Privacy Policy
Privacy Policy for Ratio° and its financial workspace, upload tools, and AI features.
Overview
Last updated:
This policy applies to the Ratio website, product pages, software services, and account workflow unless a separate agreement says otherwise.
Scope and definitions
This policy applies to the Ratio° website and product services at www.getratio.xyz, including the web app, onboarding, dashboards, imports, reporting, and AI-assisted workflow features.
In this policy, “Ratio” means the product named on this site. “Customer data” means information that your team uploads or configures in Ratio to run your financial workspace (for example transactions, statements, forecasts, and notes).
Some financial operating metrics and reporting data are business information rather than personal information, but Ratio still treats them as confidential customer data.
Ratio currently references an Australian operator in this page where implemented, but we do not publish verified legal-entity details in this policy text yet. If you need the legal name, ABN, or registered address for contracting or legal review, please contact support.
What information Ratio handles
The following data types are used in Ratio’s current implementation. This is intentionally limited to capabilities actually present in the product.
- account and profile information for invited team members (name, email, role, authentication identifiers)
- tenant and organisation details (team structure, workspace names, business profile fields entered in app setup)
- bank and card statement data uploaded as CSV/XLSX files
- investment and superannuation statements uploaded as CSV/PDF/XLSX (including holdings, cash snapshots, and activities)
- transaction records, balances, categories, merchant names, recurring schedules, reports, summaries, and tags
- payment/subscription metadata needed to manage billing and plan access
- support messages, bug reports, and feedback submitted by users
- usage metadata (events, diagnostics, and security logs) from app operation and monitoring
- AI prompts, selected workspace context, and generated outputs stored for continuity
How information is collected
We collect information through direct input, upload workflows, and authenticated product operations.
- Directly from users and workspace administrators when creating accounts, managing members, creating accounts, or adding notes and assumptions
- From uploaded source files during the import preview and confirm flow (CSV, XLSX, and supported PDF statements)
- From billing events emitted by Stripe during checkout, subscription, cancellation, or payment lifecycle events
- From AI requests generated in-app, where prompts and selected context are used to answer questions
- Automatically through log and monitoring tooling for operational safety, rate limiting, and reliability
Customer data roles and responsibilities
For account security, communication, support, billing operations, and platform management, Ratio is the data controller.
For your financial ledger, imports, and AI analysis that reflect your business records, Ratio processes that information on your instructions as a processor for your workspace operations.
- You are responsible for ensuring your team has rights to submit or use any financial or customer/supplier information
- You are responsible for your own notices and consents that relate to your business’s privacy obligations
- You are responsible for member access, role assignments, and removal of team access when people leave
- If a Data Processing Addendum exists for your contract, it supersedes or supplements this policy; if it is not currently in place, that is a required legal deliverable for enterprise onboarding
Integrations and authorisation
Ratio currently processes most financial input via file upload and manual mapping, not live banking APIs.
- Banking and card imports are supported through institution-specific file adapters (for example AMEX, Commonwealth Bank, HSBC, Xero)
- Investment data imports are supported from provider-specific statement files (for example CommSec, Stake, Hostplus)
- Authentication can be provided through sign-in providers configured in the auth system, which may pass identity identifiers and profile details from those providers
- In this product version, integrations are generally read/ingest only via uploads; write-back to external accounting or banking systems is not the primary flow
- You can stop using an integration workflow in your workspace by disconnecting or uninviting users and removing the associated upload flow; imported records remain according to retention rules below
Why we use information
Ratio uses information for these specific purposes:
- secure authentication, session management, and account administration
- processing uploaded statements into a usable workspace ledger
- producing summaries, reports, forecasts, and financial views
- serving AI-assisted insights and retrieving your selected workspace data
- managing billing, trial flow, entitlements, and subscription access
- support triage, incident handling, and abuse prevention
- maintaining operational logs and security/audit controls
- compliance with legal and tax/accounting record requirements
AI processing and automated decisions
Ratio’s AI features are powered by an AI model provider currently configured as OpenAI. AI tools receive the user prompt, the selected workspace context (such as account and period selections), and tool results built from your uploaded financial records.
- Prompts and AI output text are persisted with your conversation context in database records so that chat continuity is preserved
- Ratio currently resolves AI responses through database lookups and summarisation, not through a long-term vector search index
- Prompt, output, and tool-call metadata may be processed in the provider’s infrastructure where model inference takes place
- Support and reliability teams can review conversation records for quality and safety where needed
- AI outputs are advisory; you should review any recommendation before making material financial decisions
- If a materially automated output influences a significant outcome, you can request manual review and additional confirmation before action
As the Australian automated-decision transparency regime comes into effect from 10 December 2026, important decisions should remain human-reviewed and clearly attributable.
