Legal
Privacy Policy.
Last updated 25 August 2026.
This Privacy Policy explains how Event Foundry Inc. (“Summely”, “we”, “us”) collects, uses, discloses and protects personal information when you visit summely.com or use the Summely accounting application (together, the “Services”). It forms part of, and should be read with, our Terms of Service.
Summely is an accounting system. Most of what we hold on your behalf is your business’s financial records, which we treat as your confidential information and process only to provide the Services to you.
1. Who we are.
Event Foundry Inc., 1550 Larimer St., Ste 861, Denver, CO 80202, is the controller of personal information processed through the Services, except where we act as a processor on your behalf (see “Customer Data” below). You can reach us at privacy@summely.com.
2. Information we collect.
Information you provide
- Account information. Your name, email address and password (stored only as a cryptographic hash). If you sign in with Google, we receive your email address, name and a stable identifier from Google; we never receive your Google password.
- Organization information. Your business name, home currency, financial year and the people you invite.
- Customer Data. The accounting records you enter or import — invoices, bills, payments, journal entries, contacts, documents you upload, and everything derived from them.
- Communications. Messages you send us and our replies.
Information from connected services
- Bank data via Plaid. If you connect a financial institution, you authenticate with Plaid, not with us. We never receive or store your banking credentials. We receive an access token, which we hold encrypted at rest under a key managed separately from the application database, and the transaction and balance data you authorize.
- Accounting data via Intuit QuickBooks. If you import from QuickBooks, we receive the records you authorize and OAuth tokens, stored encrypted.
- Payment information via Stripe. Subscriptions are processed by Stripe. We do not receive or store your full card number. We receive a customer and subscription identifier, the card brand, its last four digits and its expiry.
Information collected automatically
- Server logs. The request made, the time, an IP address and a user agent, kept to operate the Services and detect abuse.
- Device and session information. A device identifier you can inspect and revoke from the Devices screen, so that signing a device out actually ends its session. This identifier is a random value the application generates for itself on first run and stores on the device. It is not a hardware serial number, not an advertising identifier, and not the iOS Identifier for Vendors or the Android Advertising ID — we do not read any identifier the operating system assigns to your device.
- Product usage. A fixed, published list of named product events — that an invoice was created, that a report was exported, that a bank was connected, and roughly a dozen more — together with the platform the application was running on (iOS, Android or web), associated with your account. Each event carries at most a handful of properties, and every property is either a value drawn from a fixed list (a plan name, a report name) or a whole-number count. There is no free-text field anywhere in this data, so a customer name, an invoice memo or an amount has no shape in which it could travel; it never includes the contents of your accounting records. We do not record screen views, taps or scrolling. We use this only to understand and improve the product, under the legitimate-interests basis described below, and you can switch it off for your account at any time in the application’s settings — when you do, the application stops collecting on your device and we discard anything that arrives anyway.
- Audit records. Actions taken in your organization’s books, including who took them and when. These exist so your books can be audited and are retained as part of your records.
The iOS and Android applications
Everything above applies to the mobile applications. These disclosures are specific to them.
- Face ID, Touch ID and Android biometrics. You can choose to lock the application behind your device’s biometric unlock. The check is performed entirely by iOS or Android: the operating system shows the prompt, matches the fingerprint or face against what is enrolled on the device, and tells the application only whether the attempt succeeded. Your biometric data never leaves your device, and Summely never receives, stores or has any way to obtain it. All we store is your preference, on the device, that the lock is on. Turning it off in your device settings, or removing your enrolment, simply returns you to signing in with your password.
- Credentials stored on the device. Your sign-in tokens are held in the operating system’s own secure storage — the iOS Keychain and the Android Keystore — and are marked as available only while the device is unlocked and only on that device. They are not written to ordinary application storage, and signing out removes them.
- Work saved on the device. So that nothing you enter is lost when you are offline or on a bad connection, the applications keep a queue of your unsent changes in a local database on the device. Entries are removed once our servers confirm them. This is a working copy of your own Customer Data, held on your own device.
- Bank connections. On mobile, Plaid’s own software runs inside the application to collect your bank credentials. It is Plaid’s code and your credentials go to Plaid, not to us; see “Bank data via Plaid” above and section 5.
