The short version: MosoFin reads your financial data on demand to build reports inside Claude. MosoFin reads permitted financial data on demand through read-only tools, we don't sell your data, and relevant tool and permission activity is recorded in each workspace's activity history. The details are below.
1. Scope
This Privacy Policy explains how BambooX LLC, a California limited liability company that operates MosoFin (“MosoFin”, “we”, “us”), handles personal information when you visit our website, create an account, and use the MosoFin service (the “Service”), including the MosoFin MCP server used within Claude. It applies to our own processing. For data we process on behalf of a business customer, that customer is the controller and its agreement with us governs.
2. Information we collect
Account & contact information
Your name, work email, workspace details, and the role/permissions you set up. If you contact us, we keep your correspondence.
Connection details
When you connect a data source (for example, QuickBooks Online), we store the authorization tokens and connection settings needed to make read-only calls on your behalf — scoped to your workspace, role and limits. We store these to operate the connection, not your underlying financial records (see “Your financial data”).
Usage, requests & activity history
Records of the actions taken through the Service — which tools were called, which skills ran, timestamps, and the request/response metadata that makes up your workspace's activity history — plus standard log and device data (such as IP address and browser type).
Website & marketing data
Information collected on our website through cookies and analytics, and details you provide if you sign up for updates or a demo.
3. How we collect it
We collect information directly from you (when you register, configure the Service, or contact us); automatically (through cookies and logs when you use the website or Service); and from the services you authorize us to connect (for example, when you grant access to your accounting system, we receive the access tokens and the specific data you ask the Service to read at the moment of a request).
4. How we use it
- to provide, operate, and maintain the Service and your connections;
- to run the reports, dashboards and drafts you request, and to power skills inside Claude;
- to maintain your activity history and enforce your permissions and usage limits;
- to provide support and send service-related communications;
- to secure the Service, prevent abuse, and debug;
- to improve the Service using aggregated or de-identified information;
- to send marketing where permitted (you can opt out at any time); and
- to comply with legal obligations and enforce our terms.
5. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Service you request); our legitimate interests (to secure and improve the Service, and for B2B marketing), balanced against your rights; your consent (for non-essential cookies and certain marketing), which you may withdraw; and compliance with legal obligations.
6. Your financial data: read-only, nothing stored
This is core to how MosoFin works. When the Service needs your financial data to build a report, it reads it from your connected system on demand and uses it to produce the output you asked for. The Service does not run a background sync of your books. The Service is read-only — it has no tools that write back to or change your connected systems. The outputs you generate, and the activity history of tool and permission events, are retained as described below.
8. Data retention
We keep account and connection information for as long as your account is active, and connection tokens until you disconnect a source or close your account. Activity history is retained for the period needed to provide the Service and meet legal and security obligations. We may keep aggregated or de-identified information that no longer identifies you. When information is no longer needed, we delete or de-identify it. You can request deletion as described below.
9. International transfers
We may process information in countries other than yours, including the United States. Where required, we use appropriate safeguards for cross-border transfers, such as the European Commission's Standard Contractual Clauses, and take steps to ensure your information remains protected.
10. Security
We use technical and organizational measures designed to protect your information, including encryption in transit, access controls, scoped connection tokens, read-only access to connected systems, and a record of activity. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; please keep your credentials confidential.
11. Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. If you are in California, you may request to know, delete, or correct your information and to opt out of “sale” or “sharing” — and we do not sell your personal information. We will not discriminate against you for exercising these rights.
To make a request, contact [email protected]. We may need to verify your identity. If we process your data on behalf of a business customer, we will refer your request to that customer.
13. Children
MosoFin is a business tool that is not directed to children and is not intended for anyone under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
14. Third-party links
Our website and the Service may link to third-party sites and services that we don't control. This Policy doesn't cover their practices; please review their privacy policies.
15. Changes to this Policy
We may update this Privacy Policy from time to time. We'll post the updated version with a new “last updated” date and, for material changes, take additional steps to notify you where appropriate. Your continued use of the Service after an update takes effect constitutes acceptance.
16. Contact
Questions or requests about your privacy? Contact us at [email protected].