data is: (a) your consent when you create an account; (b) performance of a contract (providing the Service); and (c) our legitimate interests in operating and improving the Service. You have the right to lodge a complaint with your local data protection authority.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a prominent notice on the Service. The "Last updated" date at the top of this page indicates when the policy was last revised. Your continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.

13. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Format Partners LLC
Email: hello[at]format[dot]partners