- No third-party analytics or advertising software. The applications contain no advertising software development kit, no third-party analytics or attribution software, and no cross-app or cross-site tracking. The product usage described above is first-party: the events are sent by our own code directly to our own API and are stored by us. No third party receives them.
- Camera, photo library, contacts and location. The applications ask for none of these and have no access to them. The only permissions the Android application declares are the two that allow the biometric prompt to be shown. Attaching a document uses your device’s own file picker: you choose the file, and only the file you chose is given to the application. If any of this ever changes, it will change in a release that goes through the app stores, and this Policy and the store listings will say so first.
3. Cookies and similar technologies.
The marketing site at summely.com uses Google Analytics to count visits and see which pages are read. It sets Google’s own analytics cookies (names beginning _ga) and loads one script from googletagmanager.com; nothing else on the site comes from a third party — no fonts, no advertising, no other trackers. Google Analytics is configured for measurement only: we do not enable its advertising or audience-sharing features, and the site sends Google no name, email address or anything else that identifies you. The application at app.summely.com carries no Google Analytics and no third-party analytics of any kind, which is the boundary that matters — your books are never measured by anybody but us.
If you would rather not be counted, any browser setting or extension that blocks Google Analytics will stop it, and the site works exactly the same without it. We do not treat visitors differently for blocking it.
The application stores authentication tokens on your device (in browser storage on the web, and in the operating system keychain on iOS and Android) because you cannot stay signed in otherwise. A short-lived session cookie may be set during sign-up, email verification and password reset to carry the state of that flow. We do not use advertising cookies and we do not track you across other websites.
The iOS and Android applications use no cookies and no advertising or tracking technology of any kind. What they keep on the device is described in section 2: your sign-in tokens, your own preferences, the queue of unsent changes, and the device identifier the Devices screen lets you revoke. Uninstalling the application removes all of it.
4. How we use information.
- To provide, maintain and secure the Services.
- To authenticate you, and to let you manage and revoke your own sessions.
- To process subscriptions and send billing notices.
- To send transactional messages — verification codes, password resets, invoices and receipts you ask us to deliver, and notices about the Services.
- To extract data from documents you upload, so that a bill or receipt becomes a draft entry you review before it is posted.
- To provide support you request, and to investigate abuse, fraud or violations of our Terms.
- To understand how the Services are used, in aggregate, so that we can improve them. This is counted from records we already hold — chiefly the audit trail described above — and it is counted, never read: it tells us how many organizations posted a transaction on a given day, not what any transaction said.
- To comply with legal obligations.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use your Customer Data to train machine-learning models for anyone else’s benefit.
Legal bases (UK/EU)
Where the UK GDPR or EU GDPR applies, we rely on: performance of a contract (providing the Services you have signed up for); legitimate interests (securing the Services, preventing abuse, and improving the product, balanced against your rights); consent (where asked for, and withdrawable at any time); and legal obligation (records we are required to keep).
5. How we share information.
We disclose information only as described here. We use the following service providers (subprocessors), each bound by contract to protect the information they handle:
- Amazon Web Services — hosting, database, file storage, email delivery, and document text extraction (Amazon Textract and Amazon Bedrock). United States.
- Plaid — bank account connections and transaction feeds, including Plaid’s own software running inside the iOS and Android applications. Plaid processes the information you give it under its End User Privacy Policy.
- Stripe — subscription billing and card processing.
- Intuit — QuickBooks import, where you choose to use it.
- Google — sign-in with Google, where you choose to use it; and Google Analytics on the marketing site only, as described in section 3.
We may also disclose information: to your own organization’s members and anyone you invite, according to the role you give them; where you direct us to (for example, emailing an invoice to your customer); to professional advisers; to comply with law or valid legal process, where we will notify you unless legally prohibited; to protect the rights, safety and property of Summely, our users or the public; and to a successor in connection with a merger, acquisition or sale of assets, subject to this Policy.
6. International transfers.
We operate in the United States, and information is processed there. If you are in the United Kingdom, the European Economic Area or Switzerland, transfers are made under the UK International Data Transfer Agreement or Addendum and the European Commission’s Standard Contractual Clauses, together with additional safeguards where required.
7. Retention.
We keep Customer Data for as long as your account exists. Accounting records are subject to statutory retention periods in most jurisdictions, so we do not delete your books automatically when a subscription lapses — an unpaid account becomes read-only, not erased.