We only share information with service providers required to operate the product, to the extent needed for the function described.
- Clerk for authentication and account/session identity orchestration
- Neon-hosted PostgreSQL for primary storage of records and logs
- OpenAI for chat model inference and AI runtime
- Stripe for checkout, invoicing, entitlements, and subscription lifecycle processing
- PostHog for product analytics and optional session recording where enabled in environment configuration
- Resend for transactional email delivery in production
- MailHog in local development environments for email testing (no external production routing)
- Sentry for operational error monitoring and exception reporting
- platform and hosting infrastructure for delivery of the web app and API endpoints
We do not sell your data. We only use processors where the service is required to deliver the function above.
Overseas processing and safeguards
Some processing occurs outside Australia where vendor infrastructure or API endpoints are located.
- PostHog requests can be sent to configured hosts, including US/EU-hosted endpoints (for example us.i.posthog.com, eu.i.posthog.com)
- AI and email providers are processed through their cloud services, governed by their data handling and contract terms
- We choose providers with contract and configuration controls that allow us to apply purpose limitation, access restrictions, and security controls
Retention, deletion, export and backups
Retention is based on operational, legal, and contractual needs. Where an exact period is not yet implemented in this policy, we treat that as a product requirement to define and document.
- account and profile records are retained while the workspace is active and then reviewed for retention requirements after closure
- imported customer financial records (transactions, statements, summaries, snapshots) are retained to preserve ledger continuity and reviewability
- AI conversations and outputs are retained to support continuity, quality, safety, and dispute resolution
- Stripe customer/subscription records are retained to meet billing and tax recordkeeping requirements
- bug reports, support notes, and operational logs are retained as needed for service reliability and legal defensibility
- deleted workspace records follow workspace controls and then backup retention policy
- backups are kept in provider-managed retention windows and may outlive immediate deletion requests for recovery and security purposes
- for export or account closure requests, we process a manual support request to provide a data export and to confirm scope of deletion
- any legal hold, dispute, fraud, or regulator request can require selective retention beyond the ordinary period
Security and breach handling
Ratio applies layered safeguards appropriate to the sensitivity of financial information.
- authentication controls, session boundaries, and tenant-scoped authorization
- least-privilege internal access patterns, role checks, and audit logging around write operations
- encrypted transport and provider-level database protections from hosted infrastructure
- operational monitoring, error capture, and incident alerting
- periodic review of external processor settings, API keys, and access permissions
If an incident occurs that meets applicable notification thresholds, Ratio will address and escalate it according to legal obligations and regulatory guidance, including where individuals or regulators need to be notified.
We use operational cookies and browser storage needed for authenticated sessions and app behaviour. We also support analytics events where enabled in production.
- event names and metadata are filtered to reduce sensitive field capture (for example masked URL and sensitive property filtering)
- session replay settings are enabled by provider config; masking is applied to reduce personal visibility risk
- support and system emails include unsubscribe handling where communication preferences apply
- if you prefer, update your marketing preferences by contacting support or using account communication controls where available
Children and age
Ratio is designed for business users and is intended for use by adults and authorised staff in a business context. If we become aware that a child has provided information improperly, we will take reasonable steps to address it.
Privacy rights and support process
Depending on the jurisdiction and role, you can request:
- access to the personal and business data linked to your account
- correction of inaccurate records
- deletion of account access or data where legally permitted
- data export (provided with scope confirmation)
- marketing-preference updates and direct consent withdrawal
- information on how your account is authorised and configured
For customer data that belongs operationally to your organisation, we may direct some requests back to your tenant owner where the individual belongs to their employer’s system of records.
Complaints
Privacy concerns can be sent in writing to support. Our process is to acknowledge receipt, investigate, and provide a response in a reasonable timeframe, and generally within 30 days where practical.
- include your account details, the data involved, and the outcome you are seeking
- include date range and supporting details where a specific incident is alleged
- unresolved matters may be referred to the Office of the Australian Information Commissioner (OAIC)
OAIC guidance and complaint resources are available at OAIC privacy complaints.
Changes to this policy
We may update this policy when service capabilities, legal requirements, or processing practices change. Material updates are reflected by updating the Last Updated date and, where practical, by direct communication.
Contact
For privacy questions, access requests, corrections, deletion requests, complaint escalations, or integration-related questions, email support@getratio.xyz.