When you ask us to delete your account, we delete or de-identify Customer Data within 30 days, except where we are required to retain it by law or need it to resolve disputes or enforce our agreements. Backups are purged on a rolling schedule not exceeding 90 days. Server logs are retained for up to 12 months.
When something we are processing for you fails. If an upload or an import cannot be processed — an unreadable bank statement, a document our reader could not make sense of — we keep what you sent us rather than discarding it, so that it can be retried and finished rather than asked for again. That copy is held for no more than 30 days after the work is completed or handed to a person, and it is deleted along with everything else if you delete your organization. It is held in the same encrypted storage as your books, and is used for nothing except completing the work you asked for.
Deleting your account
You can ask us to delete your account and its data at any time, whether you signed up on the web, on iOS or on Android, and whether or not you have ever paid us. You do not need an active subscription to make the request, and you do not need to reinstall or open the application to make it. There are three routes: More → Account → Delete my account inside the application, the account deletion page published on summely.com, and writing to privacy@summely.com from the email address on the account. All three reach the same place.
We will confirm the request, verify that it comes from you, and tell you what will happen before anything is destroyed. Deleting an organization destroys its books in full: the accounting records, the documents you uploaded, and the connections to Plaid, QuickBooks and Stripe made for it. Deleting a user removes the person and severs them from any usage records we still hold, which survive only as counts that identify nobody. What we may keep is limited to what the law requires us to keep, and what we need to resolve a dispute or enforce our agreements — anything kept on those grounds is kept for that purpose only.
Deletion is not reversible and it is not the same as cancelling. Cancelling a subscription leaves your books intact and readable, as the first paragraph of this section and our Terms of Service describe. If what you want is to stop paying and keep your records, cancel; ask for deletion only when you want the records gone. Export anything you need first — every report exports, and the API is available to you.
Product usage events are kept in identifiable form for up to 90 days, after which only aggregate statistics remain.
Aggregate statistics — counts that identify nobody, such as how many organizations were active on a given day — are kept indefinitely, because they are how we tell whether the product is getting better. Any figure attached to a particular organization is deleted along with that organization.
8. Security.
We use industry-standard measures appropriate to financial data, including encryption in transit (TLS) and at rest, encryption of third-party access tokens under separately managed keys, role-based access controls within each organization, optional two-factor authentication, device-level session revocation, and an immutable audit trail. On iOS and Android, sign-in tokens are held in the operating system’s keychain, and you can additionally lock the application behind Face ID, Touch ID or your device’s biometric unlock — a check the operating system performs and reports back only as a yes or a no, described in section 2.
No system is perfectly secure. If a breach affects your personal information we will notify you and any regulator without undue delay, and in any case within the time required by applicable law.
9. Your rights.
Depending on where you live, you may have the right to: access the personal information we hold about you; correct it; delete it; restrict or object to processing; receive it in a portable format; withdraw consent; and not be discriminated against for exercising these rights.
Much of this you can do yourself: every report exports, and the API the applications are built on is available to you, so there is no export we can perform that you cannot. You can switch product usage collection off for your account in the application’s settings, on any platform, which is how to exercise the right to object to it. Deletion has its own route, described under “Deleting your account” in section 7. For anything else, write to privacy@summely.com and we will respond within the period required by law (generally 30 days). We may need to verify your identity first.
California residents. We do not sell personal information or share it for cross-context behavioural advertising, and we have not done so in the preceding 12 months. You may exercise your rights to know, delete, correct and limit as described above, and may use an authorized agent.
UK and EEA residents. You may lodge a complaint with your supervisory authority, including the UK Information Commissioner’s Office.
10. Customer Data and our role.
Where your books contain personal information about your customers, employees or contacts, you are the controller of that information and we act as your processor, handling it only on your documented instructions. Our Terms of Service set out those instructions; if you require a separate Data Processing Agreement, write to us and we will provide one.
11. Children.
The Services are for business use and are not directed to anyone under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, write to us and we will delete it.
12. Changes.
We will post any change here and update the date above. If a change is material we will give you notice by email or in the application before it takes effect.
13. Contact.
Privacy questions: privacy@summely.com. Anything else: hello@summely.com.